{"id":94527,"date":"2020-09-18T07:42:25","date_gmt":"2020-09-18T05:42:25","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/ipsec-tunnel-mezhdu-strongswan-za-nat-i-vmware-nsx-edge"},"modified":"2020-09-18T07:42:25","modified_gmt":"2020-09-18T05:42:25","slug":"ipsec-tunnel-mezhdu-strongswan-za-nat-i-vmware-nsx-edge","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/ipsec-tunnel-mezhdu-strongswan-za-nat-i-vmware-nsx-edge","title":{"rendered":"IPSec-Tunnel zwischen Strongswan hinter NAT und VMWare NSX Edge","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Aufgrund verschiedener Gr\u00fcnde war es notwendig, eine VPN-Verbindung zwischen dem Netzwerk in VMWare Cloud Director und einer separaten Ubuntu-Maschine in der Cloud einzurichten. Diese Notiz erhebt nicht den Anspruch auf eine vollst\u00e4ndige Beschreibung, sondern ist lediglich ein kleines How-To.<\/p>\n<p><img decoding=\"async\" alt=\"IPSec-Tunnel zwischen Strongswan hinter NAT und VMWare NSX Edge\" src=\"\/wp-content\/uploads\/2020\/09\/0290844ea4fa5a1575d74020299e6747.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nEs fand sich nur ein einziger Artikel aus dem Jahr 2015 zu diesem Thema \u201e<noindex><a rel=\"nofollow\" href=\"http:\/\/www.routereflector.com\/2015\/03\/site-to-site-ipsec-vpn-between-nsx-edge-and-linux-strongswan\/\">Site-to-Site IPSEC VPN zwischen NSX Edge und Linux strongSwan<\/a><\/noindex>\u00bb.<\/p>\n<p>Leider konnte ich ihn nicht direkt verwenden, da ich eine sicherere Verschl\u00fcsselung ohne selbstsigniertes Zertifikat wollte und die beschriebene Konfiguration hinter NAT nicht funktionieren w\u00fcrde.<\/p>\n<p>Deshalb musste ich mich hinsetzen und die Dokumentation durchforsten.<\/p>\n<p>Ich habe als Grundlage eine bereits lange von mir verwendete Konfiguration genommen, die es erm\u00f6glicht, sich praktisch von jedem Betriebssystem aus zu verbinden, und habe nur einen Abschnitt hinzugef\u00fcgt, der die Verbindung zum NSX Edge erm\u00f6glicht.<\/p>\n<p>Da die Installation und die umfassende Konfiguration des Strongswan-Servers den Rahmen dieser Notiz sprengen, erlaube ich mir, auf <noindex><a rel=\"nofollow\" href=\"https:\/\/eboyko.ru\/blog\/posts\/strongswan-ipsec-vpn-late-2017\">ein gutes Material zu diesem Thema Bezug zu nehmen<\/a><\/noindex>.<\/p>\n<p>Kommen wir also direkt zu den Einstellungen.<\/p>\n<p>Das Schema der Verbindung wird wie folgt aussehen:<\/p>\n<p><img decoding=\"async\" alt=\"IPSec-Tunnel zwischen Strongswan hinter NAT und VMWare NSX Edge\" src=\"\/wp-content\/uploads\/2020\/09\/8c3d3413467e8c0e974e41090a0e146d.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<pre><code class=\"plaintext\">von VMWare die externe Adresse 33.33.33.33 und das interne Netzwerk 192.168.1.0\/24\nvon Linux die externe Adresse 22.22.22.22 und das interne Netzwerk 10.10.10.0\/24\nzudem ist ein Let's Encrypt-Zertifikat f\u00fcr die Adresse vpn.linux.ext erforderlich\nPSK von beiden Seiten: ChangeMeNow!<\/code><\/pre>\n<p>\nKonfiguration auf der NSX Edge-Seite:<\/p>\n<p>                        <b class=\"spoiler_title\">Text<\/b><\/p>\n<pre><code class=\"plaintext\">Enabled: yes\nEnable perfect forward secrecy (PFS): yes\nName: VPN_strongswan (beliebig, nach Ihrer Wahl)\nLocal Id: 33.33.33.33\nLocal Endpoint: 33.33.33.33\nLocal Subnets: 192.168.1.0\/24\nPeer Id: vpn.linux.ext\nPeer Endpoint: 22.22.22.22\nPeer Subnets: 10.10.10.0\/24\nEncryption Algorithm: AES256\nAuthentication: PSK\nPre-Shared Key: ChangeMeNow!\nDiffie-Hellman Group: 14 (2048 Bit \u2014 akzeptabler Kompromiss zwischen Geschwindigkeit und Sicherheit. Aber wenn Sie m\u00f6chten, k\u00f6nnen Sie auch mehr einstellen)\nDigest Algorithm: SHA256\nIKE Option: IKEv2\nIKE Responder Only: no\nSession Type: Policy Based Session<\/code><\/pre>\n<p><\/p>\n<p>                        <b class=\"spoiler_title\">Screenshots<\/b><br \/>\n                        <img decoding=\"async\" alt=\"IPSec-Tunnel zwischen Strongswan hinter NAT und VMWare NSX Edge\" src=\"\/wp-content\/uploads\/2020\/09\/f6ef2a7a96b65fb82b26ad89d1652c8c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<img decoding=\"async\" alt=\"IPSec-Tunnel zwischen Strongswan hinter NAT und VMWare NSX Edge\" src=\"\/wp-content\/uploads\/2020\/09\/248225ee13fe6f063b14bfac18af0162.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n                    <br \/>\nKonfiguration auf der Strongswan-Seite:<\/p>\n<p>                        <b class=\"spoiler_title\">ipsec.conf<\/b><\/p>\n<pre><code class=\"plaintext\"># \/etc\/ipsec.conf\nconfig setup\n\nconn %default\n\tdpdaction=clear\n\tdpddelay=35s\n\tdpdtimeout=300s\n\n\tfragmentation=yes\n\trekey=no\n\n\tike=aes256gcm16-aes256gcm12-aes128gcm16-aes128gcm12-sha256-sha1-modp2048-modp4096-modp1024,aes256-aes128-sha256-sha1-modp2048-modp4096-modp1024,3des-sha1-modp1024!\n\tesp=aes128gcm12-aes128gcm16-aes256gcm12-aes256gcm16-modp2048-modp4096-modp1024,aes128-aes256-sha1-sha256-modp2048-modp4096-modp1024,aes128-sha1-modp2048,aes128-sha1-modp1024,3des-sha1-modp1024,aes128-aes256-sha1-sha256,aes128-sha1,3des-sha1!\n\n\tleft=%any\n\tleftsubnet=10.10.10.0\/24\n        leftcert=certificate.pem\n\tleftfirewall=yes\n\tleftsendcert=always\n\n\tright=%any\n\trightsourceip=192.168.1.0\/24\n\trightdns=77.88.8.8,8.8.4.4\n\n\teap_identity=%identity\n\n# IKEv2\nconn IPSec-IKEv2\n\tkeyexchange=ikev2\n\tauto=add\n\n# BlackBerry, Windows, Android\nconn IPSec-IKEv2-EAP\n\talso=&quot;IPSec-IKEv2&quot;\n\trightauth=eap-mschapv2\n\n# macOS, iOS\nconn IKEv2-MSCHAPv2-Apple\n\talso=&quot;IPSec-IKEv2&quot;\n\trightauth=eap-mschapv2\n\tleftid=vpn.linux.ext\n\n# Android IPsec Hybrid RSA\nconn IKEv1-Xauth\n\tkeyexchange=ikev1\n\trightauth=xauth\n\tauto=add\n\n# VMWare IPSec VPN\nconn linux-nsx-psk\n\tauthby=secret\n\tauto=start\n\tleftid=vpn.linux.ext\n\tleft=10.10.10.10\n\tleftsubnet=10.10.10.0\/24\n\trightid=33.33.33.33\n\tright=33.33.33.33\n\trightsubnet=192.168.1.0\/24\n\tikelifetime=28800\n\tkeyexchange=ikev2\n\tlifebytes=0\n\tlifepackets=0\n\tlifetime=1h<\/code><\/pre>\n<p><\/p>\n<p>                        <b class=\"spoiler_title\">ipsec.secret<\/b><\/p>\n<pre><code class=\"plaintext\"># \/etc\/ipsec.secrets\n: RSA privkey.pem\n\n# Create VPN users accounts\n# \u0412\u041d\u0418\u041c\u0410\u041d\u0418\u0415! \u041f\u043e\u0441\u043b\u0435 \u043b\u043e\u0433\u0438\u043d\u0430 \u0441\u043d\u0430\u0447\u0430\u043b\u0430 \u043f\u0440\u043e\u0431\u0435\u043b, \u043f\u043e\u0442\u043e\u043c \u0434\u0432\u043e\u0435\u0442\u043e\u0447\u0438\u0435.\n\nuser1 : EAP &quot;stongPass1&quot;\nuser2 : EAP &quot;stongPass2&quot;\n%any 33.33.33.33 : PSK &quot;ChangeMeNow!&quot;<\/code><\/pre>\n<p>\nNach diesem Schritt reicht es, die Konfiguration zu \u00fcberpr\u00fcfen, die Verbindung zu starten und sicherzustellen, dass sie hergestellt wurde:<\/p>\n<pre><code class=\"plaintext\">ipsec update\nipsec rereadsecrets\nipsec up linux-nsx-psk\nipsec status<\/code><\/pre>\n<p>\nIch hoffe, diese kleine Notiz erweist sich als n\u00fctzlich und spart jemandem ein paar Stunden.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/519410\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0441\u0438\u043b\u0443 \u0440\u044f\u0434\u0430 \u043f\u0440\u0438\u0447\u0438\u043d, \u043f\u043e\u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043b\u043e\u0441\u044c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c VPN-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 \u0441\u0435\u0442\u044c\u044e \u0432 VMWare Cloud Director \u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u043e\u0439 Ubuntu \u0432 \u043e\u0431\u043b\u0430\u043a\u0435. \u0417\u0430\u043c\u0435\u0442\u043a\u0430 \u043d\u0435 \u043f\u0440\u0435\u0442\u0435\u043d\u0434\u0443\u0435\u0442 \u043d\u0430 \u043f\u043e\u043b\u043d\u043e\u0446\u0435\u043d\u043d\u043e\u0435 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435, \u044d\u0442\u043e \u043f\u0440\u043e\u0441\u0442\u043e \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0435 howto. \u0412 \u0441\u0435\u0442\u0438 \u043d\u0430\u0448\u043b\u0430\u0441\u044c \u0435\u0434\u0438\u043d\u0441\u0442\u0432\u0435\u043d\u043d\u0430\u044f \u0441\u0442\u0430\u0442\u044c\u044f 2015 \u0433\u043e\u0434\u0430 \u043d\u0430 \u044d\u0442\u0443 \u0442\u0435\u043c\u0443 \u00abSite to Site IPSEC VPN between NSX Edge and Linux strongSwan\u00bb. \u041a \u0441\u043e\u0436\u0430\u043b\u0435\u043d\u0438\u044e, \u043d\u0430\u043f\u0440\u044f\u043c\u0443\u044e \u0435\u0451 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":94528,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-94527","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0441\u0438\u043b\u0443 \u0440\u044f\u0434\u0430 \u043f\u0440\u0438\u0447\u0438\u043d, \u043f\u043e\u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043b\u043e\u0441\u044c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c VPN-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 \u0441\u0435\u0442\u044c\u044e \u0432 VMWare Cloud Director \u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u043e\u0439 Ubuntu \u0432 \u043e\u0431\u043b\u0430\u043a\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/ipsec-tunnel-mezhdu-strongswan-za-nat-i-vmware-nsx-edge\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47IPSec \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u043c\u0435\u0436\u0434\u0443 Strongswan \u0437\u0430 NAT \u0438 VMWare NSX Edge | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0441\u0438\u043b\u0443 \u0440\u044f\u0434\u0430 \u043f\u0440\u0438\u0447\u0438\u043d, \u043f\u043e\u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043b\u043e\u0441\u044c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c VPN-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 \u0441\u0435\u0442\u044c\u044e \u0432 VMWare Cloud Director \u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u043e\u0439 Ubuntu \u0432 \u043e\u0431\u043b\u0430\u043a\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/ipsec-tunnel-mezhdu-strongswan-za-nat-i-vmware-nsx-edge\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-18T05:42:25+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-18T05:42:25+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47IPSec-Tunnel zwischen Strongswan hinter NAT und VMWare NSX Edge | ProHoster","description":"Aufgrund verschiedener Gr\u00fcnde war es notwendig, eine VPN-Verbindung zwischen dem Netzwerk in VMWare Cloud Director und einer separaten Ubuntu-Maschine in der Cloud einzurichten.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/ipsec-tunnel-mezhdu-strongswan-za-nat-i-vmware-nsx-edge","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47IPSec \u0442\u0443\u043d\u043d\u0435\u043b\u044c \u043c\u0435\u0436\u0434\u0443 Strongswan \u0437\u0430 NAT \u0438 VMWare NSX Edge | ProHoster","og:description":"\u0412 \u0441\u0438\u043b\u0443 \u0440\u044f\u0434\u0430 \u043f\u0440\u0438\u0447\u0438\u043d, \u043f\u043e\u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043b\u043e\u0441\u044c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c VPN-\u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u043c\u0435\u0436\u0434\u0443 \u0441\u0435\u0442\u044c\u044e \u0432 VMWare Cloud Director \u0438 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0439 \u043c\u0430\u0448\u0438\u043d\u043e\u0439 Ubuntu \u0432 \u043e\u0431\u043b\u0430\u043a\u0435.","og:url":"https:\/\/prohoster.info\/de\/blog\/administrirovanie\/ipsec-tunnel-mezhdu-strongswan-za-nat-i-vmware-nsx-edge","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-18T05:42:25+00:00","article:modified_time":"2020-09-18T05:42:25+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"94527","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:25:23","updated":"2022-09-27 15:07:33","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/94527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=94527"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/94527\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/94528"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=94527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=94527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=94527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}