Estou usando ADSL nos dois pontos com ipfixo. a configura��o do ipsec.conf segue abaixo:
# /etc/ipsec.conf - FreeS/WAN IPsec configuration file
# More elaborate and more varied sample configurations can be found # in FreeS/WAN's doc/examples file, and in the HTML documentation.
# basic configuration config setup # THIS SETTING MUST BE CORRECT or almost nothing will work; # %defaultroute is okay for most simple cases. interfaces=%defaultroute # Debug-logging controls: "none" for (almost) none, "all" for lots. klipsdebug=none plutodebug=none # Use auto= parameters in conn descriptions to control startup actions. plutoload=%search plutostart=%search # Close down old connection when new one using same ID shows up. uniqueids=yes
# defaults for subsequent connection descriptions # (mostly to fix internal defaults which, in retrospect, were badly chosen) conn %default keyingtries=0 disablearrivalcheck=no esp=3des-md5-96 authby=rsasig leftrsasigkey=%dns rightrsasigkey=%dns
# connection description for (experimental!) opportunistic encryption
# (requires KEY record in your DNS reverse map; see doc/opportunism.howto)
conn me-to-anyone
left=%defaultroute
right=%opportunistic
keylife=8h
rekey=no
# uncomment this next line to enable it
#auto=route# sample VPN connection
conn vpn
# Left security gateway, subnet behind it, next hop toward right.
left=200.xxx.xxx.xxx (modem adsl)
leftsubnet=192.168.1.0/24
leftnexthop=200.xxx.xxx.xxx
leftrsasigkey=xxxxxxxx
# Right security gateway, subnet behind it, next hop toward left.
right= 200.xxx.xxx.xxx (modem adsl)
rightsubnet=192.168.0.0/24
rightnexthop=200.xxx.xxx.xxx (depois do modem adsl)
rightrsasigkey=xxxxxx
# To authorize this connection, but not actually start it, at startup,
# uncomment this.
auto=startDistribuicao
Conectiva 8
Obrigado,
-- Claudio Santos
Aben�oado Sejam os Perssimistas, que fizeram Backup.
Auto: Desconhecido.
--------------------------------------------------------------------------- Esta lista � patrocinada pela Conectiva S.A. Visite http://www.conectiva.com.br
Arquivo: http://bazar2.conectiva.com.br/mailman/listinfo/linux-br Regras de utiliza��o da lista: http://linux-br.conectiva.com.br FAQ: http://www.zago.eti.br/menu.html
