全文検索:
- 01 Linux ipsec Server
- pp ==== 一番下に下記を追加 <code|/etc/ppp/options.xl2tpd> netmask 255.255.255.0 persist require-mschap-v2 logfi... sctl.conf ==== 一番下に下記を追加 <code|/etc/sysctl.conf> net.core.xfrm_larval_drop = 1 net.ipv4.conf.all.send_redirects = 0 net.ipv4.conf.default.send_redirects = 0 net.ipv4.conf.eth0.send_redi
- 07 Wireguard Client設定
- ps://www.wireguard.com/install/]] {{:01_linux:10_network:pasted:20240316-043457.png}} ===== 2.インストール... ard-installer.exeをダブルクリックでインストール {{:01_linux:10_network:pasted:20240316-043930.png}} {{:01_linux:10_network:pasted:20240316-043849.png|}} ===== 3.タスクバーからWireGuardをクリック ===== {{:01_linux:10_network:pasted:20240605-050820.png}} ===== 4.ファイルから
- 03 Strongswan IKEv2 with PSK
- load </code> ===== 3.forward ===== sysctl -w net.ipv4.ip_forward=1 ===== 4.ipsec.conf(tokyo) ===... modp2048 conn osaka leftid=@tokyo leftsubnet=10.10.0.0/16 rightid=@osaka right=200.200.0.200 rightsubnet=172.16.0.0/24 auto=start </code> ===== 5.ips... modp2048 conn tokyo leftid=@osaka leftsubnet=172.16.0.0/24 rightid=@tokyo right=100.10
- 05 KVM Multi-Queue
- ide/sect-virtualization_tuning_optimization_guide-networking-multi-queue_virtio-net]] ===== xml修正 ===== <color #ed1c24><driver name='vhost' queues='N'/></color> この部分追加 <code> <interface type='network'> <source network='default'/> <model type='virtio'/> <driver name='vhost' queues
- 02 Linux IPsec Client
- .16.0.0/12 nat_traversal=yes protostack=netkey oe=no conn L2TP-PSK authby=secret ... R_UP> mtu 65536 qdisc noqueue state UNKNOWN inet 127.0.0.1/8 scope host lo 2: eth0: <BROADCAST,MUL... mtu 1500 qdisc pfifo_fast state UP qlen 1000 inet XXX.XXX.XXX.XXX/24 brd 211.125.67.255 scope globa... u 1410 qdisc pfifo_fast state UNKNOWN qlen 3 inet 192.168.1.128 peer 192.168.1.99/32 scope global p
- 04 Strongswan IKEv2 EAP
- 6-sha256-modp2048 conn IPSec-IKEv2-EAP leftsubnet=0.0.0.0/0 leftid=vpn.hogehoge.com left=%a... -reload </code> ==== 5.forward ==== sysctl -w net.ipv4.ip_forward=1 ===== Windows側 ===== ==== VPN接続作成 ==== {{:01_linux:10_network:2022-03-23_19h10_19.png?400|}} ==== PowerSh... rts/cert.pem' failed: Permission denied </code> === 対応 === setenforce 0 {{tag>network strongswan}}
- 06 WireGuard
- oqueue state UNKNOWN group default qlen 1000 inet 10.0.0.1/24 scope global wg0 valid_lft for... ]] をファイルに書いて、WireGuardから読み込むだけです。 {{:01_linux:10_network:pasted:20240215-032251.png}} {{:01_linux:10_network:pasted:20240215-032627.png}} ===== 8.Linuxクラ... ddddddddddd= preshared key: (hidden) allowed ips: 10.0.1.2/32 </code> {{tag>network vpn Wireguard}}