Projet

Général

Profil

Télécharger (46,5 ko) Statistiques
| Branche: | Tag: | Révision:

univnautes / etc / inc / vpn.inc @ 21cd92ac

# Date Auteur Commentaire
21cd92ac 12 novembre 2014 21:41 Ermal

Oops wrong choice the checkbox is only for javascript

c9b70c0a 12 novembre 2014 21:41 Ermal

Remove redundant code and check for dpd_enable checkbox to be set

63ba4729 11 novembre 2014 20:57 Ermal

Use leftcert for more options on IPsec authentication

80be089f 07 novembre 2014 19:28 Ermal

Fixes #3995. Do not set rightsourceip on site-to-site VPNs but only on mobile users ones otherwise nothing works.

e82a1d11 07 novembre 2014 14:14 Ermal

Reload also the configuration not only the secrets before trying to apply existing configuration. Ticket #3981

d3d23754 07 novembre 2014 05:03 Chris Buechler

fix text, PPPoE Server, not VPN

dbb95f38 06 novembre 2014 19:49 Chris Buechler

set install_routes=no for charon to avoid the issues noted in ticket

531686c1 05 novembre 2014 02:09 Chris Buechler

use tabs rather than spaces, as most of this already did.

32171e59 05 novembre 2014 01:18 Chris Buechler

fix invalid ipsec.conf

0810a719 04 novembre 2014 21:21 Ermal

Restore 3 values back on NAT-T settings Just Enable now its Auto as per strongswan default. and off disabled mobike. Ticket #3979

8cb7d3e3 01 novembre 2014 23:41 Ermal

Properly configure NAT Tranversal setting.

6af85718 01 novembre 2014 20:54 Ermal

Remove debugging code

737b18f2 30 octobre 2014 21:35 Ermal

Allow accept_unencrypted_mainmode_messages to be enabled if needed

23ed5b78 24 octobre 2014 19:18 Ermal

Enable unity plugin as per request from https://forum.pfsense.org/index.php?topic=79737.msg452808#msg452808

7e7f07ae 12 septembre 2014 21:17 Ermal

This really does not need the =

3d77ec5d 12 septembre 2014 19:49 Ermal

Ooops restore this

3b9ef0ef 12 septembre 2014 19:40 Ermal

Inverse the sense of the toggles to avoid configuration upgrades

16c02722 12 septembre 2014 19:34 Ermal

Actually use the new toggles

fa4e059e 12 septembre 2014 19:22 Ermal

Provide a first implementation of EAP-TLS authentication with IKEv2. It is a start and might not work on all cases

e373e4cd 12 septembre 2014 17:13 Ermal

Make this work properly and not throw out errors.

3b977eff 10 septembre 2014 18:38 Ermal

Put some tuning on number of half open connection possible in one time.

816672f1 10 septembre 2014 18:36 Ermal

Provide some parallellizm on the IKESA lookups for heavy loaded boxes.

c966c7ec 10 septembre 2014 00:43 Ermal

Actually roll this back since it was a testing glitch

38f5ac9b 09 septembre 2014 21:38 Ermal

Correct generating loglevels for startup through ipsec.conf

76fa9adb 09 septembre 2014 17:28 Ermal

Blah unconditionally set rightsourceip per https://forum.pfsense.org/index.php?topic=80300.0 Until pools can be supported properly.

5bce82b4 18 août 2014 22:13 Ermal

Correct processing and assignment on ikeid variable so it does the right thing

c650b2f7 18 août 2014 21:18 Ermal

Allow HASH algorithms to be empty for phase2 in case the encryption one is AES-GCM

ae170e96 18 août 2014 12:25 Ermal

Do not allow duplicate subnet entries on left|rightsubnet specification since it will blackhole all traffic to that subnet when connection is setup as route

5d37d515 18 août 2014 12:18 Ermal

Do not accept proposal out of that configured even for IKEv2 even though there is no possibility in the GUI to set more than one proposal for Phase1 so far.

3b68ec45 18 août 2014 08:52 Ermal

Restore behaviour as with racoon to trigger tunnel startup from traffic that needs to go into the tunnel. Even related to Ticket #3806.

154298f1 14 août 2014 07:14 Chris Buechler

rightsourceip must be used with PSK+Xauth.

7f1b720f 14 août 2014 06:59 Chris Buechler

This is required for PSK+Xauth. I'll commit that clarification in a bit.
Revert "Revert "Fix assignment of tunnel IPs to mobile clients.""

This reverts commit 23ba08fc940b711f3b44551199890dc8e28a63b6.

23ba08fc 13 août 2014 11:52 Ermal

Revert "Fix assignment of tunnel IPs to mobile clients."
This normally is not needed since the attr plugin deals with all this.

This reverts commit 00311d6a841c0f6fc162ea11da06569f10220f5e.

1c70bdff 12 août 2014 23:11 Ermal

Actually disable this plugin for now. It was not really needed for solving the issues with IKEv1

00311d6a 11 août 2014 12:19 Chris Buechler

Fix assignment of tunnel IPs to mobile clients.

dc63467f 09 août 2014 00:09 Matt Smith

Fix #3798 - 'IPsec phase 2 pinghost is not used if the source IP should be a virtual IP address'

bf8aab82 08 août 2014 15:40 Ermal

Correct this so the dpdaction is created properly as restart

9f6a5b50 07 août 2014 22:53 Ermal

Do a reload on the cofniguration which is better than update. Also let the keyingtries to 3 rather than forever to avoid problems on recovery.

0b5fc1d1 07 août 2014 20:53 Ermal

Change the logic of the vpn config generation to make connectivity more stable especially ipsec. Also for IKEv1 just generate the policies and only on traffic start them.

b31a2c76 07 août 2014 17:52 Ermal

Move the rekey to yes always to avoid issues.

f088b8cd 01 août 2014 22:52 Ermal

Do not try to rekey for IKEv1.

9b915686 01 août 2014 22:39 Ermal

Use a uniqid() to track phase2 entries to avoid confustion and various mistakes when modifying and editing them.

fa0a1411 30 juillet 2014 17:57 Matt Smith

Fix for #3785 - 'strongswan config being generated with ike SA lifetime set to value of ipsec SA lifetime'

9280a998 29 juillet 2014 17:59 Matt Smith

Fix #3781 - 'strongswan dpdtimeout value not generated correctly'

1f2acda1 23 juillet 2014 18:19 Matt Smith

Fix for bug 3769

971de1f9 08 juillet 2014 01:06 Renato Botelho

Convert almost all /sbin/sysctl calls to php functions

649b6b85 24 juin 2014 20:09 Ermal

Actually use ph1ent ikeid here otherwise will duplicate ids here.

75786d2a 20 mai 2014 17:41 jim-p

Correct variable test here, too. Ticket #3662

8f5ac1a1 19 mai 2014 22:22 jim-p

Fix test (variable is a checkbox, not an array/string). Fixes #3662

aeb0f546 19 mai 2014 22:19 jim-p

Use correct variable name here.

29629bca 17 mai 2014 17:32 Ermal

Make some fixes related to Ticket #3662. Its mostly cleanup.

5ed13df0 16 mai 2014 21:22 Ermal

Actually make this correct

3060dcd4 16 mai 2014 20:43 Ermal

Use subnet rather than address/netmask to allow multiple clients to behave properly

95589abd 15 mai 2014 19:34 jim-p

Move duplicated code into a function; Include local ID on mobile tunnel key line in ipsec.secrets.

4767004f 15 mai 2014 16:17 Ermal

Use the right specification for ahnding over the subnet to mobile clients

7a1f391a 15 mai 2014 16:03 Ermal

Do not specify the rightid in mobile tunnels since it makes things not work

6586b30f 15 mai 2014 15:50 Ermal

Oops this was moved accidentally

b4ad5b1c 15 mai 2014 15:39 Ermal

Correct sense of match and move the code up to since it makes more sense

abd3c8f4 15 mai 2014 15:29 Ermal

Actually this should be rightauth2 since they should send the extra infor to be validated

466a5a81 09 mai 2014 22:13 Ermal

Allow to use PSK+agressive mode since user should have the choice even though it poses security risks

9879f03a 09 mai 2014 21:47 Ermal

This slipped in wrongly

f1bede03 09 mai 2014 21:41 Ermal

Allow a key to specified for all users as for exmpale when connecting from Apple iOS

9abaa8f7 09 mai 2014 19:52 Ermal

Pass the loglevels on the config rather than execing commands to specify these loglevels. This allows somethings to be properly logged as config logs

f9fb8d2b 09 mai 2014 17:40 Ermal

No need to have the ip let strongswan do it for us! Keeping still filterdns to properly evaluate dns behaviour here

484e6adc 09 mai 2014 17:31 Ermal

Strongswan does not need the quotes here

8d0a3abd 09 mai 2014 16:03 Ermal

Remove generate policy option since its not relevant with strongswan

6ae8b844 09 mai 2014 15:36 Ermal

Some adjustments to the code for logging

ad750d3b 28 avril 2014 22:05 Warren Baker

If unbound is configured then assign it for the vpn service

4a4fc162 28 avril 2014 15:02 Ermal

Another dir to be created

3ad5fd27 28 avril 2014 15:01 Ermal

Correct the definitions of certificate path to correct place to allow the daemon to start

9e5dfe47 28 avril 2014 14:44 Ermal

Update binaries used

b305f795 26 mars 2014 17:54 Ermal

Make this a global so no errors occur

e26e5e25 24 mars 2014 21:01 Ermal

Make this more usable by putting a delimiter in there

543c91ff 24 mars 2014 20:36 Ermal

Also configure log levels any time the daemon is restarted.

b7b3bc71 24 mars 2014 20:35 Ermal

Try to put the connection name in the logs for easy identification

8b4abd59 12 mars 2014 19:48 Ermal

More removal of racoon from referenced in sources

1dcb00bb 12 mars 2014 19:44 Ermal

Remove remeants of racoon

3eeac256 12 mars 2014 19:42 Ermal

Generate nat rules for ipsec when needed

63159749 06 mars 2014 22:59 Ermal

Better just use start here seems to be more reliable

d60eea55 06 mars 2014 21:38 Ermal

Correct the generation of the config for mobile tunnels as well

c6efc8fd 25 février 2014 11:10 Ermal

Push log changes for IPSec and fix generation of strongswan.conf and ipsec.secrets to be properly considered

7335fa53 25 février 2014 11:10 Ermal
  • Correct logging to syslog and proper file for ipsec from strongswan
  • Use proper commands to reload strongswan rather than just the daemon
ff3d516f 12 février 2014 15:05 Ermal

Be specific on the authentication method to use since xauth-eap will be active as well

ede14b23 12 février 2014 10:42 Ermal

Correct script path

6c576b27 12 février 2014 10:41 Ermal

Remove references to racoon and correct some handling of ipsec configuration

ecc37958 12 février 2014 10:36 Ermal

Remove copy paste leftover

91287d1f 12 février 2014 10:35 Ermal

If specified add authentication script configuration to strongswan.conf

496acde1 06 février 2014 12:49 Ermal

First swing at converting from racoon to StrongSWAN.
It allows to use existing configurations on xml to generate StrongSWAN configurations.
So its only IKEv1

  • Missing support for dynamic ips(hostnames)
    - resolver plugin of StrongSWAN needs to be configured in strongswan.conf...
cc263020 19 décembre 2013 15:52 Ermal

Provide a setting to disable the auto added LAN SPDs in the DB

aebf41df 10 décembre 2013 15:08 Renato Botelho

Use current racoon.conf syntax to avoid issues when deprecated one is removed, it fixes #3338

0c21eb70 06 décembre 2013 20:16 Ermal

Use _vip as identified for CARP vip IPs to allow easier upgrade code. This way only ipaliases on carp need to be upgraded.

7238e0cf 28 novembre 2013 19:36 Ermal

Remove references to _vip interface and provide proper configuration for carp on FreeBSD 10. Still some places to deal with this and certainly missing upgrade code

03131eb9 03 septembre 2013 20:13 Renato Botelho

Remove SPD when disable phase2, it fixes #2719

083a9e6d 22 août 2013 21:14 Renato Botelho

Delete old route for remote gateway when its IP changes. It fixes #3155

8ab8d853 06 août 2013 16:05 jim-p

Don't print this message for a mobile IPsec setup. It's normal for it to not have an endpoint, and not worth spamming the log about.

c766d411 04 juin 2013 13:25 Renato Botelho

Remove extra parenthesis

4eb3ac52 04 juin 2013 13:24 Renato Botelho

Also consider 0.0.0.0/0 here since it fails on is_subnet() but is a valid/special config. Fixes #3016

50813d24 03 juin 2013 14:38 jim-p

vpn.inc calls functions from ipsec.inc but doesn't actually include it in all cases where it's needed.

da6aebbb 22 mai 2013 16:48 Renato Botelho

Remove unecessary if

5b23c83d 16 mai 2013 19:00 jim-p

This didn't fix anything, made another syntax error. Revert "Seems to be missing a semicolon here."

This reverts commit 47a24491e2ea07a19d360d29325c1780652026a4.