Hej,
Jag försöker få igång min config i swanctl.conf istället för ipsec.conf men jag får det inte att lira, är det någon som kan peka mig i rätt riktning?
ipsec.conf (fungerar)
conn pelle
left=%defaultroute
leftsourceip=%config
leftauth=eap-mschapv2
eap_identity=min user
right=vpn.kallstrom.me
rightsubnet=0.0.0.0/0
rightauth=pubkey
rightid=%vpn.mindomän
rightca=/etc/ipsec.d/cacerts/pelle.cer
keyexchange=ikev2
type=tunnel
mobike=yes
dpdaction=hold
closeaction=hold
dpdtimeout=300s
dpddelay=120s
keylife=20m
rekeymargin=3m
reauth=no
ikelifetime=60m
lifetime=1h
keyingtries=1
auto=start
keyexchange=ikev2
esp=aes128-sha2_256-modp2048!
ike=aes128-sha2_256-modp2048!
swanctl.conf (fungerar ej)
connections {
vpn {
version = 2
proposals = aes128-sha256-modp2048!
rekey_time = 0s
fragmentation = allow
dpd_delay = 300s
local_addrs = %defaultroute
remote_addrs = vpn.mindomän
vips=0.0.0.0,::
local {
auth = eap-mschapv2
eap_id = min user
}
remote {
auth = pubkey
rightca=/etc/ipsec.d/cacerts/pelle.cer
id = %any
}
children {
vpn {
mode = tunnel
remote_ts = 0.0.0.0/0,::/0
rekey_time = 0s
dpd_action = clear
esp_proposals = aes128-sha256-modp2048!
}
}
}
}
secrets {
eap-vpn {
id = minuser
secret = mittlösen
}
}
Edit: Felet verkar ligga i mina proposals.. vet dock inte hur jag får till det
Daemon.log
Jul 9 10:52:19 pelle-manjaro systemd[1]: Starting strongSwan IPsec IKEv1/IKEv2 daemon using swanctl...
Jul 9 10:52:19 pelle-manjaro swanctl[7737]: no files found matching '/etc/swanctl/conf.d/*.conf'
Jul 9 10:52:19 pelle-manjaro swanctl[7737]: no authorities found, 0 unloaded
Jul 9 10:52:19 pelle-manjaro swanctl[7737]: no pools found, 0 unloaded
Jul 9 10:52:19 pelle-manjaro swanctl[7737]: loading connection 'vpn' failed: invalid value for: proposals, config discarded
Jul 9 10:52:19 pelle-manjaro swanctl[7737]: loaded 0 of 1 connections, 1 failed to load, 0 unloaded
Jul 9 10:52:19 pelle-manjaro swanctl[7737]: loaded eap secret 'eap-vpn'
Jul 9 10:52:19 pelle-manjaro systemd[1]: strongswan.service: Control process exited, code=exited, status=22/n/a
Jul 9 10:52:19 pelle-manjaro systemd[1]: strongswan.service: Failed with result 'exit-code'.
Jul 9 10:52:19 pelle-manjaro systemd[1]: Failed to start strongSwan IPsec IKEv1/IKEv2 daemon using swanctl.