我自己搭建了一个IPSEC 的IKEV2服务端。 windows IOS 安卓上测试连接无问题。
但在路由上配置始终提示未连接 路由日志也没找到哪里有。
能帮忙看看吗?
配置文件如下
- config setup
- uniqueids=never
- conn iOS_cert
- keyexchange=ikev1
- fragmentation=yes
- left=%defaultroute
- leftauth=pubkey
- leftsubnet=0.0.0.0/0
- leftcert=server.cert.pem
- right=%any
- rightauth=pubkey
- rightauth2=xauth
- rightsourceip=10.31.2.0/24
- rightcert=client.cert.pem
- auto=add
- conn android_xauth_psk
- keyexchange=ikev1
- left=%defaultroute
- leftauth=psk
- leftsubnet=0.0.0.0/0
- right=%any
- rightauth=psk
- rightauth2=xauth
- rightsourceip=10.31.2.0/24
- auto=add
- conn networkmanager-strongswan
- keyexchange=ikev2
- left=%defaultroute
- leftauth=pubkey
- leftsubnet=0.0.0.0/0
- leftcert=server.cert.pem
- right=%any
- rightauth=pubkey
- rightsourceip=10.31.2.0/24
- rightcert=client.cert.pem
- auto=add
- conn ios_ikev2
- keyexchange=ikev2
- ike=aes256-sha256-modp2048,3des-sha1-modp2048,aes256-sha1-modp2048!
- esp=aes256-sha256,3des-sha1,aes256-sha1!
- rekey=no
- left=%defaultroute
- leftid=ikev2.devops.newzqxq.com
- leftsendcert=always
- leftsubnet=0.0.0.0/0
- leftcert=server.cert.pem
- right=%any
- rightauth=eap-mschapv2
- rightsourceip=10.31.2.0/24
- rightsendcert=never
- eap_identity=%any
- dpdaction=clear
- fragmentation=yes
- auto=add
- conn windows7
- keyexchange=ikev2
- ike=aes256-sha1-modp1024!
- rekey=no
- left=%defaultroute
- leftauth=pubkey
- leftsubnet=0.0.0.0/0
- leftcert=server.cert.pem
- right=%any
- rightauth=eap-mschapv2
- rightsourceip=10.31.2.0/24
- rightsendcert=never
- eap_identity=%any
- auto=add
复制代码
路由上的设置
|