Openwan

Seni
Seni used Ask the Experts™
on
Hi Guys,

I want to establish a p2p ipsec vpn between a cisco asa and linux server running on Centos 5.x.

From the Linux server side, the server will be both the peer and internal source however, the Cisco ASA needs to different IPs.

1. Peer IP
2. Internal hosts for encryption.

To overcome this limitation, I have created a logical interface on the Linux server to act as my encrypted host.

So far, I have managed to get IPsec phase 1 up. I'm struggling to get Phase2. I have attached my configuration from both ends.

Kindly assist in review and let me know where I'm going wrong. cisco-asa-openswan.txt cisco-asa-openswan.txt
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
nociSoftware Engineer
Distinguished Expert 2018

Commented:
Leftnext hop should be the address of your gateway en route to your ASA server.
rightnexthop should be the address of the gateway on your ASA en route to YOU (not relevant in this case).
leftsubnet is the spec that is communicated for phase 2. so:
    leftsubnet=192.168.10.5/32
leftsourceip is the source for packets that should go through the tunnel... so you need to keep that

Author

Commented:
hi,

I tried that but still facing the same problem. phase 2 is not coming up.

Does someone have a working configuration that I could edit?
nociSoftware Engineer
Distinguished Expert 2018

Commented:
Any chance of showing some logging information?

grep pluto /var/log/security
please review that it doesn't show any secrets. Ip address can be obfusciated if needed but should be kept distinctive.

should show something.
The same for Cisco, show log (filterred to relevant lines).
Angular Fundamentals

Learn the fundamentals of Angular 2, a JavaScript framework for developing dynamic single page applications.

Author

Commented:
Hi guys,

Openswan was consuming too much time to troubleshoot and deploy. I decided to drop it and move to another solution due to time limitation.

Will take on Openswan another time when I have no time restriction.
Software Engineer
Distinguished Expert 2018
Commented:
OK.

Author

Commented:
Solution did not work.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial