FireBrick Road Warrior OSX: Difference between revisions
Appearance
Content deleted Content added
| (5 intermediate revisions by the same user not shown) | |||
| Line 2: | Line 2: | ||
It is possible to connect an modern Apple Mac with OSX to a FireBrick over IPSEC with IKEv2 and EAP. |
|||
It is possible to connect an Apple Mac with OSX to a FireBrick over IPSEC with IKEv2 and EAP. Regrettably the IPSEC facilities within OSX before version 'El Capitan' are not fully enough featured to achieve this alone, so some additional VPN client software can be installed called StrongSwan. Details below describe how to install the CA certificate from the FireBrick to your Apple computer and then how to set up the VPN connection either by using El Capitan's built in VPN settings or by using StronSwan. |
|||
=OSX versions 10.11 El Capitan, and newer= |
|||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
'''The details below are only useful of you have a very old mac or need to install the certificate if you're not using Lets Encrypt.''' |
|||
==Non-Lets Encrypt Certificates== |
|||
| ⚫ | |||
| ⚫ | |||
Note: this guide doesn't go into actual configuration of the FireBrick to be an endpoint, merely how to connect your Mac client to it. Therefore, it is assumed the certificate already exists on the FireBrick. It may also be that this is emailed to you by whoever maintains your FireBrick, in which case skip this step. |
Note: this guide doesn't go into actual configuration of the FireBrick to be an endpoint, merely how to connect your Mac client to it. Therefore, it is assumed the certificate already exists on the FireBrick. It may also be that this is emailed to you by whoever maintains your FireBrick, in which case skip this step. |
||
| Line 16: | Line 45: | ||
#At the right hand end of the row corresponding the certificate you wish to download, click on the PEM link. |
#At the right hand end of the row corresponding the certificate you wish to download, click on the PEM link. |
||
== Installing the CA certificate into OSX == |
=== Installing the CA certificate into OSX === |
||
'''(This is not needed if you are using Let's Encrypt)''' |
'''(This is not needed if you are using Let's Encrypt)''' |
||
| Line 31: | Line 60: | ||
</gallery> |
</gallery> |
||
=OSX |
=OSX version 10.10,'Yosemite' and earlier (Legacy information)= |
||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
| ⚫ | |||
=OSX version 10.10,'Yosemite' and earlier= |
|||
For versions 10.10 and earlier you'll need to use the StronSwan program. You will still need to install the CA certificate as above. |
For versions 10.10 and earlier you'll need to use the StronSwan program. You will still need to install the CA certificate as above. |
||
=== |
=== Downloading & installing the StrongSwan Native Client === |
||
'''Usually on OSX, you can simply use the built in VPN settings as above.''' |
'''Usually on OSX, you can simply use the built in VPN settings as above.''' |
||
| Line 67: | Line 73: | ||
</gallery> |
</gallery> |
||
==Configure strongSwan== |
===Configure strongSwan=== |
||
Run strong swan by either: |
Run strong swan by either: |
||
#Go to Applications and click on the strongSwan icon |
#Go to Applications and click on the strongSwan icon |
||
| Line 87: | Line 93: | ||
</gallery> |
</gallery> |
||
==Connect!== |
===Connect!=== |
||
#Click on the <del>Dalek</del> StrongSwan icon once more, |
#Click on the <del>Dalek</del> StrongSwan icon once more, |
||
#Click your connection name then connect. |
#Click your connection name then connect. |
||