Jump to content

This is the support site for Andrews & Arnold Ltd, a UK Internet provider. Information on these pages is generally for our customers but may be useful to others, enjoy!

Category:FireBrick IPsec Road Warrior: Difference between revisions

m
no edit summary
mNo edit summary
mNo edit summary
(24 intermediate revisions by 2 users not shown)
<indicator name="Tunnels">[[File:Menu-IPsec.svg|link=:Category:FireBrick IPsec|30px|Back up to the FireBrick IPsec Tunnels Category Page]]</indicator>
__NOTOC__
 
The FireBrick manual goes into some detail on configuring IPsec. ThisThese pagepages containsbelow contain specific examples for a simple scenario where you have one or more clients devices - iPhones iPads, Android phones/tablets or Windows machines, and a FireBrick in your home or office, and you would like to VPN (using IPsec) to the FireBrick and have an IP address on your LAN.
 
'''First''' Create certificates:
In this example we are assuming you can allocate some IP addresses on you LAN. You do this by picking a range of addresses and setting up a roaming-pool (see below). You need to ensure the IP range does not clash with devices on the LAN and is not in the DHCP ranges that could allocate to the LAN. You also need to set proxy-arp on the LAN interface settings to allow communications to other devices on your LAN. Alternatively you could set private IP addresses in the pool and set the nat setting. You should probably also consider firewalling rules for traffic to/from IPsec connections.
 
First, create certificates and the FireBrick config, then look at the pages for the device you are wanting to configure
 
<div class="AAMenuRow">
{{AAMenu|img=Menu-Certificate.svg|link=FireBrick_Road_Warrior_Certificates|title=Certificates|text='''First:''' Create the required 'CA' and 'Server' Certificates, weand haveupload somethem toolsto availableyour toFireBrick. makeUsing thisLet's aEncrypt littleis easiereasy}}
 
{{AAMenu|img=Menu-FireBrick.svg|link=FireBrick_Road_Warrior_FireBrick_Config|title=FireBrick config|text='''Second:''' Configure the FireBrick}}
'''Second:''' Create the FireBrick config:
 
{{AAMenu|img=Menu-FireBrick.svg|link=FireBrick_Road_Warrior_FireBrick_Config|title=FireBrick config|text='''Second:''' Upload the Configure the FireBrick with IKE, EAP Users, and roaming pools of addresses! (easier than it sounds!)}}
</div>
 
 
<div class="AAMenuRow">
{{AAMenu|img=Menu-Apple.svg|link=FireBrick_Road_Warrior_iPhone_iPadFireBrick_Road_Warrior_iPhone_iPad_iOS8|title=iPhone & iPad iOS8|text=Creating a VPN profile for Apple iPhones and Apple iPads to connect to your FireBrick}}
{{AAMenu|img=Menu-AndroidApple.svg|link=FireBrick_Road_Warrior_AndroidFireBrick_Road_Warrior_iPhone_iPad_iOS9|title=AndroidiPhone & iPad iOS9|text=Android,Creating ega phonesVPN connection for Apple iPhones and tabletsApple iPads running iOS 9 to connect to your FireBrick}}
{{AAMenu|img=Menu-WindowsApple.svg|link=FireBrick_Road_Warrior_WindowsFireBrick_Road_Warrior_OSX|title=WindowsApple Desktops & Laptops|text=WindowsUsing Strongswan on Apple OS X computers, eg Macbook & Air laptops, iMac, Mini etc to 7connect andto Windowsyour 10FireBrick}}
 
{{AAMenu|img=Menu-Apple.svg|link=FireBrick_Road_Warrior_OSX|title=Apple OSX|text=Apple OSX, eg Macbook laptops etc}}
{{AAMenu|img=Menu-Android.svg|link=FireBrick_Road_Warrior_Android|title=Android|text=Using Strongswan on Android phones and tablets to connect to your FireBrick}}
{{AAMenu|img=Menu-Windows.svg|link=FireBrick_Road_Warrior_Windows_7|title=Windows 7|text=Using the built in VPN features of Windows 7 to connect to your FireBrick}}
{{AAMenu|img=Menu-Windows.svg|link=FireBrick_Road_Warrior_Windows_10|title=Windows 10|text=Using the built in VPN features of Windows 10 to connect to your FireBrick}}
 
{{AAMenu|img=Menu-swan.svg|link=FireBrick_Road_Warrior_strongSwan|title=strongSwan (Debian et al)|text=Using strongSwan on Debain (or other distros) to connect to your FireBrick}}
{{AAMenu|img=Menu-swan.svg|link=FireBrick_Road_Warrior_strongSwan_Network_Manager|title=strongSwan via Network Manager (Fedora)|text=Using strongSwan via the Network Manager GUI in CentOS/Fedora etc}}
 
 
</div>
[[Category:FireBrick IPsec]]
autoreview, Bureaucrats, editor, Interface administrators, reviewer, Administrators
12,270

edits