Jump to content

This is the support site for Andrews & Arnold Ltd, a UK Internet provider. Information on these pages is generally for our customers but may be useful to others, enjoy!

FireBrick Road Warrior strongSwan Network Manager: Difference between revisions

Fix syntax
mNo edit summary
(Fix syntax)
 
(4 intermediate revisions by one other user not shown)
 
'''FireBrick acting as the ipsec 'server', and configuring a strongSwan client on Fedora using Network Manager.'''
 
 
 
*Also see: [[FireBrick_Road_Warrior_strongSwan]] (setting up via non-network manager
*Also see: [[FireBrick to Openswan Strongswan IPsec (Howto)]]
*Also see the official StrongSwan network manager page: https://wiki.strongswan.org/projects/strongswan/wiki/NetworkManager
 
 
===Install Packages===
 
Fedora:
dnf install NetworkManager-strongswan NetworkManager-strongswan-gnome -y
Ubuntu:
apt install network-manager-strongswan
 
===(optional) Certificate Installation on the client===
 
If you're using self-signed certs, generated by the FireBrick then do the following, otherwise (eg if you are using the easily installed Let's Encrypt cert on the FireBrick then you can skip this stage)
===Certificate Installation===
 
#Go to your VPN end point FireBrick and log in.
##sudo cp /home/user/brick-ca-cert.crt /etc/ssl/certs/
 
Note: When doing this with a LetsEncrypt Cert it is the DSTISRG-Root-CA-X3X1.pem cert not the Let'sEncryptAuthorityX3 cert that is needed in /etc/ssl/certs/. This only seems to be for Linux as iOS, OSX, Window 10 and Android-strongswan all work with the Let'sEncryptAuthorityX3 cert. - the ISRG-Root-X1 is usually already installed by the OS.
 
===Set Up VPN===
If you require split tunnelling then please select the IPv4 and IPv6 tabs and tick the box for “Use this connection only for resources on its network” (pic above)
 
[[Category:FireBrick IPsec Road Warrior|Network Manager]]
editor
699

edits