当前位置:网站首页>Pfsense configuring IPSec site to site tunneling using certificate authentication Guide
Pfsense configuring IPSec site to site tunneling using certificate authentication Guide
2022-04-21 20:12:00 【Iron Man】
stay pfSense Site to site IPsec VPN And routing Internet Configuration Guide in , This paper introduces how to configure by using shared key IPsec VPN And routing Internet The process of , In this paper , Using certificates to configure IPsec VPN Methods . Compared with the authentication method of pre shared key , Using certificate authentication will be relatively complex , But the security will be improved . Because the two methods are only different in Authentication , Therefore, this paper tries to simplify the narrative process , Unless otherwise indicated , Everything else goes with pfSense Site to site IPsec VPN And routing Internet The configuration guidelines are consistent .
If you need to further exchange your experience in firewall , You can join QQ Group 286850453 Discuss . Also welcome to pay attention to wechat public account ”pfSense A firewall ”, It is convenient to receive first-hand articles pushed in time .
Create certificate
At the site A And sites B Create a certification authority on (CA) And certificates . For the sake of distinguishing , Site A Dark theme , Site B The light color theme .
Site A
establish CA
- Navigate to System > Certificate management ,CAs tab
- Click on ” “ add to
- The setting options are shown in the figure below :
Create certificate
- Navigate to System > Certificate management , certificate tab
- Click on ” “ add to
- The setting options are shown in the figure below :
- Certificate Properties section , The certificate type is user certificate , Alternate name enter the host name and... Respectively IP Address (LAN Address ), This information will be in phase 1 Used for authentication in .
Site B
establish CA As shown in the figure below :
Create the certificate as shown in the figure below :
Import CA
For mutual authentication , The firewalls of the two sites need to import each other's CA.
1、 On two sites , Export the created... Separately CA. Click the icon shown in the figure below , export CA certificate .
2、 Import each other's CA. Navigate to System > Certificate management ,CAs tab , Click the Add button below , In the certificate source option , Choose to import an existing certification authority . Open the other party's certificate file with a text program , Copy the contents to the certificate data column , And click save .
After the save ,CAs Under tabs , There will be two sites CA Information . The following figure shows the site A And sites B Of CA list :
The revision phase 1 Set up
Modify site A And sites B The stage of 1 Set up , Will propose ( authentication ) Change it to Mutual certificate( Mutual certificate ), And adjust the corresponding option settings . Adopt certification according to ID Different types , There are three ways of mutual authentication :
1、 Use ANSI.1 Proprietary name . Use... In the certificate ANSI.1 Use proper names to authenticate each other .ANSI.1 The distinguished name can be viewed by clicking the certificate details icon in the certificate list , As shown in the figure below DN Later :
2、 Use FQDN. Use when creating a certificate , Enter in the alternate name section of the certificate properties FQDN To authenticate .
3、 Use IP Address . Use when creating a certificate , Enter in the alternate name section of the certificate properties IP Address to authenticate .
The above three kinds of certification ID Type tested , Can be authenticated and connected normally , Use any one of them .
Using certificate authentication is compared with shared key authentication IPsec VPN One more tunnel is created CA And certificate process , The proposal ( authentication ) Options are set differently , in addition to , The other settings of the two are exactly the same , I won't go into that here .
Related articles :
版权声明
本文为[Iron Man]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204211832447667.html
边栏推荐
- After learning this tutorial of capturing packages by Charles, I unloaded Fiddler directly
- 【转】FC(红白机)游戏nes文件的汉化技术
- One click installation of ROS and rosdep (no wall)
- Lenovo announced the new progress of ESG: it promised that 100% of all computer products would contain recycled plastics by 2025
- 全国各大城市的经纬度表,留着以后做查询库用
- Common sense question bank system is a must for civil servants and knowledgeable people. From programmer to poet
- 高效c语言 内存拷贝. 测试结果 rand, loop, operator= % in x86-64 SUSE
- [original] BigInteger. Large number multiplication. Large number operation. "Infinite number" multiplication. Comparison of two methods of large number multiplication
- Employment of college students in the "most difficult employment season": more than half of the graduates have landed, and higher vocational colleges produce sweet pastries
- Im instant messaging development technology: 1-10 million high concurrency architecture evolution
猜你喜欢
Practice of spark SQL in snowball

Changan dark blue c385 product information exposure aims at 200000 level, and the number one target is model 3!

Surface point cloud normal

如何在不加锁的情况下解决线程安全问题

JUC queue interface and its implementation class

Lenovo announced the new progress of ESG: it promised that 100% of all computer products would contain recycled plastics by 2025

长安深蓝C385产品信息曝光 瞄准20万级别,头号目标Model 3!

【时序】LSTNet:结合 CNN、RNN 以及 AR 的时间序列预测模型

Three implementation methods of quick sorting

Discussion on the hot and cold issues of open source license grounding gas
随机推荐
R language data analysis from entry to advanced: (8) data format conversion of data cleaning skills (including the conversion between wide data and long data)
php处理视频ffmpeg(转)
Mandelbrot集的最新变化形态一览——MandelBox,Mandelbulb,Burning Ship,NebulaBrot
First acquaintance with EEMBC coremark
Share the advantages of Intranet instant messaging software
Redis Foundation
My medical experience of "traditional Chinese medicine"
Know that Chuangyu issued a heavy strategic plan to build a practical defense system for continuous exchange of fire
CUDA02 - 访存优化和Unified Memory
Gbase 8A round or reject the double value, and the result is not the analysis and solution of rounding problem
Jmeter如何设置参数化
Install mysql, MSSQL, Oracle, mongdb and redis collections in docker
GBase 8a对 double 数值进行 round 取舍结果不是四舍五入问题分析及解决方案
Esaycode template
How to check the slow response of the system with high CPU?
艾尔登法环“无法加载保存数据”解决方法
C# 双保险进程监视器 lol 保证被监视的程序'几乎'永远运行. 关键字:进程操作 进程查看 创建进程
【 summer internship 】
快速排序的三种实现方式
Practice of spark SQL in snowball