Author: kendiv
Date: 2006.12.20
*************************************
Requirements
*************************************
A. Linux kernel, either 2.0, 2.2, 2.4 or 2.6 based.
B. If building from source, libgmp development libraries.
*************************************
Klips & netkey (aka "26sec" or "native ")
*************************************
For linux kernels 2.6.0 and higher, openswan gives you the choice of using the built in IPsec stack (netkey)
Or the openswan stack (klips). Only the userland component of openswan is required to use openswan with netkey.
Please use at least version 2.6.9, as prior versions have bugs in the IPsec stack, causing complete machine crashes.
*************************************
About GMP
*************************************
Openswan needs the GMP (GNU multi-precision) library for the large integer calculations it uses in public key cryptography.
The GMP library is supported in most Linux distributions.
Typically, there are two rpms, libgmp and libgmp-devel, you need to install both,
Either from your distribution CDs or from your vendor's Web site.
*************************************
About the openswan Kernel patches
*************************************
The are 2 openswan patches.
A. Nat-T patch: Provides nattraversal support for 2.4 linux kernels
B. klips Patch: Provides the klips IPSec stack for stock 2.4 kernels.
If you are using rhel3, there is already an IPsec stack in the kernel named netkey.
It is a backport (done by RedHat) of the 2.6 linux kernels IPSec Stack
Userland:
1) from the openswan source directory:
# Make programs
2) as root, install the userland tools:
# Make install
Optional: klips ipstack
0) a kernel patch must be applied to make the option config_ipsec_nat_traversal available
# Make nattpatch2.6> ../nat-t-patch-2.6.diff
# CD ../Linux
# Patch-P1 <../nat-t-patch-2.6.diff
# Make menuconfig and enable networking/networking options/IPSec Nat-Traversal
Recompile and install new kernel
1) from the openswan source directory:
# Export kernelsrc =/lib/modules/'uname-R'/build
# Make module26
# Make minstall26
# Depmod-
If compiling for x86_64 (aka amd athlon 64/XP) Add-M64 to user_compile and add-M64-MnO-red-zones to klipscompile
2) unload netkey before loading klips: rmmod af_key esp4 AH4 ipcomp
3) Load klips: modprobe IPSec
You can see which IPSec stack you are using with 'ipsec -- version'
Note: the choice to use klips for 2.6 kernels is available starting in openswan version 2.3.0; previous openswan releases had only support for the builtin IPSec stack when running with 2.6 kernels
*************************************
Klips install 2.6.12-6 kernels
*************************************
# Cd/usr/local/src/Linux
# Make clean
# Patch-P1-S <openswan-2.4.7.kernel-2.6-klips.patch.gz
# Patch-P1-S <openswan-2.4.7.kernel-2.6-natt.patch.gz
# Make menuconfig # Note: enable networking/networking options/IPSec nat-traversal/klips
# Make-J20
# Make modules_install
# Make install
Now, reboot and choose new kernels.
Note:
If you want NAT-T support (nattraversal), you need to patch your kernel and build a new bzimage
Then, if you only want klips, use the command sequence below.
# Cd/usr/src/openswan-2 .#.#
# Export kernelsrc =/usr/src/kernels/linux-2.6.18/
# Make Module
# Make module_install
1) unload netkey before loading klips: rmmod af_key esp4 AH4 ipcomp
2) Load klips: modprobe IPSec
3) modify your/etc/rc. d/rc. Local, add this blow:
/Sbin/modprobe IPSec
*************************************
Build openswan
*************************************
# Cd/usr/local/src/openswan-2.4.7
# Make programs
# Make install
*************************************
Start openswan and test your install
*************************************
Bring openswan up:
# Service IPSec start
# IPSec verify # Note: to check that you have a successful install.
You shoshould see at least:
Checking your system to see if IPSec got installed and started correctly
Version Check and IPSec on-path [OK]
Checking for klips support in kernel [OK]
Checking for RSA private key (/etc/IPSec. Secrets) [OK]
Checking that Pluto is running [OK]
*************************************
Firewall & Nat
*************************************
You need to allow UDP 500 and ESP (Protocol 50) through your firewall.
Do not Nat the packets you will be tunneling.
*************************************
Generate RSA key
*************************************
Summary 0000288: newhostkey may block indefinitely
Description 'ipsec newhostkey' CILS rsasigkey without the -- random option.
That means the device/dev/random is used. On some systems this device blocks indefinitely
Because not enough entropy is available.
The device/dev/urandom shoshould be used instead or at least this shoshould be possible as an option.
Additional information I changed line 59 of/usr/libexec/IPSec/newhostkey:
IPSec rsasigkey $ verbose -- random/dev/urandom $ host $ bits
To make it work on my Gentoo system.
In my system, used like blow:
# Vi/usr/local/libexec/IPSec/newhostkey
# IPSec newhostkey -- output/etc/IPSec. Secrets
*************************************
Enable IP Forwarding
*************************************
# Echo "1">/proc/sys/NET/IPv4/ip_forward
Or
Edit # vi/etc/sysctl. conf
Set net. ipv4.ip _ forward = 1
/*************************** End *********** **************************************** */