{"id":52,"date":"2024-08-20T11:06:27","date_gmt":"2024-08-20T03:06:27","guid":{"rendered":"https:\/\/cnsn.rr.nu\/?p=52"},"modified":"2024-08-20T11:06:27","modified_gmt":"2024-08-20T03:06:27","slug":"ipsec%e4%bc%a0%e8%be%93%e6%a8%a1%e5%bc%8f%e9%85%8d%e7%bd%ae","status":"publish","type":"post","link":"https:\/\/blog.cnsn.fun\/?p=52","title":{"rendered":"IPsec\u4f20\u8f93\u6a21\u5f0f\u914d\u7f6e"},"content":{"rendered":"<h3>\u5728Linux\u670d\u52a1\u5668\u4e0a\u914d\u7f6eIPsec\u670d\u52a1\u7aef<\/h3>\n<h4>1. \u5b89\u88c5\u5fc5\u8981\u7684\u8f6f\u4ef6<\/h4>\n<p>\u9996\u5148\uff0c\u5b89\u88c5<code>strongSwan<\/code>\u6765\u7ba1\u7406\u548c\u914d\u7f6eIPsec\u3002<\/p>\n<pre><code class=\"language-bash\">sudo apt-get update\nsudo apt-get install strongswan<\/code><\/pre>\n<h4>2. \u914d\u7f6eIPsec<\/h4>\n<p>\u4fee\u6539<code>\/etc\/ipsec.conf<\/code>\u6587\u4ef6\uff0c\u914d\u7f6eIPsec\u670d\u52a1\u7aef\u3002<\/p>\n<pre><code class=\"language-conf\">config setup\n    charondebug=&quot;ike 2, knl 2, cfg 2&quot;\n\nconn windows-connection\n    authby=secret\n    auto=add\n    left=%defaultroute  # \u672c\u5730\u4e3b\u673aIP\uff0c\u53ef\u4ee5\u4f7f\u7528%defaultroute\u81ea\u52a8\u68c0\u6d4b\n    leftid=@server.example.com  # \u53ef\u9009\uff0c\u6307\u5b9a\u670d\u52a1\u7aefID\n    right=192.168.1.2  # \u8fdc\u7a0bWindows\u5ba2\u6237\u7aefIP\n    rightid=@client.example.com  # \u53ef\u9009\uff0c\u6307\u5b9a\u5ba2\u6237\u7aefID\n    type=transport\n    esp=aes256-sha256-modp2048\n    ike=aes256-sha256-modp2048\n    keyexchange=ikev2\n    dpdaction=clear  # \u6b7b\u5bf9\u7b49\u68c0\u6d4b\n    dpddelay=30s\n    dpdtimeout=120s<\/code><\/pre>\n<h4>3. \u914d\u7f6e\u9884\u5171\u4eab\u5bc6\u94a5<\/h4>\n<p>\u5728<code>\/etc\/ipsec.secrets<\/code>\u6587\u4ef6\u4e2d\u914d\u7f6e\u9884\u5171\u4eab\u5bc6\u94a5\uff08PSK\uff09\uff1a<\/p>\n<pre><code class=\"language-conf\">@server.example.com @client.example.com : PSK &quot;your_pre_shared_key&quot;<\/code><\/pre>\n<h4>4. \u542f\u52a8IPsec\u670d\u52a1<\/h4>\n<p>\u542f\u52a8\u5e76\u542f\u7528IPsec\u670d\u52a1\uff1a<\/p>\n<pre><code class=\"language-bash\">sudo systemctl start strongswan\nsudo systemctl enable strongswan<\/code><\/pre>\n<h4>5. \u9a8c\u8bc1\u914d\u7f6e<\/h4>\n<p>\u4f7f\u7528<code>ipsec status<\/code>\u547d\u4ee4\u67e5\u770bIPsec\u8fde\u63a5\u7684\u72b6\u6001\uff1a<\/p>\n<pre><code class=\"language-bash\">sudo ipsec status<\/code><\/pre>\n<h3>\u5728Windows\u5ba2\u6237\u7aef\u4e0a\u914d\u7f6eIPsec\u5ba2\u6237\u7aef<\/h3>\n<h4>1. \u6253\u5f00\u201c\u7f51\u7edc\u548c\u5171\u4eab\u4e2d\u5fc3\u201d<\/h4>\n<p>\u901a\u8fc7\u201c\u63a7\u5236\u9762\u677f\u201d\u6253\u5f00\u201c\u7f51\u7edc\u548c\u5171\u4eab\u4e2d\u5fc3\u201d\u3002<\/p>\n<h4>2. \u521b\u5efa\u65b0\u7684VPN\u8fde\u63a5<\/h4>\n<ol>\n<li>\u70b9\u51fb\u201c\u8bbe\u7f6e\u65b0\u7684\u8fde\u63a5\u6216\u7f51\u7edc\u201d\u3002<\/li>\n<li>\u9009\u62e9\u201c\u8fde\u63a5\u5230\u5de5\u4f5c\u533a\u201d\uff0c\u7136\u540e\u70b9\u51fb\u201c\u4e0b\u4e00\u6b65\u201d\u3002<\/li>\n<li>\u9009\u62e9\u201c\u4f7f\u7528\u6211\u7684Internet\u8fde\u63a5(VPN)\u201d\u3002<\/li>\n<\/ol>\n<h4>3. \u914d\u7f6eVPN\u8fde\u63a5<\/h4>\n<ol>\n<li>\u5728\u201cInternet\u5730\u5740\u201d\u5b57\u6bb5\u4e2d\u8f93\u5165Linux\u670d\u52a1\u5668\u7684IP\u5730\u5740\u3002<\/li>\n<li>\u5728\u201c\u76ee\u6807\u540d\u79f0\u201d\u5b57\u6bb5\u4e2d\u8f93\u5165\u4e00\u4e2a\u540d\u79f0\uff0c\u4f8b\u5982\u201cIPsec VPN\u201d\u3002<\/li>\n<li>\u70b9\u51fb\u201c\u521b\u5efa\u201d\u3002<\/li>\n<\/ol>\n<h4>4. \u914d\u7f6eVPN\u5c5e\u6027<\/h4>\n<ol>\n<li>\u5728\u201c\u7f51\u7edc\u548c\u5171\u4eab\u4e2d\u5fc3\u201d\u4e2d\u627e\u5230\u521a\u521a\u521b\u5efa\u7684VPN\u8fde\u63a5\uff0c\u70b9\u51fb\u201c\u66f4\u6539\u9002\u914d\u5668\u8bbe\u7f6e\u201d\u3002<\/li>\n<li>\u53f3\u952e\u70b9\u51fb\u65b0\u521b\u5efa\u7684VPN\u8fde\u63a5\uff0c\u9009\u62e9\u201c\u5c5e\u6027\u201d\u3002<\/li>\n<li>\u5728\u201c\u5b89\u5168\u201d\u9009\u9879\u5361\u4e2d\uff0c\u8bbe\u7f6e\u5982\u4e0b\uff1a\n<ul>\n<li>VPN\u7c7b\u578b\uff1a\u9009\u62e9\u201cIKEv2\u201d\u3002<\/li>\n<li>\u6570\u636e\u52a0\u5bc6\uff1a\u9009\u62e9\u201c\u9700\u8981\u52a0\u5bc6\uff08\u65ad\u5f00\u8fde\u63a5\u5982\u679c\u670d\u52a1\u5668\u62d2\u7edd\uff09\u201d\u3002<\/li>\n<\/ul>\n<\/li>\n<li>\u70b9\u51fb\u201c\u9ad8\u7ea7\u8bbe\u7f6e\u201d\uff0c\u9009\u62e9\u201c\u4f7f\u7528\u9884\u5171\u4eab\u5bc6\u94a5\u8fdb\u884c\u8eab\u4efd\u9a8c\u8bc1\u201d\uff0c\u7136\u540e\u8f93\u5165\u4e0e\u4f60\u5728Linux\u670d\u52a1\u5668\u4e0a\u914d\u7f6e\u7684PSK\u76f8\u540c\u7684\u9884\u5171\u4eab\u5bc6\u94a5\u3002<\/li>\n<\/ol>\n<h4>5. \u914d\u7f6eIPsec\u8bbe\u7f6e<\/h4>\n<ol>\n<li>\u5728\u201c\u5b89\u5168\u201d\u9009\u9879\u5361\u4e2d\uff0c\u70b9\u51fb\u201cIPsec\u8bbe\u7f6e\u201d\u3002<\/li>\n<li>\u786e\u4fdd\u542f\u7528\u4e86\u201c\u4f7f\u7528IPsec\u8fdb\u884c\u6b64VPN\u8fde\u63a5\u201d\u3002<\/li>\n<li>\u8f93\u5165\u9884\u5171\u4eab\u5bc6\u94a5\u3002<\/li>\n<\/ol>\n<h4>6. \u8fde\u63a5\u5230VPN<\/h4>\n<ol>\n<li>\u5728\u201c\u7f51\u7edc\u548c\u5171\u4eab\u4e2d\u5fc3\u201d\u4e2d\uff0c\u627e\u5230\u521a\u521a\u521b\u5efa\u7684VPN\u8fde\u63a5\u3002<\/li>\n<li>\u70b9\u51fb\u201c\u8fde\u63a5\u201d\uff0c\u8f93\u5165VPN\u7528\u6237\u540d\u548c\u5bc6\u7801\uff08\u5982\u679c\u9700\u8981\uff09\uff0c\u7136\u540e\u8fde\u63a5\u3002<\/li>\n<\/ol>\n<h3>\u5728window\u4e0bqt\u7a0b\u5e8f\u4e2d\u7684\u914d\u7f6e<\/h3>\n<p>\u5728Windows\u4e0a\u4f7f\u7528QT\u7a0b\u5e8f\u5b9e\u73b0IPsec\u914d\u7f6e\uff0c\u53ef\u4ee5\u901a\u8fc7\u8c03\u7528Windows API\u6216\u4f7f\u7528\u547d\u4ee4\u884c\u5de5\u5177\u6765\u5b8c\u6210\u3002\u8fd9\u9700\u8981\u5bf9Windows\u7f51\u7edc\u914d\u7f6eAPI\u6709\u6240\u4e86\u89e3\uff0c\u4ee5\u53ca\u5982\u4f55\u901a\u8fc7QT\u8c03\u7528\u8fd9\u4e9bAPI\u6216\u6267\u884c\u547d\u4ee4\u3002\u4ee5\u4e0b\u662f\u4e00\u4e2a\u7b80\u5355\u7684\u793a\u4f8b\uff0c\u5c55\u793a\u5982\u4f55\u4f7f\u7528QT\u7a0b\u5e8f\u6765\u914d\u7f6eIPsec\u8fde\u63a5\u3002<\/p>\n<h4>1.\u6b65\u9aa4\u6982\u8ff0<\/h4>\n<ol>\n<li>\u4f7f\u7528QT\u521b\u5efa\u4e00\u4e2a\u57fa\u672c\u7684GUI\u5e94\u7528\u7a0b\u5e8f\u3002<\/li>\n<li>\u901a\u8fc7QT\u8c03\u7528Windows\u547d\u4ee4\u884c\u914d\u7f6eVPN\u8fde\u63a5\u3002<\/li>\n<li>\u914d\u7f6eIPsec\u76f8\u5173\u8bbe\u7f6e\u3002<\/li>\n<\/ol>\n<h4>2.\u521b\u5efa\u57fa\u672c\u7684QT\u5e94\u7528\u7a0b\u5e8f<\/h4>\n<p>\u9996\u5148\uff0c\u521b\u5efa\u4e00\u4e2aQT Widget\u5e94\u7528\u7a0b\u5e8f\u3002\u5728QT Creator\u4e2d\uff0c\u9009\u62e9\u201cNew Project\u201d-&gt;\u201cApplication\u201d-&gt;\u201cQT Widgets Application\u201d\u3002<\/p>\n<h4>3.\u754c\u9762\u8bbe\u8ba1<\/h4>\n<p>\u4f7f\u7528QT Designer\u521b\u5efa\u4e00\u4e2a\u7b80\u5355\u7684\u754c\u9762\uff0c\u5305\u62ec\uff1a<\/p>\n<ul>\n<li>\u4e00\u4e2a\u6587\u672c\u6846\uff0c\u7528\u4e8e\u8f93\u5165\u670d\u52a1\u5668IP\u5730\u5740\u3002<\/li>\n<li>\u4e00\u4e2a\u6587\u672c\u6846\uff0c\u7528\u4e8e\u8f93\u5165\u9884\u5171\u4eab\u5bc6\u94a5\u3002<\/li>\n<li>\u4e00\u4e2a\u6309\u94ae\uff0c\u7528\u4e8e\u63d0\u4ea4\u914d\u7f6e\u3002<\/li>\n<\/ul>\n<h4>4.\u4e3b\u7a97\u53e3\u4ee3\u7801<\/h4>\n<p>\u4fee\u6539\u4e3b\u7a97\u53e3\u7684\u5934\u6587\u4ef6\uff08<code>mainwindow.h<\/code>\uff09\uff1a<\/p>\n<pre><code class=\"language-cpp\">#ifndef MAINWINDOW_H\n#define MAINWINDOW_H\n\n#include &lt;QMainWindow&gt;\n\nnamespace Ui {\nclass MainWindow;\n}\n\nclass MainWindow : public QMainWindow\n{\n    Q_OBJECT\n\npublic:\n    explicit MainWindow(QWidget *parent = nullptr);\n    ~MainWindow();\n\nprivate slots:\n    void on_connectButton_clicked();\n    void on_disconnectButton_clicked();\n\nprivate:\n    Ui::MainWindow *ui;\n    void configureIPsec(const QString &amp;serverIp, const QString &amp;psk);\n    void disconnectIPsec();\n};\n\n#endif \/\/ MAINWINDOW_H<\/code><\/pre>\n<p>\u4fee\u6539\u4e3b\u7a97\u53e3\u7684\u6e90\u6587\u4ef6\uff08<code>mainwindow.cpp<\/code>\uff09\uff1a<\/p>\n<pre><code class=\"language-cpp\">#include &quot;mainwindow.h&quot;\n#include &quot;ui_mainwindow.h&quot;\n#include &lt;QProcess&gt;\n#include &lt;QMessageBox&gt;\n\nMainWindow::MainWindow(QWidget *parent) :\n    QMainWindow(parent),\n    ui(new Ui::MainWindow)\n{\n    ui-&gt;setupUi(this);\n\n    \/\/ Connect the disconnect button signal to the slot\n    connect(ui-&gt;disconnectButton, &amp;QPushButton::clicked, this, &amp;MainWindow::on_disconnectButton_clicked);\n}\n\nMainWindow::~MainWindow()\n{\n    \/\/ Ensure IPsec connection is closed on exit\n    disconnectIPsec();\n    delete ui;\n}\n\nvoid MainWindow::on_connectButton_clicked()\n{\n    QString serverIp = ui-&gt;serverIpTextBox-&gt;text();\n    QString psk = ui-&gt;pskTextBox-&gt;text();\n\n    if (serverIp.isEmpty() || psk.isEmpty()) {\n        QMessageBox::warning(this, &quot;Input Error&quot;, &quot;Please enter both server IP and PSK.&quot;);\n        return;\n    }\n\n    configureIPsec(serverIp, psk);\n}\n\nvoid MainWindow::on_disconnectButton_clicked()\n{\n    disconnectIPsec();\n    QMessageBox::information(this, &quot;VPN Disconnection&quot;, &quot;IPsec VPN has been disconnected.&quot;);\n}\n\nvoid MainWindow::configureIPsec(const QString &amp;serverIp, const QString &amp;psk)\n{\n    QString connectionName = &quot;IPsecVPN&quot;;\n    QString createVpnCmd = QString(&quot;powershell -Command \\&quot;Add-VpnConnection -Name &#039;%1&#039; -ServerAddress &#039;%2&#039; -TunnelType IKEv2 -AuthenticationMethod MachineCertificate -EncryptionLevel Required -PassThru\\&quot;&quot;)\n                            .arg(connectionName).arg(serverIp);\n\n    QProcess::execute(createVpnCmd);\n\n    QString setPreSharedKeyCmd = QString(&quot;powershell -Command \\&quot;Set-VpnConnectionIPsecConfiguration -ConnectionName &#039;%1&#039; -AuthenticationTransformConstants GCMAES128 -CipherTransformConstants GCMAES256 -EncryptionMethod GCMAES256 -IntegrityCheckMethod SHA256 -DHGroup Group14 -PfsGroup PFS2048 -PassThru -EncryptionType Require -PreSharedKey &#039;%2&#039;\\&quot;&quot;)\n                                 .arg(connectionName).arg(psk);\n\n    QProcess::execute(setPreSharedKeyCmd);\n\n    QString connectVpnCmd = QString(&quot;powershell -Command \\&quot;rasdial %1\\&quot;&quot;).arg(connectionName);\n    QProcess::execute(connectVpnCmd);\n\n    QMessageBox::information(this, &quot;VPN Configuration&quot;, &quot;IPsec VPN has been configured and connected.&quot;);\n}\n\nvoid MainWindow::disconnectIPsec()\n{\n    QString connectionName = &quot;IPsecVPN&quot;;\n    QString disconnectVpnCmd = QString(&quot;powershell -Command \\&quot;rasdial %1 \/disconnect\\&quot;&quot;).arg(connectionName);\n    QProcess::execute(disconnectVpnCmd);\n\n    QString removeVpnCmd = QString(&quot;powershell -Command \\&quot;Remove-VpnConnection -Name &#039;%1&#039; -Force\\&quot;&quot;).arg(connectionName);\n    QProcess::execute(removeVpnCmd);\n}<\/code><\/pre>\n<h4>5.\u754c\u9762\u6587\u4ef6\u4fee\u6539<\/h4>\n<p>\u4fee\u6539\u754c\u9762\u6587\u4ef6\uff08<code>mainwindow.ui<\/code>\uff09\uff1a<\/p>\n<ol>\n<li>\u6dfb\u52a0\u4e24\u4e2a<code>QLineEdit<\/code>\u63a7\u4ef6\uff0c\u7528\u4e8e\u8f93\u5165\u670d\u52a1\u5668IP\u5730\u5740\u548c\u9884\u5171\u4eab\u5bc6\u94a5\uff0c\u5206\u522b\u547d\u540d\u4e3a<code>serverIpTextBox<\/code>\u548c<code>pskTextBox<\/code>\u3002<\/li>\n<li>\u6dfb\u52a0\u4e24\u4e2a<code>QPushButton<\/code>\u63a7\u4ef6\uff0c\u7528\u4e8e\u63d0\u4ea4\u914d\u7f6e\u4ee5\u53ca\u5173\u95ed\u8fde\u63a5\uff0c\u547d\u540d\u4e3a<code>connectButton<\/code>\u548c<code>disconnectButton<\/code>\u3002<\/li>\n<\/ol>\n<h4>6.\u5f02\u5e38\u5904\u7406<\/h4>\n<p>\u4e3a\u4e86\u786e\u4fdd\u5728\u7a0b\u5e8f\u5f02\u5e38\u9000\u51fa\u65f6\u4e5f\u80fd\u65ad\u5f00IPsec\u8fde\u63a5\uff0c\u53ef\u4ee5\u901a\u8fc7QT\u7684\u4fe1\u53f7\u4e0e\u69fd\u673a\u5236\u6355\u6349\u5e94\u7528\u7a0b\u5e8f\u7684\u5173\u95ed\u4e8b\u4ef6\u3002<\/p>\n<p>\u5728\u4e3b\u7a97\u53e3\u7684\u6784\u9020\u51fd\u6570\u4e2d\u6dfb\u52a0\u5982\u4e0b\u4ee3\u7801\u4ee5\u6355\u6349\u5173\u95ed\u4e8b\u4ef6\uff1a<\/p>\n<pre><code>cpp\u590d\u5236\u4ee3\u7801MainWindow::MainWindow(QWidget *parent) :\n    QMainWindow(parent),\n    ui(new Ui::MainWindow)\n{\n    ui-&gt;setupUi(this);\n\n    \/\/ Connect the disconnect button signal to the slot\n    connect(ui-&gt;disconnectButton, &amp;QPushButton::clicked, this, &amp;MainWindow::on_disconnectButton_clicked);\n\n    \/\/ Handle application close event\n    connect(QApplication::instance(), &amp;QCoreApplication::aboutToQuit, this, &amp;MainWindow::disconnectIPsec);\n}<\/code><\/pre>\n<h4>7.\u6743\u9650\u7ba1\u7406<\/h4>\n<p>\u786e\u4fdd\u4ee5\u7ba1\u7406\u5458\u8eab\u4efd\u8fd0\u884c\u7a0b\u5e8f\uff0c\u56e0\u4e3a\u6dfb\u52a0VPN\u8fde\u63a5\u548c\u914d\u7f6eIPsec\u9700\u8981\u7ba1\u7406\u5458\u6743\u9650\u3002<\/p>\n<h4>8.\u4ee3\u7801\u8bf4\u660e<\/h4>\n<ol>\n<li><code>QProcess::execute<\/code>\u7528\u4e8e\u6267\u884c\u547d\u4ee4\u884c\u6307\u4ee4\u3002\u6211\u4eec\u4f7f\u7528PowerShell\u547d\u4ee4\u6765\u6dfb\u52a0VPN\u8fde\u63a5\u548c\u914d\u7f6eIPsec\u3002<\/li>\n<li><code>Add-VpnConnection<\/code> PowerShell\u547d\u4ee4\u7528\u4e8e\u521b\u5efaVPN\u8fde\u63a5\u3002<\/li>\n<li><code>Set-VpnConnectionIPsecConfiguration<\/code> PowerShell\u547d\u4ee4\u7528\u4e8e\u914d\u7f6eIPsec\u7684\u9884\u5171\u4eab\u5bc6\u94a5\u548c\u52a0\u5bc6\u8bbe\u7f6e\u3002<\/li>\n<li><code>rasdial<\/code>\u547d\u4ee4\u7528\u4e8e\u8fde\u63a5VPN\u3002<\/li>\n<\/ol>\n<h4>9.\u5b8c\u6210<\/h4>\n<p>\u901a\u8fc7\u4ee5\u4e0a\u6b65\u9aa4\uff0c\u4f60\u53ef\u4ee5\u4f7f\u7528QT\u7a0b\u5e8f\u5728Windows\u4e0a\u914d\u7f6eIPsec VPN\u8fde\u63a5\u3002\u8fd9\u4e2a\u793a\u4f8b\u5c55\u793a\u4e86\u57fa\u672c\u7684\u5b9e\u73b0\u601d\u8def\uff0c\u5b9e\u9645\u5e94\u7528\u4e2d\u53ef\u80fd\u9700\u8981\u6839\u636e\u5177\u4f53\u9700\u6c42\u8fdb\u884c\u8c03\u6574\u548c\u6269\u5c55\u3002<\/p>\n<h3>\u9a8c\u8bc1\u8fde\u63a5<\/h3>\n<p>\u5728\u6210\u529f\u8fde\u63a5\u540e\uff0c\u4f60\u53ef\u4ee5\u5728Windows\u5ba2\u6237\u7aef\u4e0a\u4f7f\u7528<code>ping<\/code>\u6216\u5176\u4ed6\u7f51\u7edc\u5de5\u5177\u6765\u6d4b\u8bd5\u4e0eLinux\u670d\u52a1\u5668\u7684\u8fde\u63a5\u3002\u4f60\u8fd8\u53ef\u4ee5\u5728Linux\u670d\u52a1\u5668\u4e0a\u4f7f\u7528<code>ipsec status<\/code>\u6765\u67e5\u770b\u8fde\u63a5\u72b6\u6001\u548c\u6d3b\u52a8\u4f1a\u8bdd\u3002<\/p>\n<h3>\u989d\u5916\u6ce8\u610f\u4e8b\u9879<\/h3>\n<ol>\n<li><strong>\u9632\u706b\u5899\u914d\u7f6e<\/strong>\uff1a\u786e\u4fddLinux\u670d\u52a1\u5668\u7684\u9632\u706b\u5899\u5141\u8bb8IPsec\u76f8\u5173\u7684\u6d41\u91cf\uff08\u4f8b\u5982UDP 500\u548c4500\u7aef\u53e3\u7528\u4e8eIKE\uff0cESP\u534f\u8bae\u6d41\u91cf\uff09\u3002<\/li>\n<li><strong>\u8bc1\u4e66\u8ba4\u8bc1<\/strong>\uff1a\u867d\u7136\u672c\u6587\u793a\u4f8b\u4f7f\u7528\u7684\u662f\u9884\u5171\u4eab\u5bc6\u94a5\u8ba4\u8bc1\uff0c\u4f60\u4e5f\u53ef\u4ee5\u914d\u7f6e\u8bc1\u4e66\u8ba4\u8bc1\u4ee5\u63d0\u9ad8\u5b89\u5168\u6027\u3002<\/li>\n<li><strong>\u7f51\u7edc\u62d3\u6251<\/strong>\uff1a\u6839\u636e\u4f60\u7684\u7f51\u7edc\u62d3\u6251\u548c\u5177\u4f53\u9700\u6c42\uff0c\u53ef\u80fd\u9700\u8981\u8c03\u6574\u914d\u7f6e\u4ee5\u4f18\u5316\u6027\u80fd\u548c\u517c\u5bb9\u6027\u3002<\/li>\n<\/ol>\n<p>\u901a\u8fc7\u4ee5\u4e0a\u6b65\u9aa4\uff0c\u4f60\u53ef\u4ee5\u5728Linux\u670d\u52a1\u5668\u4e0a\u914d\u7f6eIPsec\u670d\u52a1\u7aef\uff0c\u5e76\u5728Windows\u5ba2\u6237\u7aef\u4e0a\u914d\u7f6eIPsec\u5ba2\u6237\u7aef\uff0c\u4ee5\u5b9e\u73b0\u52a0\u5bc6\u901a\u4fe1\u3002\u8fd9\u79cd\u65b9\u5f0f\u9002\u7528\u4e8e\u9700\u8981\u5b89\u5168\u3001\u52a0\u5bc6\u7684\u7aef\u5230\u7aef\u901a\u4fe1\u573a\u666f\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5728Linux\u670d\u52a1\u5668\u4e0a\u914d\u7f6eIPsec\u670d\u52a1\u7aef 1. \u5b89\u88c5\u5fc5\u8981\u7684\u8f6f\u4ef6 \u9996\u5148\uff0c\u5b89\u88c5strongSwan\u6765\u7ba1\u7406\u548c\u914d\u7f6eIP [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[17,22],"class_list":["post-52","post","type-post","status-publish","format-standard","hentry","category-qt","tag-ipsec","tag-qt"],"_links":{"self":[{"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=\/wp\/v2\/posts\/52","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=52"}],"version-history":[{"count":0,"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=\/wp\/v2\/posts\/52\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=52"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=52"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.cnsn.fun\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=52"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}