Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/vyos/vyatta-cfg-vpn

Vyatta VPN configuration
https://github.com/vyos/vyatta-cfg-vpn

Set default pfs and ike dh group. (required by strongswan charon)

8353f0f8fc746c69d6006e5bba9baf45afe16385 authored almost 9 years ago by Kim Hagen <[email protected]>
Remove charonstart an interfaces from ipsec.conf file, they are depricated.

fbddff7f2b6b485c93b5d3cf4d60a75f84c3a2b6 authored almost 9 years ago by Kim Hagen <[email protected]>
Merge branch 'current' of github.com:vyos/vyatta-cfg-vpn into current

4b73a852d2fbc9ce60a31c10c7052ef5aef16fee authored almost 9 years ago by Kim Hagen <[email protected]>
Use dhcp instead of dhcp3.

bbd5b2a113cb64c872142b236b35c650804271eb authored almost 9 years ago by Kim Hagen <[email protected]>
vyatta-cfg-vpn: Properly implement force-encapsulation and fix descriptions

5ee99ec9d5cca8c13804964eee23ce0b15578edf authored almost 9 years ago by Jeff Leung <[email protected]>
0.12.105+vyos2+current2

b558c886bf89e0fdf88ee991dc88d45f3b8dc95d authored almost 9 years ago by Daniil Baturin <[email protected]>
Remove dependency on vyatta-ipsec for migration to upstream strongswan.

Update standards version and description.

28cb3d1d5b62595f3c033b85029132fec11b3c2d authored almost 9 years ago by Daniil Baturin <[email protected]>
0.12.105+vyos2+current1

d6bb593aa88a8ffbd4eeb46e1e96b4a6dcb3fb16 authored almost 9 years ago by Kim Hagen <[email protected]>
Fix build depends.

cf093a78ecae246c52be0ad39ac894013aa2adfd authored about 9 years ago by Thomas Jepp <[email protected]>
Merge branch 'lithium' into lithium-strongswan5

Conflicts:
templates/vpn/ipsec/esp-group/node.tag/proposal/node.tag/encryption/node.def
templa...

9e5c1863dde4762120d52f851d25178d8be5bb24 authored about 9 years ago by Jeff Leung <[email protected]>
vyatta-cfg-vpn: formatting changes for style consistency

Perltidy run on scripts/vyatta-vti-config.pl to have consistent
identation levels and style thro...

133cf61f7abee867dc6b7007c077254ec8ba1443 authored about 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: further tidy up of vyatta-vti-config.pl

Remove old comments and other minor tidying up / rearranging of
scripts/vyatta-vti-config.pl

013fd2ac5dc2cd426d85e850496bb826cb483109 authored about 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: validate local address for vti based vpn connections

Validate the local address used for VTI based VPN connections to ensure
only either an IPv4 or I...

33140773880aa3f4a94426c35c667096259d9c3d authored about 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: vti interfaces remain link down after ipsec sa renewal

VTI interfaces can remain link down after IPSec SA expiry and renewal,
leaving the actual IPSec ...

9254caf8bd4d8dfc0e76f1eb5958e6ebcdf1032d authored about 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: validate peer address for vti based vpn connections

Validate the peer address used for VTI based VPN connections to ensure
only either an IPv4 or IP...

209d0ae7650cb76a18feedaf75052eb03036c184 authored about 9 years ago by Alex Harpin <[email protected]>
Bug #469: add options for AES-128/256-GCM mode.

fcab32f8c5cc416829dc054a41e578eae45951fa authored about 9 years ago by Daniil Baturin <[email protected]>
Move execution of nhrp script to "end" of ipsec config so it executes on all changes made

to the ipsec config

c9484a3906157a059b02c7619df4617ab8e2dee1 authored about 9 years ago by Kim Hagen <[email protected]>
Add ChaCha20 Poly1305 cipher as an available cipher for IKE exchanges.

Starting with strongSwan 5.3.3, chacha20poly1305 is a supported cipher for
IKE and ESP configura...

e35a282eef077d8cc91e8e5fd7b7a1dcf91750c4 authored about 9 years ago by Jeff Leung <[email protected]>
Whitespace fixes

f179c69fcfd84d4889aec93bf87fdb265106f29e authored about 9 years ago by Jeff Leung <[email protected]>
Allow the user to include a custom ipsec.secrets file.

This may be useful for scenarios where a user prefers to use an ECDSA key
or implement an xauth ...

bb0034b11cbb5797e5a3e820fd7c9416964f91eb authored about 9 years ago by Jeff Leung <[email protected]>
Actually implement custom ipsec.conf files

8aa86bf3a045c51bae264a5716dd3d9c1063411e authored about 9 years ago by Jeff Leung <[email protected]>
0.12.105+vyos2+lithium17

5c1672341b33dc726da5d7845725bd74e3cc7cb6 authored over 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: validate local address for vti based vpn connections

Validate the local address used for VTI based VPN connections to ensure
only either an IPv4 or I...

dc093ef387d2514c3b81b0766dda8bdc78890129 authored over 9 years ago by Alex Harpin <[email protected]>
0.12.105+vyos2+lithium16

6237d4de2e8c64c1de42c42a070ef74907810dd7 authored over 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: validate peer address for vti based vpn connections

Validate the peer address used for VTI based VPN connections to ensure
only either an IPv4 or IP...

831e28ad6ea858dd434ca95bcf8bc6a76476b880 authored over 9 years ago by Alex Harpin <[email protected]>
0.12.105+vyos2+lithium15

64fb9c14f25580ee6412643566c90879cd247ff1 authored over 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: vti interfaces remain link down after ipsec sa renewal

VTI interfaces can remain link down after IPSec SA expiry and renewal,
leaving the actual IPSec ...

37d78aacd2ff84a3b462ea70c5b72e027378de73 authored over 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: further tidy up of vyatta-vti-config.pl

Remove old comments and other minor tidying up / rearranging of
scripts/vyatta-vti-config.pl

20acaff5f8a6215fd7c5b89c6405261deb069f87 authored over 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: formatting changes for style consistency

Perltidy run on scripts/vyatta-vti-config.pl to have consistent
identation levels and style thro...

5667f7acff29152be79f60585c92cd4e0370fd08 authored over 9 years ago by Alex Harpin <[email protected]>
0.12.105+vyos2+lithium14

e0df1591e69b4228af9cb695853cb7c67fed6e2d authored over 9 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: update dh_gencontrol with new development build flag

e4899aa23be30061fa94bd9c19b17431e299b709 authored over 9 years ago by Alex Harpin <[email protected]>
0.12.105+vyos2+lithium13

88aac84e3e49fd179ab2c75d8563c231aeda4926 authored over 9 years ago by Daniil Baturin <[email protected]>
Bug #504: add an option for pulling IPsec local id from the cert.

5bfd6dcf50a76a9427141cc3d62f23f8be7f4543 authored over 9 years ago by Daniil Baturin <[email protected]>
Merge pull request #1 from ryanriske/lithium-strongswan5-rsa

Update support for RSA keys with strongSwan 5.2.x

070c754a733258a4b6900b01dd3ec141debcc9a8 authored over 9 years ago by Jeff Leung <[email protected]>
0.12.105+vyos2+lithium12

321419cbd0cb81a8573316fb84a6bbbc20aa29f4 authored over 9 years ago by Daniil Baturin <[email protected]>
Bug #469: add options for AES-128/256-GCM mode.

a914ffc44c888dc2591965c36363aa2a8de4a3bd authored over 9 years ago by Daniil Baturin <[email protected]>
0.12.105+vyos2+lithium11

158f7b865099010be751517d65c223c12c60dbdd authored almost 10 years ago by Alex Harpin <[email protected]>
Fix ipsec.secrets generation for PEM-formatted RSA key.

6656e3ae1a2e9a1b4bb7d8eecf320f840b6837c2 authored almost 10 years ago by Ryan Riske <[email protected]>
Exclude '0s' from public key string input in rsa_convert_pubkey_pem

57d284aded5003468dee946f906bf88f09a79d5a authored almost 10 years ago by Ryan Riske <[email protected]>
Add support for RSA keys with strongSwan 5.2.x

strongSwan 5.2.x no longer recognizes keys in RFC 3110 format inlined in
ipsec.conf and ipsec.se...

7c6c1e2073207612a2d819471bc680564c945cc7 authored almost 10 years ago by Ryan Riske <[email protected]>
Move execution of nhrp script to "end" of ipsec config so it executes on all changes made

to the ipsec config

2e30fd044c830bddae7e4951b46b2346d7e3fbc0 authored almost 10 years ago by Kim Hagen <[email protected]>
Remove the automatic generation of implicit connections

Since charon's existence, generating them is redundant and as a matter of fact
causes issues wit...

7d94dd6e4d32eef9cea4a4f7270b0ea0d895dd12 authored almost 10 years ago by Jeff Leung <[email protected]>
Allow the user to force UDP encapsulation for a named peer

This might help with strongSwan traversing through firewalls that
filter proto 51, but not UDP t...

c6864b6ca7c18ab4ec248186e1310e46b7a97676 authored almost 10 years ago by Jeff Leung <[email protected]>
0.12.105+vyos2+lithium10

6d36ea1fce45ec0cf4e085b5e8c441fd71659f54 authored almost 10 years ago by Alex Harpin <[email protected]>
Removing generation of leftsourceip= parameter in ipsec.conf

As confirmed by Thermi in the strongSwan IRC channel inside freenode,
this parameter should not ...

a69985d6853537d296027be5d2d1c44d73fbeccc authored almost 10 years ago by Jeff Leung <[email protected]>
Slightly alter aggressive mode selection logic

If the user defines main mode, the config script will always enable
aggressive mode. Fix the log...

6b652b14199b748089f50bc417b7866300cd0a2f authored almost 10 years ago by Jeff Leung <[email protected]>
Correct typo'd aggressive option

Originally we meant aggressive, not ikev2

832208422595261e1044890c18c16998a9aaf421 authored almost 10 years ago by Jeff Leung <[email protected]>
Remove the code that generates our ipsec logger at runtime

Since we're invoking the logger at runtime, there's really no point
on keeping this codeblock

3a343f34372c4d2a920758161b864d74c685f570 authored almost 10 years ago by Jeff Leung <[email protected]>
Configure the ipsec debug logger at runtime

Instead of configuring the ipsec logger at config time, configure
it at runtime. The codeblock t...

0e4aed338c5a72b93931f7e16afae4246347be6a authored almost 10 years ago by Jeff Leung <[email protected]>
Merge remote branch 'origin/lithium' into lithium-strongswan5

f0493b3e300c9553c9a2fbe813ef02de0af41e3f authored almost 10 years ago by Jeff Leung <[email protected]>
Properly clean up site-to-site tunnels on removal

strongSwan's charon by design maintains all established connections
regardless, even if the conn...

8852024ad3e33f30c893d02c31031393080ab816 authored almost 10 years ago by Jeff Leung <[email protected]>
Update references from pluto.ctl to charon.ctl

This needs to be updated or VPN configurations won't be properly
handled on subsequent updates.

29666fa797d4cd62fbfc7fb9f8532f36196e78cc authored almost 10 years ago by Jeff Leung <[email protected]>
Remove the default value in ipsec ike-group $name mode

Setting this to a default value breaks ikev2 configurations since
aggressive mode is only applic...

82c41cedf5a295ebd2ad28700c4c9a5c9b5a91d3 authored almost 10 years ago by Jeff Leung <[email protected]>
Use ipsec reload instead of update

For some odd reason doing an ipsec update does not make charon
pick up any newly created tunnels...

91f54b8d8ca8565371006beb38e978c726192188 authored almost 10 years ago by Jeff Leung <[email protected]>
Update ipsec logging log-modes to point towards charon's loggers

log-modes now expose charon's keywords instead of pluto's keywords.

Refer to the strongSwan's m...

cb76ae8fbdffa0c8dee28b95867776955806f025 authored almost 10 years ago by Jeff Leung <[email protected]>
Allow users to specify a custom file to be included with ipsec.conf

a64d08fe6cfbc6275c2682fbe92d4856334deec2 authored almost 10 years ago by Jeff Leung <[email protected]>
Allow users to specify aggressive mode for IKEv1 key exchanges

Although strongly not recommended by the developers of strongSwan,
sometimes remote VPN gateways...

de318d8d25427a27c80206c16dc36c0021dfca2c authored almost 10 years ago by Jeff Leung <[email protected]>
Bug #367 - DMVPN Testing, but I do not see ESP traffic.

1be0e699d43e2ea72b791c502749d78d9acc9e84 authored almost 10 years ago by Kim Hagen <[email protected]>
Removing pfs and pfsgroup parameter generation

In strongSwan 5.0.0 and later series, pfs= and pfsgroup= parameters have
now been removed.

9d20c1dc27d91e362e79221dd773dd9418d5af99 authored almost 10 years ago by Jeff Leung <[email protected]>
Generate PFS group settings alongside with our ESP settings

Since strongSwan 5.0.0, defining the PFS group settings has moved in the
esp= parameter.

If PFS...

d1618604bde40ae38ba3b587e655f16948212917 authored almost 10 years ago by Jeff Leung <[email protected]>
Have the IKE parameter parser to use our new get_dh_cipher_result submodule

The IKE parameter parser now uses the new get_dh_cipher_result submodule
instead of the old if/e...

9587a7eb06ecef9610260657d98736d8286feab0 authored almost 10 years ago by Jeff Leung <[email protected]>
Add get_dh_cipher_result submodule

By adding this submodule we can reduce the amount of code we need to
maintain by having a single...

c3240731283eb3128bf5654b3e4ffb1ae81a0718 authored almost 10 years ago by Jeff Leung <[email protected]>
Removing charonstart from the config setup section

In preperation of moving towards the strongSwan 5.x series, we are
removing the legacy charonsta...

d72efb828bd9bb88a6fb6d219b2b1cb88406507e authored almost 10 years ago by Jeff Leung <[email protected]>
0.12.105+vyos2+lithium9

791097277d7ec62cc6c3f9b418d75b4a1a713759 authored almost 10 years ago by Daniil Baturin <[email protected]>
Remove @ from the id/remote-id help string. It was never required.

c17fd43333abc10cd0c9f644e2cb66b87064be00 authored almost 10 years ago by Daniil Baturin <[email protected]>
0.12.105+vyos2+lithium8

d7a394249c54dc951b8e78d2294b9e9c50612204 authored almost 10 years ago by Daniil Baturin <[email protected]>
Bug #348: remove unnecessary restrictions on the PSK format.

a020c3ac4bb4bb22d909261d370811d35e9799b8 authored almost 10 years ago by Daniil Baturin <[email protected]>
0.12.105+vyos2+lithium7

5cf14ba5c537a4df57522e0b54a44b8912168be6 authored almost 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: update pre-shared secret key help for single quotes

Updated the help for pre-shared secret key usage when special
characters are used. These need t...

2e341aac4ed4df5481f58505c6ea0425bf93dc98 authored almost 10 years ago by Alex Harpin <[email protected]>
0.12.105+vyos2+lithium6

90057becb0a3aac0636282b43aaf8b7ac4e7b967 authored about 10 years ago by Alex Harpin <[email protected]>
Update maintainer address

993f47c0d9eac439ae6d698a75d2e6e6b98a963d authored about 10 years ago by Alex Harpin <[email protected]>
0.12.105+vyos2+lithium5

831009e4c755e1e0ea16e5931b0416a21430d4a6 authored about 10 years ago by Daniil Baturin <[email protected]>
Bug #415: use remote-id for peer ID unconditionally if it's set.

9ebf737b55b8974edac26d1275c77da15a6199a2 authored about 10 years ago by Daniil Baturin <[email protected]>
Bug #414: quote the leftid value to avoid problems with non-alphanumeric characters.

abd609b8947b8d731b0a1fa084c724b08dcbf3a6 authored about 10 years ago by Daniil Baturin <[email protected]>
Merge pull request #11 from jhendryUK/ikev2_reauth_option

Ikev2 reauth option

7b0e7ce1c46cec565952b18a5044f7bc7be82196 authored about 10 years ago by Daniil Baturin <[email protected]>
0.12.105+vyos2+lithium4

478615bf9d92e79b66d89c37473b4bd457a76260 authored about 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: remove the cfgvti helper program

The cfgvti helper program was originally added for configuring VTIs.
The functionality it provid...

d8400e8a419c2d2566517f011b6e1e9e8d7c6614 authored about 10 years ago by Alex Harpin <[email protected]>
0.12.105+vyos2+lithium3

a304c0754bdbf7cf70d30d12aac59c21f813dcf7 authored about 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: formatting changes for style consistency

Update lib/Vyatta/VPN/vtiIntf.pm to have consistent identation levels
and style throughout.

d5448365594d4980e3ee15e18cfb33ff74a80871 authored about 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: reduce the vti mark base to prevent integer overflow

Reduce the vtiMarkBase value to prevent integer overflow on the created
ip xfrm states and polic...

0730a384b600b122a49c9c2332544cfaa71780cb authored about 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: update vti creation in line with changes to strongswan

Update the VTI creation process to go along with the changes added to
the vyatta-strongswan pack...

e8b6f69422f26b85008e640a3d8f6f4726571db6 authored about 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: update parseVtiTun to account for vti changes

Update the parseVtiTun function to account for the new way of
configuring VTIs.

Bug #358 http:/...

09f1979c4bf0cfe1e1c60ca48b4d9be3cc5e0454 authored about 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: move scripts/vtiIntf.pm to lib/Vyatta/VPN/vtiIntf.pm

Move vtiIntf.pm to a more logical place, in line with all the other
packages.

d145e830c27ba601d27b6130e54accce65186dda authored about 10 years ago by Alex Harpin <[email protected]>
Fixing syntax error in vpn-config.pl, fixing allowed parameters in the per-tunnel ikev2-reauth node

259abd0641a999e390d67cb424c9093e1c0f72bf authored about 10 years ago by Jason Hendry <[email protected]>
Exposing ikev2 reauth option in CLI, defaulting to 'no'

ae063db6eb21bb52ae5e995dfa4bef195de599be authored about 10 years ago by Jason Hendry <[email protected]>
0.12.105+vyos2+lithium2

dd17f6db97ad7e7f58e371e4b6f3ca5eceb4f3a0 authored about 10 years ago by Daniil Baturin <[email protected]>
Update changelog for the new branch.

d6bdf4f5edda42d0cef7b9146c0b9477e6a4f7a5 authored about 10 years ago by Daniil Baturin <[email protected]>
0.12.105+vyos1+helium4

15caf2de5ee1f40568c30b3276f305a5708276ac authored about 10 years ago by Daniil Baturin <[email protected]>
Remove the VTI script after use.

d4221b8a5b38333e57b2fd5f8c42b7316fc8df59 authored about 10 years ago by Daniil Baturin <[email protected]>
0.12.105+vyos1+helium3

8f276005e1e0fd61801b98e3e8e2bb90c15005c3 authored over 10 years ago by Daniil Baturin <[email protected]>
Merge pull request #10 from cyclops8456/helium

Commits for Bug #291 and Bug #332

be48755c2d00210f8c80696aea3b4be74bff0247 authored over 10 years ago by Daniil Baturin <[email protected]>
vyatta-cfg-vpn: prevent duplicate local rsa key includes

Prevent duplicate include statements, for the local rsa keys, being
added to the ipsec.secrets f...

46ed80c828754c052d4d448fdc9563c89f917fda authored over 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: formatting changes for style consistency

Update scripts/vpn-config.pl to have consistent identation levels and
style throughout.

1d2040456666b91963dbe5fd704e2f496c76974f authored over 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: rename vti-up-down.sh to vti-up-down

Rename vti-up-down.sh to vti-up-down to be consistent with others.

a45c529838e42e5584b9cb991c893d1675054b35 authored over 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: fix for vti interface going down remains routed

Revert the fix put in place for Bug #183 as this causes multiple routes
to be installed when mor...

c53fca329e2ff49625321c516917896d566add6e authored over 10 years ago by Alex Harpin <[email protected]>
Merge pull request #9 from cyclops8456/helium

vyatta-cfg-vpn: add libnfnetlink-dev to build dependencies

62253b1ddf16631ec772cb8ff480d35bd989ffb6 authored over 10 years ago by Daniil Baturin <[email protected]>
vyatta-cfg-vpn: updated the debian package maintainer address

c72ae615426b77084e62672eaa62f6f40ba7e2c8 authored over 10 years ago by Alex Harpin <[email protected]>
vyatta-cfg-vpn: add libnfnetlink-dev to build dependencies

Add libnfnetlink-dev to the list of build dependencies, required for
compiling src/cfgcti.

Bug ...

cf2c33b51d1799a70bb1b685edf1467f612c88d2 authored over 10 years ago by Alex Harpin <[email protected]>
Remove gre-multipoint reference

f1db9734ca1538f7bfc4829f53d56047fa921c32 authored over 10 years ago by Kim Hagen <[email protected]>
Rename vyatta-update-nhrp.pl to vyos-update-nhrp.pl and change options

65a56dafd8acb7caa09a47a8e013472c6a03a016 authored over 10 years ago by Kim Hagen <[email protected]>