<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=IPSec%3A_ESP_Tunnel_di_UBuntu_untuk_IPv6</id>
	<title>IPSec: ESP Tunnel di UBuntu untuk IPv6 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=IPSec%3A_ESP_Tunnel_di_UBuntu_untuk_IPv6"/>
	<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_UBuntu_untuk_IPv6&amp;action=history"/>
	<updated>2026-05-07T04:49:21Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.4</generator>
	<entry>
		<id>https://onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_UBuntu_untuk_IPv6&amp;diff=43702&amp;oldid=prev</id>
		<title>Onnowpurbo: New page: IPv6 Enkripsi: Contoh IPsec Tunnel Menggunakan racoon   Pada kesempatan ini akan di berikan contoh untuk membuat Ipsec tunnel menggunakan racoon pada dua gateway Linux berbasis sistem oper...</title>
		<link rel="alternate" type="text/html" href="https://onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_UBuntu_untuk_IPv6&amp;diff=43702&amp;oldid=prev"/>
		<updated>2015-07-07T02:05:20Z</updated>

		<summary type="html">&lt;p&gt;New page: IPv6 Enkripsi: Contoh IPsec Tunnel Menggunakan racoon   Pada kesempatan ini akan di berikan contoh untuk membuat Ipsec tunnel menggunakan racoon pada dua gateway Linux berbasis sistem oper...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;IPv6 Enkripsi: Contoh IPsec Tunnel Menggunakan racoon &lt;br /&gt;
&lt;br /&gt;
Pada kesempatan ini akan di berikan contoh untuk membuat Ipsec tunnel menggunakan racoon pada dua gateway Linux berbasis sistem operasi Ubuntu 14.04.&lt;br /&gt;
&lt;br /&gt;
 Gateway A: IPv6 2001:470:19:b37::100/64	VPN Network: 2002::/64&lt;br /&gt;
 Gateway B: IPv6 2001:470:19:b37::101/64	VPN Network: 2003::/64&lt;br /&gt;
&lt;br /&gt;
==Kernel IP Forwarding==&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A dan Gateway B, kita perlu mengaktifkan kernel IP forwarding ,&lt;br /&gt;
&lt;br /&gt;
 echo 1 &amp;gt; /proc/sys/net/ipv4/conf/all/forwarding&lt;br /&gt;
 echo 1 &amp;gt; /proc/sys/net/ipv6/conf/all/forwarding&lt;br /&gt;
&lt;br /&gt;
==Instalasi racoon dan ipsec-tools==&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A dan Gateway B, instalasi:&lt;br /&gt;
&lt;br /&gt;
 # apt-get update&lt;br /&gt;
 # apt-get install racoon ipsec-tools &lt;br /&gt;
&lt;br /&gt;
Pada pertanyaan “Configuration mode for racoon IKE daemon:” jawab “direct”&lt;br /&gt;
&lt;br /&gt;
==Konfigurasi racoon==&lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway A===&lt;br /&gt;
&lt;br /&gt;
Gateway A Konfigurasi /etc/racoon/racoon.conf &lt;br /&gt;
&lt;br /&gt;
 log notify;&lt;br /&gt;
 path pre_shared_key &amp;quot;/etc/racoon/psk.txt&amp;quot;;&lt;br /&gt;
 path certificate &amp;quot;/etc/racoon/certs&amp;quot;;&lt;br /&gt;
 remote 2001:470:19:b37::101 { &lt;br /&gt;
         exchange_mode main,aggressive; &lt;br /&gt;
         proposal { &lt;br /&gt;
                 encryption_algorithm 3des; &lt;br /&gt;
                 hash_algorithm sha1; &lt;br /&gt;
                 authentication_method pre_shared_key; &lt;br /&gt;
                 dh_group 2; &lt;br /&gt;
         } &lt;br /&gt;
 } &lt;br /&gt;
 &lt;br /&gt;
 sainfo address 2002::/64 any address 2003::/64 any { &lt;br /&gt;
         pfs_group 2; &lt;br /&gt;
         lifetime time 1 hour ; &lt;br /&gt;
         encryption_algorithm 3des, blowfish 448, rijndael ; &lt;br /&gt;
         authentication_algorithm hmac_sha1, hmac_md5 ; &lt;br /&gt;
         compression_algorithm deflate ; &lt;br /&gt;
 } &lt;br /&gt;
&lt;br /&gt;
Gateway A Konfigurasi /etc/racoon/psk.txt &lt;br /&gt;
&lt;br /&gt;
 2001:470:19:b37::101 a9993e364706816aba3e &lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway B===&lt;br /&gt;
&lt;br /&gt;
Gateway B Konfigurasi /etc/racoon/racoon.conf &lt;br /&gt;
&lt;br /&gt;
 log notify;&lt;br /&gt;
 path pre_shared_key &amp;quot;/etc/racoon/psk.txt&amp;quot;;&lt;br /&gt;
 path certificate &amp;quot;/etc/racoon/certs&amp;quot;;&lt;br /&gt;
 remote 2001:470:19:b37::100 { &lt;br /&gt;
         exchange_mode main,aggressive; &lt;br /&gt;
         proposal { &lt;br /&gt;
                 encryption_algorithm 3des; &lt;br /&gt;
                 hash_algorithm sha1; &lt;br /&gt;
                 authentication_method pre_shared_key; &lt;br /&gt;
                 dh_group 2; &lt;br /&gt;
         } &lt;br /&gt;
 } &lt;br /&gt;
 &lt;br /&gt;
 sainfo address 2003::/64 any address 2002::/64 any { &lt;br /&gt;
         pfs_group 2; &lt;br /&gt;
         lifetime time 1 hour ; &lt;br /&gt;
         encryption_algorithm 3des, blowfish 448, rijndael ; &lt;br /&gt;
         authentication_algorithm hmac_sha1, hmac_md5 ; &lt;br /&gt;
         compression_algorithm deflate ; &lt;br /&gt;
 } &lt;br /&gt;
&lt;br /&gt;
Gateway B Konfigurasi /etc/racoon/psk.txt &lt;br /&gt;
&lt;br /&gt;
 2001:470:19:b37::100  a9993e364706816aba3e &lt;br /&gt;
&lt;br /&gt;
==Security Policies ==&lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway A===&lt;br /&gt;
&lt;br /&gt;
Gateway A Konfigurasi /etc/ipsec-tools.conf &lt;br /&gt;
&lt;br /&gt;
 flush; &lt;br /&gt;
 spdflush; &lt;br /&gt;
 &lt;br /&gt;
 spdadd 2002::/64 2003::/64 any -P out ipsec &lt;br /&gt;
            esp/tunnel/2001:470:19:b37::100-2001:470:19:b37::101/require; &lt;br /&gt;
 spdadd 2003::/64 2002::/64 any -P in ipsec &lt;br /&gt;
            esp/tunnel/2001:470:19:b37::101-2001:470:19:b37::100/require; &lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway B===&lt;br /&gt;
&lt;br /&gt;
Gateway B Konfigurasi /etc/ipsec-tools.conf &lt;br /&gt;
&lt;br /&gt;
 flush; &lt;br /&gt;
 spdflush;  &lt;br /&gt;
 &lt;br /&gt;
 spdadd 2003::/64 2002::/64 any -P out ipsec &lt;br /&gt;
            esp/tunnel/2001:470:19:b37::101-2001:470:19:b37::100/require;&lt;br /&gt;
 spdadd 2002::/64 2003::/64 any -P in ipsec &lt;br /&gt;
            esp/tunnel/2001:470:19:b37::100-2001:470:19:b37::101/require; &lt;br /&gt;
&lt;br /&gt;
==Run==&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A maupun Gateway B jalankan perintah berikut&lt;br /&gt;
&lt;br /&gt;
 /etc/init.d/setkey restart &lt;br /&gt;
 /etc/init.d/racoon restart &lt;br /&gt;
&lt;br /&gt;
Akan tampak&lt;br /&gt;
&lt;br /&gt;
  * Flushing IPsec SA/SP database:                                 [ OK ]&lt;br /&gt;
  * Loading IPsec SA/SP database:                                  [ OK ]&lt;br /&gt;
  * Restarting IKE (ISAKMP/Oakley) server racoon                   [ OK ] &lt;br /&gt;
&lt;br /&gt;
Cek /var/log/syslog &lt;br /&gt;
&lt;br /&gt;
 # tail /var/log/syslog&lt;br /&gt;
&lt;br /&gt;
Akan keluar kira-kira&lt;br /&gt;
 Jul  7 07:42:01 server100 racoon: INFO: @(#)ipsec-tools 0.8.0 (http://ipsec-tools.sourceforge.net)&lt;br /&gt;
 Jul  7 07:42:01 server100 racoon: INFO: @(#)This product linked OpenSSL 1.0.1f 6 Jan 2014 (http://www.openssl.org/)&lt;br /&gt;
 Jul  7 07:42:01 server100 racoon: INFO: Reading configuration from &amp;quot;/etc/racoon/racoon.conf&amp;quot;&lt;br /&gt;
Pastikan tidak ada error. Jika ada error timeout, restart ipsec dan racoon.&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A tambahkan routing&lt;br /&gt;
 ip -6 addr add 2002::1/64 dev eth0 &lt;br /&gt;
 ip -6 route add to 2003::/64 via 2002::1 src 2002::1&lt;br /&gt;
&lt;br /&gt;
Pada Gateway B tambahkan routing&lt;br /&gt;
 ip -6 addr add 2003::1/64 dev eth0 &lt;br /&gt;
 ip -6 route add to 2002::/64 via 2003::1 src 2003::1&lt;br /&gt;
&lt;br /&gt;
Setelah VPN tersambung, coba dari Gateway A:&lt;br /&gt;
&lt;br /&gt;
 ping6 2003::1&lt;br /&gt;
&lt;br /&gt;
==Debugging==&lt;br /&gt;
&lt;br /&gt;
Dari mesin  Gateway B 2001:470:19:b37::101 &lt;br /&gt;
Proses debugging jika dibutuhkan dapat menggunakan tcpdump dengan perintah, misalnya,&lt;br /&gt;
&lt;br /&gt;
 #  tcpdump -t -n -i eth0 -vv ip6 host 2001:470:19:b37::100&lt;/div&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
</feed>