首次配置IPSEC遇套接字写入权限问题求助
Hey there, let's break down what's going on with your IPsec setup. The critical error in your logs is error writing to socket: Operation not permitted—this tells us your system is blocking the IKE (Internet Key Exchange) packets needed to establish Phase 1 of the IPsec tunnel. Here's a step-by-step guide to fix this:
Key Checks to Resolve the "Operation Not Permitted" Error
Verify Firewall Rules for IKE Ports
IPsec Phase 1 uses UDP port 500, and NAT-Traversal (if needed) uses UDP port 4500. Make sure your firewall isn't blocking these ports:- List current rules with:
iptables -L -n | grep -E '500|4500'orufw status(if using UFW) - If the ports aren't open, add the necessary rules:
# Allow incoming IKE traffic iptables -A INPUT -p udp --dport 500 -j ACCEPT iptables -A INPUT -p udp --dport 4500 -j ACCEPT # Allow outgoing IKE traffic iptables -A OUTPUT -p udp --dport 500 -j ACCEPT iptables -A OUTPUT -p udp --dport 4500 -j ACCEPT
Don't forget to save your rules (e.g.,
iptables-save > /etc/iptables/rules.v4on Debian/Ubuntu) to keep them after a reboot.- List current rules with:
Check SELinux/AppArmor Restrictions
Security modules like SELinux (common on RHEL/CentOS) or AppArmor (Debian/Ubuntu) might be blocking the IPsec daemon from writing to network sockets:- For SELinux, temporarily disable it to test:
setenforce 0 - Restart your IPsec service (e.g.,
systemctl restart strongswanorsystemctl restart ipsec) - If the tunnel starts working, you'll need to create a permanent SELinux policy to allow the IPsec daemon's network operations. Use these commands to generate and install the policy:
ausearch -m avc -ts recent | audit2allow -M ipsec-custom semodule -i ipsec-custom.pp - For AppArmor, check if the IPsec profile is enforcing:
aa-statusand adjust the profile in/etc/apparmor.d/if needed.
- For SELinux, temporarily disable it to test:
Confirm IPsec Daemon Run Context
Most IPsec daemons (like strongSwan, OpenSwan) require root privileges to operate network sockets. Check if your daemon is running as root:ps aux | grep strongswanIf it's running as a non-root user, update your service configuration to run it as root (this is the default for most setups, but sometimes custom configs change this).
Ensure Required Kernel Modules Are Loaded
IPsec relies on kernel modules likexfrmandipsecto handle encryption and tunneling. Check if they're loaded:lsmod | grep -E 'xfrm|ipsec'If missing, load them manually:
modprobe xfrm_ipsec modprobe xfrm_user modprobe af_keyAdd these modules to
/etc/modules-load.d/ipsec.confto load them on boot.Rule Out NAT Interference
If your machine is behind a NAT router, make sure:- The router forwards UDP 500 and 4500 ports to your local IP
- Your IPsec configuration has NAT-Traversal enabled (look for
nat_traversal=yesin your config file—most daemons enable this by default)
After trying these steps, restart your IPsec service and check the logs again. If the "Operation not permitted" error is gone, you should see progress in establishing the Phase 1 IKE SA.
内容的提问来源于stack exchange,提问作者Synbitz Prowduczions

