You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

StrongSwan IPSec隧道无法建立及HA配置缺失提示问题排查求助

StrongSwan IPSec隧道无法建立及HA配置缺失提示问题排查求助

各位好,我现在遇到个棘手的问题:我在Raspbian 12系统上部署了StrongSwan,想要从外部网络打通到PfSense的IPSec隧道,但无论怎么调试,隧道都建立不起来。相同的配置在Ubiquiti EdgeRouter ER-X上是能正常工作的,我也试过换成libreSwan,结果还是一样。想请大家帮忙看看问题出在哪。

本地StrongSwan配置(/etc/ipsec.conf)

config setup

conn %default
    keyexchange=ikev1

conn peer-ipsec.xxx.de-tunnel-1
    left=%any
    leftid="xx.zapto.org"
    right=ipsec.xx.de
    rightid="%any"
    leftsubnet=10.130.117.0/24
    rightsubnet=10.128.0.0/16
    ike=aes128-sha256-modp2048,aes128-sha256-modp2048!
    keyexchange=ikev2
    reauth=no
    ikelifetime=28800s
    esp=aes128-sha256-modp2048,aes128-sha256-modp2048!
    keylife=3600s
    rekeymargin=540s
    type=tunnel
    compress=no
    authby=secret
    auto=route
    keyingtries=%forever

PfSense端配置

  • 密钥交换版本:IKEv2
  • 互联网协议:IPv4
  • 远程网关:xx.zapto.org
  • 认证方式:Mutual PSK(预共享密钥)
  • 我的标识符:我的IP地址
  • 对等体标识符:完全限定域名 xx.zapto.org
  • 加密算法:AES 128 bit SHA256 DH Group 14(后续会升级)
  • Phase 2配置:
    • 本地网络:10.128.0.0/0
    • NAT:无
    • 远程网络:10.130.117.0/24
    • 协议:ESP
    • 加密算法:AES 128, AES12-GCM 128 SHA256 PFS密钥组14

本地网络信息

  • 本地IP:192.168.2.117
  • 能正常ping通ipsec.xx.de
  • nftables无任何规则配置

StrongSwan启动日志(sudo /usr/sbin/ipsec start --nofork --debug --debug-more)

Starting strongSwan 5.9.8 IPsec [starter]...
Loading config setup
Loading conn 'peer-ipsec.xx.de-tunnel-1'
authby=secret
auto=route
compress=no
esp=aes128-sha256-modp2048,aes128-sha256-modp2048!
ike=aes128-sha256-modp2048,aes128-sha256-modp2048!
ikelifetime=28800s
keyexchange=ikev2
keyingtries=%forever
keylife=3600s
left=%any
leftid=xx.zapto.org
leftsubnet=10.130.117.0/24
reauth=no
rekeymargin=540s
right=ipsec.xx.de
rightid=%any
rightsubnet=10.128.0.0/16
type=tunnel
Attempting to start charon...
00[DMN] Starting IKE charon daemon (strongSwan 5.9.8, Linux 6.1.0-rpi7-rpi-v8, aarch64)
00[LIB] providers loaded by OpenSSL: legacy default
00[NET] using forecast interface eth1
00[CFG] joining forecast multicast groups: 224.0.0.1,224.0.0.22,224.0.0.251,224.0.0.252,239.255.255.250
00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
00[CFG] loading crls from '/etc/ipsec.d/crls'
00[CFG] loading secrets from '/etc/ipsec.secrets'
00[CFG]   loaded IKE secret for %any %any
00[CFG] loaded 0 RADIUS server configurations
00[CFG] HA config misses local/remote address
00[LIB] loaded plugins: charon aes rc2 sha2 sha1 md5 mgf1 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs12 pgp dnskey sshkey pem openssl pkcs8 fips-prf gmp agent xcbc hmac kdf gcm drbg attr kernel-netlink resolve socket-default connmark forecast farp stroke vici updown eap-identity eap-aka eap-md5 eap-gtc eap-mschapv2 eap-radius eap-tls eap-ttls eap-tnc xauth-generic xauth-eap xauth-pam tnc-tnccs dhcp lookip error-notify certexpire led addrblock unity counters
00[LIB] dropped capabilities, running as uid 0, gid 0
00[JOB] spawning 16 worker threads
charon (14801) started after 140 ms
04[CFG] received stroke: add connection 'peer-ipsec.xx.de-tunnel-1'
04[CFG] added configuration 'peer-ipsec.xx.de-tunnel-1'
05[CFG] received stroke: route 'peer-ipsec.xx.de-tunnel-1'
'peer-ipsec.xx.de-tunnel-1' routed

我的疑问

  1. 明明配置看起来和EdgeRouter上的一致,为什么隧道就是无法建立?
  2. 日志里的HA config misses local/remote address是什么意思?这会不会是导致隧道无法建立的原因?

麻烦各位大佬帮忙分析下,谢谢!

备注:内容来源于stack exchange,提问作者LeifSec

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 11:29:50