Giter Site home page Giter Site logo

trijetscud / vyos-agile-vpn Goto Github PK

View Code? Open in Web Editor NEW
18.0 18.0 7.0 86 KB

This is the source package for enabling an EdgeOS/VyOS router to host IKEv2 (Agile) Remote Access VPNs.

License: GNU General Public License v2.0

Perl 96.45% Makefile 1.58% M4 1.98%

vyos-agile-vpn's People

Contributors

c0defre4k avatar nextgens avatar trijetscud avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar

vyos-agile-vpn's Issues

Static ip with ike rsa or ecdsa

hello
the vpn work perfektly with ecdsa key
but the vpn ip is not static (with l2tp, it's possible but i have other big problem)
is there a solution to implement a static ip per certificate or other solution ?
it's for use in squid/squidguard fot best filtering ;)

edit :
i have search a lot :
it's possible to associate a certtificate client with an ip
like l2tp associate a name with an ip, , it's possible to add in the gui an optionnal association with the client certificate and an ip ?

https://www.strongswan.org/uml/testresults/ikev1/config-payload-push/moon.ipsec.conf

sorry for my bad english ;)

Thank you very much in advance

Cannot disable leftfirewall=yes

Hi,

First of all thank you for the great job you did with this package. It saved me hours of manual configuration to add IKEv2 remote access to my EdgeRouter Lite.

I'm however facing a small annoying issue: On my local network I have several VLANs, one of them being a management VLAN that is isolated from the others (I'm using zone policies on the router to achieve that). It appears that users connected through the remote access have access to everything, including this isolated VLAN.

After investigating a bit, I saw that when "leftfirewall=yes" is set, strongswan prepends rules to the FORWARD chain, thus bypassing all the other rules. I'm not sure it can be easily changed without modifying the strongswan scripts.

So what I would like, is to be able to create my firewall rules manually and then have an option to set leftfirewall to no. Do you think you could add this in a future release ?

Thank you.

Upload debian package for 0.1.1

I noticed the is a GitHub release that adds the necessary OSX/iOS server id key, but no debian release. Could you upload the .deb to the release, and/or provide the recommend build instructions to generate it from source?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.