<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://lms.onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=IPSec%3A_ESP_Tunnel_di_Ubuntu_untuk_IPv4</id>
	<title>IPSec: ESP Tunnel di Ubuntu untuk IPv4 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://lms.onnocenter.or.id/wiki/index.php?action=history&amp;feed=atom&amp;title=IPSec%3A_ESP_Tunnel_di_Ubuntu_untuk_IPv4"/>
	<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_Ubuntu_untuk_IPv4&amp;action=history"/>
	<updated>2026-04-25T17:42:45Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://lms.onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_Ubuntu_untuk_IPv4&amp;diff=43704&amp;oldid=prev</id>
		<title>Onnowpurbo: /* Debugging */</title>
		<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_Ubuntu_untuk_IPv4&amp;diff=43704&amp;oldid=prev"/>
		<updated>2015-07-07T02:14:34Z</updated>

		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Debugging&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 02:14, 7 July 2015&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l145&quot;&gt;Line 145:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 145:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Debugging==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Debugging==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Dari mesin  Gateway B &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;2001:470:19:b37::&lt;/del&gt;101  &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Dari mesin  Gateway B &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;192.168.0.&lt;/ins&gt;101&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Proses debugging jika dibutuhkan dapat menggunakan tcpdump dengan perintah, misalnya,&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Proses debugging jika dibutuhkan dapat menggunakan tcpdump dengan perintah, misalnya,&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #  tcpdump -t -n -i eth0 -vv &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;ip6 &lt;/del&gt;host &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;2001:470:19:b37::&lt;/del&gt;100&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;  #  tcpdump -t -n -i eth0 -vv host &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;192.168.0.&lt;/ins&gt;100&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
	<entry>
		<id>https://lms.onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_Ubuntu_untuk_IPv4&amp;diff=43703&amp;oldid=prev</id>
		<title>Onnowpurbo: New page: IPv6 Enkripsi: Contoh IPsec Tunnel Menggunakan racoon   Pada kesempatan ini akan di berikan contoh untuk membuat Ipsec tunnel menggunakan racoon pada dua gateway Linux berbasis sistem oper...</title>
		<link rel="alternate" type="text/html" href="https://lms.onnocenter.or.id/wiki/index.php?title=IPSec:_ESP_Tunnel_di_Ubuntu_untuk_IPv4&amp;diff=43703&amp;oldid=prev"/>
		<updated>2015-07-07T02:13:58Z</updated>

		<summary type="html">&lt;p&gt;New page: IPv6 Enkripsi: Contoh IPsec Tunnel Menggunakan racoon   Pada kesempatan ini akan di berikan contoh untuk membuat Ipsec tunnel menggunakan racoon pada dua gateway Linux berbasis sistem oper...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;IPv6 Enkripsi: Contoh IPsec Tunnel Menggunakan racoon &lt;br /&gt;
&lt;br /&gt;
Pada kesempatan ini akan di berikan contoh untuk membuat Ipsec tunnel menggunakan racoon pada dua gateway Linux berbasis sistem operasi Ubuntu 14.04.&lt;br /&gt;
&lt;br /&gt;
 Gateway A: 192.168.0.100/24	VPN Network: 10.10.0.0/24&lt;br /&gt;
 Gateway B: 192.168.0.101/24	VPN Network: 10.20.0.0/24&lt;br /&gt;
&lt;br /&gt;
==Kernel IP Forwarding==&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A dan Gateway B, kita perlu mengaktifkan kernel IP forwarding ,&lt;br /&gt;
&lt;br /&gt;
 echo 1 &amp;gt; /proc/sys/net/ipv4/conf/all/forwarding&lt;br /&gt;
 echo 1 &amp;gt; /proc/sys/net/ipv6/conf/all/forwarding&lt;br /&gt;
&lt;br /&gt;
==Instalasi racoon dan ipsec-tools==&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A dan Gateway B, instalasi:&lt;br /&gt;
&lt;br /&gt;
 # apt-get update&lt;br /&gt;
 # apt-get install racoon ipsec-tools &lt;br /&gt;
&lt;br /&gt;
Pada pertanyaan “Configuration mode for racoon IKE daemon:” jawab “direct”&lt;br /&gt;
&lt;br /&gt;
==Konfigurasi racoon==&lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway A===&lt;br /&gt;
&lt;br /&gt;
Gateway A Konfigurasi /etc/racoon/racoon.conf &lt;br /&gt;
&lt;br /&gt;
 log notify;&lt;br /&gt;
 path pre_shared_key &amp;quot;/etc/racoon/psk.txt&amp;quot;;&lt;br /&gt;
 path certificate &amp;quot;/etc/racoon/certs&amp;quot;;&lt;br /&gt;
 remote 192.168.0.101 { &lt;br /&gt;
         exchange_mode main,aggressive; &lt;br /&gt;
         proposal { &lt;br /&gt;
                 encryption_algorithm 3des; &lt;br /&gt;
                 hash_algorithm sha1; &lt;br /&gt;
                 authentication_method pre_shared_key; &lt;br /&gt;
                 dh_group 2; &lt;br /&gt;
         } &lt;br /&gt;
 } &lt;br /&gt;
 &lt;br /&gt;
 sainfo address 10.10.0.0/24 any address 10.20.0.0/24 any { &lt;br /&gt;
         pfs_group 2; &lt;br /&gt;
         lifetime time 1 hour ; &lt;br /&gt;
         encryption_algorithm 3des, blowfish 448, rijndael ; &lt;br /&gt;
         authentication_algorithm hmac_sha1, hmac_md5 ; &lt;br /&gt;
         compression_algorithm deflate ; &lt;br /&gt;
 } &lt;br /&gt;
&lt;br /&gt;
Gateway A Konfigurasi /etc/racoon/psk.txt &lt;br /&gt;
&lt;br /&gt;
 192.168.0.101 a9993e364706816aba3e &lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway B===&lt;br /&gt;
&lt;br /&gt;
Gateway B Konfigurasi /etc/racoon/racoon.conf &lt;br /&gt;
&lt;br /&gt;
 log notify;&lt;br /&gt;
 path pre_shared_key &amp;quot;/etc/racoon/psk.txt&amp;quot;;&lt;br /&gt;
 path certificate &amp;quot;/etc/racoon/certs&amp;quot;;&lt;br /&gt;
 remote 192.168.0.100 { &lt;br /&gt;
         exchange_mode main,aggressive; &lt;br /&gt;
         proposal { &lt;br /&gt;
                 encryption_algorithm 3des; &lt;br /&gt;
                 hash_algorithm sha1; &lt;br /&gt;
                 authentication_method pre_shared_key; &lt;br /&gt;
                 dh_group 2; &lt;br /&gt;
         } &lt;br /&gt;
 } &lt;br /&gt;
 &lt;br /&gt;
 sainfo address 10.20.0.0/24 any address 10.10.0.0/24 any { &lt;br /&gt;
         pfs_group 2; &lt;br /&gt;
         lifetime time 1 hour ; &lt;br /&gt;
         encryption_algorithm 3des, blowfish 448, rijndael ; &lt;br /&gt;
         authentication_algorithm hmac_sha1, hmac_md5 ; &lt;br /&gt;
         compression_algorithm deflate ; &lt;br /&gt;
 } &lt;br /&gt;
&lt;br /&gt;
Gateway B Konfigurasi /etc/racoon/psk.txt &lt;br /&gt;
&lt;br /&gt;
 192.168.0.100  a9993e364706816aba3e &lt;br /&gt;
&lt;br /&gt;
==Security Policies ==&lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway A===&lt;br /&gt;
&lt;br /&gt;
Gateway A Konfigurasi /etc/ipsec-tools.conf &lt;br /&gt;
&lt;br /&gt;
 flush; &lt;br /&gt;
 spdflush; &lt;br /&gt;
 &lt;br /&gt;
 spdadd 10.10.0.0/24 10.20.0.0/24 any -P out ipsec &lt;br /&gt;
            esp/tunnel/192.168.0.100-192.168.0.101/require; &lt;br /&gt;
 spdadd 10.20.0.0/24 10.10.0.0/24 any -P in ipsec &lt;br /&gt;
            esp/tunnel/192.168.0.101-192.168.0.100/require; &lt;br /&gt;
&lt;br /&gt;
===Konfigurasi Gateway B===&lt;br /&gt;
&lt;br /&gt;
Gateway B Konfigurasi /etc/ipsec-tools.conf &lt;br /&gt;
&lt;br /&gt;
 flush; &lt;br /&gt;
 spdflush;  &lt;br /&gt;
 &lt;br /&gt;
 spdadd 10.20.0.0/24 10.10.0.0/24 any -P out ipsec &lt;br /&gt;
            esp/tunnel/192.168.0.101-192.168.0.100/require;&lt;br /&gt;
 spdadd 10.10.0.0/24 10.20.0.0/24 any -P in ipsec &lt;br /&gt;
            esp/tunnel/192.168.0.100-192.168.0.101/require; &lt;br /&gt;
&lt;br /&gt;
==Run==&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A maupun Gateway B jalankan perintah berikut&lt;br /&gt;
&lt;br /&gt;
 /etc/init.d/setkey restart &lt;br /&gt;
 /etc/init.d/racoon restart &lt;br /&gt;
&lt;br /&gt;
Akan tampak&lt;br /&gt;
&lt;br /&gt;
  * Flushing IPsec SA/SP database:                                 [ OK ]&lt;br /&gt;
  * Loading IPsec SA/SP database:                                  [ OK ]&lt;br /&gt;
  * Restarting IKE (ISAKMP/Oakley) server racoon                   [ OK ] &lt;br /&gt;
&lt;br /&gt;
Cek /var/log/syslog &lt;br /&gt;
&lt;br /&gt;
 # tail /var/log/syslog&lt;br /&gt;
&lt;br /&gt;
Akan keluar kira-kira&lt;br /&gt;
 Jul  7 07:42:01 server100 racoon: INFO: @(#)ipsec-tools 0.8.0 (http://ipsec-tools.sourceforge.net)&lt;br /&gt;
 Jul  7 07:42:01 server100 racoon: INFO: @(#)This product linked OpenSSL 1.0.1f 6 Jan 2014 (http://www.openssl.org/)&lt;br /&gt;
 Jul  7 07:42:01 server100 racoon: INFO: Reading configuration from &amp;quot;/etc/racoon/racoon.conf&amp;quot;&lt;br /&gt;
Pastikan tidak ada error. Jika ada error timeout, restart ipsec dan racoon.&lt;br /&gt;
&lt;br /&gt;
Pada Gateway A tambahkan routing&lt;br /&gt;
 ip addr add 10.10.0.1/24 dev eth0 &lt;br /&gt;
 ip route add to 10.20.0.0/24 via 10.10.0.1 src 10.10.0.1&lt;br /&gt;
&lt;br /&gt;
Pada Gateway B tambahkan routing&lt;br /&gt;
 ip addr add 10.20.0.1/24 dev eth0 &lt;br /&gt;
 ip route add to 10.10.0.0/24 via 10.20.0.1 src 10.20.0.1&lt;br /&gt;
&lt;br /&gt;
Setelah VPN tersambung, coba dari Gateway A:&lt;br /&gt;
&lt;br /&gt;
 ping 10.20.0.1&lt;br /&gt;
&lt;br /&gt;
==Debugging==&lt;br /&gt;
&lt;br /&gt;
Dari mesin  Gateway B 2001:470:19:b37::101 &lt;br /&gt;
Proses debugging jika dibutuhkan dapat menggunakan tcpdump dengan perintah, misalnya,&lt;br /&gt;
&lt;br /&gt;
 #  tcpdump -t -n -i eth0 -vv ip6 host 2001:470:19:b37::100&lt;/div&gt;</summary>
		<author><name>Onnowpurbo</name></author>
	</entry>
</feed>