rwclient Cleartext-Password := "passw0rd", Simultaneous-Use := "1" Framed-IP-Address = 192.168.10.99, Framed-IP-Netmask = 255.255.255.255, Framed-Route = "10.99.0.0/24 192.168.10.1 1"
EnabledBackend: radius-servereverything else UNSET
Respond onlyIKEv1 mainMutual PSK + XauthIP address identifier<psk>AES256 SHA256 PFS14Lifetime 28800everything else UNSET
IPv4 tunnelLAN subnetAES256 SHA256 PFS14Lifetime 3600everything else UNSET
conn opnsense keyexchange=ikev1 aggressive=no ike=aes256-sha256-modp2048 esp=aes256-sha256-modp2048 auto=start authby=xauthpsk leftid=rwclient leftsourceip=%modeconfig right=<opnsense pub ip> rightid=<opnsense pub ip> rightsubnet=10.99.0.0/24
<opnsense pub ip> : PSK "<psk>"rwclient: XAUTH "passw0rd"
2022-11-01T14:35:55 Informational charon 05[ENC] <con2|8> generating INFORMATIONAL_V1 request 1520615772 [ HASH N(INVAL_ID) ] 2022-11-01T14:35:55 Informational charon 05[IKE] <con2|8> no matching CHILD_SA config found for 192.168.1.105/32 === 10.99.0.0/24 2022-11-01T14:35:55 Informational charon 05[ENC] <con2|8> parsed QUICK_MODE request 1074724946 [ HASH SA No KE ID ID ] 2022-11-01T14:35:55 Informational charon 05[NET] <con2|8> received packet: from 217.140.xxx.xxx[46716] to 10.254.1.5[4500] (460 bytes) 2022-11-01T14:35:55 Informational charon 05[NET] <con2|8> sending packet: from 10.254.1.5[4500] to 217.140.xxx.xxx[46716] (76 bytes) 2022-11-01T14:35:55 Informational charon 05[ENC] <con2|8> generating TRANSACTION response 1061020512 [ HASH CP ] 2022-11-01T14:35:55 Informational charon 05[IKE] <con2|8> no virtual IP found for %any requested by 'rwclient' 2022-11-01T14:35:55 Informational charon 05[IKE] <con2|8> peer requested virtual IP %any
2022-11-01T14:40:10 Informational charon 11[IKE] <con2|9> CHILD_SA con2{22} established with SPIs cc662891_i cc66c029_o and TS 10.99.0.0/24 === 192.168.99.1/32 2022-11-01T14:40:10 Informational charon 11[ENC] <con2|9> parsed QUICK_MODE request 323113376 [ HASH ] 2022-11-01T14:40:10 Informational charon 11[NET] <con2|9> received packet: from 217.140.xxx.xxx[46716] to 10.254.1.5[4500] (76 bytes) 2022-11-01T14:40:10 Informational charon 11[NET] <con2|9> sending packet: from 10.254.1.5[4500] to 217.140.xxx.xxx[46716] (460 bytes) 2022-11-01T14:40:10 Informational charon 11[ENC] <con2|9> generating QUICK_MODE response 323113376 [ HASH SA No KE ID ID ] 2022-11-01T14:40:10 Informational charon 11[CFG] <con2|9> selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/MODP_2048/NO_EXT_SEQ 2022-11-01T14:40:10 Informational charon 11[ENC] <con2|9> parsed QUICK_MODE request 323113376 [ HASH SA No KE ID ID ] 2022-11-01T14:40:10 Informational charon 11[NET] <con2|9> received packet: from 217.140.xxx.xxx[46716] to 10.254.1.5[4500] (460 bytes) 2022-11-01T14:40:10 Informational charon 11[NET] <con2|9> sending packet: from 10.254.1.5[4500] to 217.140.xxx.xxx[46716] (188 bytes) 2022-11-01T14:40:10 Informational charon 11[ENC] <con2|9> generating TRANSACTION response 3117777291 [ HASH CPRP(ADDR SUBNET SUBNET SUBNET SUBNET U_SPLITINC U_SPLITINC U_SPLITINC U_SPLITINC) ] 2022-11-01T14:40:10 Informational charon 11[IKE] <con2|9> assigning virtual IP 192.168.99.1 to peer 'rwclient' 2022-11-01T14:40:10 Informational charon 11[CFG] <con2|9> assigning new lease to 'rwclient' 2022-11-01T14:40:10 Informational charon 11[IKE] <con2|9> peer requested virtual IP %any
User: rwclient authenticated successfully.This user is a member of these groups:Attributes received from server:Framed-IP-Address => 192.168.10.99Framed-IP-Netmask => 255.255.255.255Framed-Route => 10.99.0.0/24 192.168.10.1 1
conn opnsense auto=start keyexchange=ikev2 ike=aes256-sha256-modp2048 esp=aes256-sha256-modp2048 leftid=rwclient leftauth=eap-md5 leftsourceip=%modeconfig leftsendcert=no right=<opnsense pub ip> rightid=rwserver rightsubnet=10.99.0.0/24 closeaction=restart dpdaction=restart keyingtries=%forever
rwclient : EAP "passw0rd"
2022-11-11T13:03:30 Informational charon 07[IKE] <con2|398> assigning virtual IP 192.168.10.99 to peer 'rwclient' 2022-11-11T13:03:30 Informational charon 07[IKE] <con2|398> peer requested virtual IP %any