home.social

#strongswan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #strongswan, aggregated by home.social.

fetched live
  1. Following upstream, IKEv1 protocol has been disabled in Debian strongSwan package in unstable. Stable users still using it should plan their migration to IKEv2.

    More details at corsac.net/index.php?rub=blog& and strongswan.org/blog/2026/09/07

    #debian #ipsec #strongswan #ikev2

  2. Following upstream, IKEv1 protocol has been disabled in Debian strongSwan package in unstable. Stable users still using it should plan their migration to IKEv2.

    More details at corsac.net/index.php?rub=blog& and strongswan.org/blog/2026/09/07

    #debian #ipsec #strongswan #ikev2

  3. Following upstream, IKEv1 protocol has been disabled in Debian strongSwan package in unstable. Stable users still using it should plan their migration to IKEv2.

    More details at corsac.net/index.php?rub=blog& and strongswan.org/blog/2026/09/07

    #debian #ipsec #strongswan #ikev2

  4. CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec

    valtersit.com/cve/CVE-2026-478

  5. CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec

    valtersit.com/cve/CVE-2026-478

  6. CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec

    valtersit.com/cve/CVE-2026-478

  7. Note to self: Just don't touch #ipsec. It's shit all way round and always breaks. Just use something else.

    Why?

    Every time I want an encrypted tunnel between two public IPs I think like "oh yea, using IPSec here would be easy and straight forward".

    And then it never fucking works reliably. And if it does work it stops to work the next time you try to apply the exact same config. And it fails with shit like this...

    What have I done wrong?!? Why work sometimes??

    #networking #strongswan #ipv6

  8. Note to self: Just don't touch #ipsec. It's shit all way round and always breaks. Just use something else.

    Why?

    Every time I want an encrypted tunnel between two public IPs I think like "oh yea, using IPSec here would be easy and straight forward".

    And then it never fucking works reliably. And if it does work it stops to work the next time you try to apply the exact same config. And it fails with shit like this...

    What have I done wrong?!? Why work sometimes??

    #networking #strongswan #ipv6

  9. Note to self: Just don't touch #ipsec. It's shit all way round and always breaks. Just use something else.

    Why?

    Every time I want an encrypted tunnel between two public IPs I think like "oh yea, using IPSec here would be easy and straight forward".

    And then it never fucking works reliably. And if it does work it stops to work the next time you try to apply the exact same config. And it fails with shit like this...

    What have I done wrong?!? Why work sometimes??

    #networking #strongswan #ipv6

  10. Note to self: Just don't touch #ipsec. It's shit all way round and always breaks. Just use something else.

    Why?

    Every time I want an encrypted tunnel between two public IPs I think like "oh yea, using IPSec here would be easy and straight forward".

    And then it never fucking works reliably. And if it does work it stops to work the next time you try to apply the exact same config. And it fails with shit like this...

    What have I done wrong?!? Why work sometimes??

    #networking #strongswan #ipv6

  11. Note to self: Just don't touch #ipsec. It's shit all way round and always breaks. Just use something else.

    Why?

    Every time I want an encrypted tunnel between two public IPs I think like "oh yea, using IPSec here would be easy and straight forward".

    And then it never fucking works reliably. And if it does work it stops to work the next time you try to apply the exact same config. And it fails with shit like this...

    What have I done wrong?!? Why work sometimes??

    #networking #strongswan #ipv6

  12. A 15-year-old flaw in strongSwan lets attackers crash VPNs using a simple integer underflow flaw. No auth needed, affects versions used for over a decade. Patch now.

    Read: hackread.com/strongswan-flaw-a

  13. A 15-year-old flaw in strongSwan lets attackers crash VPNs using a simple integer underflow flaw. No auth needed, affects versions used for over a decade. Patch now.

    Read: hackread.com/strongswan-flaw-a

    #CyberSecurity #Infosec #VPN #Vulnerability #strongSwan

  14. A 15-year-old flaw in strongSwan lets attackers crash VPNs using a simple integer underflow flaw. No auth needed, affects versions used for over a decade. Patch now.

    Read: hackread.com/strongswan-flaw-a

    #CyberSecurity #Infosec #VPN #Vulnerability #strongSwan

  15. A 15-year-old flaw in strongSwan lets attackers crash VPNs using a simple integer underflow flaw. No auth needed, affects versions used for over a decade. Patch now.

    Read: hackread.com/strongswan-flaw-a

    #CyberSecurity #Infosec #VPN #Vulnerability #strongSwan

  16. A 15-year-old flaw in strongSwan lets attackers crash VPNs using a simple integer underflow flaw. No auth needed, affects versions used for over a decade. Patch now.

    Read: hackread.com/strongswan-flaw-a

    #CyberSecurity #Infosec #VPN #Vulnerability #strongSwan

  17. Da muss man auch erst mal drauf kommen dass das #vici plugin für #strongswan im Paket strongswan-swanctl steckt.

  18. Da muss man auch erst mal drauf kommen dass das #vici plugin für #strongswan im Paket strongswan-swanctl steckt.

  19. Da muss man auch erst mal drauf kommen dass das #vici plugin für #strongswan im Paket strongswan-swanctl steckt.

  20. Da muss man auch erst mal drauf kommen dass das #vici plugin für #strongswan im Paket strongswan-swanctl steckt.

  21. Anything missing for a general purpose x86 router?
    #StrongSwan for my reverse proxy setup, and #netbird eventually for future usage.

    #OpenWRT

  22. Anything missing for a general purpose x86 router?
    #StrongSwan for my reverse proxy setup, and #netbird eventually for future usage.

    #OpenWRT

  23. Wow! After delving into IPSec strongSwan rekeying, I now know that the initial 'data key' (Child SA) is like a quick handshake with no fancy secret exchange (PFS) (RTFM! [1]). However, for rekeys, it's full secret agent handshake mode! Writing the GitHub bug report, which turned out not to be a bug, helped me to understand my situation better. [2] Finally migrated to the new IPSEC connection setup in OPNsense and updated my blog post. [3]

    (Now I expect to get answers, aka 'Use WireGuard!')

    [1]: docs.strongswan.org/docs/lates
    [2]: github.com/opnsense/core/issue
    [3]: du.nkel.dev/blog/2021-11-19_pf

    #IPsec #PFS #strongSwan #GeekAdventures #OPNsense

  24. Wow! After delving into IPSec strongSwan rekeying, I now know that the initial 'data key' (Child SA) is like a quick handshake with no fancy secret exchange (PFS) (RTFM! [1]). However, for rekeys, it's full secret agent handshake mode! Writing the GitHub bug report, which turned out not to be a bug, helped me to understand my situation better. [2] Finally migrated to the new IPSEC connection setup in OPNsense and updated my blog post. [3]

    (Now I expect to get answers, aka 'Use WireGuard!')

    [1]: docs.strongswan.org/docs/lates
    [2]: github.com/opnsense/core/issue
    [3]: du.nkel.dev/blog/2021-11-19_pf

    #IPsec #PFS #strongSwan #GeekAdventures #OPNsense

  25. I am struggling to get my #archlinux IKE2 VPN working. I used to be able to just add the certificate and private key with the NetworkManager plug- in but now it complains about not being able to find the private key.

    #strongswan

  26. Харденинг strongSwan на всякий постквантовый

    strongSwan — опенсорсная имплементация IPsec, фреймворка VPN. Несмотря на полувековой стаж, проект продолжает развиваться: последняя на сегодня версия приложения вышла в декабре. У него подробная документация , есть блог с CVE и публичная база тестов . По полезной пропускной способности, задержке и утилизации CPU strongSwan превосходит Wireguard, но остаётся в тени — из-за сложности и малой пригодности для обхода блокировок. Зато перед теми, кто не ленится, он открывает широкий простор для экспериментов.

    habr.com/ru/articles/887458/

    #strongswan #mlkem #ppk #криптографические_алгоритмы

  27. Харденинг strongSwan на всякий постквантовый

    strongSwan — опенсорсная имплементация IPsec, фреймворка VPN. Несмотря на полувековой стаж, проект продолжает развиваться: последняя на сегодня версия приложения вышла в декабре. У него подробная документация , есть блог с CVE и публичная база тестов . По полезной пропускной способности, задержке и утилизации CPU strongSwan превосходит Wireguard, но остаётся в тени — из-за сложности и малой пригодности для обхода блокировок. Зато перед теми, кто не ленится, он открывает широкий простор для экспериментов.

    habr.com/ru/articles/887458/

    #strongswan #mlkem #ppk #криптографические_алгоритмы

  28. Харденинг strongSwan на всякий постквантовый

    strongSwan — опенсорсная имплементация IPsec, фреймворка VPN. Несмотря на полувековой стаж, проект продолжает развиваться: последняя на сегодня версия приложения вышла в декабре. У него подробная документация , есть блог с CVE и публичная база тестов . По полезной пропускной способности, задержке и утилизации CPU strongSwan превосходит Wireguard, но остаётся в тени — из-за сложности и малой пригодности для обхода блокировок. Зато перед теми, кто не ленится, он открывает широкий простор для экспериментов.

    habr.com/ru/articles/887458/

    #strongswan #mlkem #ppk #криптографические_алгоритмы

  29. @lns Amen! I use strongSwan (maybe even more complex than ovpn?) but have it all tooled up, and not that impressed with #wg except on #pi4 and earlier where it smokes. But both #ovpn and #strongswan pretty much match it on a #pi5. I also like that literally EVERY OS has built-in drivers for strongSwan (#ipsec). github.com/gitbls/pistrong

  30. @lns Amen! I use strongSwan (maybe even more complex than ovpn?) but have it all tooled up, and not that impressed with #wg except on #pi4 and earlier where it smokes. But both #ovpn and #strongswan pretty much match it on a #pi5. I also like that literally EVERY OS has built-in drivers for strongSwan (#ipsec). github.com/gitbls/pistrong

  31. @lns Amen! I use strongSwan (maybe even more complex than ovpn?) but have it all tooled up, and not that impressed with #wg except on #pi4 and earlier where it smokes. But both #ovpn and #strongswan pretty much match it on a #pi5. I also like that literally EVERY OS has built-in drivers for strongSwan (#ipsec). github.com/gitbls/pistrong

  32. @lns Amen! I use strongSwan (maybe even more complex than ovpn?) but have it all tooled up, and not that impressed with except on and earlier where it smokes. But both and pretty much match it on a . I also like that literally EVERY OS has built-in drivers for strongSwan (#ipsec). github.com/gitbls/pistrong

  33. @lns Amen! I use strongSwan (maybe even more complex than ovpn?) but have it all tooled up, and not that impressed with #wg except on #pi4 and earlier where it smokes. But both #ovpn and #strongswan pretty much match it on a #pi5. I also like that literally EVERY OS has built-in drivers for strongSwan (#ipsec). github.com/gitbls/pistrong

  34. @maswan @mhoye
    I am surprised nobody has mentioned Cisco. They have made hardware so difficult to deploy with all their licensing BS that I'm now looking at alternatives such as #wireguard and #StrongSwan for VPN solutions.

  35. @maswan @mhoye
    I am surprised nobody has mentioned Cisco. They have made hardware so difficult to deploy with all their licensing BS that I'm now looking at alternatives such as #wireguard and #StrongSwan for VPN solutions.

  36. @maswan @mhoye
    I am surprised nobody has mentioned Cisco. They have made hardware so difficult to deploy with all their licensing BS that I'm now looking at alternatives such as #wireguard and #StrongSwan for VPN solutions.

  37. @maswan @mhoye
    I am surprised nobody has mentioned Cisco. They have made hardware so difficult to deploy with all their licensing BS that I'm now looking at alternatives such as #wireguard and #StrongSwan for VPN solutions.

  38. Мониторинг ipsec strongSwan

    Всем привет! Работая DevOps-инженером, я задумался о мониторинге IPsec-туннелей, которых у нас уже накопилось достаточно. Они в основном используются для связи между облаками, так как инфраструктура разнесена — например, dev и prod живут у разных облачных провайдеров. Также есть интеграции со сторонними организациями, кластеры Kubernetes в AWS, GCP и т.д. Основная цель — получать алерты о падении туннеля раньше, чем сработают алерты о недоступности сервисов. Это особенно важно, поскольку Prometheus у нас один, он живёт в одном из облаков, а prometheus-stack в Kubernetes-кластерах работают в режиме агентов. Первая проблема - выбор экспортера или разработка своего Изначально наткнулся на экспортер от dennisstritzke , но проект уже архивный, последний релиз датируется сентябрем 2021 года, в README автор рекомендует использовать более свежий и поддерживаемый экспортер . Однако он использует VICI , соответственно необходима миграция с более старого подхода конфигурирования с помощью ipsec.conf на swanctl.conf. В документации есть подробное описание , и даже ссылка на скрипт-конвертор . Но зачем ломать то, что уже работает, пусть даже и deprecated? В итоге написал свой python скрипт, который дергает ipsec status, парсит вывод и формирует необходимые мне метрики для Prometheus.

    habr.com/ru/articles/862506/

    #prometheus #ipsec #strongswan

  39. Мониторинг ipsec strongSwan

    Всем привет! Работая DevOps-инженером, я задумался о мониторинге IPsec-туннелей, которых у нас уже накопилось достаточно. Они в основном используются для связи между облаками, так как инфраструктура разнесена — например, dev и prod живут у разных облачных провайдеров. Также есть интеграции со сторонними организациями, кластеры Kubernetes в AWS, GCP и т.д. Основная цель — получать алерты о падении туннеля раньше, чем сработают алерты о недоступности сервисов. Это особенно важно, поскольку Prometheus у нас один, он живёт в одном из облаков, а prometheus-stack в Kubernetes-кластерах работают в режиме агентов. Первая проблема - выбор экспортера или разработка своего Изначально наткнулся на экспортер от dennisstritzke , но проект уже архивный, последний релиз датируется сентябрем 2021 года, в README автор рекомендует использовать более свежий и поддерживаемый экспортер . Однако он использует VICI , соответственно необходима миграция с более старого подхода конфигурирования с помощью ipsec.conf на swanctl.conf. В документации есть подробное описание , и даже ссылка на скрипт-конвертор . Но зачем ломать то, что уже работает, пусть даже и deprecated? В итоге написал свой python скрипт, который дергает ipsec status, парсит вывод и формирует необходимые мне метрики для Prometheus.

    habr.com/ru/articles/862506/

    #prometheus #ipsec #strongswan

  40. Мониторинг ipsec strongSwan

    Всем привет! Работая DevOps-инженером, я задумался о мониторинге IPsec-туннелей, которых у нас уже накопилось достаточно. Они в основном используются для связи между облаками, так как инфраструктура разнесена — например, dev и prod живут у разных облачных провайдеров. Также есть интеграции со сторонними организациями, кластеры Kubernetes в AWS, GCP и т.д. Основная цель — получать алерты о падении туннеля раньше, чем сработают алерты о недоступности сервисов. Это особенно важно, поскольку Prometheus у нас один, он живёт в одном из облаков, а prometheus-stack в Kubernetes-кластерах работают в режиме агентов. Первая проблема - выбор экспортера или разработка своего Изначально наткнулся на экспортер от dennisstritzke , но проект уже архивный, последний релиз датируется сентябрем 2021 года, в README автор рекомендует использовать более свежий и поддерживаемый экспортер . Однако он использует VICI , соответственно необходима миграция с более старого подхода конфигурирования с помощью ipsec.conf на swanctl.conf. В документации есть подробное описание , и даже ссылка на скрипт-конвертор . Но зачем ломать то, что уже работает, пусть даже и deprecated? В итоге написал свой python скрипт, который дергает ipsec status, парсит вывод и формирует необходимые мне метрики для Prometheus.

    habr.com/ru/articles/862506/

    #prometheus #ipsec #strongswan

  41. Bouncing around a few things today.

    - Building custom #OpenWrt images for $dayjob to run on modified BT Home Hub 5a units
    - Connecting to a test BT Hub 5a over TTL to see what's going on during boot
    - Trying to remember #Strongswan configs for talking to Cisco ASAs over IPsec VPN, again for $dayjob
    - Building #MAME 0.266 on #HaikuOS R1B5 in the background, because MAME 0.269 and 0.270 are failing and I don't know why
    - Dipping into #CTRAN's #ObjectPascal source when I want a break (!!!)