quarta-feira, 20 de julho de 2016

FortiGate - VPN IPSec x Client IPSec no Linux ( Debian )

Fortinet não fornece o Forticlient para Linux, procurando na internet encontrei algumas alternativas, porém nenhuma foi estável.

Durante a procura sobre algo que funcione legal, encontrei o projeto Shrew https://www.shrew.net/home

Instalação das dependências:

sudo apt-get install cmake libqt4-core libqt4-dev libqt4-gui libedit-dev libssl-dev checkinstall flex bison

Download da última versão:
 
wget https://www.shrew.net/download/ike/ike-2.2.1-release.tbz2

Extraindo

tar xvfvj ike-2.2.1-release.tbz2

Acesse a pasta e execute o cmake, no README.TXT sobre o procedimento.

cd ike
cmake -DCMAKE_INSTALL_PREFIX=/usr -DQTGUI=YES -DETCDIR=/etc -DNATT=YES 

checkinstall -y

make

sudo make install

cd /source/iked/

mv iked.conf.samp /etc/iked.conf


Execute o shrew 

# iked

ii : created ike socket 0.0.0.0:500
ii : created natt socket 0.0.0.0:4500
## : IKE Daemon, ver 2.2.1
## : Copyright 2013 Shrew Soft Inc.
## : This product linked OpenSSL 1.0.1t  3 May 2016





Execute a interface gráfica do Shrew
# qikea

Para conseguir acessar a VPN IPSec do FortiGate entre com as seguintes informações.

Clique em ADD

Guia General

Remote Host

Host Name or IP Address = IP do FortiGate

Port = 500
Auto Configuration = Ike config pull

Local Host

Address Method = Use a Virtual adapter and assigned address
Marque a caixa de seleção = Obtain Automatically

Guia Client

Firewall Options

Nat Traversal = enable
Nat Traversal Port = 4500
Keep-Alive Packet Rate = 15 secs
IKE Fragmentation = disable


Other Options

Marque as 3 caixas de seleção
Enable Dead Peer Detection
Enable IKSAMP Failure Notifications
Enable Client Login Banner


Guia Name Resolution

Marque
Enable DNS
Obtain Automatically


Guia Authentication

Autentication Method = Mutual PSK + XAuth

Local Identity

Identification Type = Fully Qualified Domain Name

Remote Identity = Any

Credentials - Pre Shared Key = Inserir a Senha Compartilhada


Guia Phase 1

Proposal Parameters 

Exchange Type = Aggressive
DH Exchange =group 5
Cipher Algorithm = aes
Cipher Key Length = 128 bits
Hash Algorithm = sha1
Key Life Time Limit = 86400 Secs
Key Life Data Limit = 0 Kbs


Guia Phase 2 

Proposal Parameters

Transform Algorithm = auto
HMAC Algorithm = sha1
PFS Exchange group 5
Compression  Algorithm = deflate
Key Life Time Limit = 43200 Secs
Key Life Data Limite = 5120 KBs


Guia Policy

IPsec Policy Configuration

Policy Generation Level = Auto

Marque - Obtain Topology Automatically or Tunnel All

Clique em Save.

Execute a conexão e entre com o usuário e senha.


 















sexta-feira, 20 de março de 2015

Instalação Team Viewer 10 - Centos 7

[root@computer Downloads]# yum -y install libpng12.so.0
Plugins carregados: fastestmirror, langpacks
Loading mirror speeds from cached hostfile
 * base: centos.xpg.com.br
 * epel: mirror.globo.com
 * extras: centos.xpg.com.br
 * nux-dextop: mirror.li.nux.ro
 * updates: centos.xpg.com.br
Resolvendo dependências
--> Executando verificação da transação
---> O pacote libpng12.i686 0:1.2.50-6.el7 será instalado
--> Resolução de dependências finalizada

Dependências resolvidas

================================================================================
 Package            Arq.           Versão                  Repo            Tam.
================================================================================
Instalando:
 libpng12           i686           1.2.50-6.el7            base           181 k

Resumo da transação
================================================================================
Instalar  1 Package

Tamanho total do download: 181 k
Tamanho depois de instalado: 653 k
Downloading packages:
libpng12-1.2.50-6.el7.i686.rpm                             | 181 kB   00:00  
Running transaction check
Running transaction test
Transaction test succeeded
Running transaction
  Instalando   : libpng12-1.2.50-6.el7.i686                                 1/1
  Verifying    : libpng12-1.2.50-6.el7.i686                                 1/1

Instalados:
  libpng12.i686 0:1.2.50-6.el7                                                

Concluído!
[root@computer Downloads]# rpm -Uvh teamviewer_10.0.37742.i686.rpm
aviso: teamviewer_10.0.37742.i686.rpm: Cabeçalho V4 DSA/SHA1 Signature, ID da chave 72db573c: NOKEY
Preparando...                         ################################# [100%]
Updating / installing...
   1:teamviewer-10.0.37742-0          ################################# [100%]
[root@computer Downloads]#