Differences between revisions 4 and 9 (spanning 5 versions)
Revision 4 as of 2019-12-11 14:18:31
Size: 344
Editor: Sciuro
Comment:
Revision 9 as of 2019-12-20 09:44:53
Size: 1098
Editor: Sciuro
Comment:
Deletions are marked like this. Additions are marked like this.
Line 5: Line 5:

= IPSEC site to site VPN =
{{{
configure
edit vpn ipsec

# Fase 1
set ike-group unifi key-exchange ikev2
set ike-group unifi lifetime 14400
set ike-group unifi proposal 1 dh-group 14
set ike-group unifi proposal 1 encryption aes128
set ike-group unifi proposal 1 hash sha1

# Fase 2
set esp-group unifi compression disable
set esp-group unifi lifetime 14400
set esp-group unifi mode tunnel
set esp-group unifi pfs dh-group14
set esp-group unifi proposal 1 encryption aes128
set esp-group unifi proposal 1 hash sha1

# IPSEC VPN
# ToDo
}}}
Line 18: Line 42:

= Links =
 * [[https://freetime.mikeconnelly.com/archives/6373]]
 * [[https://robpickering.com/working-around-incomplete-ubiquiti-unifi-security-gateway-dns-service/]]
Line 19: Line 47:
CategoryNetwork CategoryNetwork CategoryHardware

IPSEC site to site VPN

configure
edit vpn ipsec

# Fase 1
set ike-group unifi key-exchange ikev2
set ike-group unifi lifetime 14400
set ike-group unifi proposal 1 dh-group 14
set ike-group unifi proposal 1 encryption aes128
set ike-group unifi proposal 1 hash sha1

# Fase 2
set esp-group unifi compression disable
set esp-group unifi lifetime 14400
set esp-group unifi mode tunnel
set esp-group unifi pfs dh-group14
set esp-group unifi proposal 1 encryption aes128
set esp-group unifi proposal 1 hash sha1

# IPSEC VPN
# ToDo

Unifi on FreeBSD

Install

pkg install unifi5

Edit /etc/rc.conf

unifi_enable="YES"

Keep in mind that Unifi uses the mongodb package, but run it by it's own, on a different port. So you don't have to start mongodb at boot time.

Links


CategoryNetwork CategoryHardware

Howto/Unifi (last edited 2020-03-10 20:24:22 by Sciuro)