b
update your package repository and install the package directly using apt. Libreswan is commonly used for IPsec VPN connections, with configurations managed in
/etc/ipsec.conf
and secrets in
/etc/ipsec.secrets.
echo "192.168.1.1 %any : PSK bernbern" >> /etc/ipsec.secrets

Update the Package Repository:
bash
sudo apt update

echo "Install Libreswan"
bash
sudo apt install libreswan -y 

echo "Verify Installation"
bash
sudo systemctl enable ipsec
sudo systemctl start ipsec
echo "check the service status"
sudo systemctl status ipsec
ipsec --version
 
Basic Configuration
Configuration File:
/etc/ipsec.conf
echo "add line for default protocol"
echo "ikev2=insist" >> /etc/ipsec.conf

Secrets File for psk keys, server client
/etc/ipsec.secrets.
echo "%defaultroute %any : PSK bernbern" >> /etc/ipsec.secrets

open ports
500 4500
or disable firewal
check status
sudo ufw status
disable or enable
sudo ufw disable

Start/Enable Service:
bash
sudo systemctl enable ipsec --now

Check Status:
bash
sudo ipsec verify


steps to open ports 500 4500
open ufw firewal
sudo ufw allow 500/udp
sudo ufw allow 4500/udp

check the rules
sudo ufw status verbose

ufw is auto setup for iptables
if you are not using ufw, you can use iptables manual setup
sudo iptables -A INPUT -p udp --dport 500 -j ACCEPT
sudo iptables -A INPUT -p udp --dport 4500 -j ACCEPT

ipsec considerations: for vpn setups, you may also need to allow protocol 50 esp and 51 ah
sudo ufw allow 50/tcp
sudo ufw allow 51/tcp 
restart
sudo ufw reload

echo "enabling ip forwarding"
sysctl -w net.ipv4.ip_forward=1

detailed setup
echo "Allow IKE and NAT-T"
sudo iptables -A INPUT -p udp --dport 500 -j ACCEPT
sudo iptables -A INPUT -p udp --dport 4500 -j ACCEPT
echo "Allow ESP and AH protocols"
sudo iptables -A INPUT -p esp -j ACCEPT
sudo iptables -A INPUT -p ah -j ACCEPT
echo "Allow IPsec traffic via policy"
sudo iptables -I INPUT -m policy --pol ipsec --dir in -j ACCEPT
sudo iptables -I FORWARD -m policy --pol ipsec --dir in -j ACCEPT
echo "Masquerade traffic (assuming eth0 is your interface, adjust accordingly)"
sudo iptables -t nat -A POSTROUTING -o eth0 -m policy --pol ipsec --dir out -j ACCEPT
sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
