StrongSwan 是一个基于 OpenWrt 的 VPN 服务器软件,支持多种 VPN 协议,如 IKEv2、IPSec、OpenVPN 等,以下是安装和配置 StrongSwan 的步骤:
前置准备
- 确保你的路由器已经安装了 OpenWrt 系统。
- 通过 SSH 连接到你的路由器(如果路由器支持 SSH 服务器)。
通过 Luci 界面安装 StrongSwan
- 登录路由器的 Luci 界面(默认地址:192.168.1.1,用户名和密码与你的路由器设置一致)。
- 进入
工具>包管理器。 - 在搜索栏输入
strongswan,然后点击搜索。 - 勾选
strongswan和所需的依赖包(如libipsec和polarssl),然后点击安装。
通过命令行安装
如果不想使用 Luci,可以通过命令行安装:
opkg update opkg install strongswan strongswan-luci
启用 StrongSwan 服务
安装完成后,启用并启动 StrongSwan 服务:
uci set service @strongswan "enabled=1" uci commit service strongswan restart
配置 StrongSwan
配置文件位于 /etc/strongswan 目录,你可以使用 Luci 界面或命令行编辑配置文件。
使用 Luci 配置
- 进入 Luci 界面,进入
网络>VPN>StrongSwan。 - 配置服务器参数,如接口名称、地址、端口、协议等。
使用命令行配置
vi /etc/strongswan/strongswan.conf
listen_port=5555
auth=psk
key=your-secure-key
# 客户端配置
client=eth
server=192.168.1.1
server_port=5555
设置默认路由
在配置完成后,设置默认路由:
uci set network@zone-localhost/general "default_route=.../" uci commit
防火墙设置
确保防火墙允许 VPN трафик:
uci set firewall@zone-lan "allow-arp=1" uci set firewall@zone-lan "allow-icmp=1" uci set firewall@zone-lan "allow-iper=1" uci commit
启动并测试 VPN 服务
service strongswan restart
在另一台设备上测试连接:
- 服务器地址:你的路由器 IP 或外部 IP
- 端口:配置的端口(如 5555)
- 服务器地址:如 192.168.1.1
常用配置示例
使用 AES 加密
listen_port=5555
auth=psk
key=your-secure-key
# 使用 AES 加密
cipher= aes-256-cbc
默认路由配置
在配置文件中添加:
# 默认路由 pull-filter=route pull=yes
故障排除
- 如果服务启动失败,检查日志:
tail -f /var/log/messages.log
- 确保防火墙规则正确,允许必要的连接。
管理服务
- 重启服务:
service strongswan restart
- 升级服务:
opkg update opkg upgrade strongswan
通过以上步骤,你可以成功安装并配置 StrongSwan VPN 服务器,安全使用,确保你的密码和密钥保密!









