Sign inSign up

talmai/docker-ipsec-vpn-server

By talmai

•Updated almost 8 years ago

Docker image to run an IPsec VPN server for multiple users (IPsec/L2TP and IPsec/XAuth)

Image
0

576

talmai/docker-ipsec-vpn-server repository overview

⁠IPsec VPN Server on Docker

Docker Pulls Docker Stars

Docker image to run a multi-user, IPsec VPN server with support for both IPsec/L2TP and IPsec/XAuth ("Cisco IPsec"). Based on Lin Song's IPsec VPN Server on Docker⁠ and forked from mobilejazz⁠.

⁠Install Docker

Follow these instructions⁠ to get Docker running on your server.

⁠Available on Docker Hub (prebuilt) or built from source
git clone https://github.com/talmai/docker-ipsec-vpn-server.git
docker pull talmai/docker-ipsec-vpn-server
cd docker-ipsec-vpn-server
./helper.sh

Or build from source

git clone https://github.com/talmai/docker-ipsec-vpn-server.git
cd docker-ipsec-vpn-server
docker build -t talmai/docker-ipsec-vpn-server .
./helper.sh

⁠Run the helper script

./helper.sh

    -b, --begin           start ipsec server
    -s, --status          get status
    -a, --add <user>      creates new user
    -l, --list            lists all users
    -r, --remove <user>   removes user

⁠Adding a new user

Create a new VPN user with the add command. This will generate an individual password for this user (user specific, usually called "password") and also display the shared key of the server (same for all users, usually called "PSK" or "Pre-Shared Key").

The user will be available immediately, there is no need to restart the server.

IMPORTANT: Due to a limitation in the IPSec protocol design, several devices can not connect to the same server behind the same NAT router. We recommend creating a separate account for each device a user owns. This will also make revocation of credentials easier if a user lost a device.

⁠Check server status

To check the status of your IPsec VPN server, you can use the status command.

⁠Next steps

Get your computer or device to use the VPN. Please refer to:

Configure IPsec/L2TP VPN Clients⁠
Configure IPsec/XAuth ("Cisco IPsec") VPN Clients⁠

If you get an error when trying to connect, see Troubleshooting⁠.

⁠Technical details

There are two services running: Libreswan (pluto) for the IPsec VPN, and xl2tpd for L2TP support.

Clients are configured to use Google Public DNS⁠ when the VPN connection is active.

The default IPsec configuration supports:

  • IKEv1 with PSK and XAuth ("Cisco IPsec")
  • IPsec/L2TP with PSK

The ports that are exposed for this container to work are:

  • 4500/udp and 500/udp for IPsec

⁠Extending the configuration

The default configuration will work out of the box in most cases. However, you might want to tweak some little settings, like the routing table, or maybe something specific to your environment. If you you mount a /pre-up.sh script, it will be executed before starting the VPN.

⁠Backing up your VPN configuration

The etc directory is created with the helper script. You can back up this directory.

⁠See also

Tag summary

Content type

Image

Digest

Size

91.6 MB

Last updated

almost 8 years ago

docker pull talmai/docker-ipsec-vpn-server