ℹ️ Tổng quan Đây là bước quan trọng nhất - cấu hình Libreswan IPsec trên EC2 Customer Gateway để thiết lập VPN tunnels với AWS.

Trong hộp thoại Download Configuration
💡 Lưu ý: Libreswan là phiên bản kế thừa của OpenSwan, cấu hình tương thích


sudo dnf install libreswan -y
💡 Libreswan: IPsec VPN implementation cho Linux, kế thừa từ OpenSwan

sudo vi /etc/ipsec.conf

sudo vi /etc/sysctl.conf
net.ipv4.ip_forward = 1
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
⚠️ Quan trọng: IP forwarding bắt buộc để Customer Gateway có thể route traffic giữa VPN tunnel và local network


sudo sysctl -p

sudo vi /etc/ipsec.d/aws.conf
🔑 Các thông số quan trọng:
💡 Lưu ý quan trọng:
auth=esp (không cần cho Amazon Linux)modp1024 thành modp2048 (bảo mật cao hơn)auto=route thành auto=start



sudo touch /etc/ipsec.d/aws.secrets
sudo vi /etc/ipsec.d/aws.secrets

🔐 Format:
<Customer Gateway Public IP> <AWS VPN Endpoint IP>: PSK "<pre-shared-key>"
Ấn ESC và :wq! để lưu
Kiểm tra file:
sudo cat /etc/ipsec.d/aws.secrets

sudo systemctl restart systemd-networkd
sudo systemctl enable ipsec
sudo systemctl start ipsec
sudo systemctl status ipsec
✅ Kết quả mong đợi: Service status = active (running)

sudo systemctl restart systemd-networkd
sudo systemctl restart ipsec
💡 Kiểm tra tunnel status:
sudo ipsec status
ping <EC2-Private-IP> -c5
✅ Thành công: Nhận được ping replies qua VPN tunnel

ping <Customer-Gateway-Private-IP> -c5
✅ Thành công: Kết nối 2 chiều qua VPN hoạt động!

🏗️ Kiến trúc VPN Hoàn chỉnh
AWS VPC (10.10.0.0/16)
├── EC2 Private (10.10.4.x)
↓
Virtual Private Gateway
↓
VPN Tunnel (IPsec) - ESTABLISHED ✅
├── Tunnel 1: UP
└── Tunnel 2: Standby
↓
Customer Gateway (Libreswan)
├── Public IP: x.x.x.x
└── Private IP: 10.11.1.x
↓
VPN VPC (10.11.0.0/16)
💡 Troubleshooting Tips:
sudo journalctl -u ipsec -fsudo ipsec statusip route showsudo ip route add 10.10.4.0/24 dev ens5🔒 Security Notes:
chmod 600 /etc/ipsec.d/aws.secrets✅ Hoàn thành: VPN Site-to-Site đã được cấu hình thành công và hoạt động!