> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Before you start

> Prepare the supported software and network access for strongSwan.

Complete these prerequisites before you deploy the integration.

## Software and platform

* Use CryptoHub 7.3.0.x build 7.3.0.0b or later. This guide uses the REST-based CryptoHub Client Library rather than the legacy Host API library.
* Use Ubuntu 24.04 with strongSwan 5.9.13 or a compatible release. Package names and AppArmor paths differ on other distributions.
* Install `strongswan`, `strongswan-swanctl`, `strongswan-pki`, and `libstrongswan-extra-plugins`. The extra-plugins package provides `libstrongswan-pkcs11.so`.
* Install `opensc` for `pkcs11-tool` verification.

Run:

```shell theme={null}
sudo apt update
sudo apt install strongswan strongswan-swanctl strongswan-pki \
  libstrongswan-extra-plugins opensc openssl
```

<Check>
  Run `ipsec --version`, `swanctl --version`, and `test -f /usr/lib/ipsec/plugins/libstrongswan-pkcs11.so`. Each command must succeed.
</Check>

## Network access

* Allow the strongSwan gateway to reach CryptoHub over TCP 443. FxChlibs sends authentication and signing requests over this connection.
* Allow IKEv2 between the gateways over UDP 500 and UDP 4500. Permit ESP when the peers do not use UDP encapsulation.
* Exempt the CryptoHub TLS connection from interception. The endpoint bundle pins the trust material that authenticates CryptoHub.

Verify CryptoHub reachability:

```shell theme={null}
curl --fail --silent --show-error https://<CRYPTOHUB_HOST>/home/v1/status
```

Replace `<CRYPTOHUB_HOST>` with the CryptoHub hostname. The command must return a status document.

## CryptoHub access

Obtain two CryptoHub administrator identities. Dual control protects service and endpoint deployment.

## Version and scope

<Note>
  This guide was validated on Ubuntu 24.04 with strongSwan 5.9.13. It does not provide RHEL package names or SELinux policy.
</Note>
