# /etc/ipsec.conf - strongSwan IPsec configuration file config setup conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev2 dpdaction=clear dpddelay=60s conn hub leftcert=carolCert.pem leftid=carol@strongswan.org leftfirewall=yes lefthostaccess=yes right=%any leftsubnet=0.0.0.0/0 rightsubnet=0.0.0.0/0 compress=yes auto=add