# /etc/ipsec.conf - strongSwan IPsec configuration file config setup conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev2 mobike=no dpdaction=restart dpddelay=60s left=%defaultroute leftfirewall=yes conn medsrv leftid=av9oEPMz@medsrv.org leftauth=psk right=PH_IP_CAROL rightid=carol@strongswan.org rightauth=pubkey mediation=yes auto=start conn peer leftcert=bobCert.pem leftid=bob@strongswan.org right=%any rightid=alice@strongswan.org rightsubnet=PH_IP_ALICE/32 mediated_by=medsrv me_peerid=6cu1UTVw@medsrv.org auto=add