| 12345678910111213141516171819202122232425262728293031 | 
							- # /etc/ipsec.conf - strongSwan IPsec configuration file
 
- config setup
 
- ca strongswan
 
- 	cacert=strongswanCert.pem
 
- 	crluri=http://crl.strongswan.org/strongswan.crl
 
- 	auto=add
 
- conn %default
 
- 	ikelifetime=60m
 
- 	keylife=20m
 
- 	rekeymargin=3m
 
- 	keyingtries=1
 
- 	keyexchange=ikev1
 
- 	left=PH_IP_MOON
 
- 	leftcert=moonCert.pem
 
- 	leftsendcert=ifasked
 
- 	leftid=@moon.strongswan.org
 
- conn alice
 
- 	leftsubnet=PH_IP_ALICE/32
 
- 	right=%any
 
- 	rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
 
- 	auto=add
 
- conn venus
 
- 	leftsubnet=PH_IP_VENUS/32
 
- 	right=%any
 
- 	rightca="C=CH, O=strongSwan Project, CN=strongSwan Root CA"
 
- 	auto=add
 
 
  |