ipsec.conf 467 B

12345678910111213141516171819202122232425262728
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. config setup
  3. uniqueids=no
  4. strictcrlpolicy=yes
  5. conn %default
  6. ikelifetime=60m
  7. keylife=20m
  8. rekeymargin=3m
  9. keyingtries=1
  10. keyexchange=ikev2
  11. left=PH_IP_CAROL
  12. leftid=carol@strongswan.org
  13. leftfirewall=yes
  14. right=PH_IP_MOON
  15. rightid=@moon.strongswan.org
  16. conn alice
  17. leftcert=carolCert.pem
  18. rightsubnet=PH_IP_ALICE/32
  19. auto=add
  20. conn venus
  21. leftcert=carolCert-002.pem
  22. rightsubnet=PH_IP_VENUS/32
  23. auto=add