ipsec.conf 770 B

1234567891011121314151617181920212223242526272829303132333435363738394041
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. config setup
  3. strictcrlpolicy=yes
  4. ca strongswan
  5. cacert=strongswanCert.pem
  6. ocspuri=http://ocsp.strongswan.org:8880
  7. auto=add
  8. ca research
  9. cacert=researchCert.pem
  10. ocspuri=http://ocsp.strongswan.org:8881
  11. auto=add
  12. ca sales
  13. cacert=salesCert.pem
  14. ocspuri=http://ocsp.strongswan.org:8882
  15. auto=add
  16. conn %default
  17. ikelifetime=60m
  18. keylife=20m
  19. rekeymargin=3m
  20. keyingtries=1
  21. keyexchange=ikev2
  22. left=PH_IP_MOON
  23. leftcert=moonCert.pem
  24. leftid=@moon.strongswan.org
  25. conn alice
  26. leftsubnet=PH_IP_ALICE/32
  27. right=%any
  28. rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
  29. auto=add
  30. conn venus
  31. leftsubnet=PH_IP_VENUS/32
  32. right=%any
  33. rightca="C=CH, O=strongSwan Project, OU=Sales, CN=Sales CA"
  34. auto=add