ipsec.conf 575 B

12345678910111213141516171819202122232425262728293031
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. conn %default
  3. ikelifetime=60m
  4. keylife=20m
  5. rekeymargin=3m
  6. keyingtries=1
  7. keyexchange=ikev2
  8. conn alice
  9. rightid=alice@strongswan.org
  10. mark_in=10/0xffffffff
  11. mark_out=11/0xffffffff
  12. also=sun
  13. auto=add
  14. conn venus
  15. rightid=@venus.strongswan.org
  16. mark_in=20 #0xffffffff is used by default
  17. mark_out=21 #0xffffffff is used by default
  18. also=sun
  19. auto=add
  20. conn sun
  21. left=PH_IP_SUN
  22. leftcert=sunCert.pem
  23. leftid=@sun.strongswan.org
  24. leftsubnet=10.2.0.0/16
  25. leftupdown=/etc/mark_updown
  26. right=%any
  27. rightsubnet=0.0.0.0/0