ipsec.conf 501 B

1234567891011121314151617181920212223242526272829
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. conn %default
  3. ikelifetime=60m
  4. keylife=20m
  5. rekeymargin=3m
  6. keyingtries=1
  7. keyexchange=ikev2
  8. conn alice
  9. rightid=alice@strongswan.org
  10. mark=10/0xffffffff
  11. also=sun
  12. auto=add
  13. conn venus
  14. rightid=@venus.strongswan.org
  15. mark=20 #0xffffffff is used by default
  16. also=sun
  17. auto=add
  18. conn sun
  19. left=PH_IP_SUN
  20. leftcert=sunCert.pem
  21. leftid=@sun.strongswan.org
  22. leftsubnet=10.2.0.0/16
  23. leftupdown=/etc/mark_updown
  24. right=%any
  25. rightsubnet=0.0.0.0/0