ipsec.conf 468 B

1234567891011121314151617181920212223242526272829303132
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. conn %default
  3. ikelifetime=60m
  4. keylife=20m
  5. rekeymargin=3m
  6. keyingtries=1
  7. keyexchange=ikev2
  8. mobike=no
  9. conn dscp-be
  10. leftid=@sun-be
  11. rightid=@moon-be
  12. mark=10
  13. also=net-net
  14. auto=add
  15. conn dscp-ef
  16. leftid=@sun-ef
  17. rightid=@moon-ef
  18. mark=20
  19. also=net-net
  20. auto=add
  21. conn net-net
  22. left=PH_IP_SUN
  23. leftsubnet=10.2.0.0/16
  24. leftfirewall=yes
  25. leftauth=psk
  26. right=PH_IP_MOON
  27. rightsubnet=10.1.0.0/16
  28. rightauth=psk