strongswan.conf 701 B

1234567891011121314151617181920212223242526272829303132333435363738
  1. # /etc/strongswan.conf - strongSwan configuration file
  2. charon-systemd {
  3. load = random nonce aes sha1 sha2 md5 pem pkcs1 gmp hmac x509 revocation curl vici kernel-netlink socket-default eap-identity eap-ttls eap-md5 eap-tnc tnc-tnccs tnccs-20 tnc-imv updown
  4. multiple_authentication = no
  5. syslog {
  6. daemon {
  7. tnc = 3
  8. imv = 2
  9. }
  10. }
  11. plugins {
  12. eap-ttls {
  13. phase2_method = md5
  14. phase2_piggyback = yes
  15. phase2_tnc = yes
  16. }
  17. }
  18. }
  19. libtls {
  20. suites = TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
  21. }
  22. libimcv {
  23. plugins {
  24. imv-test {
  25. rounds = 0
  26. }
  27. imv-scanner {
  28. closed_port_policy = yes
  29. tcp_ports = 22
  30. udp_ports = 500 4500
  31. }
  32. }
  33. }