ipsec.conf 544 B

1234567891011121314151617181920212223242526272829303132
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. config setup
  3. conn %default
  4. ikelifetime=60m
  5. keylife=20m
  6. rekeymargin=3m
  7. keyingtries=1
  8. conn finance
  9. left=PH_IP_MOON
  10. leftcert=moonCert.pem
  11. leftid=@moon.strongswan.org
  12. leftsubnet=10.1.0.10/32
  13. leftfirewall=yes
  14. right=%any
  15. rightid=*@strongswan.org
  16. rightgroups=finance
  17. keyexchange=ikev2
  18. auto=add
  19. conn sales
  20. left=PH_IP_MOON
  21. leftcert=moonCert.pem
  22. leftid=@moon.strongswan.org
  23. leftsubnet=10.1.0.20/32
  24. leftfirewall=yes
  25. right=%any
  26. rightgroups=sales
  27. keyexchange=ikev2
  28. auto=add