ipsec.conf 1.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. config setup
  3. strictcrlpolicy=yes
  4. ca strongswan
  5. cacert=strongswanCert.pem
  6. crluri="ldap://ldap.strongswan.org/cn=strongSwan Root CA, o=strongSwan Project, c=CH?certificateRevocationList"
  7. auto=add
  8. ca research
  9. cacert=researchCert.pem
  10. crluri="ldap://ldap.strongswan.org/cn=Research CA, ou=Research, o=strongSwan Project, c=CH?certificateRevocationList"
  11. auto=add
  12. ca sales
  13. cacert=salesCert.pem
  14. crluri="ldap://ldap.strongswan.org/cn=Sales CA, ou=Sales, o=strongSwan Project, c=CH?certificateRevocationList"
  15. auto=add
  16. conn %default
  17. ikelifetime=60m
  18. keylife=20m
  19. rekeymargin=3m
  20. keyingtries=1
  21. keyexchange=ikev2
  22. left=PH_IP_MOON
  23. leftcert=moonCert.pem
  24. leftid=@moon.strongswan.org
  25. leftfirewall=yes
  26. conn alice
  27. leftsubnet=PH_IP_ALICE/32
  28. right=%any
  29. rightca="C=CH, O=strongSwan Project, OU=Research, CN=Research CA"
  30. auto=add
  31. conn venus
  32. leftsubnet=PH_IP_VENUS/32
  33. right=%any
  34. rightca="C=CH, O=strongSwan Project, OU=Sales, CN=Sales CA"
  35. auto=add