ipsec.conf 470 B

12345678910111213141516171819202122232425262728
  1. # /etc/ipsec.conf - strongSwan IPsec configuration file
  2. config setup
  3. strictcrlpolicy=yes
  4. ca strongswan
  5. cacert=strongswanCert.pem
  6. ocspuri=http://ocsp.strongswan.org:8880
  7. auto=add
  8. conn %default
  9. ikelifetime=60m
  10. keylife=20m
  11. rekeymargin=3m
  12. keyingtries=1
  13. keyexchange=ikev2
  14. left=PH_IP_CAROL
  15. leftcert=carolCert.pem
  16. right=PH_IP_MOON
  17. rightid=@moon.strongswan.org
  18. conn alice
  19. rightsubnet=PH_IP_ALICE/32
  20. auto=add
  21. conn venus
  22. rightsubnet=PH_IP_VENUS/32
  23. auto=add