1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44
|
# /etc/ipsec.conf - Libreswan IPsec configuration file
config setup
ikev1-policy=accept
# put the logs in /tmp for the UMLs, so that we can operate
# without syslogd, which seems to break on UMLs
logfile=/tmp/pluto.log
logtime=no
logappend=no
dumpdir=/tmp
plutodebug=all
conn %default
keyexchange=ikev1
conn westnet-eastnet-etc-hosts
left=192.1.2.45
# Left security gateway, subnet behind it, next hop toward right.
leftid=@west
# Right security gateway, subnet behind it, next hop toward left.
rightid=@east
also=west-leftrsasigkey
also=east-rightrsasigkey
leftsubnet=192.0.1.0/24
rightsubnet=192.0.2.0/24
#right=east-from-hosts-file.example.com
right=east-from-hosts-file
auto=ignore
conn westnet-eastnet-etc-hosts-auto-add
left=192.1.2.45
# Left security gateway, subnet behind it, next hop toward right.
leftid=@west
# Right security gateway, subnet behind it, next hop toward left.
rightid=@east
also=west-leftrsasigkey
also=east-rightrsasigkey
leftsubnet=192.0.1.0/24
rightsubnet=192.0.2.0/24
#right=east-from-hosts-file.example.com
right=east-from-hosts-file
auto=add
include /testing/baseconfigs/all/etc/ipsec.d/rsasigkey.conf
|