1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37
|
# /etc/ipsec.conf - Libreswan IPsec configuration file
version 2.0
config setup
ikev1-policy=accept
# put the logs in /tmp for the UMLs, so that we can operate
# without syslogd, which seems to break on UMLs
logfile=/tmp/pluto.log
logtime=no
logappend=no
plutodebug=all
dumpdir=/tmp
conn base
keyexchange=ikev1
rightid=@east
right=192.1.2.23
leftid=192.1.3.174
ike=3des-sha1
authby=secret
conn east
also=base
#leftsubnet=192.0.1.0/24
#rightsubnet=192.0.2.0/24
leftsubnet=192.0.1.0/30
rightsubnet=192.0.2.0/30
left=%any
conn road
also=base
#leftsubnet=192.0.1.0/24
#rightsubnet=192.0.2.0/24
leftsubnet=192.0.1.128/30
rightsubnet=192.0.2.128/30
left=%defaultroute
|