1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61
|
# /etc/ipsec.conf - Libreswan IPsec configuration file
version 2.0
config setup
ikev1-policy=accept
logfile=/tmp/pluto.log
logtime=yes
logappend=no
plutodebug="all"
dumpdir=/tmp
conn %default
keyexchange=ikev1
conn north-a-dpd
also=northnet-eastnet-a
dpddelay=3
dpdtimeout=10
dpdaction=restart
conn north-b
also=northnet-eastnet-b
conn northnet-eastnet-b
# Left security gateway, subnet behind it, next hop toward right.
left=192.1.3.33
leftnexthop=192.1.3.254
leftrsasigkey=%cert
leftcert=north
leftid=%fromcert
# Right security gateway, subnet behind it, next hop toward left.
right=192.1.2.23
rightid=%fromcert
rightrsasigkey=%cert
rightcert=east
rightnexthop=192.1.2.254
rightsubnet=192.0.2.0/24
leftsubnet=192.0.3.0/24
auto=ignore
conn northnet-eastnet-a
also=north-east-x509
rightsubnet=192.0.22.0/24
leftsubnet=192.0.3.0/24
auto=ignore
# we should split this conn so we can re-use it without hardcoded left/rightcert=
conn north-east-x509
# Left security gateway, subnet behind it, next hop toward right.
left=192.1.3.33
leftnexthop=192.1.3.254
leftrsasigkey=%cert
leftcert=north
leftid=%fromcert
# Right security gateway, subnet behind it, next hop toward left.
right=192.1.2.23
rightid=%fromcert
rightrsasigkey=%cert
rightcert=east
rightnexthop=192.1.2.254
|