1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43
|
# /etc/ipsec.conf - Libreswan IPsec configuration file
config setup
ikev1-policy=accept
logfile=/tmp/pluto.log
logtime=no
logappend=no
dumpdir=/tmp
plutodebug=all
conn base
keyexchange=ikev1
rightcert=east
right=192.1.2.23
rightmodecfgserver=yes
leftmodecfgclient=yes
modecfgpull=yes
rightxauthserver=yes
leftxauthclient=yes
modecfgdns="1.2.3.4, 5.6.7.8"
leftid=%fromcert
rightid=%fromcert
conn any-east
also=base
left=%any
leftaddresspool=192.0.2.101-192.0.2.200
xauthby=alwaysok
rightsubnet=0.0.0.0/0
conn road-east
also=base
# leftsubnet=<addresspool>
left=%defaultroute
rightsubnet=0.0.0.0/0
leftcert=road
conn road-narrows-east
also=base
# leftsubnet=<addresspool>
rightsubnet=192.0.2.0/24
left=%defaultroute
leftcert=road
|