1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45
|
# /etc/ipsec.conf - Libreswan IPsec configuration file
version 2.0
config setup
ikev1-policy=accept
# put the logs in /tmp for the UMLs, so that we can operate
# without syslogd, which seems to break on UMLs
logfile=/tmp/pluto.log
logtime=no
logappend=no
logip=no
dumpdir=/tmp
plutodebug=all
virtual-private=%v4:192.1.3.0/24
conn %default
keyexchange=ikev1
conn modecfg-road-east
also=modecfg-road-east-x509-base
also=modecfg-east
conn modecfg-road
left=%defaultroute
conn modecfg-east
left=%any
leftsubnet=192.0.2.19/32
conn modecfg-road-east-x509-base
auto=ignore
rightxauthserver=yes
leftxauthclient=yes
rightmodecfgserver=yes
leftmodecfgclient=yes
right=192.1.2.23
rightsubnet=0.0.0.0/0
modecfgpull=yes
modecfgdns="1.2.3.4, 5.6.7.8"
xauthby=alwaysok
leftid=%fromcert
leftcert=road
rightid=%fromcert
rightcert=east
|