1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42
|
# /etc/ipsec.conf - Libreswan IPsec configuration file
config setup
ikev1-policy=accept
logfile=/tmp/pluto.log
logtime=no
logappend=no
dumpdir=/tmp
plutodebug=all
virtual-private=%v4:192.1.3.0/24
conn %default
keyexchange=ikev1
conn north-east
also=xauth-base
left=%defaultroute
leftcert=north
conn road-east
also=xauth-base
left=%defaultroute
leftcert=road
conn east-any
also=xauth-base
left=%any
leftaddresspool=192.0.2.100-192.0.2.200
xauthby=alwaysok
rightcert=east
modecfgdns="1.2.3.4, 5.6.7.8"
conn xauth-base
leftid=%fromcert
rightid=%fromcert
rightxauthserver=yes
leftxauthclient=yes
rightmodecfgserver=yes
leftmodecfgclient=yes
right=192.1.2.23
rightsubnet=192.0.2.0/24
modecfgpull=yes
|