Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # ip x s ls
- # ip x p ls
- src 10.120.0.36/30 dst 172.36.0.0/22
- dir out priority 1040873 ptype main
- tmpl src 0.0.0.0 dst 0.0.0.0
- proto esp reqid 0 mode transport
- src ::/0 dst ::/0
- socket out priority 0 ptype main
- src ::/0 dst ::/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket out priority 0 ptype main
- src 0.0.0.0/0 dst 0.0.0.0/0
- socket in priority 0 ptype main
- src ::/0 dst ::/0 proto ipv6-icmp type 135
- dir out priority 1 ptype main
- src ::/0 dst ::/0 proto ipv6-icmp type 135
- dir fwd priority 1 ptype main
- src ::/0 dst ::/0 proto ipv6-icmp type 135
- dir in priority 1 ptype main
- src ::/0 dst ::/0 proto ipv6-icmp type 136
- dir out priority 1 ptype main
- src ::/0 dst ::/0 proto ipv6-icmp type 136
- dir fwd priority 1 ptype main
- src ::/0 dst ::/0 proto ipv6-icmp type 136
- dir in priority 1 ptype main
- # basic configuration
- config setup
- strictcrlpolicy=no
- uniqueids= yes
- # Add connections here.
- conn %default
- type= tunnel
- authby= secret
- keyexchange=ike
- ikelifetime= 86400s
- aggressive= no
- # Outras configurações
- compress= no
- forceencaps= yes
- # IPSEC Fase 1
- ike= aes256-sha1-modp1536,aes256gcm16-sha256-ecp521,aes256-sha256-ecp384,aes256gcm16-sha256-ecp256!
- # IPSEC Fase 2
- esp= aes256-sha1-modp1024,aes256gcm16-sha256,aes256-sha256!
- conn vpnipsec-myclient
- keyexchange=ike
- leftprotoport= %any
- ikev2=insist
- # IPSEC Fase 1
- ike= aes256-sha256-modp2048
- # IPSEC Fase 2
- esp= aes256-sha256-modp2048
- # Left security
- left= 173.X.X.X
- leftid= 173.X.X.X
- leftsubnet= 10.120.0.36/30
- leftauth= secret
- # Right security
- right= 177.X.X.X
- rightid= 177.X.X.X
- rightauth= secret
- rightsubnet= 172.36.0.0/22
- auto= start
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement