Guest User

Untitled

a guest
Apr 22nd, 2018
115
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.76 KB | None | 0 0
  1. # ipsec.conf - strongSwan IPsec configuration file
  2.  
  3. # basic configuration
  4.  
  5. config setup
  6. charondebug="ike 2, knl 2, cfg 2, net 2, esp 2, dmn 2, mgr 2"
  7. # strictcrlpolicy=yes
  8. # uniqueids = no
  9.  
  10. # Add connections here.
  11. conn %default
  12. keyexchange=ikev2
  13. ike=aes128-sha256-ecp256,aes256-sha384-ecp384,aes128-sha256-modp2048,aes128-sha1-modp2048,aes256-sha384-modp4096,aes256-sha256-modp4096,aes256-sha1-modp4096,aes128-sha256-modp1536,aes128-sha1-modp1536,aes256-sha384-modp2048,aes256-sha256-modp2048,aes256-sha1-modp2048,aes128-sha256-modp1024,aes128-sha1-modp1024,aes256-sha384-modp1536,aes256-sha256-modp1536,aes256-sha1-modp1536,aes256-sha384-modp1024,aes256-sha256-modp1024,aes256-sha1-modp1024,aes256-sha-modp1024,aes256-sha512-modp4096!
  14. esp=aes128gcm16-ecp256,aes256gcm16-ecp384,aes128-sha256-ecp256,aes256-sha384-ecp384,aes128-sha256-modp2048,aes128-sha1-modp2048,aes256-sha384-modp4096,aes256-sha256-modp4096,aes256-sha1-modp4096,aes128-sha256-modp1536,aes128-sha1-modp1536,aes256-sha384-modp2048,aes256-sha256-modp2048,aes256-sha1-modp2048,aes128-sha256-modp1024,aes128-sha1-modp1024,aes256-sha384-modp1536,aes256-sha256-modp1536,aes256-sha1-modp1536,aes256-sha384-modp1024,aes256-sha256-modp1024,aes256-sha1-modp1024,aes128gcm16,aes256gcm16,aes128-sha256,aes128-sha1,aes256-sha384,aes256-sha256,aes256-sha1,aes256-sha-modp1024,aes256-sha512-modp4096!
  15. dpdaction=clear
  16. dpddelay=300s
  17. rekey=no
  18. left=%any
  19. leftsubnet=0.0.0.0/0
  20. leftcert=serverCert.der
  21. right=%any
  22. rightdns=8.8.8.8,8.8.4.4
  23. rightsourceip=10.20.30.0/24
  24.  
  25. conn IPSec-IKEv2
  26. keyexchange=ikev2
  27. auto=add
  28.  
  29. conn IPSec-IKEv2-EAP
  30. also="IPSec-IKEv2"
  31. rightauth=eap-mschapv2
  32. rightauthby2=pubkey
  33. rightsendcert=never
  34. eap_identity=%any
Add Comment
Please, Sign In to add comment