Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- config user peer
- edit "MachineAuth"
- set ca "CA_Cert_4" #SubCA from Clients and IKE Peer/Signature Cert
- next
- end
- config user peergrp
- edit "MachineAuthGrp"
- set member "MachineAuth"
- next
- end
- # Currently not used
- config user group
- edit "AlwaysOn MachineAuth"
- set member "MachineAuth"
- next
- end
- config vpn ipsec phase1-interface
- edit "DeviceTunnel"
- set type dynamic
- set interface "AlwaysOn-VPN"
- set ike-version 2
- set local-gw 1.1.1.1
- set authmethod signature
- set net-device disable
- set mode-cfg enable
- set ipv4-dns-server1 172.17.12.1
- set proposal aes128-sha256 aes256-sha256 aes128gcm-prfsha256 aes256gcm-prfsha384 chacha20poly1305-prfsha256
- set dpd on-idle
- set dhgrp 19 14 2
- set certificate "AlwaysOn-VPN_DeviceTunnel_2022"
- set peer "MachineAuth"
- set ipv4-start-ip 10.251.0.0
- set ipv4-end-ip 10.251.250.250
- set dpd-retryinterval 60
- next
- end
- config vpn ipsec phase2-interface
- edit "AlwaysOn-Device"
- set phase1name "DeviceTunnel"
- set proposal aes128-sha1 aes256-sha1 aes128-sha256 aes256-sha256 aes128gcm aes256gcm chacha20poly1305
- set dhgrp 19 14 2
- set keepalive enable
- next
- end
- config firewall policy
- edit 6
- set uuid 11ca083a-2f66-51eb-921a-75456ca4c5cc
- set srcintf "DeviceTunnel"
- set dstintf "Internal"
- set action accept
- set srcaddr "all"
- set dstaddr "all"
- set schedule "always"
- set service "ALL"
- set logtraffic all
- next
- end
Advertisement
Add Comment
Please, Sign In to add comment