Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- path pre_shared_key "/usr/local/etc/racoon/psk.txt";
- log notify; #log verbosity setting: set to 'notify' when testing and debugging is complete
- padding # options are not to be changed
- {
- maximum_length 20;
- randomize off;
- strict_check off;
- exclusive_tail off;
- }
- timer # timing options. change as needed
- {
- counter 5;
- interval 20 sec;
- persend 1;
- # natt_keepalive 15 sec;
- phase1 30 sec;
- phase2 15 sec;
- }
- listen # address [port] that racoon will listen on
- {
- isakmp <source ip> [500];
- isakmp_natt <source ip> [4500];
- }
- remote <dest ip> {
- exchange_mode main;
- lifetime time 28800 seconds;
- doi ipsec_doi;
- situation identity_only;
- my_identifier address <source ip>;
- peers_identifier address <dest ip>;
- lifetime time 8 hour;
- passive off;
- proposal_check obey;
- # nat_traversal off;
- generate_policy off;
- proposal {
- encryption_algorithm aes128;
- hash_algorithm sha1;
- authentication_method pre_shared_key;
- dh_group 2;
- }
- generate_policy off;
- }
- sainfo address <internal source tunnel ip/30> any address <internal destination tunnel ip/30> any {
- pfs_group 2;
- lifetime time 3600 seconds;
- encryption_algorithm aes128;
- authentication_algorithm hmac_sha1;
- compression_algorithm deflate;
- }
- sainfo address <internal source tunnel ip/30> any address <destination-LAN net> any {
- pfs_group 2;
- lifetime time 3600 seconds;
- encryption_algorithm aes128;
- authentication_algorithm hmac_sha1;
- compression_algorithm deflate;
- }
- sainfo address <source-LAN net> any address <destination-LAN net> any {
- pfs_group 2;
- lifetime time 3600 seconds;
- encryption_algorithm aes128;
- authentication_algorithm hmac_sha1;
- compression_algorithm deflate;
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement