Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # ipsec.conf - strongSwan IPsec configuration file
- config setup
- charondebug="ike 2, knl 2, cfg 2, net 2, esp 2, dmn 2, mgr 2"
- conn %default
- ikelifetime=24h
- keylife=24h
- keyexchange=ikev2
- dpdaction=clear
- dpdtimeout=3600s
- dpddelay=3600s
- compress=yes
- conn test
- keyexchange=ikev2
- ike=aes128-sha256-ecp256,aes256-sha384-ecp384,aes128-sha256-modp2048,aes128-sha1-modp2048,aes256-sha384-modp4096,aes256-sha256-modp4096,aes256-sha1-modp4096,aes128-sha256-modp1536,aes128-sha1-modp1536,aes256-sha384-modp2048,aes256-sha256-modp2048,aes256-sha1-modp2048,aes128-sha256-modp1024,aes128-sha1-modp1024,aes256-sha384-modp1536,aes256-sha256-modp1536,aes256-sha1-modp1536,aes256-sha384-modp1024,aes256-sha256-modp1024,aes256-sha1-modp1024!
- esp=aes128gcm16-ecp256,aes256gcm16-ecp384,aes128-sha256-ecp256,aes256-sha384-ecp384,aes128-sha256-modp2048,aes128-sha1-modp2048,aes256-sha384-modp4096,aes256-sha256-modp4096,aes256-sha1-modp4096,aes128-sha256-modp1536,aes128-sha1-modp1536,aes256-sha384-modp2048,aes256-sha256-modp2048,aes256-sha1-modp2048,aes128-sha256-modp1024,aes128-sha1-modp1024,aes256-sha384-modp1536,aes256-sha256-modp1536,aes256-sha1-modp1536,aes256-sha384-modp1024,aes256-sha256-modp1024,aes256-sha1-modp1024,aes128gcm16,aes256gcm16,aes128-sha256,aes128-sha1,aes256-sha384,aes256-sha256,aes256-sha1!
- dpdaction=clear
- dpddelay=300s
- rekey=no
- left=%any
- leftsubnet=192.168.99.1/24
- leftcert=vpnHostCert.der
- right=%any
- rightdns=8.8.8.8,8.8.4.4
- rightsourceip=192.168.10.100/16
- conn test2
- keyexchange=ikev2
- ike=aes128-sha256-ecp256,aes256-sha384-ecp384,aes128-sha256-modp2048,aes128-sha1-modp2048,aes256-sha384-modp4096,aes256-sha256-modp4096,aes256-sha1-modp4096,aes128-sha256-modp1536,aes128-sha1-modp1536,aes256-sha384-modp2048,aes256-sha256-modp2048,aes256-sha1-modp2048,aes128-sha256-modp1024,aes128-sha1-modp1024,aes256-sha384-modp1536,aes256-sha256-modp1536,aes256-sha1-modp1536,aes256-sha384-modp1024,aes256-sha256-modp1024,aes256-sha1-modp1024!
- esp=aes128gcm16-ecp256,aes256gcm16-ecp384,aes128-sha256-ecp256,aes256-sha384-ecp384,aes128-sha256-modp2048,aes128-sha1-modp2048,aes256-sha384-modp4096,aes256-sha256-modp4096,aes256-sha1-modp4096,aes128-sha256-modp1536,aes128-sha1-modp1536,aes256-sha384-modp2048,aes256-sha256-modp2048,aes256-sha1-modp2048,aes128-sha256-modp1024,aes128-sha1-modp1024,aes256-sha384-modp1536,aes256-sha256-modp1536,aes256-sha1-modp1536,aes256-sha384-modp1024,aes256-sha256-modp1024,aes256-sha1-modp1024,aes128gcm16,aes256gcm16,aes128-sha256,aes128-sha1,aes256-sha384,aes256-sha256,aes256-sha1!
- dpdaction=clear
- dpddelay=300s
- rekey=no
- left=%any
- leftsubnet=192.168.99.1/24
- # leftcert=vpnHostCert.der
- rightsendcert=never
- right=%any
- rightdns=8.8.8.8,8.8.4.4
- rightsourceip=192.168.20.100/16
- conn IPSec-IKEv2
- keyexchange=ikev2
- auto=add
- conn IPSec-IKEv2-EAP
- also="IPSec-IKEv2"
- rightauth=eap-mschapv2
- rightauthby2=pubkey
- rightsendcert=never
- eap_identity=%any
- conn CiscoIPSec
- keyexchange=ikev1
- forceencaps=yes
- authby=xauthrsasig
- xauth=server
- auto=add
Advertisement
Add Comment
Please, Sign In to add comment