ipsec.conf 946 B

12345678910111213141516171819202122232425262728293031323334
  1. version 2.0
  2. config setup
  3. interfaces=%defaultroute
  4. nat_traversal=yes # required on both ends
  5. uniqueids=yes # makes sense on client, not server
  6. hidetos=no
  7. conn %default
  8. authby=rsasig
  9. keyingtries=3
  10. keyexchange=ike
  11. left=%defaultroute
  12. leftrsasigkey=%cert
  13. rightrsasigkey=%cert
  14. dpdtimeout=30 # keepalive must arrive within
  15. dpddelay=5 # secs before keepalives start
  16. compress=no # breaks double nat installations
  17. pfs=yes
  18. conn sample
  19. leftca=%same
  20. leftcert=my.certificate.crt
  21. leftsourceip=192.168.10.1
  22. leftsubnet=192.168.10.0/24
  23. right=my.vpn.concentrator.net.
  24. rightca=%same
  25. rightid="C=??, ST=??, O=??, OU=??, CN=my.vpn.concentrator.net, [email protected]"
  26. rightsourceip=192.168.11.1
  27. rightsubnet=192.168.11.0/24
  28. dpdaction=hold
  29. auto=start