2018-07-27 15:34:21 -05:00
|
|
|
config setup
|
|
|
|
#strictcrlpolicy=yes
|
|
|
|
cachecrls=yes
|
|
|
|
|
|
|
|
|
|
|
|
conn %default
|
2018-12-01 11:30:10 -06:00
|
|
|
#keyexchange=ikev2
|
2018-07-27 15:34:21 -05:00
|
|
|
keyingtries=%forever
|
2018-11-18 16:18:29 -06:00
|
|
|
dpdtimeout=10
|
2018-11-18 15:06:53 -06:00
|
|
|
dpddelay=2
|
2018-11-18 15:14:26 -06:00
|
|
|
dpdaction=hold
|
|
|
|
#closeaction=none
|
2018-11-30 11:27:18 -06:00
|
|
|
#rekeyfuzz = 100%
|
|
|
|
ikelifetime = 4h
|
|
|
|
margintime = 12m
|
|
|
|
reauth = no
|
2018-07-27 15:34:21 -05:00
|
|
|
type=transport
|
2018-11-30 11:27:18 -06:00
|
|
|
ike=aes256-sha512-modp4096!
|
|
|
|
esp=aes256-sha512-modp4096!
|
2018-09-17 14:28:02 -05:00
|
|
|
leftcert=FQHOSTNAME.crt
|
|
|
|
leftid="C=US, O=Wit, CN=FQHOSTNAME"
|
|
|
|
rightid="C=US, O=Wit, CN=*"
|
|
|
|
auto=route
|
2018-07-27 15:34:21 -05:00
|
|
|
|
|
|
|
|
2018-11-18 15:06:53 -06:00
|
|
|
conn local4
|
|
|
|
left=LOOPBACKv4
|
|
|
|
leftsubnet=LOOPBACKv4
|
|
|
|
right=LOOPBACKv4
|
|
|
|
rightsubnet=LOOPBACKv4
|
|
|
|
auth=none
|
|
|
|
type=passthrough
|
|
|
|
|
|
|
|
|
2018-09-17 14:28:02 -05:00
|
|
|
conn loopback4
|
2018-10-31 17:06:30 -05:00
|
|
|
left=LOOPBACKv4
|
2018-10-23 16:28:29 -05:00
|
|
|
leftsubnet=LOOPBACKv4
|
2018-11-18 15:06:53 -06:00
|
|
|
right=IPSEC_IPV4_SUBNETS
|
2018-10-19 12:57:07 -05:00
|
|
|
rightsubnet=IPSEC_IPV4_SUBNETS
|
2018-11-18 15:06:53 -06:00
|
|
|
|
|
|
|
|
|
|
|
conn local6
|
|
|
|
left=LOOPBACKv6
|
|
|
|
leftsubnet=LOOPBACKv6
|
|
|
|
right=LOOPBACKv6
|
|
|
|
rightsubnet=LOOPBACKv6
|
|
|
|
auth=none
|
|
|
|
type=passthrough
|
2018-09-17 14:28:02 -05:00
|
|
|
|
|
|
|
|
|
|
|
conn loopback6
|
2018-10-31 17:06:30 -05:00
|
|
|
left=LOOPBACKv6
|
2018-10-23 16:28:29 -05:00
|
|
|
leftsubnet=LOOPBACKv6
|
2018-09-17 14:28:02 -05:00
|
|
|
right=%any6
|
2018-11-18 15:06:53 -06:00
|
|
|
rightsubnet=IPSEC_IPV6_SUBNETS
|
2018-07-27 15:34:21 -05:00
|
|
|
|