ipsec: no changes, just unified formating and cleanup of config
This commit is contained in:
parent
51f6a94ccd
commit
0494fb2e21
|
@ -1,56 +1,56 @@
|
|||
config setup
|
||||
#strictcrlpolicy=yes
|
||||
cachecrls=yes
|
||||
#strictcrlpolicy = yes
|
||||
cachecrls = yes
|
||||
|
||||
|
||||
conn %default
|
||||
#keyexchange=ikev2
|
||||
keyingtries=%forever
|
||||
dpdtimeout=10
|
||||
dpddelay=2
|
||||
dpdaction=hold
|
||||
#closeaction=none
|
||||
#keyexchange = ikev2
|
||||
keyingtries = %forever
|
||||
dpdtimeout = 10
|
||||
dpddelay = 2
|
||||
dpdaction = hold
|
||||
#closeaction = none
|
||||
#rekeyfuzz = 100%
|
||||
ikelifetime = 4h
|
||||
margintime = 12m
|
||||
reauth = no
|
||||
type=transport
|
||||
ike=aes256-sha512-modp4096!
|
||||
esp=aes256-sha512-modp4096!
|
||||
leftcert=FQHOSTNAME.crt
|
||||
leftid="C=US, O=Wit, CN=FQHOSTNAME"
|
||||
rightid="C=US, O=Wit, CN=*"
|
||||
auto=route
|
||||
type = transport
|
||||
ike = aes256-sha512-modp4096!
|
||||
esp = aes256-sha512-modp4096!
|
||||
leftcert = FQHOSTNAME.crt
|
||||
leftid = "C=US, O=Wit, CN=FQHOSTNAME"
|
||||
rightid = "C=US, O=Wit, CN=*"
|
||||
auto = route
|
||||
|
||||
|
||||
conn local4
|
||||
left=LOOPBACKv4
|
||||
leftsubnet=LOOPBACKv4
|
||||
right=LOOPBACKv4
|
||||
rightsubnet=LOOPBACKv4
|
||||
auth=none
|
||||
type=passthrough
|
||||
left = LOOPBACKv4
|
||||
leftsubnet = LOOPBACKv4
|
||||
right = LOOPBACKv4
|
||||
rightsubnet = LOOPBACKv4
|
||||
auth = none
|
||||
type = passthrough
|
||||
|
||||
|
||||
conn loopback4
|
||||
left=LOOPBACKv4
|
||||
leftsubnet=LOOPBACKv4
|
||||
right=IPSEC_IPV4_SUBNETS
|
||||
rightsubnet=IPSEC_IPV4_SUBNETS
|
||||
left = LOOPBACKv4
|
||||
leftsubnet = LOOPBACKv4
|
||||
right = IPSEC_IPV4_SUBNETS
|
||||
rightsubnet = IPSEC_IPV4_SUBNETS
|
||||
|
||||
|
||||
conn local6
|
||||
left=LOOPBACKv6
|
||||
leftsubnet=LOOPBACKv6
|
||||
right=LOOPBACKv6
|
||||
rightsubnet=LOOPBACKv6
|
||||
auth=none
|
||||
type=passthrough
|
||||
left = LOOPBACKv6
|
||||
leftsubnet = LOOPBACKv6
|
||||
right = LOOPBACKv6
|
||||
rightsubnet = LOOPBACKv6
|
||||
auth = none
|
||||
type = passthrough
|
||||
|
||||
|
||||
conn loopback6
|
||||
left=LOOPBACKv6
|
||||
leftsubnet=LOOPBACKv6
|
||||
right=%any6
|
||||
rightsubnet=IPSEC_IPV6_SUBNETS
|
||||
left = LOOPBACKv6
|
||||
leftsubnet = LOOPBACKv6
|
||||
right = %any6
|
||||
rightsubnet = IPSEC_IPV6_SUBNETS
|
||||
|
||||
|
|
Loading…
Reference in New Issue