From 0494fb2e21e9ecf62576d9ad4e91114b40bf0482 Mon Sep 17 00:00:00 2001 From: toby Date: Wed, 5 Dec 2018 21:26:06 +0100 Subject: [PATCH] ipsec: no changes, just unified formating and cleanup of config --- files/ipsec.conf.wit | 70 ++++++++++++++++++++++---------------------- 1 file changed, 35 insertions(+), 35 deletions(-) diff --git a/files/ipsec.conf.wit b/files/ipsec.conf.wit index 966ef37..8dfb7ca 100644 --- a/files/ipsec.conf.wit +++ b/files/ipsec.conf.wit @@ -1,56 +1,56 @@ config setup - #strictcrlpolicy=yes - cachecrls=yes + #strictcrlpolicy = yes + cachecrls = yes conn %default - #keyexchange=ikev2 - keyingtries=%forever - dpdtimeout=10 - dpddelay=2 - dpdaction=hold - #closeaction=none + #keyexchange = ikev2 + keyingtries = %forever + dpdtimeout = 10 + dpddelay = 2 + dpdaction = hold + #closeaction = none #rekeyfuzz = 100% ikelifetime = 4h margintime = 12m reauth = no - type=transport - ike=aes256-sha512-modp4096! - esp=aes256-sha512-modp4096! - leftcert=FQHOSTNAME.crt - leftid="C=US, O=Wit, CN=FQHOSTNAME" - rightid="C=US, O=Wit, CN=*" - auto=route + type = transport + ike = aes256-sha512-modp4096! + esp = aes256-sha512-modp4096! + leftcert = FQHOSTNAME.crt + leftid = "C=US, O=Wit, CN=FQHOSTNAME" + rightid = "C=US, O=Wit, CN=*" + auto = route conn local4 - left=LOOPBACKv4 - leftsubnet=LOOPBACKv4 - right=LOOPBACKv4 - rightsubnet=LOOPBACKv4 - auth=none - type=passthrough + left = LOOPBACKv4 + leftsubnet = LOOPBACKv4 + right = LOOPBACKv4 + rightsubnet = LOOPBACKv4 + auth = none + type = passthrough conn loopback4 - left=LOOPBACKv4 - leftsubnet=LOOPBACKv4 - right=IPSEC_IPV4_SUBNETS - rightsubnet=IPSEC_IPV4_SUBNETS + left = LOOPBACKv4 + leftsubnet = LOOPBACKv4 + right = IPSEC_IPV4_SUBNETS + rightsubnet = IPSEC_IPV4_SUBNETS conn local6 - left=LOOPBACKv6 - leftsubnet=LOOPBACKv6 - right=LOOPBACKv6 - rightsubnet=LOOPBACKv6 - auth=none - type=passthrough + left = LOOPBACKv6 + leftsubnet = LOOPBACKv6 + right = LOOPBACKv6 + rightsubnet = LOOPBACKv6 + auth = none + type = passthrough conn loopback6 - left=LOOPBACKv6 - leftsubnet=LOOPBACKv6 - right=%any6 - rightsubnet=IPSEC_IPV6_SUBNETS + left = LOOPBACKv6 + leftsubnet = LOOPBACKv6 + right = %any6 + rightsubnet = IPSEC_IPV6_SUBNETS