ipsec: no changes, just unified formating and cleanup of config
This commit is contained in:
parent
51f6a94ccd
commit
0494fb2e21
|
@ -1,56 +1,56 @@
|
||||||
config setup
|
config setup
|
||||||
#strictcrlpolicy=yes
|
#strictcrlpolicy = yes
|
||||||
cachecrls=yes
|
cachecrls = yes
|
||||||
|
|
||||||
|
|
||||||
conn %default
|
conn %default
|
||||||
#keyexchange=ikev2
|
#keyexchange = ikev2
|
||||||
keyingtries=%forever
|
keyingtries = %forever
|
||||||
dpdtimeout=10
|
dpdtimeout = 10
|
||||||
dpddelay=2
|
dpddelay = 2
|
||||||
dpdaction=hold
|
dpdaction = hold
|
||||||
#closeaction=none
|
#closeaction = none
|
||||||
#rekeyfuzz = 100%
|
#rekeyfuzz = 100%
|
||||||
ikelifetime = 4h
|
ikelifetime = 4h
|
||||||
margintime = 12m
|
margintime = 12m
|
||||||
reauth = no
|
reauth = no
|
||||||
type=transport
|
type = transport
|
||||||
ike=aes256-sha512-modp4096!
|
ike = aes256-sha512-modp4096!
|
||||||
esp=aes256-sha512-modp4096!
|
esp = aes256-sha512-modp4096!
|
||||||
leftcert=FQHOSTNAME.crt
|
leftcert = FQHOSTNAME.crt
|
||||||
leftid="C=US, O=Wit, CN=FQHOSTNAME"
|
leftid = "C=US, O=Wit, CN=FQHOSTNAME"
|
||||||
rightid="C=US, O=Wit, CN=*"
|
rightid = "C=US, O=Wit, CN=*"
|
||||||
auto=route
|
auto = route
|
||||||
|
|
||||||
|
|
||||||
conn local4
|
conn local4
|
||||||
left=LOOPBACKv4
|
left = LOOPBACKv4
|
||||||
leftsubnet=LOOPBACKv4
|
leftsubnet = LOOPBACKv4
|
||||||
right=LOOPBACKv4
|
right = LOOPBACKv4
|
||||||
rightsubnet=LOOPBACKv4
|
rightsubnet = LOOPBACKv4
|
||||||
auth=none
|
auth = none
|
||||||
type=passthrough
|
type = passthrough
|
||||||
|
|
||||||
|
|
||||||
conn loopback4
|
conn loopback4
|
||||||
left=LOOPBACKv4
|
left = LOOPBACKv4
|
||||||
leftsubnet=LOOPBACKv4
|
leftsubnet = LOOPBACKv4
|
||||||
right=IPSEC_IPV4_SUBNETS
|
right = IPSEC_IPV4_SUBNETS
|
||||||
rightsubnet=IPSEC_IPV4_SUBNETS
|
rightsubnet = IPSEC_IPV4_SUBNETS
|
||||||
|
|
||||||
|
|
||||||
conn local6
|
conn local6
|
||||||
left=LOOPBACKv6
|
left = LOOPBACKv6
|
||||||
leftsubnet=LOOPBACKv6
|
leftsubnet = LOOPBACKv6
|
||||||
right=LOOPBACKv6
|
right = LOOPBACKv6
|
||||||
rightsubnet=LOOPBACKv6
|
rightsubnet = LOOPBACKv6
|
||||||
auth=none
|
auth = none
|
||||||
type=passthrough
|
type = passthrough
|
||||||
|
|
||||||
|
|
||||||
conn loopback6
|
conn loopback6
|
||||||
left=LOOPBACKv6
|
left = LOOPBACKv6
|
||||||
leftsubnet=LOOPBACKv6
|
leftsubnet = LOOPBACKv6
|
||||||
right=%any6
|
right = %any6
|
||||||
rightsubnet=IPSEC_IPV6_SUBNETS
|
rightsubnet = IPSEC_IPV6_SUBNETS
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue