added
[strongswan.git] / testing / tests / ikev2 / nat-one-rw / hosts / sun / etc / ipsec.conf
1 # /etc/ipsec.conf - strongSwan IPsec configuration file
2
3 config setup
4         strictcrlpolicy=no
5         plutostart=no
6
7 conn %default
8         ikelifetime=60m
9         keylife=20m
10         rekeymargin=3m
11         keyingtries=1
12         keyexchange=ikev2
13         left=PH_IP_SUN
14         leftcert=sunCert.pem
15         leftid=@sun.strongswan.org
16
17 conn net-net
18         leftsubnet=10.2.0.0/16
19         right=PH_IP_MOON
20         rightsubnet=10.1.0.0/16
21         rightid=@moon.strongswan.org
22         auto=add
23
24 conn host-host
25         right=PH_IP_MOON
26         rightid=@moon.strongswan.org
27         auto=add
28
29 conn nat-t
30         leftsubnet=10.2.0.0/16
31         right=%any
32         rightsubnetwithin=10.1.0.0/16
33         auto=add