added
[strongswan.git] / testing / tests / ikev2 / ocsp-local-cert / hosts / moon / etc / ipsec.conf
1 # /etc/ipsec.conf - strongSwan IPsec configuration file
2
3 config setup
4         crlcheckinterval=180
5         strictcrlpolicy=yes
6         plutostart=no
7
8 ca strongswan-ca
9         cacert=strongswanCert.pem
10         ocspuri=http://ocsp.strongswan.org:8880
11         auto=add
12
13 conn %default
14         keyexchange=ikev2
15         ikelifetime=60m
16         keylife=20m
17         rekeymargin=3m
18         keyingtries=1
19
20 conn rw
21         left=PH_IP_MOON
22         leftnexthop=%direct
23         leftcert=moonCert.pem
24         leftid=@moon.strongswan.org
25         leftsubnet=10.1.0.0/16
26         right=%any
27         auto=add