added
[strongswan.git] / testing / tests / ikev2 / ocsp-timeouts-unknown / hosts / moon / etc / ipsec.conf
1 # /etc/ipsec.conf - strongSwan IPsec configuration file
2
3 config setup
4         crlcheckinterval=180
5         strictcrlpolicy=yes
6         plutostart=no
7
8 ca strongswan-ca
9         cacert=strongswanCert.pem
10         ocspuri1=http://bob.strongswan.org:8800
11         ocspuri2=http://ocsp2.strongswan.org:8880
12         auto=add
13
14 conn %default
15         keyexchange=ikev2
16         ikelifetime=60m
17         keylife=20m
18         rekeymargin=3m
19         keyingtries=1
20
21 conn rw
22         left=PH_IP_MOON
23         leftnexthop=%direct
24         leftcert=moonCert.pem
25         leftid=@moon.strongswan.org
26         leftsubnet=10.1.0.0/16
27         right=%any
28         auto=add