Enabled IKEv2 fragmentation in ipv6/net2net-ikev2 scenario
[strongswan.git] / testing / tests / ipv6 / net2net-ikev2 / hosts / moon / etc / ipsec.conf
1 # /etc/ipsec.conf - strongSwan IPsec configuration file
2
3 config setup
4
5 ca strongswan
6         cacert=strongswanCert.pem
7         certuribase=http://ip6-winnetou.strongswan.org/certs/
8         crluri=http://ip6-winnetou.strongswan.org/strongswan.crl
9         auto=add
10
11 conn %default
12         ikelifetime=60m
13         keylife=20m
14         rekeymargin=3m
15         keyingtries=1
16         keyexchange=ikev2
17         fragmentation=yes
18         mobike=no
19
20 conn net-net
21         also=host-host
22         leftsubnet=fec1::0/16
23         rightsubnet=fec2::0/16
24
25 conn host-host
26         left=PH_IP6_MOON
27         leftcert=moonCert.pem
28         leftid=@moon.strongswan.org
29         leftfirewall=yes
30         right=PH_IP6_SUN
31         rightid=@sun.strongswan.org
32         auto=add