1 DROP TABLE IF EXISTS identities
;
2 CREATE TABLE identities (
3 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
9 DROP TABLE IF EXISTS child_configs
;
10 CREATE TABLE child_configs (
11 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
13 lifetime
INTEGER NOT NULL DEFAULT '1200',
14 rekeytime
INTEGER NOT NULL DEFAULT '1020',
15 jitter
INTEGER NOT NULL DEFAULT '180',
16 updown
TEXT DEFAULT NULL,
17 hostaccess
INTEGER NOT NULL DEFAULT '0',
18 mode INTEGER NOT NULL DEFAULT '1',
19 dpd_action
INTEGER NOT NULL DEFAULT '0',
20 close_action
INTEGER NOT NULL DEFAULT '0'
22 DROP INDEX IF EXISTS child_configs_name
;
23 CREATE INDEX child_configs_name
ON child_configs (
27 DROP TABLE IF EXISTS child_config_traffic_selector
;
28 CREATE TABLE child_config_traffic_selector (
29 child_cfg
INTEGER NOT NULL,
30 traffic_selector
INTEGER NOT NULL,
33 DROP INDEX IF EXISTS child_config_traffic_selector
;
34 CREATE INDEX child_config_traffic_selector_all
ON child_config_traffic_selector (
35 child_cfg
, traffic_selector
38 DROP TABLE IF EXISTS ike_configs
;
39 CREATE TABLE ike_configs (
40 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
41 certreq
INTEGER NOT NULL DEFAULT '1',
42 force_encap
INTEGER NOT NULL DEFAULT '0',
47 DROP TABLE IF EXISTS peer_configs
;
48 CREATE TABLE peer_configs (
49 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
51 ike_version
INTEGER NOT NULL DEFAULT '2',
52 ike_cfg
INTEGER NOT NULL,
53 local_id
TEXT NOT NULL,
54 remote_id
TEXT NOT NULL,
55 cert_policy
INTEGER NOT NULL DEFAULT '1',
56 uniqueid
INTEGER NOT NULL DEFAULT '0',
57 auth_method
INTEGER NOT NULL DEFAULT '1',
58 eap_type
INTEGER NOT NULL DEFAULT '0',
59 eap_vendor
INTEGER NOT NULL DEFAULT '0',
60 keyingtries
INTEGER NOT NULL DEFAULT '1',
61 rekeytime
INTEGER NOT NULL DEFAULT '0',
62 reauthtime
INTEGER NOT NULL DEFAULT '3600',
63 jitter
INTEGER NOT NULL DEFAULT '180',
64 overtime
INTEGER NOT NULL DEFAULT '300',
65 mobike
INTEGER NOT NULL DEFAULT '1',
66 dpd_delay
INTEGER NOT NULL DEFAULT '120',
67 virtual
TEXT DEFAULT NULL,
68 pool
TEXT DEFAULT NULL,
69 mediation
INTEGER NOT NULL DEFAULT '0',
70 mediated_by
INTEGER NOT NULL DEFAULT '0',
71 peer_id
INTEGER NOT NULL DEFAULT '0'
73 DROP INDEX IF EXISTS peer_configs_name
;
74 CREATE INDEX peer_configs_name
ON peer_configs (
78 DROP TABLE IF EXISTS peer_config_child_config
;
79 CREATE TABLE peer_config_child_config (
80 peer_cfg
INTEGER NOT NULL,
81 child_cfg
INTEGER NOT NULL,
82 PRIMARY KEY (peer_cfg
, child_cfg
)
85 DROP TABLE IF EXISTS traffic_selectors
;
86 CREATE TABLE traffic_selectors (
87 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
88 type INTEGER NOT NULL DEFAULT '7',
89 protocol
INTEGER NOT NULL DEFAULT '0',
90 start_addr
BLOB DEFAULT NULL,
91 end_addr
BLOB DEFAULT NULL,
92 start_port
INTEGER NOT NULL DEFAULT '0',
93 end_port
INTEGER NOT NULL DEFAULT '65535'
96 DROP TABLE IF EXISTS certificates
;
97 CREATE TABLE certificates (
98 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
99 type INTEGER NOT NULL,
100 keytype
INTEGER NOT NULL,
104 DROP TABLE IF EXISTS certificate_identity
;
105 CREATE TABLE certificate_identity (
106 certificate
INTEGER NOT NULL,
107 identity INTEGER NOT NULL,
108 PRIMARY KEY (certificate
, identity)
111 DROP TABLE IF EXISTS private_keys
;
112 CREATE TABLE private_keys (
113 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
114 type INTEGER NOT NULL,
118 DROP TABLE IF EXISTS private_key_identity
;
119 CREATE TABLE private_key_identity (
120 private_key
INTEGER NOT NULL,
121 identity INTEGER NOT NULL,
122 PRIMARY KEY (private_key
, identity)
125 DROP TABLE IF EXISTS shared_secrets
;
126 CREATE TABLE shared_secrets (
127 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
128 type INTEGER NOT NULL,
132 DROP TABLE IF EXISTS shared_secret_identity
;
133 CREATE TABLE shared_secret_identity (
134 shared_secret
INTEGER NOT NULL,
135 identity INTEGER NOT NULL,
136 PRIMARY KEY (shared_secret
, identity)
139 DROP TABLE IF EXISTS ike_sas
;
140 CREATE TABLE ike_sas (
141 local_spi
BLOB NOT NULL PRIMARY KEY,
142 remote_spi
BLOB NOT NULL,
144 initiator
INTEGER NOT NULL,
145 local_id_type
INTEGER NOT NULL,
146 local_id_data
BLOB NOT NULL,
147 remote_id_type
INTEGER NOT NULL,
148 remote_id_data
BLOB NOT NULL,
149 host_family
INTEGER NOT NULL,
150 local_host_data
BLOB NOT NULL,
151 remote_host_data
BLOB NOT NULL,
152 created
INTEGER NOT NULL DEFAULT CURRENT_TIMESTAMP
155 DROP TABLE IF EXISTS logs
;
157 id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT
,
158 local_spi
BLOB NOT NULL,
159 signal
INTEGER NOT NULL,
160 level INTEGER NOT NULL,
162 time INTEGER NOT NULL DEFAULT CURRENT_TIMESTAMP
167 INSERT INTO identities (
169 ) VALUES ( /* fec0::1 */
170 5 , X
'fec00000000000000000000000000001'
173 INSERT INTO identities (
175 ) VALUES ( /* fec0::10 */
176 5 , X
'fec00000000000000000000000000010'
179 INSERT INTO identities (
181 ) VALUES ( /* fec0::20 */
182 5 , X
'fec00000000000000000000000000020'
185 INSERT INTO identities (
187 ) VALUES ( /* %any */
193 INSERT INTO shared_secrets (
196 1, X
'16964066a10de938bdb2ab7864fe4459cab1'
199 INSERT INTO shared_secrets (
202 1, X
'8d5cce342174da772c8224a59885deaa118d'
205 INSERT INTO shared_secret_identity (
206 shared_secret
, identity
211 INSERT INTO shared_secret_identity (
212 shared_secret
, identity
217 INSERT INTO shared_secret_identity (
218 shared_secret
, identity
223 INSERT INTO shared_secret_identity (
224 shared_secret
, identity
231 INSERT INTO ike_configs (
234 'PH_IP6_MOON', '0::0'
237 INSERT INTO peer_configs (
238 name, ike_cfg
, local_id
, remote_id
, auth_method
243 INSERT INTO child_configs (
246 'rw', 'ipsec _updown iptables'
249 INSERT INTO peer_config_child_config (
255 INSERT INTO traffic_selectors (
256 type, start_addr
, end_addr
257 ) VALUES ( /* fec1::/16 */
258 8, X
'fec10000000000000000000000000000', X
'fec1ffffffffffffffffffffffffffff'
261 INSERT INTO traffic_selectors (
263 ) VALUES ( /* dynamic/128 */
267 INSERT INTO child_config_traffic_selector (
268 child_cfg
, traffic_selector
, kind
273 INSERT INTO child_config_traffic_selector (
274 child_cfg
, traffic_selector
, kind