Project

General

Profile

Bug #15685 ยป swanctl.conf

Danilo Zrenjanin, 08/15/2024 04:02 PM

 
1
# This file is automatically generated. Do not edit
2
connections {
3
	bypass {
4
		remote_addrs = 127.0.0.1
5
		children {
6
			bypasslan {
7
				local_ts = 192.168.1.0/24
8
				remote_ts = 192.168.1.0/24
9
				mode = pass
10
				start_action = trap
11
			}
12
		}
13
	}
14
	con-mobile : con-mobile-defaults {
15
		# Stub to load con-mobile-defaults
16
	}
17
}
18
con-mobile-defaults {
19
	fragmentation = yes
20
	unique = replace
21
	version = 2
22
	proposals = aes256-sha256-modp2048
23
	dpd_delay = 10s
24
	rekey_time = 25920s
25
	reauth_time = 0s
26
	over_time = 2880s
27
	rand_time = 2880s
28
	encap = no
29
	mobike = yes
30
	local_addrs = 172.21.10.103
31
	remote_addrs = 0.0.0.0/0,::/0
32
	pools = mobile-pool-v4
33
	send_cert = always
34
	local {
35
		id = fqdn:test.ipbgd.office
36
		auth = pubkey
37
		cert {
38
			file = /var/etc/ipsec/x509/cert-1.crt
39
		}
40
	}
41
	remote {
42
		id = %any
43
		eap_id = %any
44
		auth = eap-tls
45
		cacerts = /var/etc/ipsec/x509ca/791c09ae.0
46
	}
47
	children {
48
		con-mobile {
49
			# P2 (reqid 1): phase2
50
			mode = tunnel
51
			policies = yes
52
			life_time = 3600s
53
			rekey_time = 3240s
54
			rand_time = 360s
55
			start_action = none
56
			local_ts = 0.0.0.0/0
57
			esp_proposals = aes256gcm128-modp2048,aes256gcm96-modp2048,aes256gcm64-modp2048,aes128gcm128-modp2048,aes128-sha256-modp2048,aes128-sha384-modp2048,aes128-sha512-modp2048
58
			dpd_action = clear
59
		}
60
	}
61
}
62
pools {
63
	mobile-pool-v4 : mobile-pool {
64
		addrs = 192.168.42.0/24
65
	}
66
}
67
mobile-pool {
68
	# Mobile pool settings template
69
}
70
secrets {
71
	private-0 {
72
		file = /var/etc/ipsec/private/cert-1.key
73
	}
74
}
    (1-1/1)