ipsec.conf Reference » History » Version 11
Version 10 (Martin Willi, 05.09.2007 09:00) → Version 11/21 (Andreas Steffen, 09.04.2009 11:02)
= ipsec.conf =
strongSwan's ''/etc/ipsec.conf'' configuration file consists of three different section types:
* [wiki:ConfigSetupSection config setup] defines general configuration parameters
* [wiki:ConnSection conn <name>] defines a connection
* [wiki:CaSection ca <name>] defines a certification authority
There can be only one [wiki:ConfigSetupSection config setup] section but
an unlimited number of [wiki:ConnSection conn] and [wiki:CaSection ca] sections.
All parameters belonging to a section must be indented by at least one space or tab
character. The rest of the line after a '#' character is treated as a comment.
Comments within a section must also be indented.
== Example ==
{{{
# /etc/ipsec.conf - strongSwan IPsec configuration file
config setup
crlcheckinterval=600s
cachecrls=yes
strictcrlpolicy=yes
plutostart=no
ca strongswan #define alternative CRL distribution point
cacert=strongswanCert.pem
crluri=http://crl2.strongswan.org/strongswan.crl
auto=add
conn %default
keyingtries=1
keyexchange=ikev2
conn roadwarrior
left=192.168.0.1
leftsubnet=10.1.0.0/16
leftcert=moonCert.pem
leftid=@moon.strongswan.org
right=%any
auto=add
}}}
== IKE and ESP Cipher Suites ==
* [wiki:IKEv2CipherSuites IKEv2 Cipher Suites]
strongSwan's ''/etc/ipsec.conf'' configuration file consists of three different section types:
* [wiki:ConfigSetupSection config setup] defines general configuration parameters
* [wiki:ConnSection conn <name>] defines a connection
* [wiki:CaSection ca <name>] defines a certification authority
There can be only one [wiki:ConfigSetupSection config setup] section but
an unlimited number of [wiki:ConnSection conn] and [wiki:CaSection ca] sections.
All parameters belonging to a section must be indented by at least one space or tab
character. The rest of the line after a '#' character is treated as a comment.
Comments within a section must also be indented.
== Example ==
{{{
# /etc/ipsec.conf - strongSwan IPsec configuration file
config setup
crlcheckinterval=600s
cachecrls=yes
strictcrlpolicy=yes
plutostart=no
ca strongswan #define alternative CRL distribution point
cacert=strongswanCert.pem
crluri=http://crl2.strongswan.org/strongswan.crl
auto=add
conn %default
keyingtries=1
keyexchange=ikev2
conn roadwarrior
left=192.168.0.1
leftsubnet=10.1.0.0/16
leftcert=moonCert.pem
leftid=@moon.strongswan.org
right=%any
auto=add
}}}
== IKE and ESP Cipher Suites ==
* [wiki:IKEv2CipherSuites IKEv2 Cipher Suites]