Project

General

Profile

ipsec.conf Reference » History » Version 12

Andreas Steffen, 09.04.2009 11:02
Added Link to IKEv2 cipher suites

1 1 Martin Willi
2 12 Andreas Steffen
h1. ipsec.conf
3 1 Martin Willi
4 1 Martin Willi
5 12 Andreas Steffen
strongSwan's _/etc/ipsec.conf_ configuration file consists of three different section types:
6 1 Martin Willi
7 12 Andreas Steffen
* [[ConfigSetupSection|config setup]] defines general configuration parameters
8 12 Andreas Steffen
* [[ConnSection|conn <name>]] defines a connection
9 12 Andreas Steffen
* [[CaSection|ca <name>]] defines a certification authority
10 12 Andreas Steffen
11 12 Andreas Steffen
There can be only one [[ConfigSetupSection|config setup]] section but
12 12 Andreas Steffen
an unlimited number of [[ConnSection|conn] and [wikiCaSection ca]] sections.
13 12 Andreas Steffen
14 3 Martin Willi
All parameters belonging to a section must be indented by at least one space or tab
15 4 Martin Willi
character. The rest of the line after a '#' character is treated as a comment.
16 4 Martin Willi
Comments within a section must also be indented.
17 4 Martin Willi
18 12 Andreas Steffen
19 12 Andreas Steffen
h2. Example
20 12 Andreas Steffen
21 12 Andreas Steffen
<pre>
22 9 Martin Willi
# /etc/ipsec.conf - strongSwan IPsec configuration file
23 9 Martin Willi
24 8 Martin Willi
config setup
25 8 Martin Willi
       crlcheckinterval=600s
26 8 Martin Willi
       cachecrls=yes
27 8 Martin Willi
       strictcrlpolicy=yes
28 8 Martin Willi
       plutostart=no
29 8 Martin Willi
30 10 Martin Willi
ca strongswan  #define alternative CRL distribution point
31 8 Martin Willi
       cacert=strongswanCert.pem
32 8 Martin Willi
       crluri=http://crl2.strongswan.org/strongswan.crl
33 8 Martin Willi
       auto=add
34 8 Martin Willi
35 8 Martin Willi
conn %default
36 1 Martin Willi
       keyingtries=1
37 1 Martin Willi
       keyexchange=ikev2
38 1 Martin Willi
	
39 1 Martin Willi
conn roadwarrior
40 1 Martin Willi
       left=192.168.0.1
41 8 Martin Willi
       leftsubnet=10.1.0.0/16
42 8 Martin Willi
       leftcert=moonCert.pem
43 8 Martin Willi
       leftid=@moon.strongswan.org
44 8 Martin Willi
       right=%any
45 8 Martin Willi
       auto=add
46 12 Andreas Steffen
</pre>
47 8 Martin Willi
48 8 Martin Willi
49 12 Andreas Steffen
h2. IKE and ESP Cipher Suites
50 12 Andreas Steffen
51 12 Andreas Steffen
52 12 Andreas Steffen
* [[IKEv2CipherSuites|IKEv2 Cipher Suites]]