Project

General

Profile

ipsec.conf Reference » History » Version 14

Andreas Steffen, 17.05.2009 17:52
Added link to IKEv1 Cipher Suites

1 12 Andreas Steffen
h1. ipsec.conf
2 1 Martin Willi
3 1 Martin Willi
4 12 Andreas Steffen
strongSwan's _/etc/ipsec.conf_ configuration file consists of three different section types:
5 1 Martin Willi
6 12 Andreas Steffen
* [[ConfigSetupSection|config setup]] defines general configuration parameters
7 12 Andreas Steffen
* [[ConnSection|conn <name>]] defines a connection
8 12 Andreas Steffen
* [[CaSection|ca <name>]] defines a certification authority
9 12 Andreas Steffen
10 1 Martin Willi
There can be only one [[ConfigSetupSection|config setup]] section but
11 13 Tobias Brunner
an unlimited number of [[ConnSection|conn]] and [[CaSection|ca]] sections.
12 12 Andreas Steffen
13 3 Martin Willi
All parameters belonging to a section must be indented by at least one space or tab
14 4 Martin Willi
character. The rest of the line after a '#' character is treated as a comment.
15 4 Martin Willi
Comments within a section must also be indented.
16 4 Martin Willi
17 12 Andreas Steffen
18 12 Andreas Steffen
h2. Example
19 12 Andreas Steffen
20 12 Andreas Steffen
<pre>
21 9 Martin Willi
# /etc/ipsec.conf - strongSwan IPsec configuration file
22 9 Martin Willi
23 8 Martin Willi
config setup
24 8 Martin Willi
       crlcheckinterval=600s
25 8 Martin Willi
       cachecrls=yes
26 8 Martin Willi
       strictcrlpolicy=yes
27 8 Martin Willi
       plutostart=no
28 8 Martin Willi
29 10 Martin Willi
ca strongswan  #define alternative CRL distribution point
30 8 Martin Willi
       cacert=strongswanCert.pem
31 8 Martin Willi
       crluri=http://crl2.strongswan.org/strongswan.crl
32 8 Martin Willi
       auto=add
33 8 Martin Willi
34 8 Martin Willi
conn %default
35 1 Martin Willi
       keyingtries=1
36 1 Martin Willi
       keyexchange=ikev2
37 1 Martin Willi
	
38 1 Martin Willi
conn roadwarrior
39 1 Martin Willi
       left=192.168.0.1
40 8 Martin Willi
       leftsubnet=10.1.0.0/16
41 8 Martin Willi
       leftcert=moonCert.pem
42 8 Martin Willi
       leftid=@moon.strongswan.org
43 8 Martin Willi
       right=%any
44 8 Martin Willi
       auto=add
45 12 Andreas Steffen
</pre>
46 8 Martin Willi
47 8 Martin Willi
48 12 Andreas Steffen
h2. IKE and ESP Cipher Suites
49 12 Andreas Steffen
50 12 Andreas Steffen
51 14 Andreas Steffen
52 14 Andreas Steffen
* [[IKEv1CipherSuites|IKEv1 Cipher Suites]]
53 12 Andreas Steffen
* [[IKEv2CipherSuites|IKEv2 Cipher Suites]]