strongSwan as a Policy Enforcement Point » History » Version 3
« Previous -
Version 3/13
(diff) -
Next » -
Current version
Andreas Steffen, 14.12.2010 21:20
strongSwan as a Policy Enforcement Point¶
./configure --prefix=/usr --sysconfdir =/etc --disable-pluto --enable-curl --enable-eap-radius
/etc/strongswan.conf - strongSwan configuration file
charon { plugins { eap-radius { secret = gv6URkSs server = 10.1.0.10 filter_id = yes } } }
/etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA moonKey.pem
/etc/ipsec.conf - strongSwan IPsec configuration file
conn rw-allow rightgroups=allow leftsubnet=10.1.0.0/28 also=rw-eap auto=add conn rw-isolate rightgroups=isolate leftsubnet=10.1.0.16/28 also=rw-eap auto=add conn rw-eap leftcert=moonCert.pem leftid=@moon.strongswan.org leftauth=pubkey rightauth=eap-radius rightid=*@strongswan.org rightsendcert=never right=%any