blob: ee1d91bc48e138c3679e87a67dee9ea468e65223 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
|
# $OpenBSD: singlehost-west.conf,v 1.8 2000/05/03 13:37:33 niklas Exp $
# $EOM: singlehost-west.conf,v 1.8 2000/05/03 13:25:25 niklas Exp $
# A configuration sample for the isakmpd ISAKMP/Oakley (aka IKE) daemon.
[General]
Listen-on= 10.1.0.1
Shared-SADB= Defined
[Phase 1]
10.1.0.2= ISAKMP-peer-east
Default= ISAKMP-peer-east-aggressive
[Phase 2]
Connections= IPsec-west-east
[ISAKMP-peer-east]
Phase= 1
Transport= udp
Local-address= 10.1.0.1
Address= 10.1.0.2
Configuration= Default-main-mode
Identification= IPV4_ADDR/10.1.0.1
Authentication= mekmitasdigoat
[ISAKMP-peer-east-aggressive]
Phase= 1
Transport= udp
Local-address= 10.1.0.1
Address= 10.1.0.2
Configuration= Default-aggressive-mode
Identification= FQDN/diego.niklas.hallqvist.se
Authentication= mekmitasdigoat
[IPsec-west-east]
Phase= 2
ISAKMP-peer= ISAKMP-peer-east
Configuration= Default-quick-mode
Local-ID= Net-west
Remote-ID= Net-east
[Net-west]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.1.0
Netmask= 255.255.255.0
[Net-east]
ID-type= IPV4_ADDR_SUBNET
Network= 192.168.2.0
Netmask= 255.255.255.0
[Default-main-mode]
DOI= IPSEC
EXCHANGE_TYPE= ID_PROT
Transforms= 3DES-SHA
[Default-aggressive-mode]
DOI= IPSEC
EXCHANGE_TYPE= AGGRESSIVE
Transforms= 3DES-SHA-RSA
[Default-quick-mode]
DOI= IPSEC
EXCHANGE_TYPE= QUICK_MODE
Suites= QM-ESP-3DES-SHA-PFS-SUITE
|