Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # This file is automatically generated. Do not edit
- connections {
- bypass {
- remote_addrs = 127.0.0.1
- children {
- bypasslan {
- local_ts = 192.168.131.0/24
- remote_ts = 192.168.131.0/24
- mode = pass
- start_action = trap
- }
- }
- }
- con3 {
- # P1 (ikeid 3): customer1 - link1
- fragmentation = yes
- unique = replace
- version = 2
- proposals = aes128gcm128-sha256-modp2048,aes256gcm128-sha256-modp2048
- dpd_delay = 10s
- rekey_time = 77760s
- reauth_time = 0s
- over_time = 8640s
- rand_time = 8640s
- encap = no
- mobike = no
- local_addrs = 197.214.xxx.yyy
- remote_addrs = 105.27.aaa.bbb
- local {
- id = 197.214.xxx.yyy
- auth = psk
- }
- remote {
- id = 192.168.0.2
- auth = psk
- }
- children {
- con3 {
- # P2 (reqid 9): M/Monit to Office LAN
- # P2 (reqid 7): Unify to Office LAN
- # P2 (reqid 6): GTS1 to Office LAN
- mode = tunnel
- policies = yes
- life_time = 43196s
- rekey_time = 38876s
- rand_time = 4320s
- start_action = trap
- remote_ts = 172.16.3.0/24,172.16.3.0/24,172.16.3.0/24
- local_ts = 192.168.131.191/32,192.168.131.177,192.168.131.174
- esp_proposals = aes256gcm128-modp2048,aes256gcm96-modp2048,aes256gcm64-modp2048,aes128gcm128-modp2048,aes128gcm96-modp2048,aes128gcm64-modp2048
- dpd_action = trap
- }
- }
- }
- con4 {
- # P1 (ikeid 4): customer1 - link2
- fragmentation = yes
- unique = replace
- version = 2
- proposals = aes128gcm128-sha256-modp2048,aes256gcm128-sha256-modp2048
- dpd_delay = 10s
- rekey_time = 77760s
- reauth_time = 0s
- over_time = 8640s
- rand_time = 8640s
- encap = no
- mobike = no
- local_addrs = 197.214.xxx.yyy
- remote_addrs = 41.164.aaa.bbb
- local {
- id = 197.214.xxx.yyy
- auth = psk
- }
- remote {
- id = 41.164.aaa.bbb
- auth = psk
- }
- children {
- con4 {
- # P2 (reqid 10): M/Monit to Office LAN backup
- # P2 (reqid 8): Unify to Office LAN
- # P2 (reqid 5): GTS1 to Office LAN
- mode = tunnel
- policies = yes
- life_time = 43196s
- rekey_time = 38876s
- rand_time = 4320s
- start_action = trap
- remote_ts = 172.16.3.0/24,172.16.3.0/24,172.16.3.0/24
- local_ts = 192.168.131.191/32,192.168.131.177/32,192.168.131.174/32
- esp_proposals = aes256gcm128-modp2048,aes256gcm96-modp2048,aes256gcm64-modp2048,aes128gcm128-modp2048,aes128gcm96-modp2048,aes128gcm64-modp2048
- dpd_action = trap
- }
- }
- }
- con10 {
- # P1 (ikeid 10): gggg
- fragmentation = yes
- unique = replace
- version = 2
- proposals = aes128gcm128-sha256-modp2048
- dpd_delay = 10s
- rekey_time = 544320s
- reauth_time = 0s
- over_time = 60480s
- rand_time = 60480s
- encap = no
- mobike = no
- local_addrs = 197.214.xxx.yyy
- remote_addrs = 165.165.bbb.ddd
- local {
- id = 197.214.xxx.yyy
- auth = psk
- }
- remote {
- id = %any
- auth = psk
- }
- children {
- con10 {
- # P2 (reqid 17): gggg server
- # P2 (reqid 16): gggg server
- # P2 (reqid 15): gggg server
- # P2 (reqid 14): gggg server
- # P2 (reqid 11): gggg server
- mode = tunnel
- policies = yes
- life_time = 604800s
- rekey_time = 544320s
- rand_time = 60480s
- start_action = trap
- remote_ts = 10.10.3.0/24,10.10.4.0/24,192.168.3.0/24,10.10.2.0/24,192.168.1.0/24
- local_ts = 192.168.153.0/24,192.168.153.0/24,192.168.153.0/24,192.168.153.0/24,192.168.153.0/24
- esp_proposals = aes128gcm128,aes128gcm96,aes128gcm64
- dpd_action = trap
- }
- }
- }
- con9 {
- # P1 (ikeid 9): RC
- fragmentation = yes
- unique = replace
- version = 2
- proposals = aes128gcm128-sha256-modp2048,aes128-sha256-modp2048
- dpd_delay = 10s
- rekey_time = 544320s
- reauth_time = 0s
- over_time = 60480s
- rand_time = 60480s
- encap = no
- mobike = no
- local_addrs = 197.214.xxx.yyy
- remote_addrs = 196.250.eee.fff
- local {
- id = 197.214.xxx.yyy
- # P2 (reqid 8): Unify to Office LAN
- # P2 (reqid 8): Unify to Office LAN
- # P2 (reqid 5): GTS1 to Office LAN
- mode = tunnel
- policies = yes
- life_time = 43196s
- rekey_time = 38876s
- rand_time = 4320s
- start_action = trap
- remote_ts = 172.16.3.0/24,172.16.3.0/24,172.16.3.0/24
- local_ts = 192.168.131.191/32,192.168.131.177/32,192.168.131.174/32
- esp_proposals = aes256gcm128-modp2048,aes256gcm96-modp2048,aes256gcm64-modp2048,aes128gcm128-modp2048,aes128gcm96-modp2048,aes128gcm64-modp2048
- dpd_action = trap
- }
- }
- }
- con10 {
- # P1 (ikeid 10): gggg
- fragmentation = yes
- unique = replace
- version = 2
- proposals = aes128gcm128-sha256-modp2048
- dpd_delay = 10s
- rekey_time = 544320s
- reauth_time = 0s
- over_time = 60480s
- rand_time = 60480s
- encap = no
- mobike = no
- local_addrs = 197.214.xxx.yyy
- remote_addrs = 165.165.bbb.ddd
- local {
- id = 197.214.xxx.yyy
- auth = psk
- }
- remote {
- id = %any
- auth = psk
- }
- children {
- con10 {
- # P2 (reqid 17): gggg server
- # P2 (reqid 16): gggg server
- # P2 (reqid 15): gggg server
- # P2 (reqid 14): gggg server
- # P2 (reqid 11): gggg server
- mode = tunnel
- policies = yes
- life_time = 604800s
- rekey_time = 544320s
- rand_time = 60480s
- start_action = trap
- remote_ts = 10.10.3.0/24,10.10.4.0/24,192.168.3.0/24,10.10.2.0/24,192.168.1.0/24
- local_ts = 192.168.153.0/24,192.168.153.0/24,192.168.153.0/24,192.168.153.0/24,192.168.153.0/24
- esp_proposals = aes128gcm128,aes128gcm96,aes128gcm64
- dpd_action = trap
- }
- }
- }
- con9 {
- # P1 (ikeid 9): RC
- fragmentation = yes
- unique = replace
- version = 2
- proposals = aes128gcm128-sha256-modp2048,aes128-sha256-modp2048
- dpd_delay = 10s
- rekey_time = 544320s
- reauth_time = 0s
- over_time = 60480s
- rand_time = 60480s
- encap = no
- mobike = no
- local_addrs = 197.214.xxx.yyy
- remote_addrs = 196.250.eee.fff
- local {
- id = 197.214.xxx.yyy
- auth = psk
- }
- remote {
- id = %any
- auth = psk
- }
- children {
- con9 {
- # P2 (reqid 13): RC Subnet
- mode = tunnel
- policies = yes
- life_time = 3600s
- rekey_time = 3240s
- rand_time = 360s
- start_action = trap
- remote_ts = 192.168.0.0/24
- local_ts = 192.168.152.0/29
- esp_proposals = aes128gcm128-modp2048,aes128gcm96-modp2048,aes128gcm64-modp2048
- dpd_action = trap
- }
- }
- }
- }
- secrets {
- ike-0 {
- secret = <cut>
- id-0 = %any
- id-1 = 192.168.0.2
- }
- ike-1 {
- secret = <cut>
- id-0 = %any
- id-1 = 41.164.68.170
- }
- ike-2 {
- secret = <cut>
- id-0 = %any
- id-1 = %any
- }
- ike-3 {
- secret = <cut>
- id-0 = %any
- id-1 = %any
- }
- }
Add Comment
Please, Sign In to add comment