connections { home { local_addrs = 192.168.0.100 remote_addrs = 192.168.0.1 local { auth = pubkey certs = carolCert.pem id = carol@strongswan.org } remote { auth = pubkey id = moon.strongswan.org } children { home { remote_ts = 10.1.0.0/16 updown = /usr/local/libexec/ipsec/_updown iptables esp_proposals = aes128gcm128-ecp256 } } version = 2 proposals = aes128-sha256-ecp256 } } secrets { rsa-carol { file = carolKey.pem secret = "nH5ZQEWtku0RJEZ6" } }