# /etc/ipsec.conf - strongSwan IPsec configuration file config setup plutodebug=control crlcheckinterval=180 strictcrlpolicy=no nat_traversal=no charonstart=no conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev1 conn system left=PH_IP_ALICE leftprotoport=tcp/ssh authby=never type=passthrough right=10.1.0.254 rightprotoport=tcp auto=route conn wlan left=PH_IP_ALICE leftcert=aliceCert.pem leftid=alice@strongswan.org leftfirewall=yes right=PH_IP_MOON1 rightid=@moon.strongswan.org rightsubnet=0.0.0.0/0 auto=add