# /etc/ipsec.conf - strongSwan IPsec configuration file config setup conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev2 mobike=no dpdaction=restart dpddelay=60s left=%defaultroute leftfirewall=yes conn medsrv leftid=F1ubAio8@medsrv.org leftauth=psk right=PH_IP_CAROL rightid=carol@strongswan.org rightauth=pubkey mediation=yes auto=start conn peer leftcert=venusCert.pem leftid=@venus.strongswan.org right=%any rightid=alice@strongswan.org rightsubnet=PH_IP_ALICE/32 mediated_by=medsrv me_peerid=6cu1UTVw@medsrv.org auto=add