summaryrefslogtreecommitdiff
path: root/testing/tests/swanctl/shunt-policies-nat-rw/hosts/alice/etc/swanctl/swanctl.conf
blob: 373f8a76a123bffe77ed0f4dfb8a1785d1c7c6f7 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
connections {

   nat-t {
      remote_addrs = 192.168.0.2 
      vips = 0.0.0.0

      local {
         auth = pubkey
         certs = aliceCert.pem
         id = alice@strongswan.org
      }
      remote {
         auth = pubkey
         id = sun.strongswan.org 
      }
      children {
         nat-t {
            remote_ts = 0.0.0.0/0 

            updown = /usr/local/libexec/ipsec/_updown iptables
            esp_proposals = aes128gcm128-modp3072
         }
      }
      version = 2
      proposals = aes128-sha256-modp3072
   }

   local-net {

      children {
         local-net {
            local_ts  = 10.1.0.0/16
            remote_ts = 10.1.0.0/16

            mode = pass
            start_action = trap
         }
      }
   }
}