--- # docs.vyos.io/en/1.5/configexamples/ipsec-cisco-route-based.html - VyOS side. # WAN/LAN addresses (eth0-eth2) belong to the base role. ipsec_route_based_peers: - name: CISCO local_address: 10.0.1.2 remote_address: 10.0.2.2 psk: dGVzdA== psk_type: base64 psk_name: AUTH-PSK connection_type: initiate vti: {interface: vti1, address: 10.100.100.1/30, mtu: 1438} ipsec_route_based_ike_group: name: IKE-GROUP key_exchange: ikev1 lifetime: 28800 dh_group: 14 encryption: aes128 hash: sha1 close_action: start dead_peer_detection: {action: restart, interval: 10, timeout: 30} ipsec_route_based_esp_group: name: ESP-GROUP lifetime: 3600 pfs: disable encryption: aes256 hash: sha256 ipsec_route_based_ospf: router_id: 2.2.2.2 area: "0" networks: [10.100.100.0/30, 192.168.0.0/24, 192.168.1.0/24] passive_interfaces: [eth1, eth2] ipsec_route_based_default_gateway: 10.0.1.1