blob: a7f5c4d6a6f4ba791e38f7271798a9bfce530cf3 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
|
---
# docs.vyos.io/en/1.5/configexamples/ipsec-cisco-route-based.html - VyOS side.
# WAN/LAN addresses (eth0-eth2) belong to the base role.
ipsec_route_based_peers:
- name: CISCO
local_address: 10.0.1.2
remote_address: 10.0.2.2
psk: dGVzdA==
psk_type: base64
psk_name: AUTH-PSK
connection_type: initiate
vti: {interface: vti1, address: 10.100.100.1/30, mtu: 1438}
ipsec_route_based_ike_group:
name: IKE-GROUP
key_exchange: ikev1
lifetime: 28800
dh_group: 14
encryption: aes128
hash: sha1
close_action: start
dead_peer_detection: {action: restart, interval: 10, timeout: 30}
ipsec_route_based_esp_group:
name: ESP-GROUP
lifetime: 3600
pfs: disable
encryption: aes256
hash: sha256
ipsec_route_based_ospf:
router_id: 2.2.2.2
area: "0"
networks: [10.100.100.0/30, 192.168.0.0/24, 192.168.1.0/24]
passive_interfaces: [eth1, eth2]
ipsec_route_based_default_gateway: 10.0.1.1
|