# /etc/ipsec.conf - strongSwan IPsec configuration file config setup plutodebug=control crlcheckinterval=180 strictcrlpolicy=no charonstart=no conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 left=192.168.0.1 leftsourceip=10.1.0.1 leftcert=moonCert.pem leftid=@moon.strongswan.org leftfirewall=yes conn carol-alice also=carol leftsubnet=10.1.0.10/32 auto=add conn carol-venus also=carol leftsubnet=10.1.0.20/32 auto=add conn carol right=%any rightid=carol@strongswan.org rightsourceip=10.3.0.1 conn dave-alice also=dave leftsubnet=10.1.0.10/32 auto=add conn dave-venus also=dave leftsubnet=10.1.0.20/32 auto=add conn dave right=%any rightid=dave@strongswan.org rightsourceip=10.3.0.2