# /etc/ipsec.conf - strongSwan IPsec configuration file config setup plutodebug=control crlcheckinterval=180 strictcrlpolicy=no charonstart=no conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev1 left=192.168.0.1 leftsourceip=10.1.0.1 leftcert=moonCert.pem leftid=@moon.strongswan.org leftfirewall=yes conn carol-alice also=carol leftsubnet=10.1.0.10/32 rightsourceip=10.3.0.1 auto=add conn carol-venus also=carol leftsubnet=10.1.0.20/32 rightsourceip=%carol-alice auto=add conn carol right=%any rightid=carol@strongswan.org conn dave-alice also=dave leftsubnet=10.1.0.10/32 rightsourceip=10.3.0.2 auto=add conn dave-venus also=dave leftsubnet=10.1.0.20/32 rightsourceip=%dave-alice auto=add conn dave right=%any rightid=dave@strongswan.org