# /etc/ipsec.conf - strongSwan IPsec configuration file config setup crlcheckinterval=180 plutodebug=control charonstart=no conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev1 conn carol also=moon leftcert=moon_ec256_Cert.pem rightid=carol@strongswan.org auto=add conn dave also=moon leftcert=moon_ec384_Cert.pem rightid=dave@strongswan.org auto=add conn moon left=PH_IP_MOON leftid=@moon.strongswan.org leftsubnet=10.1.0.0/16 leftfirewall=yes right=%any