# /etc/ipsec.conf - Libreswan IPsec configuration file

version 2.0

config setup
	# put the logs in /tmp for the UMLs, so that we can operate
	# without syslogd, which seems to break on UMLs
	plutostderrlog=/tmp/pluto.log
	plutodebug=all
	plutorestartoncrash=false
	protostack=klips
	dumpdir=/tmp
	nat_traversal=yes
	virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:!192.0.1.0/24,%v6:!2001:db8:0:1::/64

conn westnet-eastnet-ikev2
	also=west-east-x509
	also=westnet-ipv4
	also=eastnet-ipv4
	ikev2=insist

include	/testing/baseconfigs/all/etc/ipsec.d/ipsec.conf.common