# /etc/ipsec.conf - Libreswan IPsec configuration file

version 2.0

config setup
	# put the logs in /tmp for the UMLs, so that we can operate
	# without syslogd, which seems to break on UMLs
	plutostderrlog=/tmp/pluto.log
	strictcrlpolicy=yes
	plutorestartoncrash=false
	dumpdir=/var/tmp

# only used in x509-pluto-02
conn north-east-x509-pluto-02
	also=eastnet
	also=northnet
	# Left security gateway, subnet behind it, next hop toward right.
	left=192.1.3.33
	leftrsasigkey=%cert
	leftnexthop=192.1.3.254
	leftid="C=ca, ST=Ontario, O=Libreswan, L=Toronto, CN=north.testing.libreswan.org, E=testing.libreswan.org"
	leftca="C=ca, ST=Ontario, O=Libreswan, CN=Libreswan test CA for mainca, E=testing.libreswan.org"
	# Right security gateway, subnet behind it, next hop toward left.
	right=192.1.2.23
	rightnexthop=192.1.2.254
	rightrsasigkey=%cert
	rightcert=east.crt
	auto=ignore

conn northnet
	leftsubnet=192.0.3.0/24

include /testing/baseconfigs/all/etc/ipsec.d/ipsec.conf.common

conn us
	rightsubnet=192.0.2.0/24

conn them
	leftsubnet=192.0.1.0/24