forked from M-Labs/it-infra
50 lines
1.1 KiB
Plaintext
50 lines
1.1 KiB
Plaintext
|
connections {
|
||
|
bypass-ipsec {
|
||
|
remote_addrs = 127.0.0.1
|
||
|
children {
|
||
|
bypass-isakmp-v4 {
|
||
|
local_ts = 0.0.0.0/0[udp/isakmp]
|
||
|
remote_ts = 0.0.0.0/0[udp/isakmp]
|
||
|
mode = pass
|
||
|
start_action = trap
|
||
|
}
|
||
|
bypass-isakmp-v6 {
|
||
|
local_ts = ::/0[udp/isakmp]
|
||
|
remote_ts = ::/0[udp/isakmp]
|
||
|
mode = pass
|
||
|
start_action = trap
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
m_labs {
|
||
|
version = 2
|
||
|
encap = no
|
||
|
mobike = no
|
||
|
send_certreq = no
|
||
|
proposals = aes128gcm128-sha256-prfsha256-curve25519,aes128gcm128-sha256-prfsha256-ecp256
|
||
|
local_addrs = 103.206.98.1
|
||
|
remote_addrs = 94.190.212.123
|
||
|
local {
|
||
|
auth = pubkey
|
||
|
id = fqdn:igw0.hkg.as150788.net
|
||
|
pubkeys = igw0.hkg.as150788.net
|
||
|
}
|
||
|
remote {
|
||
|
auth = pubkey
|
||
|
id = fqdn:m-labs.hk
|
||
|
pubkeys = m-labs.hk
|
||
|
}
|
||
|
children {
|
||
|
con1 {
|
||
|
mode = transport
|
||
|
ah_proposals = sha256-curve25519,sha256-ecp256
|
||
|
esp_proposals =
|
||
|
local_ts = 103.206.98.1[gre]
|
||
|
remote_ts = 94.190.212.123[gre]
|
||
|
start_action = none
|
||
|
close_action = none
|
||
|
}
|
||
|
}
|
||
|
}
|
||
|
}
|