path include "/etc/racoon";
path pre_shared_key "/etc/racoon/psk.txt";
path certificate "/etc/racoon/certs";
path script "/etc/racoon/scripts";
remote 192.168.1.107 {
exchange_mode main;
proposal {
authentication_method pre_shared_key;
dh_group modp1024;
hash_algorithm sha1;
encryption_algorithm 3des;
lifetime time 1 hour;
}
}
sainfo anonymous {
lifetime time 1 hour ;
encryption_algorithm 3des;
authentication_algorithm hmac_sha1;
compression_algorithm deflate;
}
192.168.1.107 groad
flush;
spdflush;
spdadd 192.168.1.107 192.168.1.109 any -P in ipsec
esp/transport//require
ah/transport//require;
spdadd 192.168.1.109 192.168.1.107 any -P out ipsec
esp/transport//require
ah/transport//require;
# systemctl start racoon.service
# setkey -f /etc/racoon/setkey.conf
欢迎光临 曲径通幽论坛 (http://www.groad.net/bbs/) | Powered by Discuz! X3.2 |