# /etc/ipsec.conf - Libreswan IPsec configuration file version 2.0 config setup # put the logs in /tmp for the UMLs, so that we can operate # without syslogd, which seems to break on UMLs plutostderrlog=/tmp/pluto.log plutodebug=all plutorestartoncrash=false dumpdir=/tmp nat_traversal=yes virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:!192.0.1.0/24,%v6:!2001:db8:0:1::/64 protostack=netkey conn westnet-eastnet-ipv4-psk-ikev2 left=192.1.2.45 leftid="@west" leftnexthop=192.1.2.23 leftsubnet=192.0.1.0/24 right=192.1.2.23 rightid="@east" rightnexthop=192.1.2.45 rightsubnet=192.0.2.0/24 authby=secret auto=ignore type=tunnel compress=no pfs=yes ikepad=yes rekey=yes overlapip=yes authby=secret phase2=esp ikev2=insist