ecp384bp, DIFFIE_HELLMAN_GROUP, ECP_384_BP, 0
ecp512bp, DIFFIE_HELLMAN_GROUP, ECP_512_BP, 0
curve25519, DIFFIE_HELLMAN_GROUP, CURVE_25519, 0
+x25519, DIFFIE_HELLMAN_GROUP, CURVE_25519, 0
ntru112, DIFFIE_HELLMAN_GROUP, NTRU_112_BIT, 0
ntru128, DIFFIE_HELLMAN_GROUP, NTRU_128_BIT, 0
ntru192, DIFFIE_HELLMAN_GROUP, NTRU_192_BIT, 0
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128ccm96-aesxcbc-curve25519!
- esp=aes128ccm96-curve25519!
+ ike=aes128ccm96-aesxcbc-x25519!
+ esp=aes128ccm96-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128ccm12-aesxcbc-curve25519!
- esp=aes128ccm12-curve25519!
+ ike=aes128ccm12-aesxcbc-x25519!
+ esp=aes128ccm12-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128ctr-aesxcbc-curve25519!
- esp=aes128ctr-aesxcbc-curve25519!
+ ike=aes128ctr-aesxcbc-x25519!
+ esp=aes128ctr-aesxcbc-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128ctr-aesxcbc-curve25519!
- esp=aes128ctr-aesxcbc-curve25519!
+ ike=aes128ctr-aesxcbc-x25519!
+ esp=aes128ctr-aesxcbc-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes256gcm128-aesxcbc-curve25519!
- esp=aes256gcm128-curve25519!
+ ike=aes256gcm128-aesxcbc-x25519!
+ esp=aes256gcm128-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes256gcm16-aesxcbc-curve25519!
- esp=aes256gcm16-curve25519!
+ ike=aes256gcm16-aesxcbc-x25519!
+ esp=aes256gcm16-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-aesxcbc-curve25519!
- esp=aes128-aesxcbc-curve25519!
+ ike=aes128-aesxcbc-x25519!
+ esp=aes128-aesxcbc-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-aesxcbc-curve25519!
- esp=aes128-aesxcbc-curve25519!
+ ike=aes128-aesxcbc-x25519!
+ esp=aes128-aesxcbc-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-sha256-curve25519!
- esp=aes128-sha256_96-curve25519!
+ ike=aes128-sha256-x25519!
+ esp=aes128-sha256_96-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-sha256-curve25519!
- esp=aes128-sha256_96-curve25519!
+ ike=aes128-sha256-x25519!
+ esp=aes128-sha256_96-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-sha256-curve25519!
- esp=aes128-sha256-curve25519!
+ ike=aes128-sha256-x25519!
+ esp=aes128-sha256-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-sha256-curve25519!
- esp=aes128-sha256-curve25519!
+ ike=aes128-sha256-x25519!
+ esp=aes128-sha256-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes192-sha384-curve25519!
- esp=aes192-sha384-curve25519!
+ ike=aes192-sha384-x25519!
+ esp=aes192-sha384-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes192-sha384-curve25519!
- esp=aes192-sha384-curve25519!
+ ike=aes192-sha384-x25519!
+ esp=aes192-sha384-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes256-aesxcbc-curve25519!
- esp=aes256gmac-curve25519!
+ ike=aes256-aesxcbc-x25519!
+ esp=aes256gmac-x25519!
conn home
left=PH_IP_CAROL
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes256-aesxcbc-curve25519!
- esp=aes256gmac-curve25519!
+ ike=aes256-aesxcbc-x25519!
+ esp=aes256gmac-x25519!
conn rw
left=PH_IP_MOON
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-sha256-curve25519!
+ ike=aes128-sha256-x25519!
esp=null-sha256!
conn home
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
- ike=aes128-sha256-curve25519!
+ ike=aes128-sha256-x25519!
esp=null-sha256!
conn rw
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
priority = 2
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
shunts {
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
shunts {
interface = eth0
policies_fwd_out = yes
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
shunts {
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
gw-sun {
local {
remote_ts = 10.2.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
start_action = trap
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
start_action = none
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
rekey_time = 5400
rekey_bytes = 500000000
rekey_packets = 1000000
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
reauth_time = 10800
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
start_action = start
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
start_action = none
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
mobike = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
home {
remote_ts = 10.1.0.0/16
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
net {
local_ts = 10.1.0.0/16
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
home {
remote_ts = 10.1.0.0/16
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
net {
local_ts = 10.1.0.0/16
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16[icmp]
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
ssh {
local_ts = dynamic[tcp]
remote_ts = 10.1.0.0/16[tcp/ssh]
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
hostaccess = yes
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
ssh {
local_ts = 10.1.0.0/16[tcp/ssh]
hostaccess = yes
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16[icmp/2048]
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
icmp-rep {
local_ts = dynamic[icmp/0]
remote_ts = 10.1.0.0/16[icmp/0]
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
ftp-ssh {
local_ts = dynamic[tcp/32768-65535]
remote_ts = 10.1.0.0/16[tcp/21-22]
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
hostaccess = yes
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
icmp-rep {
local_ts = 10.1.0.0/16[icmp/0]
hostaccess = yes
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
ftp-ssh {
local_ts = 10.1.0.0/16[tcp/21-22]
hostaccess = yes
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
send_certreq = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
send_certreq = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
send_certreq = no
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/28
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128-sha256-curve25519
+ esp_proposals = aes128-sha256-x25519
}
}
version = 1
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/28
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128-sha256-curve25519
+ esp_proposals = aes128-sha256-x25519
}
}
version = 1
- proposals = aes128-sha256-curve25519,3des-sha1-modp2048
+ proposals = aes128-sha256-x25519,3des-sha1-modp2048
}
rw-2 {
}
}
version = 1
- proposals = 3des-sha1-modp2048,aes128-sha256-curve25519
+ proposals = 3des-sha1-modp2048,aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/28
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 1
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/28
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 1
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
rw-2 {
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 0.0.0.0/0
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
local-net {
local_ts = 0.0.0.0/0
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
}
remote_ts = 0.0.0.0/0
updown = /usr/local/libexec/ipsec/_updown iptables
- esp_proposals = aes128gcm128-curve25519
+ esp_proposals = aes128gcm128-x25519
}
}
version = 2
- proposals = aes128-sha256-curve25519
+ proposals = aes128-sha256-x25519
}
local-net {