]> git.ipfire.org Git - thirdparty/strongswan.git/commitdiff
Upgraded IKE and ESP proposals in swanctl scenarios to consistent 128 bit security
authorAndreas Steffen <andreas.steffen@strongswan.org>
Sat, 12 Dec 2015 14:54:48 +0000 (15:54 +0100)
committerAndreas Steffen <andreas.steffen@strongswan.org>
Sat, 12 Dec 2015 14:54:48 +0000 (15:54 +0100)
46 files changed:
testing/tests/swanctl/frags-ipv4/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/frags-ipv4/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/frags-ipv4/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/frags-ipv6/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/frags-ipv6/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/frags-ipv6/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/ip-pool-db/evaltest.dat
testing/tests/swanctl/ip-pool-db/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/ip-pool-db/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/ip-pool-db/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/ip-pool/evaltest.dat
testing/tests/swanctl/ip-pool/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/ip-pool/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/ip-pool/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/multi-level-ca/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/multi-level-ca/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/multi-level-ca/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/net2net-cert/evaltest.dat
testing/tests/swanctl/net2net-cert/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/net2net-cert/hosts/sun/etc/swanctl/swanctl.conf
testing/tests/swanctl/net2net-route/evaltest.dat
testing/tests/swanctl/net2net-route/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/net2net-route/hosts/sun/etc/swanctl/swanctl.conf
testing/tests/swanctl/net2net-start/evaltest.dat
testing/tests/swanctl/net2net-start/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/net2net-start/hosts/sun/etc/swanctl/swanctl.conf
testing/tests/swanctl/ocsp-multi-level/evaltest.dat
testing/tests/swanctl/ocsp-multi-level/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/ocsp-multi-level/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/ocsp-multi-level/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-cert/evaltest.dat
testing/tests/swanctl/rw-cert/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-cert/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-cert/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-hash-and-url/evaltest.dat
testing/tests/swanctl/rw-hash-and-url/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-hash-and-url/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-hash-and-url/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-psk-fqdn/evaltest.dat
testing/tests/swanctl/rw-psk-fqdn/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-psk-fqdn/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-psk-fqdn/hosts/moon/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-psk-ipv4/evaltest.dat
testing/tests/swanctl/rw-psk-ipv4/hosts/carol/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-psk-ipv4/hosts/dave/etc/swanctl/swanctl.conf
testing/tests/swanctl/rw-psk-ipv4/hosts/moon/etc/swanctl/swanctl.conf

index 9062e657162cb4a476396e51bc82d0c3c48bdf09..6b01dfc024198802883eaf11eb7dd036866c5701 100755 (executable)
@@ -17,17 +17,12 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 1 
       fragmentation = yes
-      reauth_time = 60m
-      rekey_time =  20m
       proposals = aes128-sha256-ecp256
    }
 }
index a4abc6ffc92ba96da0ff39e8f707845cded077ce..e1d2487e936c41d2f6ed28168ea06d16e716e18b 100755 (executable)
@@ -17,18 +17,13 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       mobike = no 
       fragmentation = yes 
-      reauth_time = 60m
-      rekey_time =  20m
       proposals = aes128-sha256-ecp256
    }
 }
index a19f542541c2f88cf39fb908cf0637e3cea6363a..2d219cdf0dc80dc50ae74922f6c4168a7b8914f9 100755 (executable)
@@ -15,17 +15,12 @@ connections {
          net {
             local_ts  = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       mobike = no
       fragmentation = yes
-      reauth_time = 60m
-      rekey_time =  20m
       proposals = aes128-sha256-ecp256
    }
 }
index 9e857f69b01062257aa04a7b06a850ed6dbb7d8e..71fc4ea292f3e4607bb89788cd24c04558084fc4 100755 (executable)
@@ -17,17 +17,12 @@ connections {
          home {
             remote_ts = fec1::/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 1 
       fragmentation = yes
-      reauth_time = 60m
-      rekey_time =  20m
       proposals = aes128-sha256-ecp256
    }
 }
index bc5e541987db86186f94bc18106ad8634560fcd6..f4e8a81b53cd56d3c9aa72712b5216933e678aa7 100755 (executable)
@@ -17,18 +17,13 @@ connections {
          home {
             remote_ts = fec1::/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       mobike = no 
       fragmentation = yes 
-      reauth_time = 60m
-      rekey_time =  20m
       proposals = aes128-sha256-ecp256
    }
 }
index a59d13790a22878ef5dc316b67ceb8dc4f3ad580..a6241e9fa3c532a787beae60d666c28e570c5fc1 100755 (executable)
@@ -15,17 +15,12 @@ connections {
          net {
             local_ts = fec1::/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       mobike = no
       fragmentation = yes
-      reauth_time = 60m
-      rekey_time =  20m
       proposals = aes128-sha256-ecp256
    }
 }
index f76c35689ef1b088216df721e133a750977bead3..04edad1fd93bcbe4c621c25d095892526f75f8bf 100755 (executable)
@@ -1,7 +1,7 @@
-carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.1/32] remote-ts=\[10.1.0.0/16]::YES
-dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.2/32] remote-ts=\[10.1.0.0/16]::YES
-moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.1/32]
-moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.2/32]
+carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.1/32] remote-ts=\[10.1.0.0/16]::YES
+dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.2/32] remote-ts=\[10.1.0.0/16]::YES
+moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.1/32]
+moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.2/32]
 moon:: cat /var/log/daemon.log::assigning virtual IP 10.3.0.1 to peer.*carol@strongswan.org::YES
 moon:: cat /var/log/daemon.log::assigning virtual IP 10.3.0.2 to peer.*dave@strongswan.org::YES
 moon:: ipsec pool --status 2> /dev/null::big_pool.*10.3.0.1.*10.3.3.232.*static.*2::YES
index 0bb34148660d4307b2714a4b70b3ea2f3b03d98b..f1a76db625d233f1ab2aa1df64e717351d491136 100755 (executable)
@@ -18,16 +18,11 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index 24d2f864551ae38869dd45726ecc66b06836a664..184185bb3fbbb493880bb76c7d7d980c18b69280 100755 (executable)
@@ -18,16 +18,11 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index d05dea0056768af17b84d4818624d890587176c2..3975512d45b2349c26fecfe8c2f4bbfe2ca85c1a 100755 (executable)
@@ -16,16 +16,11 @@ connections {
          net {
             local_ts  = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index a0891c3587e91ff833b6ab4c6fd26620013c538a..9c3c72b543d483b2a7c6be1f1a70b143cecb74a0 100755 (executable)
@@ -1,7 +1,7 @@
-carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.1/32] remote-ts=\[10.1.0.0/16]::YES
-dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.2/32] remote-ts=\[10.1.0.0/16]::YES
-moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.1/32]
-moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.2/32]
+carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.1/32] remote-ts=\[10.1.0.0/16]::YES
+dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.3.0.2/32] remote-ts=\[10.1.0.0/16]::YES
+moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.1/32]
+moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.3.0.2/32]
 moon:: swanctl --list-pools --raw 2> /dev/null::rw_pool.*base=10.3.0.0 size=14 online=2 offline=0::YES
 moon:: swanctl --list-pools --raw --leases 2> /dev/null::address=10.3.0.1 identity=carol@strongswan.org status=online::YES
 moon:: swanctl --list-pools --raw --leases 2> /dev/null::address=10.3.0.2 identity=dave@strongswan.org status=online::YES
index 0bb34148660d4307b2714a4b70b3ea2f3b03d98b..f1a76db625d233f1ab2aa1df64e717351d491136 100755 (executable)
@@ -18,16 +18,11 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index 24d2f864551ae38869dd45726ecc66b06836a664..184185bb3fbbb493880bb76c7d7d980c18b69280 100755 (executable)
@@ -18,16 +18,11 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index aa31d0f261a508ac30087462c51e3b1bf7919539..8d4dd6bdd2e84911a0cb704bb6db5c12c7955234 100755 (executable)
@@ -16,17 +16,12 @@ connections {
          net {
             local_ts  = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index 89fccff92e694b820f3b0e5ad303059cdd1666f3..e6c90c063259b0c9c1df7ace92b6991e65516f3e 100755 (executable)
@@ -24,7 +24,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
index 0a87ed3b804e1420a02f1714252a9bff3bb4d73b..5ca7bb541b8b77a4041a37cb28dd29ee75b94eea 100755 (executable)
@@ -24,7 +24,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
index 496c5fdfaaeb53f622865761ace9cc2295428c64..574887d7e888b8e70c177342be3ed4933f7851d2 100755 (executable)
@@ -19,7 +19,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
@@ -43,7 +42,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
index cdbecd553541dcd90b0bd19af208e6e357b96a2c..898f2f2097e05d6994dbde1c4516f6e06f2244eb 100755 (executable)
@@ -1,5 +1,5 @@
-moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
-sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
+moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
+sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
 alice::ping -c 1 PH_IP_BOB::64 bytes from PH_IP_BOB: icmp_req=1::YES
 sun::tcpdump::IP moon.strongswan.org > sun.strongswan.org: ESP::YES
 sun::tcpdump::IP sun.strongswan.org > moon.strongswan.org: ESP::YES
index 2f0fd9da1ec8633cb158733119faea0e10b96418..b1c005b4795d6e6a69856d6679a866c06d3033e4 100755 (executable)
@@ -18,17 +18,12 @@ connections {
             local_ts  = 10.1.0.0/16 
             remote_ts = 10.2.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
       mobike = no
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index e4c85562191334c7f675af77e5c49ee07a93d7dd..c3512132f226820f932cab63b7cd44569ead8721 100755 (executable)
@@ -18,17 +18,12 @@ connections {
             local_ts  = 10.2.0.0/16 
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
       mobike = no
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index 04df90beabcd5878819463097f75c3ddfad71371..31894d2f5b089aef52982a7b8c581c3a07d90abf 100755 (executable)
@@ -1,7 +1,7 @@
 moon::swanctl --list-pols --raw 2> /dev/null::net-net.*mode=TUNNEL local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
 moon::cat /var/log/daemon.log::creating acquire job for policy 10.1.0.10/32\[icmp/8] === 10.2.0.10/32\[icmp/8]::YES
-moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
-sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
+moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
+sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
 alice::ping -c 1 PH_IP_BOB::64 bytes from PH_IP_BOB: icmp_req=1::YES
 sun::tcpdump::IP moon.strongswan.org > sun.strongswan.org: ESP::YES
 sun::tcpdump::IP sun.strongswan.org > moon.strongswan.org: ESP::YES
index 1dfcfd179bcdb570e37b20772fa84a9688e8122e..3de6edcb681afe45bf264562920038c246c1ed96 100755 (executable)
@@ -20,15 +20,11 @@ connections {
 
             start_action = trap 
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
       mobike = no
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index e4c85562191334c7f675af77e5c49ee07a93d7dd..5a9cd1308f6a2097717e342f1b25aaca0d315f22 100755 (executable)
@@ -20,15 +20,11 @@ connections {
 
             start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
       mobike = no
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index cdbecd553541dcd90b0bd19af208e6e357b96a2c..898f2f2097e05d6994dbde1c4516f6e06f2244eb 100755 (executable)
@@ -1,5 +1,5 @@
-moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
-sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
+moon::swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.2 remote-id=sun.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[10.2.0.0/16]::YES
+sun:: swanctl --list-sas --raw 2> /dev/null::gw-gw.*version=2 state=ESTABLISHED local-host=192.168.0.2 local-id=sun.strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net-net.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.2.0.0/16] remote-ts=\[10.1.0.0/16]::YES
 alice::ping -c 1 PH_IP_BOB::64 bytes from PH_IP_BOB: icmp_req=1::YES
 sun::tcpdump::IP moon.strongswan.org > sun.strongswan.org: ESP::YES
 sun::tcpdump::IP sun.strongswan.org > moon.strongswan.org: ESP::YES
index 6770f6ab79fa265458a15b19b57db65dc42ba156..0713e7d259821a72d4a1b228329b4545120c37c6 100755 (executable)
@@ -20,15 +20,11 @@ connections {
 
             start_action = start 
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
       mobike = no
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index e4c85562191334c7f675af77e5c49ee07a93d7dd..5a9cd1308f6a2097717e342f1b25aaca0d315f22 100755 (executable)
@@ -20,15 +20,11 @@ connections {
 
             start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
       mobike = no
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index db10ac1848771fde09d2a3204eb00372dfc09197..4da0a6fe68c40b82055358b1b66e17caab2536ed 100644 (file)
@@ -1,8 +1,8 @@
-moon:: swanctl --list-certs --type ocsp 2> /dev/null::issuer.*ocsp.research.strongswan.org::YES
-moon:: swanctl --list-certs --type ocsp 2> /dev/null::issuer.*ocsp.sales.strongswan.org::YES
-moon:: swanctl --list-certs --type ocsp 2> /dev/null::issuer.*ocsp.strongswan.org::YES
-carol::swanctl --list-certs --type ocsp 2> /dev/null::issuer.*ocsp.strongswan.org::YES
-dave:: swanctl --list-certs --type ocsp 2> /dev/null::issuer.*ocsp.strongswan.org::YES
+moon:: swanctl --list-certs --type ocsp_response 2> /dev/null::issuer.*ocsp.research.strongswan.org::YES
+moon:: swanctl --list-certs --type ocsp_response 2> /dev/null::issuer.*ocsp.sales.strongswan.org::YES
+moon:: swanctl --list-certs --type ocsp_response 2> /dev/null::issuer.*ocsp.strongswan.org::YES
+carol::swanctl --list-certs --type ocsp_response 2> /dev/null::issuer.*ocsp.strongswan.org::YES
+dave:: swanctl --list-certs --type ocsp_response 2> /dev/null::issuer.*ocsp.strongswan.org::YES
 moon:: cat /var/log/daemon.log::ocsp response correctly signed by.*ocsp.research.strongswan.org::YES
 moon:: cat /var/log/daemon.log::ocsp response correctly signed by.*ocsp.sales.strongswan.org::YES
 moon:: cat /var/log/daemon.log::ocsp response correctly signed by.*ocsp.strongswan.org::YES
index 26c3a898eaf595dc910c02e7bf440f6f37050626..7867fde45671b75334040c4dcc2b6a7e3f2bc602 100755 (executable)
@@ -24,7 +24,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
index 8752e9bc8ad39229ff3440d5da4e9de6b34104e2..0c305210e04dfa110492cf4d9904114c914a8bd4 100755 (executable)
@@ -24,7 +24,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
index 2cb05013ddfeb6b694b58d1e77fc657ec48007bd..c5beb2cde9cb95e4f520e1f3f022210ed57c1c3d 100755 (executable)
@@ -19,7 +19,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
@@ -43,7 +42,6 @@ connections {
             esp_proposals = aes128-sha256-ecp256
          }
       }
-
       version = 2
       proposals = aes128-sha256-ecp256
    }
index ee3fb76b4646f9931d1a912a0650934df7f18fab..f9e28bf33217a7575eea254edd654955d1e715fb 100755 (executable)
@@ -1,7 +1,7 @@
-carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
-dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
-moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]::YES
-moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]::YES
+carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
+dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
+moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]::YES
+moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]::YES
 alice::ping -c 1 192.168.0.100::64 bytes from 192.168.0.100: icmp_req=1::YES
 alice::ping -c 1 192.168.0.200::64 bytes from 192.168.0.200: icmp_req=1::YES
 moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
index 0ba243300c4c9b0c83487f3d82cdaeb9046434e2..8a29c3063e4987dd6df8a379e39b3694e3266b50 100755 (executable)
@@ -17,16 +17,11 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index a3420a4799c264f79a77f4570f3ddbc8d5fe1249..e65ec7a18d0d5e1298f6a5af407e9dd2cb4b1f1e 100755 (executable)
@@ -17,16 +17,11 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index 861d65ab6b54d9070d51257698b4f81dbf5e6c43..a3c51c889faf6b0148197fa1d289d5cfdb9b0a7a 100755 (executable)
@@ -15,16 +15,11 @@ connections {
          net {
             local_ts  = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
index 5242db17c7be62516c656c0898ce7f6a3fd87381..afad444807e76716e4c2a1c10fbfad813fb21df1 100755 (executable)
@@ -2,10 +2,10 @@ carol::cat /var/log/daemon.log::fetched certificate.*moon.strongswan.org::YES
 dave:: cat /var/log/daemon.log::fetched certificate.*moon.strongswan.org::YES
 moon:: cat /var/log/daemon.log::fetched certificate.*carol@strongswan.org::YES
 moon:: cat /var/log/daemon.log::fetched certificate.*dave@strongswan.org::YES
-carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
-dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
-moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]::YES
-moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]::YES
+carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
+dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
+moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]::YES
+moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]::YES
 alice::ping -c 1 192.168.0.100::64 bytes from 192.168.0.100: icmp_req=1::YES
 alice::ping -c 1 192.168.0.200::64 bytes from 192.168.0.200: icmp_req=1::YES
 moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
index 7b0b2adbafbc54352e6f00699cc8c2706082d551..401b9fa49851172096edf2fda2dc8ed245558a89 100755 (executable)
@@ -17,17 +17,12 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index b4d82096a5b880cf8949ce317d05bae7e8352cc7..b1e734def0046fab305d8ea2f12503ae1d0ef43e 100755 (executable)
@@ -17,17 +17,12 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index 258d9e87cb8f4098e39658fa97ef96653a9aadbe..f8931756d0f4799b4b0d02bd3fc1ea0471a0ef2c 100755 (executable)
@@ -15,17 +15,12 @@ connections {
          net {
             local_ts  = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index bb5e08bf4fe0deea48af6f6268dede381e352b97..a53332a9ae0870b219f77aeed2d28f911b2a24a3 100755 (executable)
@@ -1,7 +1,7 @@
-carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
-dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
-moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]
-moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]
+carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=carol@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
+dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=dave@strongswan.org remote-host=192.168.0.1 remote-id=moon.strongswan.org initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
+moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.100 remote-id=carol@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]
+moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=moon.strongswan.org remote-host=192.168.0.200 remote-id=dave@strongswan.org.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]
 alice::ping -c 1 192.168.0.100::64 bytes from 192.168.0.100: icmp_req=1::YES
 alice::ping -c 1 192.168.0.200::64 bytes from 192.168.0.200: icmp_req=1::YES
 moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
index c113620b37c178c57226b1bf0203fc7127f9f089..9bf759ee32ed66dad5ab824806162567b5d445f2 100755 (executable)
@@ -16,17 +16,12 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index 928fd04c099c09767f70622b63a28c7b61a5dffb..1f2beefef9922d5cb616db668aaac25e19a3162c 100755 (executable)
@@ -16,17 +16,12 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index 8cae3e82074074d04ab72028d80b5156ba24830e..7138b5d4aa2eb5989e9fa6b9b7294a251003016c 100755 (executable)
@@ -14,17 +14,12 @@ connections {
          net {
             local_ts  = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index 142e88e61502e7dbfcb3731cdaefb70cf95e6ca9..55818c9ad61a7ffd5638bdf4b2b7cd2871b6ddb8 100755 (executable)
@@ -1,7 +1,7 @@
-carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=192.168.0.100 remote-host=192.168.0.1 remote-id=192.168.0.1 initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
-dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=192.168.0.200 remote-host=192.168.0.1 remote-id=192.168.0.1 initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
-moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=192.168.0.1 remote-host=192.168.0.100 remote-id=192.168.0.100.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]
-moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=192.168.0.1 remote-host=192.168.0.200 remote-id=192.168.0.200.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_2048.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]
+carol::swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.100 local-id=192.168.0.100 remote-host=192.168.0.1 remote-id=192.168.0.1 initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.100/32] remote-ts=\[10.1.0.0/16]::YES
+dave:: swanctl --list-sas --raw 2> /dev/null::home.*version=2 state=ESTABLISHED local-host=192.168.0.200 local-id=192.168.0.200 remote-host=192.168.0.1 remote-id=192.168.0.1 initiator=yes.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*home.*state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[192.168.0.200/32] remote-ts=\[10.1.0.0/16]::YES
+moon:: swanctl --list-sas --ike-id 1 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=192.168.0.1 remote-host=192.168.0.100 remote-id=192.168.0.100.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=1 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.100/32]
+moon:: swanctl --list-sas --ike-id 2 --raw 2> /dev/null::rw.*version=2 state=ESTABLISHED local-host=192.168.0.1 local-id=192.168.0.1 remote-host=192.168.0.200 remote-id=192.168.0.200.*encr-alg=AES_CBC encr-keysize=128 integ-alg=HMAC_SHA2_256_128 prf-alg=PRF_HMAC_SHA2_256 dh-group=MODP_3072.*child-sas.*net.*reqid=2 state=INSTALLED mode=TUNNEL.*ESP.*encr-alg=AES_GCM_16 encr-keysize=128.*local-ts=\[10.1.0.0/16] remote-ts=\[192.168.0.200/32]
 alice::ping -c 1 192.168.0.100::64 bytes from 192.168.0.100: icmp_req=1::YES
 alice::ping -c 1 192.168.0.200::64 bytes from 192.168.0.200: icmp_req=1::YES
 moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
index bd00fc32ce37f2c19e5a1e93094bac31ff66fcf5..8b3863bb66b13df4c310d87e76d2d9bd377d33f8 100755 (executable)
@@ -16,17 +16,12 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index b30790b468c929b9b624963673d2d5dc84c0659b..83f3c0a7a043750863a59bfb41c40f2f749ad913 100755 (executable)
@@ -16,17 +16,12 @@ connections {
          home {
             remote_ts = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }
 
index 098b3c0ab482dea57e9de9612eee47d4415e2cf2..9b4f7cea205565fe611eeb866356c0dbdaef8225 100755 (executable)
@@ -13,17 +13,12 @@ connections {
          net {
             local_ts  = 10.1.0.0/16 
 
-            start_action = none
             updown = /usr/local/libexec/ipsec/_updown iptables
-            rekey_time = 10m 
-            esp_proposals = aes128gcm128-modp2048
+            esp_proposals = aes128gcm128-modp3072
          }
       }
-
       version = 2
-      reauth_time = 60m
-      rekey_time =  20m
-      proposals = aes128-sha256-modp2048
+      proposals = aes128-sha256-modp3072
    }
 }