[Openswan Users] Is this correct

Paul Wouters paul at xelerance.com
Mon Apr 30 10:30:03 EDT 2007


On Mon, 30 Apr 2007, Magnus Holmberg wrote:

> They said that I use encryption = 3des and authentication = sha1
>
> Is this correct for that?

> conn MyConnection
>        authby=secret
>        auto=start
>        dpddelay=3
>        dpdtimeout=120
>        dpdaction=restart
>        rekey =yes
>        left=Y.Y.Y.Y
>        leftnexthop=%direct
>        leftsubnet=192.168.2.240/29
>        auth = esp
>        esp=3des-sha1
>        ike=3des-sha1-modp1024
>        ikelifetime=86400s
>        keylife=3600s
>        pfs=no
>        aggrmode=no
>        right=X.X.X.X
>        rightnexthop=%direct
>        rightsubnet=10.1.1.0/24

type=%direct means that Y.Y.Y.Y and X.X.X.X are in the same subnet.

Paul


More information about the Users mailing list