Answer the question
In order to leave comments, you need to log in
Strongswan client linux configuration or what am I doing wrong?
strongswan server ipsec.conf
conn %default
ikelifetime=3h
keylife=20m
rekeymargin=3m
keyingtries=2
mobike=no
conn win_ike2_domain
left=%defaultroute
leftauth=pubkey
leftcert=vpnhost.pem # the host cert
[email protected] # the SAN (Alt name) in the Cert
leftsubnet=0.0.0.0/0 # The internal subnet the remote user wants to access
right=%any # Connections can come from anywhere
rightauth=eap-radius
rightsendcert=never
rightsourceip=10.10.10.0/24 # Use this pool of IPs to assign to these inbound connections
auto=add
eap_identity=%any
keyexchange=ikev2
fragmentation=yes
dpdaction=clear
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question