Re: Fwd: ikev2 active roadwarrior with openbsd

2021-02-08 Thread Stuart Henderson
>> On 2021-02-04, Riccardo Giuntoli wrote: >> > A ikev2 passive server in France that got: >> > >> > A CA >> > A server certificate for tls server >> > And a client certificate for tls client >> > >> > I export the CA in PEM format and put it on /etc/iked/ca >> > >> > Next I export the private

Fwd: ikev2 active roadwarrior with openbsd

2021-02-04 Thread Riccardo Giuntoli
-- Forwarded message - From: Riccardo Giuntoli Date: Thu, Feb 4, 2021 at 1:44 PM Subject: Re: ikev2 active roadwarrior with openbsd To: Stuart Henderson root@ganesha:/etc# cat iked.conf set dpd_check_interval 15 ikev2 'uma' active esp \ from xxx to 172.16.17.0/24 \