Re: [strongSwan] multiple remote_ts with ikev1 file format

2018-02-23 Thread Marco Berizzi
Rich Lafferty wrote: > > Is there a way to not write in every section the parameters > > common to all the children sections (rekey_time, esp_proposals…)? > I wasn’t able to find a way to set defaults, but I’ve put my common > parameters in /etc/swanctl/swanctl-ipsec.conf and then > done > "in

Re: [strongSwan] multiple remote_ts with ikev1 file format

2018-02-22 Thread Rich Lafferty
> On Feb 22, 2018, at 7:15 AM, Marco Berizzi wrote: > > I'm starting strongswan with the old 'ipsec start', and after I > issue the command: 'swanctl -q' for loading the configuration > files under /etc/swanctl/conf.d/* > > Am I right? Or is there a smarter way to start strongswan without > the

[strongSwan] multiple remote_ts with ikev1 file format

2018-02-22 Thread Marco Berizzi
Hello everyone, I would like to finally drop the ipsec.conf and ipsec.secrets configuration files from my strongswan ipsec gateway. I have a couple of questions to ask. I'm running strongswan 5.6.2 on Slackware linux (still systemd free). On my test bed, ipsec.conf and ipsec.secrets are those sh