testing: Migrated ha/both-active scenario to vici

This commit is contained in:
Andreas Steffen
2021-03-30 18:57:49 +02:00
parent 5c22e94f0f
commit 511b860916
18 changed files with 140 additions and 113 deletions
@@ -1,19 +0,0 @@
# /etc/ipsec.conf - strongSwan IPsec configuration file
config setup
conn %default
ikelifetime=60m
keylife=20m
rekeymargin=3m
keyingtries=1
conn rw
left=192.168.0.5
leftcert=marsCert.pem
[email protected]
leftsubnet=10.1.0.0/16
leftfirewall=yes
right=%any
keyexchange=ikev2
auto=add
@@ -1,3 +0,0 @@
# /etc/ipsec.secrets - strongSwan IPsec secrets file
: RSA marsKey.pem
@@ -1,12 +1,12 @@
# /etc/strongswan.conf - strongSwan configuration file
charon {
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac stroke kernel-netlink socket-default ha
charon-systemd {
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac vici kernel-netlink socket-default ha
plugins {
ha {
local = PH_IP_MOON1
remote = PH_IP_ALICE
local = 10.1.0.1
remote = 10.1.0.10
segment_count = 2
autobalance = 10
fifo_interface = yes
@@ -14,4 +14,3 @@ charon {
}
}
}
@@ -0,0 +1,25 @@
connections {
rw {
local_addrs = 192.168.0.5
local {
auth = pubkey
certs = marsCert.pem
id = mars.strongswan.org
}
remote {
auth = pubkey
}
children {
net {
local_ts = 10.1.0.0/16
updown = /usr/local/libexec/ipsec/_updown iptables
esp_proposals = aes128gcm128-x25519
}
}
version = 2
proposals = aes128-sha256-x25519
}
}