vpncfg { connections { enabled = yes; conn_type = conntype_lan; name = "VPN zu OPNSense-Server"; always_renew = yes; reject_not_encrypted = no; dont_filter_netbios = yes; localip = 0.0.0.0; local_virtualip = 0.0.0.0; remoteip = 0.0.0.0; remote_virtualip = 0.0.0.0; remotehostname = "FQDN Opensense"; localid { fqdn = "FQDN Standort A"; } remoteid { fqdn = "FQDN Opensense"; } mode = phase1_mode_idp; phase1ss = "dh14/aes/sha"; phase2ss = "esp-aes256-3des-sha/ah-no/comp-lzs-no/pfs"; keytype = connkeytype_pre_shared; key = "KEY"; cert_do_server_auth = no; use_nat_t = no; use_xauth = no; use_cfgmode = no; phase2localid { ipnet { ipaddr = 192.168.160.0; mask = 255.255.255.0; } } phase2remoteid { ipnet { ipaddr = 10.201.64.0; mask = 255.255.255.0; } } phase2ss = "esp-aes256-3des-sha/ah-no/comp-lzs-no/pfs"; accesslist = "permit ip any 10.201.64.0 255.255.255.0", "permit ip any 192.168.158.0 255.255.255.0", "permit ip any 192.168.159.0 255.255.255.0", "permit ip any 192.168.161.0 255.255.255.0", "permit ip any 192.168.162.0 255.255.255.0", "permit ip any 192.168.163.0 255.255.255.0", "permit ip any 192.168.164.0 255.255.255.0", "permit ip any 192.168.165.0 255.255.255.0", "permit ip any 192.168.166.0 255.255.255.0", "permit ip any 192.168.167.0 255.255.255.0", "permit ip any 192.168.168.0 255.255.255.0", "permit ip any 192.168.169.0 255.255.255.0", "permit ip any 192.168.170.0 255.255.255.0", "permit ip any 192.168.171.0 255.255.255.0", "permit ip any 192.168.172.0 255.255.255.0", "permit ip any 192.168.173.0 255.255.255.0", "permit ip any 192.168.174.0 255.255.255.0", "permit ip any 192.168.175.0 255.255.255.0", "permit ip any 192.168.178.0 255.255.255.0"; } ike_forward_rules = "udp 0.0.0.0:500 0.0.0.0:500", "udp 0.0.0.0:4500 0.0.0.0:4500";}
vpncfg { connections { enabled = yes; conn_type = conntype_lan; name = "VPN zu OPNSense-Server"; always_renew = yes; reject_not_encrypted = no; dont_filter_netbios = yes; localip = 0.0.0.0; local_virtualip = 0.0.0.0; remoteip = 0.0.0.0; remote_virtualip = 0.0.0.0; remotehostname = "FQDN Opensense"; localid { fqdn = "FQDN Standort B"; } remoteid { fqdn = "FQDN Opensense"; } mode = phase1_mode_idp; phase1ss = "dh14/aes/sha"; phase2ss = "esp-aes256-3des-sha/ah-no/comp-lzs-no/pfs"; keytype = connkeytype_pre_shared; key = "KEY"; cert_do_server_auth = no; use_nat_t = no; use_xauth = no; use_cfgmode = no; phase2localid { ipnet { ipaddr = 192.168.161.0; mask = 255.255.255.0; } } phase2remoteid { ipnet { ipaddr = 10.201.64.0; mask = 255.255.255.0; } } phase2ss = "esp-aes256-3des-sha/ah-no/comp-lzs-no/pfs"; accesslist = "permit ip any 10.201.64.0 255.255.255.0", "permit ip any 192.168.160.0 255.255.255.0"; } ike_forward_rules = "udp 0.0.0.0:500 0.0.0.0:500", "udp 0.0.0.0:4500 0.0.0.0:4500";}