Best practice adding a custom IPsec/StrongSWAN config?

Started by alh, July 28, 2021, 12:20:02 PM

Previous topic - Next topic
We would like to configure an IKEv2 RoadWarrior profile but miss some options from the GUI like

- eap_identity=%identity
- multiple leftsubnet entries

Is it best practice to just enaple IPsec in the GUI and put the rest of the config in ipsec.opnsense.d and strongswan.opnsense.d? Or is there a better way like overwriting/adding values to the generated config?