/usr/local/etc/swanctl/swanctl.conf
VPN SFOS { proposals = aes256-sha256-modp2048 unique = replace aggressive = no version = 2 mobike = yes local_addrs = 203.0.113.1 remote_addrs = 198.51.100.1 encap = no rekey_time = 240 dpd_delay = 10 dpd_timeout = 30 send_certreq = no keyingtries = 0 local-dd62446b-fb62-4e58-b433-XXXXXXXXX { round = 0 auth = psk id = test-net-3.example.com } remote-a463a827-21a9-41b5-8896-XXXXXXXXXX { round = 0 auth = psk id = test-net-2.example.com } children { 857d780a-f686-482f-81b8-XXXXXXXXXXX { reqid = 100 esp_proposals = aes256-sha256-modp2048 sha256_96 = no start_action = start close_action = none dpd_action = clear mode = tunnel policies = yes local_ts = 192.168.0.0/24 remote_ts = 172.16.0.0/24 rekey_time = 120 updown = /usr/local/opnsense/scripts/ipsec/updown_event.py } } }secrets { ike-a7c16b5c-9bd5-4cb5-abaa-XXXXXXXXXXXXX { id-0 = test-net-3.example.com id-1 = test-net-2.example.com secret = XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX}
VPN UTM { proposals = aes256-sha256-modp2048 unique = replace aggressive = no version = 1 mobike = no local_addrs = 203.0.113.1 remote_addrs = 198.51.100.1 encap = no rekey_time = 28800 send_certreq = no keyingtries = 0 local-c9ae352d-7fef-4f9c-9651-XXXXXXXXXXXXXXXX { round = 0 auth = psk id = 203.0.113.1 } remote-db730ddd-c161-4628-8dad-XXXXXXXXXXXXXXXX { round = 0 auth = psk id = 198.51.100.1 } children { 5c4d2b57-89d7-4910-ba92-XXXXXXXXXXXXXXXX { reqid = 130 esp_proposals = aes256-sha256-modp2048 sha256_96 = no start_action = start close_action = none dpd_action = clear mode = tunnel policies = yes local_ts = 172.16.100.0/24 remote_ts = 192.168.60.0/24 rekey_time = 3600 updown = /usr/local/opnsense/scripts/ipsec/updown_event.py } } }secrets { ike-3c14fb5c-e22a-4c69-86b6-32339a6b643a { id-0 = 203.0.113.1 id-1 = 198.51.100.1 secret = XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX}