connections { gw-gw { local_addrs = 192.168.0.2 remote_addrs = 192.168.0.1 local { auth = pubkey certs = sunCert.pem id = sun.strongswan.org } remote { auth = pubkey id = moon.strongswan.org } children { net-net { local_ts = 10.2.0.0/16 remote_ts = 10.1.0.0/16 updown = /usr/local/libexec/ipsec/_updown iptables rekey_time = 5400 rekey_bytes = 500000000 rekey_packets = 1000000 esp_proposals = aes128gcm128-x25519 } } version = 2 mobike = no reauth_time = 10800 proposals = aes128-sha256-x25519 } }