conn %default
dpdaction=clear
dpddelay=35s
dpdtimeout=300s
fragmentation=yes
type=transport
ike=aes256gcm16-aes256gcm12-aes128gcm16-aes128gcm12-sha256-sha1-modp2048-modp4096-modp1024,aes256-aes128-sha256-sha1-modp2048-modp4096-modp1024,3des-sha1-modp1024!
esp=aes128gcm12-aes128gcm16-aes256gcm12-aes256gcm16-modp2048-modp4096-modp1024,aes128-aes256-sha1-sha256-modp2048-modp4096-modp1024,aes128-sha1-modp2048,aes128-sha1-modp1024,3des-sha1-modp1024,aes128-aes256-sha1-sha256,aes128-sha1,3des-sha1!
left=%any
leftsubnet=
0.0.0.0/0 leftcert=test.xxxcom.crt
leftfirewall=yes
leftsendcert=always
right=%any
rightauth=eap-mschapv2
rightsourceip=
10.20.30.0/24 rightdns=
8.8.8.8,
8.8.4.4 eap_identity=%identity
conn mikrotik
rightauth=eap-mschapv2
rightsubnet=
10.20.30.0/24 rightauth=eap-mschapv2
auto=add