diff --git a/certidude/templates/strongswan-client-to-site.conf b/certidude/templates/strongswan-client-to-site.conf index ff8d93a..91d372d 100644 --- a/certidude/templates/strongswan-client-to-site.conf +++ b/certidude/templates/strongswan-client-to-site.conf @@ -13,7 +13,7 @@ conn %default keyexchange=ikev2 dpdaction={{dpdaction}} -conn home +conn client-to-site auto={{auto}} left=%defaultroute # Use IP of default route for listening leftsourceip=%config # Accept server suggested virtual IP as inner address for tunnel @@ -23,5 +23,4 @@ conn home right={{remote}} # Gateway IP address rightid=%any # Allow any common name rightsubnet=0.0.0.0/0 # Accept all subnets suggested by server - #rightcert=server.pem diff --git a/certidude/templates/strongswan-site-to-client.conf b/certidude/templates/strongswan-site-to-client.conf index 1e7fba6..4962b39 100644 --- a/certidude/templates/strongswan-site-to-client.conf +++ b/certidude/templates/strongswan-site-to-client.conf @@ -12,7 +12,7 @@ conn %default keyingtries=1 keyexchange=ikev2 -conn rw +conn site-to-clients auto=add right=%any # Allow connecting from any IP address rightsourceip={{subnet}} # Serve virtual IP-s from this pool