Index | Thread | Search

From:
Stuart Henderson <stu@spacehopper.org>
Subject:
another example for examples/iked.conf?
To:
tech <tech@openbsd.org>
Date:
Fri, 2 Oct 2026 16:34:02 +0100

Download raw body.

Thread
iked can select different policy blocks for clients on dynamic IPs
based on their srcid, but I find the configuration style needed
rather tricky to get right (without the "peer any" I don't see any
connections match up with the block).

Would it be ok to add another example to cover this?

Index: iked.conf
===================================================================
RCS file: /cvs/src/etc/examples/iked.conf,v
diff -u -p -r1.3 iked.conf
--- iked.conf	6 Mar 2023 13:57:45 -0000	1.3
+++ iked.conf	2 Oct 2026 15:17:05 -0000
@@ -33,3 +33,17 @@
 #	from 10.5.0.0/24 to 172.16.1.0/24 \
 #	local 192.168.1.1 peer 192.168.2.1 \
 #	psk "tyBNv13zuo3rg1WVXlaI1g1tTYNzwk962mMUYIvaLh2x8vvvyA-replace-me"
+
+# Configuration for multiple clients connecting with a pre-shared key
+# from dynamic IP addresses (even with several behind a single NATted IP).
+# this side acts as responder only; the other side must initiate and be
+# configured with the matching srcid.
+#
+#ikev2 "peer1" passive esp \
+#	from 192.0.2.0/24 to 172.27.20.0/22 \
+#	peer any dstid peer1-fqdn-identity \
+#	psk "WtV96WAtY3OFJOYgx9ME8we11RQRqHsaeNhM3REkrT-replace-me"
+#ikev2 "peer2" passive esp \
+#	from 192.0.2.0/24 to 172.27.16.0/22 \
+#	peer any dstid peer2-fqdn-identity \
+#	psk "dYxO4oX0QSROZBP1nuPHUjfCMoJOFxtVF-replace-me"