Index | Thread | Search

From:
Crystal Kolipe <kolipe.c@exoticsilicon.com>
Subject:
Re: another example for examples/iked.conf?
To:
tech <tech@openbsd.org>
Date:
Sat, 03 Oct 2026 07:32:06 -0000

Download raw body.

Thread
On Fri, Oct 02, 2026 at 04:34:02PM +0100, Stuart Henderson wrote:
> iked can select different policy blocks for clients on dynamic IPs
> based on their srcid, but I find the configuration style needed
> rather tricky to get right (without the "peer any" I don't see any
> connections match up with the block).
> 
> Would it be ok to add another example to cover this?

Makes sense to me, so OK.

> 
> Index: iked.conf
> ===================================================================
> RCS file: /cvs/src/etc/examples/iked.conf,v
> diff -u -p -r1.3 iked.conf
> --- iked.conf	6 Mar 2023 13:57:45 -0000	1.3
> +++ iked.conf	2 Oct 2026 15:17:05 -0000
> @@ -33,3 +33,17 @@
>  #	from 10.5.0.0/24 to 172.16.1.0/24 \
>  #	local 192.168.1.1 peer 192.168.2.1 \
>  #	psk "tyBNv13zuo3rg1WVXlaI1g1tTYNzwk962mMUYIvaLh2x8vvvyA-replace-me"
> +
> +# Configuration for multiple clients connecting with a pre-shared key
> +# from dynamic IP addresses (even with several behind a single NATted IP).
> +# this side acts as responder only; the other side must initiate and be
> +# configured with the matching srcid.
> +#
> +#ikev2 "peer1" passive esp \
> +#	from 192.0.2.0/24 to 172.27.20.0/22 \
> +#	peer any dstid peer1-fqdn-identity \
> +#	psk "WtV96WAtY3OFJOYgx9ME8we11RQRqHsaeNhM3REkrT-replace-me"
> +#ikev2 "peer2" passive esp \
> +#	from 192.0.2.0/24 to 172.27.16.0/22 \
> +#	peer any dstid peer2-fqdn-identity \
> +#	psk "dYxO4oX0QSROZBP1nuPHUjfCMoJOFxtVF-replace-me"
> 
>