From: Crystal Kolipe Subject: Re: another example for examples/iked.conf? To: tech Date: Sat, 03 Oct 2026 07:32:06 -0000 On Fri, Oct 02, 2026 at 04:34:02PM +0100, Stuart Henderson wrote: > iked can select different policy blocks for clients on dynamic IPs > based on their srcid, but I find the configuration style needed > rather tricky to get right (without the "peer any" I don't see any > connections match up with the block). > > Would it be ok to add another example to cover this? Makes sense to me, so OK. > > Index: iked.conf > =================================================================== > RCS file: /cvs/src/etc/examples/iked.conf,v > diff -u -p -r1.3 iked.conf > --- iked.conf 6 Mar 2023 13:57:45 -0000 1.3 > +++ iked.conf 2 Oct 2026 15:17:05 -0000 > @@ -33,3 +33,17 @@ > # from 10.5.0.0/24 to 172.16.1.0/24 \ > # local 192.168.1.1 peer 192.168.2.1 \ > # psk "tyBNv13zuo3rg1WVXlaI1g1tTYNzwk962mMUYIvaLh2x8vvvyA-replace-me" > + > +# Configuration for multiple clients connecting with a pre-shared key > +# from dynamic IP addresses (even with several behind a single NATted IP). > +# this side acts as responder only; the other side must initiate and be > +# configured with the matching srcid. > +# > +#ikev2 "peer1" passive esp \ > +# from 192.0.2.0/24 to 172.27.20.0/22 \ > +# peer any dstid peer1-fqdn-identity \ > +# psk "WtV96WAtY3OFJOYgx9ME8we11RQRqHsaeNhM3REkrT-replace-me" > +#ikev2 "peer2" passive esp \ > +# from 192.0.2.0/24 to 172.27.16.0/22 \ > +# peer any dstid peer2-fqdn-identity \ > +# psk "dYxO4oX0QSROZBP1nuPHUjfCMoJOFxtVF-replace-me" > >