1
0
mirror of https://github.com/vimagick/dockerfiles.git synced 2024-11-24 08:52:31 +02:00

strongswan: Split-Tunneling with IKEv2

This commit is contained in:
kev 2016-07-01 00:09:28 +08:00
parent d69b80858a
commit 4e1695de82
4 changed files with 5 additions and 4 deletions

View File

@ -17,6 +17,7 @@ VOLUME /etc/ipsec.d /etc/strongswan.d
ENV VPN_DEVICE=eth0
ENV VPN_NETWORK=10.20.30.0/24
ENV LAN_NETWORK=192.168.0.0/16
ENV VPN_DNS=8.8.8.8,8.8.4.4
EXPOSE 500/udp 4500/udp

View File

@ -25,9 +25,8 @@ services:
environment:
- VPN_DOMAIN=vpn.easypi.info
- VPN_NETWORK=10.20.30.0/24
- LAN_NETWORK=192.168.0.0/16
- VPN_P12_PASSWORD=secret
cap_add:
- NET_ADMIN
tmpfs: /run
privileged: yes
restart: always

View File

@ -11,9 +11,8 @@ services:
environment:
- VPN_DOMAIN=vpn.easypi.info
- VPN_NETWORK=10.20.30.0/24
- LAN_NETWORK=192.168.0.0/16
- VPN_P12_PASSWORD=secret
cap_add:
- NET_ADMIN
tmpfs: /run
privileged: yes
restart: always

View File

@ -5,6 +5,7 @@
# - VPN_DNS
# - VPN_DOMAIN
# - VPN_NETWORK
# - LAN_NETWORK
# - VPN_P12_PASSWORD
#
@ -33,6 +34,7 @@ conn %default
right=%any
rightdns=${VPN_DNS}
rightsourceip=${VPN_NETWORK}
rightsubnets=${LAN_NETWORK}
conn IPSec-IKEv2
keyexchange=ikev2