X-Git-Url: https://git.distorted.org.uk/~mdw/secnet/blobdiff_plain/08f344d3bdffe4bb83b47b5e2d53758ce231ebc4..c6f79b178fe27ee315055dccb371b63ca1a6183a:/example.conf diff --git a/example.conf b/example.conf index 0d7a546..189b442 100644 --- a/example.conf +++ b/example.conf @@ -1,7 +1,21 @@ # secnet example configuration file # Log facility -log logfile("secnet","local2"); # Not yet implemented, goes to stderr +log syslog { + ident "secnet"; + facility "local0"; +}; + +# Alternatively you could log to a file: +# log logfile { +# filename "/var/log/secnet"; +# class "info","notice","warning","error","security","fatal"; +# # There are some useful message classes that could replace +# # this list: +# # 'default' -> warning,error,security,fatal +# # 'verbose' -> info,notice,default +# # 'quiet' -> fatal +# }; # Systemwide configuration (all other configuration is per-site): # log a log facility for program messages @@ -46,6 +60,9 @@ system { # wait-time wait between unsuccessful key setup attempts, in ms # renegotiate-time set up a new key if we see any traffic after this time +setup-retries 10; +setup-timeout 2000; + # Use the universal TUN/TAP driver to get packets to and from the kernel # (use tun-old if you are not on Linux-2.4) netlink tun { @@ -111,6 +128,8 @@ log-events "setup-init","setup-timeout","activate-key","timeout-key","errors", # that it's non-blocking. XXX 'yes' isn't implemented yet. random randomfile("/dev/urandom",no); +# If you're using the make-secnet-sites.py script then your local-name +# will be of the form "vpnname/location/site" eg. "sgo/greenend/sinister" local-name "your-site-name"; local-key rsa-private("/etc/secnet/key");