From f05bf90dbc0cc43ddc5721cfe1164a48f92adc6b Mon Sep 17 00:00:00 2001 From: hwdsl2 Date: Thu, 25 Oct 2018 01:04:16 -0500 Subject: [PATCH] Update IKEv2 docs - Enable MOBIKE option for Libreswan 3.23 and newer - Add AES-GCM cipher for improved performance --- docs/ikev2-howto-zh.md | 3 ++- docs/ikev2-howto.md | 3 ++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/ikev2-howto-zh.md b/docs/ikev2-howto-zh.md index 0260b19..dde93b2 100644 --- a/docs/ikev2-howto-zh.md +++ b/docs/ikev2-howto-zh.md @@ -57,7 +57,7 @@ Libreswan 支持通过使用 RSA 签名算法的 X.509 Machine Certificates 来 rekey=no fragmentation=yes ike=3des-sha1,3des-sha2,aes-sha1,aes-sha1;modp1024,aes-sha2,aes-sha2;modp1024 - phase2alg=3des-sha1,3des-sha2,aes-sha1,aes-sha2 + phase2alg=3des-sha1,3des-sha2,aes-sha1,aes-sha2,aes_gcm-null EOF ``` @@ -73,6 +73,7 @@ Libreswan 支持通过使用 RSA 签名算法的 X.509 Machine Certificates 来 $ cat >> /etc/ipsec.conf <> /etc/ipsec.conf <