diff -ruN smeserver-libreswan-xl2tpd-0.5.old/root/etc/e-smith/db/ipsec_connections/defaults/L2TPD-PSK/status smeserver-libreswan-xl2tpd-0.5/root/etc/e-smith/db/ipsec_connections/defaults/L2TPD-PSK/status --- smeserver-libreswan-xl2tpd-0.5.old/root/etc/e-smith/db/ipsec_connections/defaults/L2TPD-PSK/status 1970-01-01 01:00:00.000000000 +0100 +++ smeserver-libreswan-xl2tpd-0.5/root/etc/e-smith/db/ipsec_connections/defaults/L2TPD-PSK/status 2019-10-13 16:05:56.435030738 +0200 @@ -0,0 +1 @@ +disabled \ No newline at end of file diff -ruN smeserver-libreswan-xl2tpd-0.5.old/root/etc/e-smith/templates/etc/ipsec.d/ipsec.conf/20defaultL2tpd smeserver-libreswan-xl2tpd-0.5/root/etc/e-smith/templates/etc/ipsec.d/ipsec.conf/20defaultL2tpd --- smeserver-libreswan-xl2tpd-0.5.old/root/etc/e-smith/templates/etc/ipsec.d/ipsec.conf/20defaultL2tpd 2019-10-13 16:01:44.453638751 +0200 +++ smeserver-libreswan-xl2tpd-0.5/root/etc/e-smith/templates/etc/ipsec.d/ipsec.conf/20defaultL2tpd 2019-10-13 16:05:56.468032361 +0200 @@ -45,6 +45,9 @@ $OUT .= " # high port, but propose \"0\" instead of their port.\n"; $OUT .= " left=%defaultroute\n"; $OUT .= " leftprotoport=17/1701\n"; + $OUT .= " # Permit Ike v1 for older xl2tpd connections/clients\n"; + $OUT .= " ikev2=permit\n"; + $OUT .= " # Apple iOS doesn't send delete notify so we need dead peer detection\n"; $OUT .= " # to detect vanishing clients\n"; @@ -62,6 +65,7 @@ # Disabled for now - needs some thought # Probably only needed if you are doing subnet <-> subnet # Most likely not required for dialin + # see https://libreswan.org/man/ipsec.conf.5.html -> leftsubnet my $rightsubnet = $ipsecDB->get_prop( $ipsecprop, 'rightsubnet' ) || ''; if ( $rightsubnet ne '' ) {