Fully qualified domain name in DNS of the right-hand side VPN device,
which is preceded by an @ sign. If DNS isn’t set up for the IP addresses,
remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail
.

conn comms27
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms27.commsgroup.ww
rightsubnet=10.10.37.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no
dpddelay=30
dpdtimeout=120
dpdaction=clear
type=transport

ipsec.secrets config :
%any 85.234.65.53 : PSK “commsr3m0t3”
@comms30.commsgroup.ww 85.234.65.53 : PSK “commsr3m0t3”

Table 35-1 Parameters of the /etc/ipsec.conf file

Parameter Description
Left Internet IP address of the left-hand side VPN device.
Leftsubnet The network protected by the left-hand side VPN device.
Leftid Fully qualified domain name in DNS of the left-hand side VPN device, which is preceded by an “@” sign. If DNS is set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Leftrsasigkey The entire left RSA sig public key for the left-hand side VPN device. This can be obtained by using the ipsec showhostkey --left command.
Leftnexthop The next hop router from the left-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.
Right Internet IP address of the right-hand side VPN device.
Rightsubnet The network protected by the right-hand side VPN device.
Rightid Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign. If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Rightrsasigkey The entire right RSA sig public key for the right-hand side VPN device. This can be obtained by using the ipsec showhostkey --right command.
Rightnexthop The next hop router from the right-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.