diff --git a/docs/ikev2-howto-zh.md b/docs/ikev2-howto-zh.md index 3273e8a..4862252 100644 --- a/docs/ikev2-howto-zh.md +++ b/docs/ikev2-howto-zh.md @@ -60,7 +60,7 @@ Libreswan 支持通过使用 RSA 签名算法的 X.509 Machine Certificates 来 pfs=no ike-frag=yes ike=aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1,aes256-sha2;modp1024,aes128-sha1;modp1024 - phase2alg=aes_gcm-null,aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1 + phase2alg=aes_gcm-null,aes128-sha1,aes256-sha1,aes128-sha2,aes256-sha2 EOF ``` diff --git a/docs/ikev2-howto.md b/docs/ikev2-howto.md index 5bb91d9..8335fa6 100644 --- a/docs/ikev2-howto.md +++ b/docs/ikev2-howto.md @@ -60,7 +60,7 @@ Before continuing, make sure you have successfully /dev/null # Update ipsec.conf IKE_NEW=" ike=aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1,aes256-sha2;modp1024,aes128-sha1;modp1024" -PHASE2_NEW=" phase2alg=aes_gcm-null,aes256-sha2_512,aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1" +PHASE2_NEW=" phase2alg=aes_gcm-null,aes128-sha1,aes256-sha1,aes256-sha2_512,aes128-sha2,aes256-sha2" sed -i".old-$(date +%F-%T)" \ -e "s/^[[:space:]]\+auth=esp\$/ phase2=esp/g" \ diff --git a/vpnsetup.sh b/vpnsetup.sh index 2069e58..b268d7d 100755 --- a/vpnsetup.sh +++ b/vpnsetup.sh @@ -259,7 +259,7 @@ conn shared dpdtimeout=120 dpdaction=clear ike=aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1,aes256-sha2;modp1024,aes128-sha1;modp1024 - phase2alg=aes_gcm-null,aes256-sha2_512,aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1 + phase2alg=aes_gcm-null,aes128-sha1,aes256-sha1,aes256-sha2_512,aes128-sha2,aes256-sha2 sha2-truncbug=yes conn l2tp-psk diff --git a/vpnsetup_centos.sh b/vpnsetup_centos.sh index 1646aa4..be7f55a 100755 --- a/vpnsetup_centos.sh +++ b/vpnsetup_centos.sh @@ -246,7 +246,7 @@ conn shared dpdtimeout=120 dpdaction=clear ike=aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1,aes256-sha2;modp1024,aes128-sha1;modp1024 - phase2alg=aes_gcm-null,aes256-sha2_512,aes256-sha2,aes128-sha2,aes256-sha1,aes128-sha1 + phase2alg=aes_gcm-null,aes128-sha1,aes256-sha1,aes256-sha2_512,aes128-sha2,aes256-sha2 sha2-truncbug=yes conn l2tp-psk