Skip to main content
Configure one CryptoHub-backed responder and one file-key initiator. Replace these placeholders before you run the commands:
  • <RESPONDER_IP>: IKE address of the CryptoHub-backed gateway
  • <INITIATOR_IP>: IKE address of the initiating gateway
  • <RESPONDER_SUBNET>: protected subnet behind the responder
  • <INITIATOR_SUBNET>: protected subnet behind the initiator

Configure the responder

Run on the responder:
The output reports successful certificate, token, and connection loads. Run sudo swanctl --list-conns and confirm that it lists responder and the net child.

Configure the initiator

Transfer initiator-key.pem, initiator-cert.pem, and ca-cert.pem to the initiator over an encrypted channel. Run:
Write /etc/swanctl/swanctl.conf:
Run:
Run sudo swanctl --list-conns. The output must list initiator and the net child.