> ## Documentation Index
> Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure the responder and the initiator

> Configure certificate-authenticated IKEv2 peers with a CryptoHub-backed responder.

Configure one CryptoHub-backed responder and one file-key initiator.

Replace these placeholders before you run the commands:

* `<RESPONDER_IP>`: IKE address of the CryptoHub-backed gateway
* `<INITIATOR_IP>`: IKE address of the initiating gateway
* `<RESPONDER_SUBNET>`: protected subnet behind the responder
* `<INITIATOR_SUBNET>`: protected subnet behind the initiator

## Configure the responder

Run on the responder:

```shell theme={null}
PIN="$(sudo cat /etc/strongswan-chlibs/token-pin)"
KEY_ID="$(sudo cat /etc/strongswan-chlibs/responder-key-id)"

sudo tee /etc/swanctl/swanctl.conf > /dev/null <<EOF
connections {
    responder {
        version = 2
        local_addrs = <RESPONDER_IP>
        remote_addrs = <INITIATOR_IP>
        proposals = aes256-sha256-modp2048

        local {
            auth = pubkey
            id = responder.example.com
            certs = responder-cert.pem
        }
        remote {
            auth = pubkey
            id = initiator.example.com
        }

        children {
            net {
                local_ts = <RESPONDER_SUBNET>
                remote_ts = <INITIATOR_SUBNET>
                esp_proposals = aes256-sha256
                mode = tunnel
                start_action = none
            }
        }
    }
}

secrets {
    token-strongswan {
        module = futurex
        slot = 0
        handle = $KEY_ID
        pin = "$PIN"
    }
}
EOF

unset PIN KEY_ID
sudo chmod 600 /etc/swanctl/swanctl.conf
sudo swanctl --load-all --clear --raw
```

<Check>
  The output reports successful certificate, token, and connection loads. Run `sudo swanctl --list-conns` and confirm that it lists `responder` and the `net` child.
</Check>

## Configure the initiator

Transfer `initiator-key.pem`, `initiator-cert.pem`, and `ca-cert.pem` to the initiator over an encrypted channel. Run:

```shell theme={null}
sudo install -d -m 755 \
  /etc/swanctl/x509 /etc/swanctl/x509ca /etc/swanctl/private
sudo install -m 644 initiator-cert.pem \
  /etc/swanctl/x509/initiator-cert.pem
sudo install -m 644 ca-cert.pem \
  /etc/swanctl/x509ca/ca-cert.pem
sudo install -m 600 initiator-key.pem \
  /etc/swanctl/private/initiator-key.pem
```

Write `/etc/swanctl/swanctl.conf`:

```conf theme={null}
connections {
    initiator {
        version = 2
        local_addrs = <INITIATOR_IP>
        remote_addrs = <RESPONDER_IP>
        proposals = aes256-sha256-modp2048

        local {
            auth = pubkey
            id = initiator.example.com
            certs = initiator-cert.pem
        }
        remote {
            auth = pubkey
            id = responder.example.com
        }

        children {
            net {
                local_ts = <INITIATOR_SUBNET>
                remote_ts = <RESPONDER_SUBNET>
                esp_proposals = aes256-sha256
                mode = tunnel
                start_action = none
            }
        }
    }
}
```

Run:

```shell theme={null}
sudo chmod 600 /etc/swanctl/swanctl.conf
sudo systemctl restart strongswan-starter
sudo swanctl --load-all --clear --raw
```

<Check>
  Run `sudo swanctl --list-conns`. The output must list `initiator` and the `net` child.
</Check>
