conn private-or-clear # Prefer IPsec, allow cleartext rightrsasigkey=%cert right=%opportunisticgroup rightca=%same left=%defaultroute leftcert=CENTOS-172 leftid=%fromcert narrowing=yes ikev2=insist auto=ondemand #authby=rsasig type=tunnel negotiationshunt=drop failureshunt=passthrough