# Do not edit this file. It is overwritten by VpnConf.
# SIGNATURE SHA2 = xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
# Creation Date : 2025-12-11 at 14:47:08
# Written by VpnCfg 6.50
# File format version 2.02
#

[TGBIKENG]
<?xml version="1.0" encoding="ISO-8859-1"?>
<tgbconfig>
  <cfg_ikev2>
    <cfg_connectionv2 name="FFF">
      <cfg_ike_sa name="FFF" family="AF_AUTO">
        <server>nebula-6877be53.d2ns-nbl.com</server>
        <port>500</port>
        <port_nat>4500</port_nat>
        <ikeauth_lifetime>86400</ikeauth_lifetime>
        <retries>3</retries>
        <gateway_timeout>5</gateway_timeout>
        <cfg_dynamic_param_lst />
        <cfg_dpd>
          <interval>30</interval>
          <retrans>5</retrans>
          <wait>15</wait>
        </cfg_dpd>
        <cfg_sa>
          <proposal protocol="IKE">
            <transform type="ENCR_ALGO" keylength="256">AES_CBC</transform>
            <transform type="PRF">PRF_HMAC_SHA2_256</transform>
            <transform type="INTEG">AUTH_HMAC_SHA2_256_128</transform>
            <transform type="DH_GROUP">DH_MODP_2048</transform>
          </proposal>
        </cfg_sa>
        <identity type="ID_FQDN" location="remote">nebula-6877be53.d2ns-nbl.com</identity>
        <authentication type="eap" sendcertrequest="yes">
          <cfg_eap type="EAP-MSCHAPV2" popup="yes" />
          <certificate type="cacert" location="file">
            <public_key>
              -----BEGIN CERTIFICATE-----
              MIIDozCCAougAwIBAgIUFVSNYvnDBsspDMIx9Cgsoi59t84wDQYJKoZIhvcNAQEL
              BQAwJzElMCMGA1UEAwwcbmVidWxhLTY4NzdiZTUzLmQybnMtbmJsLmNvbTAeFw0y
              NTEyMTExMjIzNTRaFw0zNTEyMDkxMjIzNTRaMCcxJTAjBgNVBAMMHG5lYnVsYS02
              ODc3YmU1My5kMm5zLW5ibC5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK
              AoIBAQDQMzaiF29Y5CbyBRDnfC0kPLcLEvei6JpoT3Rb6J3zYItxDWgw+lTcOZk4
              xe5l3FeQuyrTvqOSV35DHmqtsOG6uGWYShC6g3cA2EjrSRamqX5WTx23Lfh9JTDw
              FnvOZtV5byOAoir2NpKtnNAUwf+m9cOuCRB0HVr1aSdN6IM7YVsyO1JB7YkeOmcf
              +m6ZtXYtHMVFVnVvqkJtZ1zT3P7c/WHe8ewbtjqvg2QJyE7HxW5BT9yDVP8KQILN
              4h3ANSsqkbCzMwtWW68gmo6Nc6tW+lyC2B2vxPJnK1AdJUIirmz4m0y9BLvekQx7
              INP1wodE+V0vKE/nelcQBtghWk65AgMBAAGjgcYwgcMwEgYDVR0TAQH/BAgwBgEB
              /wIBATAdBgNVHQ4EFgQUkqou8da8fCfmz5SGCA173bYNKLIwDgYDVR0PAQH/BAQD
              AgK0MCcGA1UdJQQgMB4GCCsGAQUFBwMBBggrBgEFBQcDAgYIKwYBBQUIAgIwVQYD
              VR0RBE4wTKAsBgorBgEEAYI3FAIDoB4MHG5lYnVsYS02ODc3YmU1My5kMm5zLW5i
              bC5jb22CHG5lYnVsYS02ODc3YmU1My5kMm5zLW5ibC5jb20wDQYJKoZIhvcNAQEL
              BQADggEBAMaHuGEVOFUtVtrwLGJarRjhlyIY3L+gd2ohVWBUlMfoD4gybZA1w3S2
              +mzoKxSffFroljGQUO6/BtWUwJ5a1Ze03+FQhiRTCPG6Ls5FBpQFpvpzL0A0iXPU
              zNT2QHqxGmz8JwaXtBsqu8mBY1ZmHbt+z+yFQ78egG3yyuYx1LoWB+LEylEDFJ8/
              Invd/WWUO7/qBm5Mj0bS659x3unmIXlZFXtKOGDbKPIkjTqqz2MYWuMTEu0haRuG
              rZRCjU65ioGlxsjni6/q6LG1nhmHRYI0EWyonCLXWqqahG+0ID9z2u5rztS6f37I
              v9BgXGp++VqhKKUqgXCeFSEVYsJRkfc=
              -----END CERTIFICATE-----
            </public_key>
          </certificate>
        </authentication>
      </cfg_ike_sa>
      <cfg_child_sa name="RemoteAccessVPN" family="AF_INET" requestconfig="yes" tunneltype="client2server">
        <childsa_lifetime>28800</childsa_lifetime>
        <cfg_sa>
          <proposal protocol="ESP">
            <transform type="ENCR_ALGO" keylength="256">AES_CBC</transform>
            <transform type="INTEG">AUTH_HMAC_SHA2_256_128</transform>
            <transform type="DH_GROUP">DH_NONE</transform>
            <transform type="ESN">NO_EXTENDED_SEQ_NUMBER</transform>
          </proposal>
        </cfg_sa>
        <cfg_ts type="IPV4_ADDR_RANGE" location="local">
          <protocol>0</protocol>
          <start_port>0</start_port>
          <end_port>65535</end_port>
          <starting_address>0.0.0.0</starting_address>
          <ending_address>0.0.0.0</ending_address>
        </cfg_ts>
        <cfg_ts type="IPV4_ADDR_RANGE" location="remote">
          <protocol>0</protocol>
          <start_port>0</start_port>
          <end_port>65535</end_port>
          <starting_address>0.0.0.0</starting_address>
          <ending_address>(null)</ending_address>
        </cfg_ts>
        <cfg_automation />
        <cfg_remotesharing />
        <cfg_dynamic_param_lst>
          <dynamic_param name="ULBandwidthLimit" value="0" />
          <dynamic_param name="ULBucketSize" value="0" />
        </cfg_dynamic_param_lst>
      </cfg_child_sa>
    </cfg_connectionv2>
  </cfg_ikev2>
  <cfg_cnxpanel>
    <cfg_cnxpanel_connection name="FFF-RemoteAccessVPN" tunnel="FFF-RemoteAccessVPN" />
  </cfg_cnxpanel>
  <dialer_params>
    <tnd>
      <ldap_port>389</ldap_port>
      <ldaps_port>636</ldaps_port>
      <detection_type>HTTPS</detection_type>
    </tnd>
  </dialer_params>
</tgbconfig>

