--- west.console.txt 2019-08-24 18:12:56.119679353 +0000 +++ OUTPUT/west.console.txt 2019-08-26 13:27:58.841048588 +0000 @@ -14,7 +14,6 @@ # confirm clear text does not get through west # ../../pluto/bin/ping-once.sh --down -I 192.0.1.254 192.0.2.254 -[ 00.00] IN=eth1 OUT= MAC=12:00:00:64:64:45:12:00:00:64:64:23:08:00 SRC=192.0.2.254 DST=192.0.1.254 LEN=XXXX TOS=0x00 PREC=0x00 TTL=64 ID=XXXXX PROTO=ICMP TYPE=0 CODE=0 ID=XXXX SEQ=1 down west # ipsec start @@ -84,7 +83,7 @@ rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms west # ipsec whack --trafficstatus -006 #2: "westnet-eastnet-compress", type=ESP, add_time=1234567890, inBytes=649, outBytes=652, id='@east' +006 #2: "westnet-eastnet-compress", type=ESP, add_time=1234567890, inBytes=658, outBytes=662, id='@east' west # ../../pluto/bin/ipsec-look.sh west NOW @@ -151,7 +150,7 @@ ipsec auto --down westnet-eastnet-compress 002 "westnet-eastnet-compress": terminating SAs using this connection 002 "westnet-eastnet-compress" #2: deleting state (STATE_QUICK_I2) and sending notification -005 "westnet-eastnet-compress" #2: ESP traffic information: in=649B out=652B +005 "westnet-eastnet-compress" #2: ESP traffic information: in=658B out=662B 005 "westnet-eastnet-compress" #2: IPCOMP traffic information: in=0B out=0B 002 "westnet-eastnet-compress" #1: deleting state (STATE_MAIN_I4) and sending notification west # @@ -160,9 +159,12 @@ west # ../../pluto/bin/ipsec-look.sh west NOW -!!!! There should be no XFRM state/policy left here !!! XFRM state: XFRM policy: +src 192.0.1.0/24 dst 192.0.2.0/24 + dir out priority 1042407 ptype main + tmpl src 0.0.0.0 dst 0.0.0.0 + proto esp reqid REQID mode transport XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES