/testing/guestbin/swan-prep west # ipsec start Redirecting to: [initsystem] west # /testing/pluto/bin/wait-until-pluto-started west # ipsec auto --add west-east 002 added connection description "west-east" west # echo "initdone" initdone west # # we can transmit in the clear west # ping -q -c 4 -n 192.1.2.23 PING 192.1.2.23 (192.1.2.23) 56(84) bytes of data. --- 192.1.2.23 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time XXXX rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms west # # bring up the tunnel west # ipsec auto --up west-east 003 "west-east" #1: multiple DH groups in aggressive mode can cause interop failure 003 "west-east" #1: Deleting previous proposal in the hopes of selecting DH 2 or DH 5 002 "west-east" #1: initiating Aggressive Mode 003 "west-east" #1: multiple DH groups in aggressive mode can cause interop failure 003 "west-east" #1: Deleting previous proposal in the hopes of selecting DH 2 or DH 5 1v1 "west-east" #1: STATE_AGGR_I1: initiate 002 "west-east" #1: Peer ID is ID_FQDN: '@east' 002 "west-east" #1: Peer ID is ID_FQDN: '@east' 003 "west-east" #1: Authenticated using RSA 004 "west-east" #1: STATE_AGGR_I2: sent AI2, ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA1 group=MODP1536} 002 "west-east" #2: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+UP+AGGRESSIVE+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO 1v1 "west-east" #2: STATE_QUICK_I1: initiate 004 "west-east" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=active} west # # use the tunnel west # ping -q -c 4 -n 192.1.2.23 PING 192.1.2.23 (192.1.2.23) 56(84) bytes of data. --- 192.1.2.23 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time XXXX rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms west # # show the tunnel! west # echo "Tunnel should be up" Tunnel should be up west # ipsec whack --trafficstatus 006 #2: "west-east", type=ESP, add_time=1234567890, inBytes=336, outBytes=336, id='@east' west # # Let R_U_THERE packets flow west # echo "Waiting 15 seconds..." Waiting 15 seconds... west # sleep 15 west # echo "Setting up block via iptables" Setting up block via iptables west # iptables -I INPUT -s 192.1.2.23/32 -d 0/0 -j DROP west # iptables -I OUTPUT -d 192.1.2.23/32 -s 0/0 -j DROP west # west # # DPD should have triggered now west # echo "Tunnel should be down" Tunnel should be down west # ipsec whack --trafficstatus west # # Remove the Blockage west # echo "Removing block" Removing block west # iptables -D INPUT -s 192.1.2.23/32 -d 0/0 -j DROP west # iptables -D OUTPUT -d 192.1.2.23/32 -s 0/0 -j DROP west # sleep 20 west # sleep 20 west # ping -q -c 4 -n 192.1.2.23 PING 192.1.2.23 (192.1.2.23) 56(84) bytes of data. --- 192.1.2.23 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time XXXX rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms west # # Tunnel should be back up now west # echo "Tunnel should be up" Tunnel should be up west # ipsec whack --trafficstatus whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) west # echo done done west # # no tunnels left, Ma! west # west # ../bin/check-for-core.sh west # if [ -f /sbin/ausearch ]; then ausearch -r -m avc -ts recent ; fi