--- north.console.txt 2019-08-24 18:12:56.129679001 +0000 +++ OUTPUT/north.console.txt 2019-08-26 13:22:45.921004403 +0000 @@ -29,10 +29,11 @@ 002 "north-dpd/0x2" #3: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO 1v1 "north-dpd/0x1" #2: STATE_QUICK_I1: initiate 1v1 "north-dpd/0x2" #3: STATE_QUICK_I1: initiate -004 "north-dpd/0x1" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=active} 004 "north-dpd/0x2" #3: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=active} +004 "north-dpd/0x1" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=active} north # ipsec auto --status | grep northnet-eastnets +whack: log line missing NNN prefix: north # ping -n -c 2 -I 192.0.3.254 192.0.2.254 PING 192.0.2.254 (192.0.2.254) from 192.0.3.254 : 56(84) bytes of data. @@ -44,8 +45,10 @@ north # ping -n -c 2 -I 192.0.3.254 192.0.22.254 PING 192.0.22.254 (192.0.22.254) from 192.0.3.254 : 56(84) bytes of data. +From 192.1.3.254 icmp_seq=1 Destination Net Unreachable +From 192.1.3.254 icmp_seq=2 Destination Net Unreachable --- 192.0.22.254 ping statistics --- -2 packets transmitted, 0 received, 100% packet loss, time XXXX +2 packets transmitted, 0 received, +2 errors, 100% packet loss, time XXXX north # ipsec whack --trafficstatus 006 #2: "north-dpd/0x1", type=ESP, add_time=1234567890, inBytes=168, outBytes=168, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' @@ -100,7 +103,7 @@ 000 "north-dpd/0x2": aliases: north-dpd 000 "north-dpd/0x2": IKEv1 algorithm newest: AES_CBC_256-HMAC_SHA2_256-MODP2048 000 #5: "north-dpd/0x1":500 STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_RETRANSMIT in XXs; lastdpd=-1s(seq in:0 out:0); idle; -000 #1: "north-dpd/0x2":500 STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REKEY in XXs; newest ISAKMP; lastdpd=28s(seq in:17811 out:17810); idle; +000 #1: "north-dpd/0x2":500 STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REPLACE in XXs; newest ISAKMP; lastdpd=30s(seq in:13824 out:13823); idle; 000 #4: "north-dpd/0x2":500 STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_RETRANSMIT in XXs; lastdpd=-1s(seq in:0 out:0); idle; north # ip route del unreachable 192.1.2.23 @@ -114,15 +117,15 @@ north # ping -n -c 2 -I 192.0.3.254 192.0.22.254 PING 192.0.22.254 (192.0.22.254) from 192.0.3.254 : 56(84) bytes of data. +From 192.1.3.254 icmp_seq=2 Destination Net Unreachable --- 192.0.22.254 ping statistics --- -2 packets transmitted, 0 received, 100% packet loss, time XXXX +2 packets transmitted, 0 received, +1 errors, 100% packet loss, time XXXX north # # state number shuld be higher than the previous one north # ipsec whack --trafficstatus -006 #5: "north-dpd/0x1", type=ESP, add_time=1234567890, inBytes=0, outBytes=0, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' 006 #6: "north-dpd/0x1", type=ESP, add_time=1234567890, inBytes=84, outBytes=84, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' -006 #4: "north-dpd/0x2", type=ESP, add_time=1234567890, inBytes=0, outBytes=168, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' +006 #7: "north-dpd/0x2", type=ESP, add_time=1234567890, inBytes=0, outBytes=84, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' north # echo done done