--- east.console.txt 2019-08-24 18:12:56.139678648 +0000 +++ OUTPUT/east.console.txt 2019-08-26 13:15:50.999531436 +0000 @@ -151,22 +151,11 @@ initdone east # ipsec whack --trafficstatus -006 #2: "northnet-westnet-ipv4-psk", type=ESP, add_time=1234567890, inBytes=336, outBytes=336, id='@north' -006 #4: "westnet-northnet-ipv4-psk", type=ESP, add_time=1234567890, inBytes=336, outBytes=336, id='@west' +whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) east # ../../pluto/bin/ipsec-look.sh east NOW XFRM state: -src 192.1.2.45 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - auth-trunc hmac(sha1) 0xHASHKEY 96 - enc cbc(aes) 0xENCKEY -src 192.1.2.23 dst 192.1.2.45 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - auth-trunc hmac(sha1) 0xHASHKEY 96 - enc cbc(aes) 0xENCKEY src 192.1.3.33 dst 192.1.2.23 proto esp spi 0xSPISPI reqid REQID mode tunnel replay-window 32 flag af-unspec @@ -179,14 +168,6 @@ enc cbc(aes) 0xENCKEY XFRM policy: src 192.0.1.0/24 dst 192.0.3.0/24 - dir fwd priority 1042407 ptype main - tmpl src 192.1.2.45 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.1.0/24 dst 192.0.3.0/24 - dir in priority 1042407 ptype main - tmpl src 192.1.2.45 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.1.0/24 dst 192.0.3.0/24 dir out priority 1042407 ptype main tmpl src 192.1.2.23 dst 192.1.3.33 proto esp reqid REQID mode tunnel @@ -198,10 +179,6 @@ dir in priority 1042407 ptype main tmpl src 192.1.3.33 dst 192.1.2.23 proto esp reqid REQID mode tunnel -src 192.0.3.0/24 dst 192.0.1.0/24 - dir out priority 1042407 ptype main - tmpl src 192.1.2.23 dst 192.1.2.45 - proto esp reqid REQID mode tunnel XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES