FIPS Product: YES FIPS Kernel: NO FIPS Mode: NO NSS DB directory: sql:/etc/ipsec.d Initializing NSS Opening NSS database "sql:/etc/ipsec.d" read-only NSS initialized NSS crypto library initialized FIPS HMAC integrity support [enabled] FIPS mode disabled for pluto daemon FIPS HMAC integrity verification self-test FAILED libcap-ng support [enabled] Linux audit support [enabled] Linux audit activated Starting Pluto (Libreswan Version v3.28-685-gbfd5aef521-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:18938 core dump dir: /run/pluto secrets file: /etc/ipsec.secrets leak-detective enabled NSS crypto [enabled] XAUTH PAM support [enabled] | libevent is using pluto's memory allocator Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) | libevent_malloc: new ptr-libevent@0x559617672658 size 40 | libevent_malloc: new ptr-libevent@0x5596176725d8 size 40 | libevent_malloc: new ptr-libevent@0x559617672558 size 40 | creating event base | libevent_malloc: new ptr-libevent@0x559617664188 size 56 | libevent_malloc: new ptr-libevent@0x5596175eddd8 size 664 | libevent_malloc: new ptr-libevent@0x5596176acc78 size 24 | libevent_malloc: new ptr-libevent@0x5596176accc8 size 384 | libevent_malloc: new ptr-libevent@0x5596176acc38 size 16 | libevent_malloc: new ptr-libevent@0x5596176724d8 size 40 | libevent_malloc: new ptr-libevent@0x559617672458 size 48 | libevent_realloc: new ptr-libevent@0x5596175eda68 size 256 | libevent_malloc: new ptr-libevent@0x5596176ace78 size 16 | libevent_free: release ptr-libevent@0x559617664188 | libevent initialized | libevent_realloc: new ptr-libevent@0x559617664188 size 64 | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds | init_nat_traversal() initialized with keep_alive=0s NAT-Traversal support [enabled] | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized | global one-shot timer EVENT_FREE_ROOT_CERTS initialized | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds | global one-shot timer EVENT_REVIVE_CONNS initialized | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Encryption algorithms: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac NULL IKEv1: ESP IKEv2: ESP [] CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Hash algorithms: MD5 IKEv1: IKE IKEv2: SHA1 IKEv1: IKE IKEv2: FIPS sha SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 PRF algorithms: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Integrity algorithms: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac NONE IKEv1: ESP IKEv2: IKE ESP FIPS null DH algorithms: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 testing CAMELLIA_CBC: Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 128-bit key Camellia: 16 bytes with 256-bit key Camellia: 16 bytes with 256-bit key testing AES_GCM_16: empty string one block two blocks two blocks with associated data testing AES_CTR: Encrypting 16 octets using AES-CTR with 128-bit key Encrypting 32 octets using AES-CTR with 128-bit key Encrypting 36 octets using AES-CTR with 128-bit key Encrypting 16 octets using AES-CTR with 192-bit key Encrypting 32 octets using AES-CTR with 192-bit key Encrypting 36 octets using AES-CTR with 192-bit key Encrypting 16 octets using AES-CTR with 256-bit key Encrypting 32 octets using AES-CTR with 256-bit key Encrypting 36 octets using AES-CTR with 256-bit key testing AES_CBC: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key testing AES_XCBC: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) testing HMAC_MD5: RFC 2104: MD5_HMAC test 1 RFC 2104: MD5_HMAC test 2 RFC 2104: MD5_HMAC test 3 8 CPU cores online starting up 7 crypto helpers started thread for crypto helper 0 started thread for crypto helper 1 started thread for crypto helper 2 | starting up helper thread 0 | starting up helper thread 1 | status value returned by setting the priority of this thread (crypto helper 0) 22 | crypto helper 0 waiting (nothing to do) started thread for crypto helper 3 | status value returned by setting the priority of this thread (crypto helper 1) 22 | crypto helper 1 waiting (nothing to do) | starting up helper thread 3 | starting up helper thread 2 | starting up helper thread 4 | status value returned by setting the priority of this thread (crypto helper 2) 22 | status value returned by setting the priority of this thread (crypto helper 4) 22 | crypto helper 2 waiting (nothing to do) | status value returned by setting the priority of this thread (crypto helper 3) 22 started thread for crypto helper 4 | crypto helper 4 waiting (nothing to do) | crypto helper 3 waiting (nothing to do) started thread for crypto helper 5 started thread for crypto helper 6 | checking IKEv1 state table | MAIN_R0: category: half-open IKE SA flags: 0: | -> MAIN_R1 EVENT_SO_DISCARD | MAIN_I1: category: half-open IKE SA flags: 0: | -> MAIN_I2 EVENT_RETRANSMIT | MAIN_R1: category: open IKE SA flags: 200: | -> MAIN_R2 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_I2: category: open IKE SA flags: 0: | -> MAIN_I3 EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | -> UNDEFINED EVENT_RETRANSMIT | MAIN_R2: category: open IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | -> MAIN_R3 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_I3: category: open IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | -> MAIN_I4 EVENT_SA_REPLACE | -> UNDEFINED EVENT_SA_REPLACE | MAIN_R3: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | MAIN_I4: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | starting up helper thread 6 | AGGR_R0: category: half-open IKE SA flags: 0: | -> AGGR_R1 EVENT_SO_DISCARD | AGGR_I1: category: half-open IKE SA flags: 0: | -> AGGR_I2 EVENT_SA_REPLACE | -> AGGR_I2 EVENT_SA_REPLACE | AGGR_R1: category: open IKE SA flags: 200: | -> AGGR_R2 EVENT_SA_REPLACE | -> AGGR_R2 EVENT_SA_REPLACE | AGGR_I2: category: established IKE SA flags: 200: | -> UNDEFINED EVENT_NULL | AGGR_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | QUICK_R0: category: established CHILD SA flags: 0: | -> QUICK_R1 EVENT_RETRANSMIT | QUICK_I1: category: established CHILD SA flags: 0: | -> QUICK_I2 EVENT_SA_REPLACE | QUICK_R1: category: established CHILD SA flags: 0: | -> QUICK_R2 EVENT_SA_REPLACE | QUICK_I2: category: established CHILD SA flags: 200: | -> UNDEFINED EVENT_NULL | QUICK_R2: category: established CHILD SA flags: 0: | -> UNDEFINED EVENT_NULL | INFO: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | INFO_PROTECTED: category: informational flags: 0: | -> UNDEFINED EVENT_NULL | XAUTH_R0: category: established IKE SA flags: 0: | -> XAUTH_R1 EVENT_NULL | XAUTH_R1: category: established IKE SA flags: 0: | -> MAIN_R3 EVENT_SA_REPLACE | MODE_CFG_R0: category: informational flags: 0: | -> MODE_CFG_R1 EVENT_SA_REPLACE | MODE_CFG_R1: category: established IKE SA flags: 0: | -> MODE_CFG_R2 EVENT_SA_REPLACE | MODE_CFG_R2: category: established IKE SA flags: 0: | -> UNDEFINED EVENT_NULL | MODE_CFG_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_SA_REPLACE | XAUTH_I0: category: established IKE SA flags: 0: | -> XAUTH_I1 EVENT_RETRANSMIT | XAUTH_I1: category: established IKE SA flags: 0: | -> MAIN_I4 EVENT_RETRANSMIT | checking IKEv2 state table | PARENT_I0: category: ignore flags: 0: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) | PARENT_I1: category: half-open IKE SA flags: 0: | status value returned by setting the priority of this thread (crypto helper 6) 22 | crypto helper 6 waiting (nothing to do) | starting up helper thread 5 | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) | status value returned by setting the priority of this thread (crypto helper 5) 22 | crypto helper 5 waiting (nothing to do) | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) | PARENT_I2: category: open IKE SA flags: 0: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) | PARENT_I3: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) | PARENT_R0: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) | PARENT_R1: category: half-open IKE SA flags: 0: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) | PARENT_R2: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) | V2_CREATE_I0: category: established IKE SA flags: 0: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) | V2_CREATE_I: category: established IKE SA flags: 0: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) | V2_REKEY_IKE_I: category: established IKE SA flags: 0: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: | V2_CREATE_R: category: established IKE SA flags: 0: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) | V2_REKEY_IKE_R: category: established IKE SA flags: 0: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: | V2_IPSEC_I: category: established CHILD SA flags: 0: | V2_IPSEC_R: category: established CHILD SA flags: 0: | IKESA_DEL: category: established IKE SA flags: 0: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) | CHILDSA_DEL: category: informational flags: 0: Using Linux XFRM/NETKEY IPsec interface code on 5.1.18-200.fc29.x86_64 | Hard-wiring algorithms | adding AES_CCM_16 to kernel algorithm db | adding AES_CCM_12 to kernel algorithm db | adding AES_CCM_8 to kernel algorithm db | adding 3DES_CBC to kernel algorithm db | adding CAMELLIA_CBC to kernel algorithm db | adding AES_GCM_16 to kernel algorithm db | adding AES_GCM_12 to kernel algorithm db | adding AES_GCM_8 to kernel algorithm db | adding AES_CTR to kernel algorithm db | adding AES_CBC to kernel algorithm db | adding SERPENT_CBC to kernel algorithm db | adding TWOFISH_CBC to kernel algorithm db | adding NULL_AUTH_AES_GMAC to kernel algorithm db | adding NULL to kernel algorithm db | adding CHACHA20_POLY1305 to kernel algorithm db | adding HMAC_MD5_96 to kernel algorithm db | adding HMAC_SHA1_96 to kernel algorithm db | adding HMAC_SHA2_512_256 to kernel algorithm db | adding HMAC_SHA2_384_192 to kernel algorithm db | adding HMAC_SHA2_256_128 to kernel algorithm db | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db | adding AES_XCBC_96 to kernel algorithm db | adding AES_CMAC_96 to kernel algorithm db | adding NONE to kernel algorithm db | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds | setup kernel fd callback | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x55961766c378 | libevent_malloc: new ptr-libevent@0x5596176ab3e8 size 128 | libevent_malloc: new ptr-libevent@0x5596176b2478 size 16 | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x5596176b2408 | libevent_malloc: new ptr-libevent@0x559617664e38 size 128 | libevent_malloc: new ptr-libevent@0x5596176b20d8 size 16 | global one-shot timer EVENT_CHECK_CRLS initialized selinux support is enabled. | unbound context created - setting debug level to 5 | /etc/hosts lookups activated | /etc/resolv.conf usage activated | outgoing-port-avoid set 0-65535 | outgoing-port-permit set 32768-60999 | Loading dnssec root key from:/var/lib/unbound/root.key | No additional dnssec trust anchors defined via dnssec-trusted= option | Setting up events, loop start | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x5596176b28a8 | libevent_malloc: new ptr-libevent@0x5596176be788 size 128 | libevent_malloc: new ptr-libevent@0x5596176c9a78 size 16 | libevent_realloc: new ptr-libevent@0x5596176c9ab8 size 256 | libevent_malloc: new ptr-libevent@0x5596176c9be8 size 8 | libevent_realloc: new ptr-libevent@0x5596176c9c28 size 144 | libevent_malloc: new ptr-libevent@0x559617670948 size 152 | libevent_malloc: new ptr-libevent@0x5596176c9ce8 size 16 | signal event handler PLUTO_SIGCHLD installed | libevent_malloc: new ptr-libevent@0x5596176c9d28 size 8 | libevent_malloc: new ptr-libevent@0x5596175ee7b8 size 152 | signal event handler PLUTO_SIGTERM installed | libevent_malloc: new ptr-libevent@0x5596176c9d68 size 8 | libevent_malloc: new ptr-libevent@0x5596176c9da8 size 152 | signal event handler PLUTO_SIGHUP installed | libevent_malloc: new ptr-libevent@0x5596176c9e78 size 8 | libevent_realloc: release ptr-libevent@0x5596176c9c28 | libevent_realloc: new ptr-libevent@0x5596176c9eb8 size 256 | libevent_malloc: new ptr-libevent@0x5596176c9fe8 size 152 | signal event handler PLUTO_SIGSYS installed | created addconn helper (pid:18951) using fork+execve | forked child 18951 | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.1.254 | Inspecting interface eth1 | found eth1 with address 192.1.2.45 Kernel supports NIC esp-hw-offload adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.2.45:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth1/eth1 192.1.2.45:4500 adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.1.254:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface eth0/eth0 192.0.1.254:4500 adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 | NAT-Traversal: Trying sockopt style NAT-T | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 adding interface lo/lo 127.0.0.1:4500 | no interfaces to sort | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | add_fd_read_event_handler: new ethX-pe@0x5596176ca5c8 | libevent_malloc: new ptr-libevent@0x5596176be6d8 size 128 | libevent_malloc: new ptr-libevent@0x5596176ca638 size 16 | setup callback for interface lo 127.0.0.1:4500 fd 22 | add_fd_read_event_handler: new ethX-pe@0x5596176ca678 | libevent_malloc: new ptr-libevent@0x559617664ee8 size 128 | libevent_malloc: new ptr-libevent@0x5596176ca6e8 size 16 | setup callback for interface lo 127.0.0.1:500 fd 21 | add_fd_read_event_handler: new ethX-pe@0x5596176ca728 | libevent_malloc: new ptr-libevent@0x559617664808 size 128 | libevent_malloc: new ptr-libevent@0x5596176ca798 size 16 | setup callback for interface eth0 192.0.1.254:4500 fd 20 | add_fd_read_event_handler: new ethX-pe@0x5596176ca7d8 | libevent_malloc: new ptr-libevent@0x55961766c0c8 size 128 | libevent_malloc: new ptr-libevent@0x5596176ca848 size 16 | setup callback for interface eth0 192.0.1.254:500 fd 19 | add_fd_read_event_handler: new ethX-pe@0x5596176ca888 | libevent_malloc: new ptr-libevent@0x55961766c1c8 size 128 | libevent_malloc: new ptr-libevent@0x5596176ca8f8 size 16 | setup callback for interface eth1 192.1.2.45:4500 fd 18 | add_fd_read_event_handler: new ethX-pe@0x5596176ca938 | libevent_malloc: new ptr-libevent@0x55961766c2c8 size 128 | libevent_malloc: new ptr-libevent@0x5596176ca9a8 size 16 | setup callback for interface eth1 192.1.2.45:500 fd 17 | certs and keys locked by 'free_preshared_secrets' | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | saving Modulus | saving PublicExponent | ignoring PrivateExponent | ignoring Prime1 | ignoring Prime2 | ignoring Exponent1 | ignoring Exponent2 | ignoring Coefficient | ignoring CKAIDNSS | computed rsa CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 | computed rsa CKAID 7f 0f 03 50 loaded private key for keyid: PKK_RSA:AQOm9dY/4 | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.768 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) listening for IKE messages | Inspecting interface lo | found lo with address 127.0.0.1 | Inspecting interface eth0 | found eth0 with address 192.0.1.254 | Inspecting interface eth1 | found eth1 with address 192.1.2.45 | no interfaces to sort | libevent_free: release ptr-libevent@0x5596176be6d8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca5c8 | add_fd_read_event_handler: new ethX-pe@0x5596176ca5c8 | libevent_malloc: new ptr-libevent@0x5596176be6d8 size 128 | setup callback for interface lo 127.0.0.1:4500 fd 22 | libevent_free: release ptr-libevent@0x559617664ee8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca678 | add_fd_read_event_handler: new ethX-pe@0x5596176ca678 | libevent_malloc: new ptr-libevent@0x559617664ee8 size 128 | setup callback for interface lo 127.0.0.1:500 fd 21 | libevent_free: release ptr-libevent@0x559617664808 | free_event_entry: release EVENT_NULL-pe@0x5596176ca728 | add_fd_read_event_handler: new ethX-pe@0x5596176ca728 | libevent_malloc: new ptr-libevent@0x559617664808 size 128 | setup callback for interface eth0 192.0.1.254:4500 fd 20 | libevent_free: release ptr-libevent@0x55961766c0c8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca7d8 | add_fd_read_event_handler: new ethX-pe@0x5596176ca7d8 | libevent_malloc: new ptr-libevent@0x55961766c0c8 size 128 | setup callback for interface eth0 192.0.1.254:500 fd 19 | libevent_free: release ptr-libevent@0x55961766c1c8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca888 | add_fd_read_event_handler: new ethX-pe@0x5596176ca888 | libevent_malloc: new ptr-libevent@0x55961766c1c8 size 128 | setup callback for interface eth1 192.1.2.45:4500 fd 18 | libevent_free: release ptr-libevent@0x55961766c2c8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca938 | add_fd_read_event_handler: new ethX-pe@0x5596176ca938 | libevent_malloc: new ptr-libevent@0x55961766c2c8 size 128 | setup callback for interface eth1 192.1.2.45:500 fd 17 | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' loading secrets from "/etc/ipsec.secrets" | saving Modulus | saving PublicExponent | ignoring PrivateExponent | ignoring Prime1 | ignoring Prime2 | ignoring Exponent1 | ignoring Exponent2 | ignoring Coefficient | ignoring CKAIDNSS | computed rsa CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 | computed rsa CKAID 7f 0f 03 50 loaded private key for keyid: PKK_RSA:AQOm9dY/4 | certs and keys locked by 'process_secret' | certs and keys unlocked by 'process_secret' | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.2 milliseconds in whack | processing signal PLUTO_SIGCHLD | waitpid returned pid 18951 (exited with status 0) | reaped addconn helper child (status 0) | waitpid returned ECHILD (no child processes left) | spent 0.0116 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection TUNNEL-C with policy ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | No AUTH policy was set - defaulting to RSASIG | setting ID to ID_DER_ASN1_DN: 'E=user-west@testing.libreswan.org,CN=west.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading left certificate 'west' pubkey | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176ccb38 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176ccac8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176cc988 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176cc6d8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176cc688 | unreference key: 0x5596176ccb88 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | certs and keys locked by 'lsw_add_rsa_secret' | certs and keys unlocked by 'lsw_add_rsa_secret' | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org is 0 | ASCII to DN <= "C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org" | ASCII to DN => 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | ASCII to DN => 31 10 30 0e 06 03 55 04 08 13 07 4f 6e 74 61 72 | ASCII to DN => 69 6f 31 10 30 0e 06 03 55 04 07 13 07 54 6f 72 | ASCII to DN => 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 13 09 4c | ASCII to DN => 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | ASCII to DN => 0b 13 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | ASCII to DN => 6e 74 31 23 30 21 06 03 55 04 03 13 1a 65 61 73 | ASCII to DN => 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | ASCII to DN => 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | ASCII to DN => 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | connect_to_host_pair: 192.1.2.45:500 192.1.2.23:500 -> hp@(nil): none | new hp@0x5596176d2438 added connection description "TUNNEL-C" | ike_life: 60s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.0.1.254/32===192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]...192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]===192.0.2.234/32 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 1.14 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection TUNNEL-A with policy ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | No AUTH policy was set - defaulting to RSASIG | setting ID to ID_DER_ASN1_DN: 'E=user-west@testing.libreswan.org,CN=west.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading left certificate 'west' pubkey | unreference key: 0x5596176d2268 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d1fb8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d1ab8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d1548 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d0158 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176cfcd8 | unreference key: 0x5596176cff88 192.1.2.45 cnt 1-- | unreference key: 0x5596176d1378 west@testing.libreswan.org cnt 1-- | unreference key: 0x5596176d18a8 @west.testing.libreswan.org cnt 1-- | unreference key: 0x5596176d1de8 user-west@testing.libreswan.org cnt 1-- | unreference key: 0x5596176d2af8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | secrets entry for west already exists | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org is 0 | ASCII to DN <= "C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org" | ASCII to DN => 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | ASCII to DN => 31 10 30 0e 06 03 55 04 08 13 07 4f 6e 74 61 72 | ASCII to DN => 69 6f 31 10 30 0e 06 03 55 04 07 13 07 54 6f 72 | ASCII to DN => 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 13 09 4c | ASCII to DN => 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | ASCII to DN => 0b 13 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | ASCII to DN => 6e 74 31 23 30 21 06 03 55 04 03 13 1a 65 61 73 | ASCII to DN => 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | ASCII to DN => 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | ASCII to DN => 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | find_host_pair: comparing 192.1.2.45:500 to 192.1.2.23:500 but ignoring ports | connect_to_host_pair: 192.1.2.45:500 192.1.2.23:500 -> hp@0x5596176d2438: TUNNEL-C added connection description "TUNNEL-A" | ike_life: 60s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.0.1.254/32===192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]...192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]===192.0.2.254/32 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.687 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | FOR_EACH_CONNECTION_... in foreach_connection_by_alias | FOR_EACH_CONNECTION_... in conn_by_name | Added new connection TUNNEL-B with policy ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | No AUTH policy was set - defaulting to RSASIG | setting ID to ID_DER_ASN1_DN: 'E=user-west@testing.libreswan.org,CN=west.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' | loading left certificate 'west' pubkey | unreference key: 0x5596176d1de8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d15b8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d2be8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d11a8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d1158 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d2568 | unreference key: 0x5596176ccb88 192.1.2.45 cnt 1-- | unreference key: 0x5596176cff88 west@testing.libreswan.org cnt 1-- | unreference key: 0x5596176d1378 @west.testing.libreswan.org cnt 1-- | unreference key: 0x5596176d18a8 user-west@testing.libreswan.org cnt 1-- | unreference key: 0x5596176d1028 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | secrets entry for west already exists | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org is 0 | ASCII to DN <= "C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org" | ASCII to DN => 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | ASCII to DN => 31 10 30 0e 06 03 55 04 08 13 07 4f 6e 74 61 72 | ASCII to DN => 69 6f 31 10 30 0e 06 03 55 04 07 13 07 54 6f 72 | ASCII to DN => 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 13 09 4c | ASCII to DN => 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | ASCII to DN => 0b 13 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | ASCII to DN => 6e 74 31 23 30 21 06 03 55 04 03 13 1a 65 61 73 | ASCII to DN => 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | ASCII to DN => 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | ASCII to DN => 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | ASCII to DN => 77 61 6e 2e 6f 72 67 | counting wild cards for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org is 0 | find_host_pair: comparing 192.1.2.45:500 to 192.1.2.23:500 but ignoring ports | connect_to_host_pair: 192.1.2.45:500 192.1.2.23:500 -> hp@0x5596176d2438: TUNNEL-A added connection description "TUNNEL-B" | ike_life: 60s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO | 192.0.1.254/32===192.1.2.45<192.1.2.45>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org]...192.1.2.23<192.1.2.23>[C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org]===192.0.2.244/32 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.68 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | old debugging base+cpu-usage + none | base debugging = base+cpu-usage | old impairing none + suppress-retransmits | base impairing = suppress-retransmits | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.0528 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | old debugging base+cpu-usage + none | base debugging = base+cpu-usage | old impairing suppress-retransmits + none | base impairing = suppress-retransmits | revival | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.235 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | dup_any(fd@16) -> fd@23 (in whack_process() at rcv_whack.c:590) | FOR_EACH_CONNECTION_... in conn_by_name | start processing: connection "TUNNEL-A" (in initiate_a_connection() at initiate.c:186) | empty esp_info, returning defaults for ENCRYPT | connection 'TUNNEL-A' +POLICY_UP | dup_any(fd@23) -> fd@24 (in initiate_a_connection() at initiate.c:342) | FOR_EACH_STATE_... in find_phase1_state | creating state object #1 at 0x5596176d3018 | State DB: adding IKEv1 state #1 in UNDEFINED | pstats #1 ikev1.isakmp started | suspend processing: connection "TUNNEL-A" (in main_outI1() at ikev1_main.c:118) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in main_outI1() at ikev1_main.c:118) | parent state #1: UNDEFINED(ignore) => MAIN_I1(half-open IKE SA) | dup_any(fd@24) -> fd@25 (in main_outI1() at ikev1_main.c:123) | Queuing pending IPsec SA negotiating with 192.1.2.23 "TUNNEL-A" IKE SA #1 "TUNNEL-A" "TUNNEL-A" #1: initiating Main Mode | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | no specific IKE algorithms specified - using defaults | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_256=4 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_512=6 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha=2 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_256=4 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha2_512=6 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=aes=7 halg=sha=2 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_256=4 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_512=6 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha=2 modp=MODP2048=14 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_256=4 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha2_512=6 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() processing ealg=3des_cbc=5 halg=sha=2 modp=MODP1536=5 eklen=0 | oakley_alg_makedb() returning 0x5596176d5ac8 | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ikev1_out_sa pcn: 0 has 1 valid proposals | ikev1_out_sa pcn: 0 pn: 0<1 valid_count: 1 trans_cnt: 18 | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 18 (0x12) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 1 (0x1) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 2 (0x2) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 3 (0x3) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 4 (0x4) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 5 (0x5) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 6 (0x6) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 7 (0x7) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 8 (0x8) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 9 (0x9) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 10 (0xa) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 11 (0xb) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 12 (0xc) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 13 (0xd) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 14 (0xe) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 15 (0xf) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | ISAKMP transform number: 16 (0x10) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 6 (0x6) | [6 is OAKLEY_SHA2_512] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 17 (0x11) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 5 (0x5) | [5 is OAKLEY_3DES_CBC] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 2 (0x2) | [2 is OAKLEY_SHA1] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******emit ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 5 (0x5) | [5 is OAKLEY_GROUP_MODP1536] | emitting length of ISAKMP Transform Payload (ISAKMP): 32 | emitting length of ISAKMP Proposal Payload: 632 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 644 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | nat add vid | sending draft and RFC NATT VIDs | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | skipping VID_NATT_RFC | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-03] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-02_n] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 90 cb 80 91 3e bb 69 6e 08 63 81 b5 ec 42 7b 1f | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [draft-ietf-ipsec-nat-t-ike-02] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID cd 60 46 43 35 df 21 f8 7c fd b2 fc 68 b6 a4 48 | emitting length of ISAKMP Vendor ID Payload: 20 | no IKEv1 message padding required | emitting length of ISAKMP Message: 792 | sending 792 bytes for reply packet for main_outI1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #1) | 13 ce 9d 4e da e6 3a 63 00 00 00 00 00 00 00 00 | 01 10 02 00 00 00 00 00 00 00 03 18 0d 00 02 84 | 00 00 00 01 00 00 00 01 00 00 02 78 00 01 00 12 | 03 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 01 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 04 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 02 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 06 | 80 03 00 03 80 04 00 0e 80 0e 01 00 03 00 00 24 | 03 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 06 80 03 00 03 80 04 00 0e 80 0e 00 80 | 03 00 00 24 04 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 05 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 02 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 06 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 04 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 07 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 04 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 24 08 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 06 80 03 00 03 80 04 00 05 | 80 0e 01 00 03 00 00 24 09 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 06 80 03 00 03 | 80 04 00 05 80 0e 00 80 03 00 00 24 0a 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 02 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 0b 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 02 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 20 0c 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 0e | 03 00 00 20 0d 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 0e | 03 00 00 20 0e 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 0e | 03 00 00 20 0f 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 05 | 03 00 00 20 10 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 05 | 00 00 00 20 11 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 05 | 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de 7f | 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 c9 | 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c 81 | 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 14 | 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 | ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 f8 | 7c fd b2 fc 68 b6 a4 48 "TUNNEL-A" #1: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x5596176d6618 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5596176cc5d8 size 128 | #1 STATE_MAIN_I1: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.119868 | #1 spent 4.99 milliseconds in main_outI1() | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in main_outI1() at ikev1_main.c:228) | resume processing: connection "TUNNEL-A" (in main_outI1() at ikev1_main.c:228) | stop processing: connection "TUNNEL-A" (in initiate_a_connection() at initiate.c:349) | close_any(fd@23) (in initiate_connection() at initiate.c:372) | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 5.19 milliseconds in whack | spent 0.00992 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 144 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 01 10 02 00 00 00 00 00 00 00 00 90 0d 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 0d 00 00 14 40 48 b7 d5 6e bc e8 85 | 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 | 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 00 00 00 14 | 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 144 (0x90) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: IKEv1 state not found (find_state_ikev1) | State DB: found IKEv1 state #1 in MAIN_I1 (find_state_ikev1_init) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x2 opt: 0x2080 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 20 (0x14) | message 'main_inR1_outI2' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | OAKLEY proposal verified unconditionally; no alg_info to check against | Oakley Transform 0 accepted | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) | adding outI2 KE work-order 1 for state #1 | state #1 requesting EVENT_RETRANSMIT to be deleted | #1 STATE_MAIN_I1: retransmits: cleared | libevent_free: release ptr-libevent@0x5596176cc5d8 | free_event_entry: release EVENT_RETRANSMIT-pe@0x5596176d6618 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5596176d6618 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5596176cc5d8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #1 and saving MD | #1 is busy; has a suspended MD | #1 spent 0.439 milliseconds in process_packet_tail() | crypto helper 0 resuming | crypto helper 0 starting work-order 1 for state #1 | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | crypto helper 0 doing build KE and nonce (outI2 KE); request ID 1 | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.943 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 0 finished build KE and nonce (outI2 KE); request ID 1 time elapsed 0.002705 seconds | (#1) spent 2.71 milliseconds in crypto helper computing work-order 1: outI2 KE (pcr) | crypto helper 0 sending results from work-order 1 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f3e90002888 size 128 | crypto helper 0 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 0 replies to request ID 1 | calling continuation function 0x559617387b50 | main_inR1_outI2_continue for #1: calculated ke+nonce, sending I2 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 60 61 8b b1 3e 52 e1 90 e2 69 3a b3 c6 c1 a3 74 | keyex value d1 61 99 82 54 25 22 82 16 8e 4b e5 1a 6b 2e 37 | keyex value c3 32 77 84 ab 69 51 b1 90 58 3e ea e5 35 e9 f8 | keyex value d6 db 8b 93 cc 35 c9 2f 1d 25 c2 58 6e 4d 50 05 | keyex value 4b 24 e6 0d 57 32 f9 d5 35 77 08 7b 56 70 0a 57 | keyex value 06 fa fa d2 62 a1 e4 c1 96 1c 67 44 31 f8 97 58 | keyex value 9d 8a 97 b4 b5 db d2 57 fd a8 6a d2 81 3c d0 26 | keyex value fe eb e2 4a ac 40 5d b3 65 f6 13 13 a0 a5 47 d1 | keyex value 2d eb 74 9d fc d3 08 56 51 bf 7f 7e 37 0f 27 f2 | keyex value e3 0e 38 43 b9 be 8a e1 14 07 81 43 f7 b8 b3 98 | keyex value ce 38 78 11 c1 de 56 cf bc 1b b5 a8 2f 7b c9 c5 | keyex value af aa e8 b6 d9 02 d8 1c 29 ed 22 25 35 c6 a5 06 | keyex value 3a cf bf 39 ca 3c fe c7 6b 16 d0 2b 88 d7 83 1c | keyex value 9e df 98 f7 40 a0 2a fa 04 67 90 2b ae e4 23 e3 | keyex value aa c2 36 66 d1 f2 dd 5f dd 81 38 c7 fa 34 43 ed | keyex value 81 c9 ff cd f2 da 72 ea 2f 30 09 f7 34 b0 7e 05 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Ni into ISAKMP Nonce Payload | Ni 41 48 ce 59 ae 8c 0a f5 92 ba 67 8f 9c ca dc 37 | Ni 3e 56 5f d2 44 90 1f 90 7a b3 d0 99 50 6a d0 99 | emitting length of ISAKMP Nonce Payload: 36 | NAT-T checking st_nat_traversal | NAT-T found (implies NAT_T_WITH_NATD) | sending NAT-D payloads | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | natd_hash: hash= e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | NAT-D e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | emitting length of ISAKMP NAT-D Payload: 36 | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | natd_hash: hash= 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | NAT-D 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | emitting length of ISAKMP NAT-D Payload: 36 | no IKEv1 message padding required | emitting length of ISAKMP Message: 396 | State DB: re-hashing IKEv1 state #1 IKE SPIi and SPI[ir] | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_MAIN_I1 to state STATE_MAIN_I2 | parent state #1: MAIN_I1(half-open IKE SA) => MAIN_I2(open IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5596176cc5d8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5596176d6618 | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | sending 396 bytes for STATE_MAIN_I1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #1) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | 60 61 8b b1 3e 52 e1 90 e2 69 3a b3 c6 c1 a3 74 | d1 61 99 82 54 25 22 82 16 8e 4b e5 1a 6b 2e 37 | c3 32 77 84 ab 69 51 b1 90 58 3e ea e5 35 e9 f8 | d6 db 8b 93 cc 35 c9 2f 1d 25 c2 58 6e 4d 50 05 | 4b 24 e6 0d 57 32 f9 d5 35 77 08 7b 56 70 0a 57 | 06 fa fa d2 62 a1 e4 c1 96 1c 67 44 31 f8 97 58 | 9d 8a 97 b4 b5 db d2 57 fd a8 6a d2 81 3c d0 26 | fe eb e2 4a ac 40 5d b3 65 f6 13 13 a0 a5 47 d1 | 2d eb 74 9d fc d3 08 56 51 bf 7f 7e 37 0f 27 f2 | e3 0e 38 43 b9 be 8a e1 14 07 81 43 f7 b8 b3 98 | ce 38 78 11 c1 de 56 cf bc 1b b5 a8 2f 7b c9 c5 | af aa e8 b6 d9 02 d8 1c 29 ed 22 25 35 c6 a5 06 | 3a cf bf 39 ca 3c fe c7 6b 16 d0 2b 88 d7 83 1c | 9e df 98 f7 40 a0 2a fa 04 67 90 2b ae e4 23 e3 | aa c2 36 66 d1 f2 dd 5f dd 81 38 c7 fa 34 43 ed | 81 c9 ff cd f2 da 72 ea 2f 30 09 f7 34 b0 7e 05 | 14 00 00 24 41 48 ce 59 ae 8c 0a f5 92 ba 67 8f | 9c ca dc 37 3e 56 5f d2 44 90 1f 90 7a b3 d0 99 | 50 6a d0 99 14 00 00 24 e6 34 0a b5 b0 1c 19 f6 | 4e ef 3f 2b 2b 2d d3 5f e2 44 7e ff b6 f1 bd fa | 4d ea b5 71 9e 48 8e e9 00 00 00 24 5c 47 b2 7a | e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 2b c5 e2 c8 | 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | !event_already_set at reschedule "TUNNEL-A" #1: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x5596176d6618 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5596176d2ea8 size 128 | #1 STATE_MAIN_I2: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.126945 "TUNNEL-A" #1: STATE_MAIN_I2: sent MI2, expecting MR2 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 1.02 milliseconds in resume sending helper answer | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e90002888 | spent 0.0103 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 396 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | c1 44 86 cc 77 92 e1 e7 ee 57 8d 15 8d 24 9f 7d | f8 36 2b db 2d 7b 18 95 39 59 6c a9 fd 60 cd 0c | 8a ad a0 49 2a ba fe 6a f7 04 87 fd 5c 9a 04 be | 08 a6 2a 0b ef fc 35 d2 1d 79 9f 31 43 68 68 7b | 79 0f 78 bb 7d 47 67 8e e0 b1 a2 58 e9 91 3a ae | f4 8b 33 a3 b7 93 bf 61 42 ce 72 3b fb c0 68 2e | 0e 35 b1 8a 1f d8 c6 bb 7f bd 69 bf 06 7b f0 df | 77 60 5d 47 60 49 8b 86 2d 41 ae 73 83 df 89 8e | be fa 08 a3 a5 35 1d 83 d3 82 b7 9d 67 1b 47 b0 | ac ad ab 0e ab 14 01 bc 1a e3 a9 c8 2c 68 bf 44 | e5 1d a1 41 0f 33 5f d9 b3 15 95 1b 63 93 7a 53 | 02 da 2d de 93 97 eb 18 07 5f 69 50 17 43 4e b5 | a5 a4 51 e3 26 43 a6 51 1a e4 88 37 2c f5 d0 be | 82 81 59 2a 91 d3 73 95 36 b7 03 5e 29 3a 50 6b | 41 fb 1c 9e fd 3a be 64 21 31 be b5 09 68 f6 df | f8 e4 fb ab 08 41 de c1 00 50 c3 11 fe 6d 5a 87 | 14 00 00 24 37 f3 a1 2a a8 71 2f 0c c6 cf 70 8f | fa 15 b0 0a de 89 45 58 0f 34 96 81 f9 b6 e6 7c | 49 cd 05 63 14 00 00 24 5c 47 b2 7a e3 b1 25 85 | ab 2b 38 d0 b4 af 57 70 2b c5 e2 c8 8d 23 2a 34 | ce d6 24 c2 f3 5b 6d 87 00 00 00 24 e6 34 0a b5 | b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f e2 44 7e ff | b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_KE (0x4) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 396 (0x18c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #1 in MAIN_I2 (find_state_ikev1) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x410 opt: 0x102080 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x102080 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | message 'main_inR2_outI3' HASH payload not checked early | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding aggr outR1 DH work-order 2 for state #1 | state #1 requesting EVENT_RETRANSMIT to be deleted | #1 STATE_MAIN_I2: retransmits: cleared | libevent_free: release ptr-libevent@0x5596176d2ea8 | free_event_entry: release EVENT_RETRANSMIT-pe@0x5596176d6618 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5596176d6618 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x7f3e90002888 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #1 and saving MD | #1 is busy; has a suspended MD | #1 spent 0.335 milliseconds in process_packet_tail() | crypto helper 1 resuming | crypto helper 1 starting work-order 2 for state #1 | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | crypto helper 1 doing compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 2 | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 1.04 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 1 finished compute dh+iv (V1 Phase 1) (aggr outR1 DH); request ID 2 time elapsed 0.004011 seconds | (#1) spent 3.97 milliseconds in crypto helper computing work-order 2: aggr outR1 DH (pcr) | crypto helper 1 sending results from work-order 2 for state #1 to event queue | scheduling resume sending helper answer for #1 | libevent_malloc: new ptr-libevent@0x7f3e88000f48 size 128 | crypto helper 1 waiting (nothing to do) | processing resume sending helper answer for #1 | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 1 replies to request ID 2 | calling continuation function 0x559617387b50 | main_inR2_outI3_cryptotail for #1: calculated DH, sending R1 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 5:ISAKMP_NEXT_ID | thinking about whether to send my certificate: | I have RSA key: OAKLEY_RSA_SIG cert.type: CERT_X509_SIGNATURE | sendcert: CERT_ALWAYSSEND and I did not get a certificate request | so send cert. | I am sending a certificate request | I will NOT send an initial contact payload | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | natd_hash: hash= 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 13 ce 9d 4e da e6 3a 63 | natd_hash: rcookie= 77 51 4f 24 9b f8 4c 14 | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | natd_hash: hash= e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | expected NAT-D(me): 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | expected NAT-D(me): 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | expected NAT-D(him): | e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | received NAT-D: 5c 47 b2 7a e3 b1 25 85 ab 2b 38 d0 b4 af 57 70 | received NAT-D: 2b c5 e2 c8 8d 23 2a 34 ce d6 24 c2 f3 5b 6d 87 | received NAT-D: e6 34 0a b5 b0 1c 19 f6 4e ef 3f 2b 2b 2d d3 5f | received NAT-D: e2 44 7e ff b6 f1 bd fa 4d ea b5 71 9e 48 8e e9 | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.23 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_CERT (0x6) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 6:ISAKMP_NEXT_CERT | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 183 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 65 73 | my identity 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | my identity 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | my identity 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 191 "TUNNEL-A" #1: I am sending my cert | ***emit ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | cert encoding: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate Payload'.'next payload type' value 7:ISAKMP_NEXT_CR | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Certificate Payload (6:ISAKMP_NEXT_CERT) | next payload chain: saving location 'ISAKMP Certificate Payload'.'next payload type' in 'reply packet' | emitting 1260 raw bytes of CERT into ISAKMP Certificate Payload | CERT 30 82 04 e8 30 82 04 51 a0 03 02 01 02 02 01 04 | CERT 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | CERT 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | CERT 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | CERT 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | CERT 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | CERT 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | CERT 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | CERT 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | CERT 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | CERT 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | CERT 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | CERT 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | CERT 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | CERT 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | CERT 33 5a 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 | CERT 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | CERT 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | CERT 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | CERT 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | CERT 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | CERT 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 | CERT 65 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a | CERT 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 | CERT 65 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 0d 06 | CERT 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 8f | CERT 00 30 82 01 8a 02 82 01 81 00 97 74 bf cb bf e4 | CERT ee 91 0b d4 69 75 82 f9 89 a4 7c 61 ad 72 9f 63 | CERT d0 cb a1 44 70 27 f4 d2 b4 6f 56 97 f1 84 ea 4c | CERT 56 ce 73 39 bf bb e3 7d 19 bb ee d9 e7 3f e9 a3 | CERT ec 1e 7f fa 04 93 a9 f7 14 2b fb 47 74 66 5b 2f | CERT ba 23 9f b2 22 b3 ce 07 5f b7 14 41 a8 53 69 ef | CERT 37 e1 2d 74 09 ef 9b f4 67 d4 33 3b 42 39 c7 68 | CERT 67 08 db 58 d8 23 26 3e 92 ee ff 68 d8 2a 34 08 | CERT 21 ea df 77 b6 5c 62 26 96 f1 23 7f c8 86 ee eb | CERT 94 9e 86 61 b9 da 39 ca 7f f7 10 7c b3 03 d9 6f | CERT 91 e6 ef 40 ed e9 26 c1 c7 ba c4 d6 9b d1 e4 06 | CERT 54 d5 de b4 27 d7 70 a5 60 57 5f ad 31 66 fd 5e | CERT e6 b5 f8 0b 4c ad 97 4b 90 2a 92 25 9d ea 79 62 | CERT c8 36 40 41 ab 5d ae 18 c1 9c 2a 99 3e ad 19 82 | CERT 92 00 bf d9 f0 df 40 43 59 3a 87 2c 2d 96 1d e5 | CERT a8 66 34 2d df d4 0e de cd fa 4d 34 d0 1f 81 f2 | CERT 7a 2e 4c c2 e2 ae c9 df 0c b7 94 23 be b9 23 d9 | CERT ab 34 80 52 c3 61 81 01 b6 04 f3 9b 95 27 59 d1 | CERT f4 c2 a5 01 ab fa 14 fa 5b e2 93 00 fd 52 77 87 | CERT 44 20 37 b7 72 c3 92 ac e2 13 a5 01 a8 72 43 39 | CERT 43 82 fc 82 95 74 22 7a 16 f7 fa 61 86 d0 22 35 | CERT c5 d6 4d ad b8 ef de f7 aa ed e4 dc 17 42 fa 6d | CERT 10 ff c2 4f b1 8b 93 5a 98 68 57 c8 0b 31 f5 49 | CERT c6 00 d4 fc 2b a1 d4 7b 37 31 97 f9 12 31 89 1c | CERT 0a dc ad a3 4b 06 4c e6 90 03 02 03 01 00 01 a3 | CERT 82 01 06 30 82 01 02 30 09 06 03 55 1d 13 04 02 | CERT 30 00 30 47 06 03 55 1d 11 04 40 30 3e 82 1a 77 | CERT 65 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 81 1a 77 65 73 74 40 | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 87 04 c0 01 02 2d 30 0b 06 03 55 | CERT 1d 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 | CERT 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b | CERT 06 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 | CERT 07 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 | CERT 07 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d | CERT 1f 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 | CERT 70 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e | CERT 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 | CERT 76 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 | CERT 86 f7 0d 01 01 0b 05 00 03 81 81 00 5a 67 23 b0 | CERT 7e 6d 1b fc ee 9b 1f bf 83 f2 7f ee 5e 9c 9a d9 | CERT 50 b1 fa 36 e8 9b d1 a0 ed 86 39 a8 ab e3 df 81 | CERT b6 ce aa e6 ce 9f 15 04 03 59 de a4 f5 8b bd 05 | CERT 79 82 a5 ca 1b dd d5 d9 8f e4 62 19 1f 75 9e 8b | CERT 8b c6 ed b7 26 83 a8 15 16 64 a8 60 bf d4 c6 f6 | CERT 40 f9 e1 b2 d9 a2 fa 48 87 d5 07 80 36 d3 c8 53 | CERT 3f a8 cd 6a 53 7a d6 14 2c 4a cb 91 8e 53 79 3b | CERT c7 82 ad 80 1c 13 54 12 a2 86 ea 29 | emitting length of ISAKMP Certificate Payload: 1265 "TUNNEL-A" #1: I am sending a certificate request | ***emit ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | cert type: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate RequestPayload'.'next payload type' value 9:ISAKMP_NEXT_SIG | next payload chain: setting previous 'ISAKMP Certificate Payload'.'next payload type' to current ISAKMP Certificate RequestPayload (7:ISAKMP_NEXT_CR) | next payload chain: saving location 'ISAKMP Certificate RequestPayload'.'next payload type' in 'reply packet' | emitting length of ISAKMP Certificate RequestPayload: 5 | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | ***emit ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Certificate RequestPayload'.'next payload type' to current ISAKMP Signature Payload (9:ISAKMP_NEXT_SIG) | next payload chain: saving location 'ISAKMP Signature Payload'.'next payload type' in 'reply packet' | emitting 384 raw bytes of SIG_I into ISAKMP Signature Payload | SIG_I 66 43 c3 41 83 34 4b e7 dc 84 84 42 e2 4c 32 35 | SIG_I 6c ae 76 0a 29 fe 01 6b b2 7a c5 86 c9 9e a5 60 | SIG_I 4a 54 fb 96 fe 31 aa 1c f2 c3 88 6b 6f 49 8c 0a | SIG_I ea 2c 3a 46 ea cc 98 05 2a 4a 5c 6a f1 31 5d a6 | SIG_I 9f 75 6f 94 05 f1 79 ff 9b 05 6d 7b 97 f5 91 ad | SIG_I 69 e2 e0 e7 f7 c5 56 5a a5 2a 6e 75 04 5c 9d db | SIG_I 21 7a b1 f8 94 b7 44 34 60 05 9d 67 f2 40 16 d9 | SIG_I 44 b4 79 f2 da 9e 7f 49 d4 16 a1 f6 75 50 a0 2e | SIG_I 8c a6 82 ae a6 8e 40 a4 87 26 2b 0d e6 ec f0 85 | SIG_I 31 c9 fc a2 e3 aa ed f7 d0 48 4a 1d 6f c4 da 3a | SIG_I d6 16 25 a0 c4 d9 80 aa 2e 24 ee d1 ff 63 90 c6 | SIG_I 79 1e 8d 91 96 90 17 f4 41 06 0f db da c1 ef ef | SIG_I 48 74 e5 04 c0 95 5f 47 c7 e0 0e 17 fd 4b a6 69 | SIG_I 1f c8 ec 58 f7 11 ef b2 bd ae cb 38 fb ef c5 58 | SIG_I da 30 b7 41 01 be af 86 21 47 7d 96 e5 a9 77 51 | SIG_I c7 f8 0c e3 06 9e cf a3 d5 2b 99 eb 54 8b 3d 91 | SIG_I f1 a6 5a d9 1e 16 89 cd 3e c6 8a 46 66 ad 83 8d | SIG_I 66 56 dd 56 a2 7c 31 05 6b 37 7c f7 0a 27 d3 01 | SIG_I 79 d8 15 d0 80 28 51 6d f6 db 15 23 7b b6 86 cd | SIG_I f7 7d 7e a9 2f d9 65 e0 90 3e 0a a8 59 50 2b b5 | SIG_I 4b df a2 31 16 bb ac 5f d9 f9 39 f6 f3 9d e5 0f | SIG_I 12 8a f4 c4 44 82 dc 35 a6 9f c7 8e b6 58 dd aa | SIG_I 32 b4 fa a8 88 8d 0e 46 ff 26 58 a5 ee 2a f7 5c | SIG_I b3 7c 5d 6a 8f ef a4 43 38 9f 06 14 79 85 08 6b | emitting length of ISAKMP Signature Payload: 388 | Not sending INITIAL_CONTACT | emitting 7 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 1884 | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_I2 to state STATE_MAIN_I3 | parent state #1: MAIN_I2(open IKE SA) => MAIN_I3(open IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f3e90002888 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5596176d6618 | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | sending 1884 bytes for STATE_MAIN_I2 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #1) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 05 10 02 01 00 00 00 00 00 00 07 5c 60 63 1a a6 | 1a 83 e8 e2 a9 6a 05 3a 9e 20 5c 28 27 f6 10 b4 | 38 0e 50 43 01 fd 1b 89 8a b2 c7 71 4b 56 a8 9a | 0b 0c ed e8 5c 51 91 0c d9 ac 1e 83 19 e8 21 18 | ab 8d b7 c0 79 15 89 42 59 1a e3 90 f8 7b c7 28 | 0c c5 60 ff 96 5e f0 bd d6 92 86 72 cf 11 34 1d | d9 61 ba f0 ec 4c 0a 74 8f bc 0d 63 cf a3 4d da | b4 a5 25 aa ea 3f 18 80 8e 73 ad e9 0f 54 e3 62 | 9d fc 0d 6f 57 db 86 ba 68 f4 07 bd 2b 2e e6 fd | 27 e3 27 3d 99 93 2f 8e 44 2e 3b 24 a5 3a c9 ae | 95 dc 7a 31 d8 8b d5 6e 44 b2 d8 ac 6c f5 03 de | 16 70 ac ad 56 12 1d 51 c8 a1 34 0a 95 11 27 c3 | 25 75 5e 95 ff d0 c2 fc b3 96 dd dd 7f 39 20 64 | 54 14 c0 e9 a2 0d 9b 58 fb 42 e6 18 91 bd 15 36 | 49 2f 79 bb 95 08 c2 f3 66 55 a0 c4 d1 60 cd 5d | d7 9f 17 79 ef 34 31 52 b0 3f 3c d5 8b 6a 8a 87 | d6 73 a0 55 ce 77 a5 0e 8c 2d 36 e6 f7 35 95 a0 | d4 22 0c 5d d2 31 4e 33 af 07 3c ae 0f a2 82 87 | 74 67 e4 cc d0 7b ce b6 82 13 94 02 f6 40 60 21 | bd 77 b6 68 ca 51 df 28 9c 49 f9 cf ae 4f a0 e1 | 9a 26 5a f4 5c 4e f5 7a 6b b1 ad 68 10 6e 02 86 | 10 83 69 fa 6a 75 59 4f 5c b0 50 25 e4 11 ef 60 | 92 95 57 71 f6 7b 15 3e b9 92 e7 e0 c2 69 d0 35 | 5d 80 d3 b9 9e 69 95 bc c5 dd 77 f4 ab 27 3f d5 | b6 67 33 7d 0f ab 84 e6 4f 0f f6 ec ba 01 ad 66 | 90 a9 ff f7 b2 7b a3 7a 71 d6 8e 22 26 58 1d 01 | 00 cc c6 ad 6f 83 d7 cb 06 5b 49 50 6f 27 0a 3c | 79 ec 33 5a 29 47 18 b1 d8 3d 00 bf 3c 46 4e 21 | eb 30 57 82 78 68 44 bf b9 1d a6 1a 96 32 d0 bc | ea 19 32 f4 bf 33 49 88 3c db 19 f1 22 43 7d ea | 5f 1f 61 1c ea 10 38 dd 42 e4 64 75 2f 4d 92 25 | 08 a7 e0 c0 55 17 7c 81 3b 0e 11 be 6e 5a 40 ff | 54 7e f9 8b 0b 31 e6 52 44 4b d3 b2 d8 31 7a 20 | 5e 0d bf 4e 7c 0e cf a3 d7 b4 7a 9b 17 57 ee 66 | 23 12 a2 c5 f7 f4 a8 90 74 3b 0a ef 98 7a b5 1c | c0 df 1d 5c 3d 83 e0 27 0e 20 fa 85 b0 59 8e 34 | f6 e6 30 94 b8 5e 33 63 d4 ae a7 a4 db 44 bc 9b | 28 d8 be e4 bf 9b cd b2 2a 45 d0 68 74 20 c5 1f | 89 f1 f5 73 77 de ce bb 25 e1 e6 36 22 58 8b 0a | 29 1e 01 ed de 23 21 3a 32 32 ad f6 3b 5b 67 98 | 67 21 f5 4c 96 b1 1b 8c 51 75 8c 2d 86 09 e8 66 | d7 dc f4 a1 ed ce b8 6c 4a ed 52 af 6b 60 fc 93 | 0f e0 c7 b1 77 c3 4a 82 90 a0 80 2c fd e1 5d ad | 88 d8 48 2d f2 e6 ee d2 06 e6 d3 1f 79 7c 8f 49 | 69 cb c2 ed 76 62 5f 60 11 56 be ad f2 d4 4c c5 | 9a c7 e1 d3 ad 4c 1d 6d 8f 99 3b 1b 6b b3 5b bb | 6f 6a c6 4b 34 53 ee c5 52 f7 b5 af dc 88 50 f3 | 09 95 5e 45 b1 8a a0 26 ee fa e8 7a 35 d1 12 e8 | a8 fb 26 f8 cb 8f 06 67 e0 04 7f e3 49 64 0e 91 | 5c 06 c5 12 29 bd 5d 1a 56 95 8d 00 63 af 7f 70 | b8 77 ab 95 75 8c 28 e8 68 75 9e d2 91 35 70 00 | 6c f4 d5 90 00 56 c7 1d 79 0f c9 bf dd dd fd b9 | c3 13 65 71 d3 b3 49 ed 92 96 c6 58 fc da 21 ba | 32 65 fa f3 ad 81 c7 da b8 16 d2 63 42 40 87 6f | 50 40 cb 5b ee 4b 74 9c da 9b d0 86 a9 39 de ef | b2 4e b1 2f 25 6d 09 c6 4c 70 0b ae ae a0 4e fc | 74 a2 32 bd 33 ca 7c db 88 77 70 0b 4a 25 62 df | 9e ee 74 b8 1a a6 95 d8 3e 85 ea bf 7e e4 d7 73 | 04 d9 68 8f a2 00 12 e9 fe 70 3b c5 d5 74 a1 3e | 2c 37 d2 8b dc 52 f0 2d 55 65 de 9b 18 b4 91 de | 13 71 35 9e 08 60 30 e9 d7 40 ed cb ad 47 f8 2c | 9b ca 3e 69 ea 08 d4 74 66 8a db 89 4a 3b 14 8e | 65 89 56 33 91 88 07 60 45 6e 2c 3b 8c 1e c3 05 | fd 6d 6f 80 5c 52 11 3d b2 cc d4 6e 89 b9 6c 2d | 47 9b e1 56 13 26 4c 89 a5 cc fd fa b9 e4 fd 7d | 1d 62 44 be e2 c7 15 ee 0b f6 8f b2 64 15 1f 6b | 66 15 a7 0c 48 5c 28 d1 18 53 ff de 58 fa 6b 01 | dd eb 75 89 3e bd 59 18 6b 7c 96 bd fb d6 c3 a9 | 69 37 fe c3 49 86 ef 6b 52 2c 28 26 01 88 f0 53 | 7b ab 23 87 cc af ef 31 dd 1b b6 ae 42 46 60 69 | 2f 10 26 eb dc 6c be db e8 27 4c b7 62 63 94 70 | f3 ea 81 c5 de 2d 49 54 7e 60 13 15 58 b8 c4 94 | 50 ca 46 63 a1 33 3d 0d 08 9b 20 4e 0c bd d1 df | 9c 8a 1b 06 ab e7 d9 3e 44 35 7e a5 d9 4c ad eb | 52 85 cb 5a 37 d0 c0 b3 e0 76 0e a9 68 dc 4b 2d | 7f 98 58 88 51 a4 15 7e 07 c0 25 37 87 c2 04 e3 | 28 2d 91 69 26 c2 1d 0f 60 53 d5 e8 11 fd 57 d6 | cd 17 07 38 16 95 d7 71 5b a9 13 92 e5 3a 5f 8b | 59 3f 99 ea 93 c6 ac 68 8f 13 e0 c4 f3 ee 84 2a | 25 07 14 dd 50 66 a7 30 45 80 fc 57 dc ee 1a 72 | e4 26 50 a4 a2 05 49 4d 1f dc da 97 1d f7 32 7e | 30 99 dd b6 29 24 96 e1 91 9a 8d 6c 5f 04 a4 0f | 37 0e f3 75 4a 14 94 86 30 9d 17 1d 44 d8 3a 2f | 6b eb 6d 51 82 33 d4 7c 09 b4 82 e4 40 0b ce f9 | f4 fc 14 4c 92 87 da 71 ba 73 ee a8 78 e9 ec b8 | e5 64 4e ad 9d f7 f6 79 ef 9e a6 d4 79 e6 e6 95 | fd f0 8d 44 4c a0 c1 5e de 26 ad bb d9 60 5b 1a | 70 56 90 8a 70 cc 79 f4 42 87 78 26 70 97 d0 72 | 3c af f0 00 0d 38 45 67 29 b2 e3 07 62 5f 90 07 | b2 99 f6 7c 72 40 f0 31 1f f8 85 44 dc 89 a5 e5 | 20 a2 5b df 2c 4b e5 4b 77 41 3f e5 c0 fb 44 f8 | ff 57 19 95 e5 53 58 5b 87 9d da 0c e4 de 80 bf | d0 5a f0 38 f6 2f 23 05 80 be d3 80 25 54 0c 32 | c0 42 d7 ae 5c b1 ee bf c6 28 d1 1c bd 7d 05 23 | 31 a5 89 ac bc c1 95 eb 79 fd 99 11 d2 cc 91 90 | 8f fd c9 ff 93 c3 3a f3 e7 d4 99 c2 9b 26 af 8c | 28 cf 51 65 f6 c4 c9 e6 ac 3a e2 6d 32 7c 20 41 | 1a ce 6b bb 40 cb 52 2a ce 99 51 18 b4 f5 98 cf | b5 bf 0b 96 3b 53 ca 8f d4 af 9e ca a1 f8 c1 97 | 31 14 91 4d 7a 3a e7 e0 13 3a 5f 7b 59 b6 0a 58 | 19 f9 6d b7 c3 7d 1c 63 a7 8f ce c5 f0 c0 55 cc | 85 f7 9c 62 48 65 5a 6b b8 49 5b d6 b0 d2 b6 c8 | ff 4f 5f 98 e2 a7 22 4f a8 2d bc 45 00 5d 3c e7 | 74 0f aa 54 97 cc 58 b4 41 bd e3 5b 5e c4 d6 2a | f9 c6 32 7d 20 c7 0b 60 61 06 e2 84 2b 44 78 ca | ab be 74 7a 1b b4 8a 3c 0e 71 7f 22 18 b4 4e 92 | b3 12 be f5 fb 4b c9 31 f4 88 ae 33 cc 10 9f f0 | 62 75 62 fc ce ab 17 0e af e3 3c ab 3b b6 f8 23 | fe f3 5c 3b a2 ce c9 82 9f 35 d0 e5 fe 15 73 3b | d6 ea e8 46 cd 5c 09 a8 b1 e7 0b e5 77 97 3e 00 | 8a 11 7a 23 54 a6 84 8d 93 9a 77 7a 13 ac d5 6a | d5 ba 9d ca 03 4c cf 83 f8 98 30 73 7f c6 9e bb | c6 64 a6 a4 5d 6a a0 96 d5 71 b4 12 d4 68 25 bc | 01 b6 83 75 34 2f 09 03 57 69 f7 27 83 52 2a 9d | dd ab 9c b1 c4 0b 69 d0 00 d1 dd 81 c9 fb ee 31 | e2 05 5a 65 2a 37 d0 c6 97 a8 90 0e 01 1a 3d 5b | 9a 0d 23 cd 95 83 59 75 d8 7b d3 1a | !event_already_set at reschedule "TUNNEL-A" #1: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x5596176d6618 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5596176cc5d8 size 128 | #1 STATE_MAIN_I3: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.163064 "TUNNEL-A" #1: STATE_MAIN_I3: sent MI3, expecting MR3 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #1 suppresed complete_v1_state_transition() | #1 spent 25.7 milliseconds in resume sending helper answer | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e88000f48 | spent 0.0049 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 1884 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 05 10 02 01 00 00 00 00 00 00 07 5c c7 83 2e f7 | c6 08 43 4c 75 17 70 24 5d a5 fe 70 57 25 c9 ed | 46 a7 ef 35 30 f8 48 ab c9 8c 5e c7 5e de 18 b6 | 68 e3 90 b6 f4 7e bd 09 e7 2f 39 91 3d 90 65 4c | 76 84 4e b0 d1 31 dd 73 44 f7 6f be 13 68 b5 4b | 36 89 71 fc 1d 9e e2 2d bf 08 d5 56 85 5e 53 2f | f4 27 8c 71 23 ca bb 80 dc 5f 7a 93 61 4b 7a 6d | 68 d9 45 0d 4c ca 03 3b 42 5d 4c e0 19 e2 cd 92 | 24 95 5a 6b c8 f0 ce fa c8 02 3a 89 4a da 7c b1 | 42 b1 61 a2 66 41 ef 74 9e 52 ee 5d d6 d2 c3 fc | 88 31 05 6b f5 8a 74 4b cb 37 b5 13 a8 df 29 60 | c1 51 fa 14 14 9a 12 df bb f8 5f 66 ab aa 07 7f | 36 13 01 7d 91 3b 1a 8b 49 cc fb f0 21 ab 39 83 | 6f 92 df 13 1e 3f 0f 7b b1 94 2f ea 91 27 60 c6 | 04 66 0c 91 ef 5a 77 5f d7 f1 25 1f ed 30 5b 73 | 70 56 df c1 eb 8b 38 a7 79 d7 99 1d 5f c4 f2 b1 | 8e ef fb fa b0 b3 2c de 26 90 ed 3d 8c d9 02 0c | 04 1a 16 24 e9 4a 81 a0 52 33 48 7a 99 12 bb 5e | 23 4b 56 3b 3a a2 67 2a cc 31 8e 27 2f f4 de b3 | af 0b f5 d8 30 07 91 16 d6 a0 3b 4f 1d 98 b9 12 | a2 2f 79 7a d8 68 90 ab 33 1c 12 6f 7a 92 e2 78 | 10 92 83 10 8a 60 9e 69 8d 6c 63 aa c8 69 1d d9 | 8c 7d a5 d0 e6 8e 21 78 09 25 61 09 f8 37 fa 0f | 15 52 64 cc 3b ee 6c 0a d7 73 2f 0b 02 54 bd b8 | 44 9b 51 c7 8c b2 2f a8 45 f8 65 ba 7a 1d 57 c8 | f9 e1 79 65 8d 6e 8d 65 c8 28 a1 0d e6 cd 43 22 | 56 8b 6e 5f 50 33 62 6b 15 e1 bf fa 4f 5f 7f 32 | d0 a2 4d 51 5e 70 6f 73 91 8e 47 db 9a ef 2c 4c | a7 90 ac 44 b6 cd f7 c3 6b e8 0f 5d 79 bb dd c7 | 6e 89 f8 9a fd 6f a4 c8 ee 2a c4 63 ff 54 d3 f4 | 64 20 15 86 a9 81 28 1e ec 00 53 97 12 9c cd 78 | 48 0d 0f 08 e6 df 71 05 66 dd 73 6d 3e 20 1d dc | 32 2a 80 83 0d ce 63 5e 72 83 42 e6 a0 6a c5 83 | 74 af 51 c4 b8 10 13 a4 3d 03 fe 9a 9f 64 7b d6 | cd 72 89 f0 91 8b 6c 24 e2 d7 30 48 27 f8 34 5b | ff 05 ad 2c dd 82 a7 7b 44 f5 01 b2 55 e5 57 37 | b5 2e 18 9c b4 9f 58 5b 53 67 7a a4 57 14 4e b3 | ed b5 80 04 7f 4a c3 94 71 1f 60 08 8c ef 57 36 | bd 4f 86 19 50 63 cd 52 d2 a7 9c 0d e8 cb ce ef | d6 a3 4c 0a 60 a4 00 b7 63 a6 5f b5 fe 6e e5 c4 | 3b ad 8e 39 01 45 3b f9 e4 2a f6 60 ef 1d 4f 23 | ce 57 8b 94 a1 0a 21 de c4 ac e4 bb 6b 98 19 e9 | 0f 0d 46 8a 2d 08 56 8a c5 44 ba e1 37 82 29 99 | 02 82 27 77 43 48 5f 09 41 f4 fc da 04 f2 37 ab | d3 a7 ba 79 f6 87 f1 55 c0 d5 f2 7c a8 87 8f 9a | 72 68 bd 5d 1a 78 58 7b b2 1b fc 4c 4b 6c 07 be | 94 82 c2 c3 8f 46 7a 19 57 8f b1 5d 8f 4b b1 66 | 9c b1 f7 04 b7 3d b4 73 7d ef f8 3a 4d fd 1f 18 | 44 c5 1a 51 e1 bc e6 fd 98 bf f2 14 78 97 d0 00 | fd dc 46 2f 9e 5c 67 e3 40 91 b5 9a 12 08 6b fd | 64 81 f1 79 d4 e7 00 e3 4f 16 43 19 15 b0 95 55 | 67 b1 84 20 22 19 f4 0d a5 7c 70 18 4e c2 f1 2b | 95 38 15 af 97 37 78 4c 31 e4 58 94 18 77 76 5c | 3b 56 9f 2b 0e d0 db e3 07 dd b7 e6 7b 1a 4c 51 | 3a d5 46 3f d6 c8 e3 c5 8b e5 82 39 af fb 7d 48 | a1 8e f6 bd be 02 8e 69 48 85 55 99 ba 7d 48 09 | 95 d1 91 12 73 d8 b0 17 57 57 2e 6e a2 e9 1d 1d | a7 e3 0c a2 07 2c 5e 7b 34 14 23 99 c4 b2 26 4d | 4b e5 28 82 fe 1c a1 4d b4 0b 14 61 0d 35 97 a1 | 4d 05 11 39 ff 24 ee cf 27 43 91 ee cf 0b 26 6b | 9b c8 e0 0d a2 af be 3d 67 5f a4 04 62 f3 30 78 | a6 8c 02 61 14 5d b6 e6 66 22 be 28 98 d3 64 74 | 69 57 26 48 55 ce e5 ff 50 72 e3 1a f5 93 db f2 | 71 7d 2f ad a5 a8 60 b2 cc fb e9 05 7c f6 25 7c | 1a 45 32 67 66 fb d9 35 f1 89 33 48 4b 88 f0 b3 | cd 8c c2 bd 12 6c 8b 93 c9 5b a6 ad 0e f8 69 02 | b7 b6 b7 4b b0 16 8d db 5d a0 22 8c 1e bf 16 37 | 57 3f 96 fe 8f 67 31 27 ff 0a e0 b7 7c 92 e8 ff | 59 c7 12 18 cc 49 e5 3d 42 19 df 59 e3 e9 8b f4 | 0b 33 db 27 bd e0 7f 3c 5e 6c 8d da 52 64 3b eb | 46 80 6b 7e c3 e4 ad 0d 30 a7 ea 36 fa 3a 0f ea | 7e e8 b8 02 84 25 75 01 f4 7b 46 ee 72 76 3b b5 | 51 34 90 ee b2 5d ee 5c 1c 3d 69 38 19 93 89 ed | a5 92 75 f9 ab 5f c3 47 39 d2 44 5d 28 3d a3 8f | 17 83 d2 d8 82 2b 92 37 c8 6d 74 28 20 40 c6 3d | 44 29 8a d1 3f 5b b2 1c ce 71 46 ad 71 c6 f7 ed | 81 06 7b 0a 20 d1 9f b3 d3 ff 8f 76 00 89 48 0f | 7a 6c e6 61 6a d8 78 4e de fa f3 b8 66 78 57 a2 | d2 37 9f 4b 6f c1 5e 79 10 b0 43 1a e5 d8 98 2f | 7f 6a a0 7c bc 1e 3a c3 89 8a 85 3f fa b7 0b f4 | dc 25 d8 9b 69 14 ac a5 1c d5 4c a6 2e 4a 08 54 | 42 ad 34 e9 d0 87 ff 22 cc 0a 3b 49 91 54 43 ed | 26 33 49 e2 b7 d7 22 2b 99 69 95 05 51 5f 3b bf | 8c 3a f6 6f 5d 34 fc c6 dd 16 dc 2c 09 f5 12 ac | 09 f2 6c 27 a6 d3 5f c7 8b ff 77 f2 54 6b 69 55 | c4 6c 15 8d 41 ef c2 29 01 dc 08 11 40 14 ef 7a | 55 a4 42 d6 99 22 bb 20 d7 69 51 a3 ac 6c 58 76 | 2a 06 b5 02 de ec e7 24 4c 9a d1 c1 42 65 4c f6 | 23 eb c6 b8 7a e9 d4 11 85 41 6b 68 78 3a ac 08 | 71 d6 b7 a0 40 12 02 34 91 bd 22 68 b6 57 bd 20 | 5f e8 42 ea 84 e6 91 34 ee 4b 16 e4 77 1f 00 d2 | ea fe 57 95 9b 98 3a 85 59 4e dc 36 86 b2 d7 20 | bd db 8c 87 6e 77 72 02 6a fe 19 1e 5c fe 9b bd | be 79 51 bb d8 a7 bd d0 45 c4 8d 0c f6 e3 00 d7 | 24 7a 04 bc 89 ae f1 3b a4 74 3f f3 9b 13 61 f3 | 1d 60 ca 92 bc 9c 3b 7e dc 85 4d e1 a9 a0 c4 06 | ea 0f 00 14 22 21 f7 a1 6f 70 e5 5e 7e 33 1d 62 | 77 7f d1 29 e1 f0 18 a3 8a f4 8b 48 b1 4e 9a d9 | d8 30 2b 32 2c cf 52 d9 4c 4c 0a f6 0e fa 07 2e | 4c 73 c1 89 ca 38 6d fc c8 a1 20 12 6f 32 27 f8 | e9 56 6c 3f 0f 05 63 ff 41 22 be f6 60 9a a7 55 | dc cb 13 fe e9 7a 55 27 a8 37 d4 85 d6 fe e9 fb | d7 4d 5c d1 40 dd 7e c0 dc dd 8c c3 bf ba b4 da | b2 de 2b 66 66 72 aa bf e2 6e 6d 3c ed 38 15 52 | 23 58 44 e7 0b d9 b0 7e 38 48 2d 07 5a bb a1 f0 | c4 ed cc 6a ca cd 3d ba 4e d6 32 43 b7 d3 9f fa | 0c fb 94 be 0a da 26 3c ff 78 aa f1 47 19 e1 90 | 28 eb 96 f0 49 b6 2e 6a d8 9f 36 88 7f bc b2 d4 | bb 36 af 58 da 58 ce 2e f6 ba 0d 1a 85 40 96 d9 | 94 82 b8 b2 b9 16 16 ce c5 97 0f ce 9b 15 71 f6 | cb 0d 38 81 e8 a4 47 b9 f2 47 9c 9f 46 a9 90 d0 | d2 ea e0 fb d0 22 ee 69 bc cf cd 02 b9 88 57 64 | 1e de 71 90 a2 d6 9e df 91 f0 3a 9f f8 4b f8 a3 | 5b 26 ce 29 80 b3 1e 70 eb 40 4b 90 f1 62 bd 17 | c6 e1 33 0e 34 cd af 92 d2 9f 6a 1d 1d a1 ef b3 | ee 03 be 8f c9 15 ea 4d 22 46 73 d8 fe e9 94 0a | 08 f4 05 5b c8 8f cd d3 31 97 19 4f | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | length: 1884 (0x75c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #1 in MAIN_I3 (find_state_ikev1) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1459) | #1 is idle | #1 idle | received encrypted packet from 192.1.2.23:500 | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x220 opt: 0x20c0 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CERT (0x6) | length: 191 (0xbf) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | obj: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | obj: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | obj: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 1265 (0x4f1) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 388 (0x184) | removing 12 bytes of padding | message 'main_inR3' HASH payload not checked early | DER ASN1 DN: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | DER ASN1 DN: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | DER ASN1 DN: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | DER ASN1 DN: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "TUNNEL-A" #1: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds loading root certificate cache | spent 5.11 milliseconds in get_root_certs() calling PK11_ListCertsInSlot() | spent 0.0264 milliseconds in get_root_certs() filtering CAs | #1 spent 5.17 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.831 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for mainca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #1 spent 0.054 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec | certificate is valid (profile IPsec) | #1 spent 0.151 milliseconds in find_and_verify_certs() calling verify_end_cert() "TUNNEL-A" #1: certificate verified OK: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176e8bc8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176e8208 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176e8058 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176e7698 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176d56a8 | unreference key: 0x5596176f20b8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | #1 spent 0.448 milliseconds in decode_certs() calling add_pubkey_from_nss_cert() | #1 spent 6.71 milliseconds in decode_certs() | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' needs further ID comparison against 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' matched our ID | SAN ID matched, updating that.cert | X509: CERT and ID matches current connection | required RSA CA is '%any' | checking RSA keyid 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' for match with 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | key issuer CA is 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | an RSA Sig check passed with *AwEAAbEef [remote certificates] | #1 spent 0.189 milliseconds in try_all_RSA_keys() trying a pubkey "TUNNEL-A" #1: Authenticated using RSA | FOR_EACH_CONNECTION_... in ISAKMP_SA_established | complete v1 state transition with STF_OK | [RE]START processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #1 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_I3 to state STATE_MAIN_I4 | parent state #1: MAIN_I3(open IKE SA) => MAIN_I4(established IKE SA) | event_already_set, deleting event | state #1 requesting EVENT_RETRANSMIT to be deleted | #1 STATE_MAIN_I4: retransmits: cleared | libevent_free: release ptr-libevent@0x5596176cc5d8 | free_event_entry: release EVENT_RETRANSMIT-pe@0x5596176d6618 | !event_already_set at reschedule | event_schedule: new EVENT_SA_EXPIRE-pe@0x5596176d6618 | inserting event EVENT_SA_EXPIRE, timeout in 60 seconds for #1 | libevent_malloc: new ptr-libevent@0x5596176e1318 size 128 | pstats #1 ikev1.isakmp established "TUNNEL-A" #1: STATE_MAIN_I4: ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP2048} | DPD: dpd_init() called on ISAKMP SA | DPD: Peer supports Dead Peer Detection | DPD: not initializing DPD because DPD is disabled locally | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | unpending state #1 | creating state object #2 at 0x5596176e59f8 | State DB: adding IKEv1 state #2 in UNDEFINED | pstats #2 ikev1.ipsec started | duplicating state object #1 "TUNNEL-A" as #2 for IPSEC SA | #2 setting local endpoint to 192.1.2.45:500 from #1.st_localport (in duplicate_state() at state.c:1484) | suspend processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:685) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:685) | child state #2: UNDEFINED(ignore) => QUICK_I1(established CHILD SA) "TUNNEL-A" #2: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO {using isakmp#1 msgid:6218486d proposal=defaults pfsgroup=MODP2048} | adding quick_outI1 KE work-order 3 for state #2 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5596176d4778 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x5596176cc3b8 size 128 | libevent_realloc: release ptr-libevent@0x559617664188 | libevent_realloc: new ptr-libevent@0x5596176cb508 size 128 | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:764) | resume processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:764) | unqueuing pending Quick Mode with 192.1.2.23 "TUNNEL-A" | crypto helper 2 resuming | removing pending policy for no connection {0x5596176b78c8} | crypto helper 2 starting work-order 3 for state #2 | close_any(fd@24) (in release_whack() at state.c:654) | crypto helper 2 doing build KE and nonce (quick_outI1 KE); request ID 3 | #1 spent 7.36 milliseconds in process_packet_tail() | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 7.82 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 2 finished build KE and nonce (quick_outI1 KE); request ID 3 time elapsed 0.00107 seconds | (#2) spent 1.07 milliseconds in crypto helper computing work-order 3: quick_outI1 KE (pcr) | crypto helper 2 sending results from work-order 3 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f3e8c003f28 size 128 | crypto helper 2 waiting (nothing to do) | processing resume sending helper answer for #2 | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 2 replies to request ID 3 | calling continuation function 0x559617387b50 | quick_outI1_continue for #2: calculated ke+nonce, sending I1 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1645758573 (0x6218486d) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | emitting quick defaults using policy none | empty esp_info, returning defaults for ENCRYPT | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ikev1_out_sa pcn: 0 has 1 valid proposals | ikev1_out_sa pcn: 0 pn: 0<1 valid_count: 1 trans_cnt: 2 | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0xf384cffa for esp.0@192.1.2.45 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI f3 84 cf fa | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ESP): 32 | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 1 (0x1) | ESP transform ID: ESP_3DES (0x3) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | emitting length of ISAKMP Transform Payload (ESP): 28 | emitting length of ISAKMP Proposal Payload: 72 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 84 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Ni into ISAKMP Nonce Payload | Ni 05 2f 8e a1 d5 cb c3 40 d3 06 3c 9d 51 48 21 36 | Ni fb 16 1b 96 ed 57 b6 f9 6f 5b 0f 4f 49 20 80 37 | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 8b b1 92 a5 8d f4 b0 b4 22 c0 8a 02 8e 2b 86 c5 | keyex value 98 d2 94 7f 2a 47 32 55 ea 5b 54 00 83 60 1f 0d | keyex value ed 9e 29 9b cb 2c 2d c3 42 04 4b 18 43 fc ef 39 | keyex value f9 a1 17 b2 40 ff 1c ba d0 7c de 06 d7 15 68 5d | keyex value 53 d3 e0 00 b8 f1 96 c2 e5 56 aa 51 a7 b8 06 7a | keyex value b4 24 a7 38 8b c6 32 ba 2d ef c6 fb a6 f4 8f 2e | keyex value e3 34 2b fa be 3b c5 b7 30 a0 5e 21 fd f8 eb 0b | keyex value a1 f3 38 4c 4e 64 6a f8 e2 5d db 7e 0d 8b 67 48 | keyex value 01 72 15 70 13 1d b1 23 05 65 d1 97 6b 74 19 fc | keyex value c8 b2 dd 43 db f9 ef a8 38 eb f9 fd 6e c9 1d 05 | keyex value 24 e2 b1 9d ad 77 db 1f 5b d2 e4 f2 02 43 ba 55 | keyex value 93 83 3b 2e 9f a0 da 96 db bc 2e b3 b3 54 7f 66 | keyex value 8c 02 08 40 5b 62 e7 34 cb 32 11 50 14 46 ed c9 | keyex value ce fd 96 fa 6f 07 9e 69 80 c6 f5 27 76 ab d6 fd | keyex value d0 04 11 6f 5e 5f 4d 36 79 e0 60 ed b6 46 b8 10 | keyex value 09 31 31 8f 06 ee 15 83 04 42 e5 9c 2d c0 95 f4 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of client network into ISAKMP Identification Payload (IPsec DOI) | client network c0 00 01 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of client network into ISAKMP Identification Payload (IPsec DOI) | client network c0 00 02 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | outI1 HASH(1): | 85 e1 de 9e cb 08 ed 10 5c 0c be c2 6e 8a 62 ed | d6 55 bb a3 13 69 de 45 fe 6e 57 36 88 0b 9b a2 | emitting 8 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 476 | sending 476 bytes for reply packet from quick_outI1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #2) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 62 18 48 6d 00 00 01 dc 15 ff 56 3c | 47 38 56 33 81 13 63 2e 80 6b a6 ad 33 0f b2 ce | 9a 30 a9 fd 1a d4 3b 1d 6e d7 50 6f 7d dd b3 f2 | ab 6e a0 d0 81 6f a1 1d ce d6 81 bc f4 72 f2 30 | 54 28 b4 e5 10 ff b5 49 8a a2 78 e2 fb 51 8e 3f | 5c ce a5 e6 87 91 1d 6e 69 1d c4 9e f1 7c b1 61 | df 13 ca a9 0e 8f 2c 8f ee a5 c1 5f 5c bb 92 c8 | 33 54 a5 99 be 55 19 da 93 79 3d ff 56 1a 1c a8 | 33 51 8b 26 37 b7 9f d9 d6 ab 32 f6 c5 21 f2 30 | 8b 80 e0 b4 07 5d 9e 9b cc 66 6c be dd 19 f6 04 | f7 81 c4 cc 18 ca b3 0c ef 32 ee 06 4c 4b 53 18 | 4d 33 13 bf 83 72 81 3a 97 5a 9c e2 af 27 58 a8 | e5 86 84 87 aa 4d 67 5c 7c e1 c2 7a f3 db 31 c3 | 9d 34 6c bb 5e f8 14 1d 21 e1 8e 03 f6 4f 50 eb | 6a af 1e 75 c2 40 cc e0 c7 ec 84 5f 49 86 37 5f | e8 32 8a 3b 5a 91 66 e2 f7 3f 92 07 79 ee 1b 06 | b3 e5 37 78 e0 73 5f 11 80 2b 35 61 b0 7c 83 54 | 17 bc 69 5c 76 15 32 cc b0 a8 a3 87 9b 2f 1b 0b | c9 e8 ab 33 24 4b 28 26 51 4b 98 44 59 b5 26 7d | 93 f4 fb 15 fb 8c a0 f2 c4 cb 96 63 e7 0d b0 89 | 42 7d a8 db cf 59 6d 6e 2e ea cb 6b a7 04 f8 76 | bc bd 3d 8d b0 b2 5d 83 46 b9 5a 55 f1 4f 57 ba | 8b c8 b2 fa cf 0c 14 49 8f 90 28 6f 3a 4d 85 ba | 31 0c 5f fe f1 96 0b 37 f0 bc 46 ba fe 61 f5 64 | 78 71 eb 82 75 49 6d 58 bd 88 7b b9 8a fd e5 18 | 21 9b b8 e6 aa 25 8a 32 5c 4b 19 96 69 a4 ff 99 | 3c c6 88 70 7d 62 db 6d 59 6e e1 26 93 19 70 99 | 60 3f 3d 91 3b b9 0e 38 af a0 97 66 e5 4f e7 23 | 0a 3c 7b a5 c1 fd f9 97 8b 0a f7 15 | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5596176cc3b8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5596176d4778 "TUNNEL-A" #2: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x5596176d4778 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x5596176cc3b8 size 128 | #2 STATE_QUICK_I1: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.193525 | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 0.62 milliseconds in resume sending helper answer | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e8c003f28 | spent 0.00221 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 444 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 62 18 48 6d 00 00 01 bc 61 22 cc b7 | bf 9a 67 cd 2f 8b c8 33 ab 24 19 6c f4 d9 f1 1d | 50 4e 02 0e b6 5e c5 2a f1 9d 1e d0 6d 35 e7 69 | 71 9c d6 a9 48 72 08 b1 24 17 78 f2 53 d5 7f d5 | d7 50 6f 4b 0d 74 55 45 50 3e e0 31 72 c7 f9 02 | 5f c9 20 e4 ca 33 8b ff cf 35 a3 5e d7 bf 66 2d | 2a d1 c4 2b a0 8b a4 8e fa 94 7f 48 3c e6 8b 65 | 41 ae ef fa 3e 5b 80 7e 27 d5 de 29 94 4a 76 30 | a7 37 2f 18 08 48 a7 06 07 b7 b4 f9 1f 60 c0 bb | c2 86 dd 2e 2c a7 5b c0 ec 15 50 fb f0 77 62 8a | ab 62 55 eb 61 fb 83 f4 cd e5 43 60 b2 d0 c5 83 | 03 a5 10 44 c8 a6 fe 6f 9f 37 ef b1 76 9a 2b 3f | ac 8c 7f 91 59 9c ef 37 1e c3 f5 76 a4 98 74 24 | 76 7f c8 86 e1 66 73 b0 78 9d 3e 7d e5 7d a1 f5 | 43 42 97 07 a5 2f 4e 3d d5 fe e2 4a 91 db 0e b5 | 02 22 a0 f5 ee 7d 35 63 9e 69 6f ea 8c ec 38 ed | 3c 5e f3 1d 28 81 f2 92 32 a8 cc 9b a3 88 5f 62 | a1 39 27 d3 a1 4a 2a d8 17 59 02 07 7e 0e ee 37 | 5f 80 ab 51 db ac 93 e7 f0 61 8f 69 e8 7a 66 6d | fb 68 9d b7 21 dc 68 f5 47 22 fb 84 4d 76 4a 26 | 5a 82 c2 31 68 65 8a e5 2f 39 c1 b7 cb d7 41 9e | 20 7a d8 eb 3c 1d 81 03 ea 7f 81 78 83 60 53 db | ca b7 b9 2a 7c 8d 34 fe 6b 00 c2 5c 7e ac c0 c1 | 6e 99 f2 ea 00 70 86 51 04 93 e2 65 d6 f4 f5 c0 | 4e ba 19 25 6f 30 2c 5a 73 a7 4d 45 65 49 26 80 | da 20 d2 18 0a cc b4 79 5d be 4e 06 90 72 d1 5d | d1 bc 21 57 8e 04 df 0e c1 18 4a 65 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1645758573 (0x6218486d) | length: 444 (0x1bc) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #2 in QUICK_I1 (find_state_ikev1) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1633) | #2 is idle | #2 idle | received encrypted packet from 192.1.2.23:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 36 (0x24) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 260 (0x104) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 01 fe | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 02 fe | removing 4 bytes of padding | quick_inR1_outI2 HASH(2): | 5e af ae e0 00 eb ab e1 f9 ff 89 28 c4 81 15 77 | 72 e5 07 b9 95 17 6e 36 45 2c 44 b8 11 ab 0f bb | received 'quick_inR1_outI2' message HASH(2) data ok | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI ac 88 16 7e | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outI2 DH work-order 4 for state #2 | state #2 requesting EVENT_RETRANSMIT to be deleted | #2 STATE_QUICK_I1: retransmits: cleared | libevent_free: release ptr-libevent@0x5596176cc3b8 | free_event_entry: release EVENT_RETRANSMIT-pe@0x5596176d4778 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x5596176d4778 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #2 | libevent_malloc: new ptr-libevent@0x7f3e8c003f28 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #2 and saving MD | #2 is busy; has a suspended MD | #2 spent 0.194 milliseconds in process_packet_tail() | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.476 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 4 resuming | crypto helper 4 starting work-order 4 for state #2 | crypto helper 4 doing compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 4 | crypto helper 4 finished compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 4 time elapsed 0.001028 seconds | (#2) spent 1.03 milliseconds in crypto helper computing work-order 4: quick outI2 DH (pcr) | crypto helper 4 sending results from work-order 4 for state #2 to event queue | scheduling resume sending helper answer for #2 | libevent_malloc: new ptr-libevent@0x7f3e80001f78 size 128 | crypto helper 4 waiting (nothing to do) | processing resume sending helper answer for #2 | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 4 replies to request ID 4 | calling continuation function 0x559617387b50 | quick_inR1_outI2_continue for #2: calculated ke+nonce, calculating DH | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1645758573 (0x6218486d) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 01 fe | our client is 192.0.1.254/32 | our client protocol/port is 0/0 | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 02 fe | peer client is 192.0.2.254/32 | peer client protocol/port is 0/0 | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | quick_inR1_outI2 HASH(3): | b6 02 e8 2d bb f2 3b 76 6f c2 a8 85 6e de a3 1c | fc 48 e5 fa cf 64 a3 71 3e a5 f0 ca a8 60 44 9a | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | install_ipsec_sa() for #2: inbound and outbound | could_route called for TUNNEL-A (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL; eroute owner: NULL | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-A' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.ac88167e@192.1.2.23 included non-error error | set up outgoing SA, ref=0/0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-A' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.f384cffa@192.1.2.45 included non-error error | priority calculation of connection "TUNNEL-A" is 0xfdfdf | add inbound eroute 192.0.2.254/32:0 --0-> 192.0.1.254/32:0 => tun.10000@192.1.2.45 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | set up incoming SA, ref=0/0 | sr for #2: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL; eroute owner: NULL | route_and_eroute with c: TUNNEL-A (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #2 | priority calculation of connection "TUNNEL-A" is 0xfdfdf | eroute_connection add eroute 192.0.1.254/32:0 --0-> 192.0.2.254/32:0 => tun.0@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-client | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_ | popen cmd is 1295 chars long | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=C: | cmd( 160):A, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libre: | cmd( 240):swan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PL: | cmd( 320):UTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_: | cmd( 400):PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_: | cmd( 480):PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Te: | cmd( 560):st Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org': | cmd( 640): PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO_PE: | cmd( 720):ER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: | cmd( 800):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+E: | cmd( 880):NCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' P: | cmd( 960):LUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_: | cmd(1040):IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BA: | cmd(1120):NNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IF: | cmd(1200):ACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xac88167e SPI_OUT=0xf384cffa ips: | cmd(1280):ec _updown 2>&1: | route_and_eroute: firewall_notified: true | running updown command "ipsec _updown" for verb prepare | command executing prepare-client | executing prepare-client: PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANE | popen cmd is 1300 chars long | cmd( 0):PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.: | cmd( 240):libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' P: | cmd( 480):LUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, : | cmd( 560):OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan: | cmd( 640):.org' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLU: | cmd( 720):TO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0: | cmd( 800):' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSA: | cmd( 880):SIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_: | cmd( 960):NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 P: | cmd(1040):LUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PE: | cmd(1120):ER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' V: | cmd(1200):TI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xac88167e SPI_OUT=0xf384cff: | cmd(1280):a ipsec _updown 2>&1: | running updown command "ipsec _updown" for verb route | command executing route-client | executing route-client: PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' | popen cmd is 1298 chars long | cmd( 0):PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_: | cmd( 80):INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID=': | cmd( 160):C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.li: | cmd( 240):breswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32': | cmd( 320): PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_: | cmd( 400):MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLU: | cmd( 480):TO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU: | cmd( 560):=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.o: | cmd( 640):rg' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO: | cmd( 720):_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' : | cmd( 800):PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASI: | cmd( 880):G+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO: | cmd( 960):' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLU: | cmd(1040):TO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER: | cmd(1120):_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI: | cmd(1200):_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xac88167e SPI_OUT=0xf384cffa : | cmd(1280):ipsec _updown 2>&1: | route_and_eroute: instance "TUNNEL-A", setting eroute_owner {spd=0x5596176d04a8,sr=0x5596176d04a8} to #2 (was #0) (newest_ipsec_sa=#0) | #1 spent 2.05 milliseconds in install_ipsec_sa() | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 76 | inR1_outI2: instance TUNNEL-A[0], setting IKEv1 newest_ipsec_sa to #2 (was #0) (spd.eroute=#2) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #2 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_I1 to state STATE_QUICK_I2 | child state #2: QUICK_I1(established CHILD SA) => QUICK_I2(established CHILD SA) | event_already_set, deleting event | state #2 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f3e8c003f28 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x5596176d4778 | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | sending 76 bytes for STATE_QUICK_I1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #2) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 62 18 48 6d 00 00 00 4c 36 62 2f 59 | 94 2d ab 32 6e 7b f5 1e 36 95 65 d4 25 99 6f 66 | 7c 69 e8 38 02 7f 29 5a 1e 71 e7 07 d3 74 ec be | f2 e0 00 6d 47 75 eb 3f 90 a8 44 4a | !event_already_set at reschedule | event_schedule: new EVENT_v1_SA_REPLACE_IF_USED-pe@0x5596176d4778 | inserting event EVENT_v1_SA_REPLACE_IF_USED, timeout in 28048 seconds for #2 | libevent_malloc: new ptr-libevent@0x5596176e57b8 size 128 | pstats #2 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-A" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xac88167e <0xf384cffa xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | close_any(fd@25) (in release_whack() at state.c:654) | resume sending helper answer for #2 suppresed complete_v1_state_transition() | #2 spent 2.55 milliseconds in resume sending helper answer | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e80001f78 | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00812 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00402 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00382 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | dup_any(fd@16) -> fd@23 (in whack_process() at rcv_whack.c:590) | FOR_EACH_CONNECTION_... in conn_by_name | start processing: connection "TUNNEL-B" (in initiate_a_connection() at initiate.c:186) | empty esp_info, returning defaults for ENCRYPT | connection 'TUNNEL-B' +POLICY_UP | dup_any(fd@23) -> fd@24 (in initiate_a_connection() at initiate.c:342) | FOR_EACH_STATE_... in find_phase1_state | creating state object #3 at 0x5596176e6bc8 | State DB: adding IKEv1 state #3 in UNDEFINED | pstats #3 ikev1.ipsec started | duplicating state object #1 "TUNNEL-A" as #3 for IPSEC SA | #3 setting local endpoint to 192.1.2.45:500 from #1.st_localport (in duplicate_state() at state.c:1484) | in connection_discard for connection TUNNEL-A | suspend processing: connection "TUNNEL-B" (in quick_outI1() at ikev1_quick.c:685) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:685) | child state #3: UNDEFINED(ignore) => QUICK_I1(established CHILD SA) "TUNNEL-B" #3: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO {using isakmp#1 msgid:38f90549 proposal=defaults pfsgroup=MODP2048} | adding quick_outI1 KE work-order 5 for state #3 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f3e8c004218 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #3 | libevent_malloc: new ptr-libevent@0x7f3e80001f78 size 128 | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:764) | resume processing: connection "TUNNEL-B" (in quick_outI1() at ikev1_quick.c:764) | stop processing: connection "TUNNEL-B" (in initiate_a_connection() at initiate.c:349) | close_any(fd@23) (in initiate_connection() at initiate.c:372) | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.155 milliseconds in whack | crypto helper 3 resuming | crypto helper 3 starting work-order 5 for state #3 | crypto helper 3 doing build KE and nonce (quick_outI1 KE); request ID 5 | crypto helper 3 finished build KE and nonce (quick_outI1 KE); request ID 5 time elapsed 0.000554 seconds | (#3) spent 0.558 milliseconds in crypto helper computing work-order 5: quick_outI1 KE (pcr) | crypto helper 3 sending results from work-order 5 for state #3 to event queue | scheduling resume sending helper answer for #3 | libevent_malloc: new ptr-libevent@0x7f3e84002888 size 128 | crypto helper 3 waiting (nothing to do) | processing resume sending helper answer for #3 | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 3 replies to request ID 5 | calling continuation function 0x559617387b50 | quick_outI1_continue for #3: calculated ke+nonce, sending I1 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 955843913 (0x38f90549) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | emitting quick defaults using policy none | empty esp_info, returning defaults for ENCRYPT | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ikev1_out_sa pcn: 0 has 1 valid proposals | ikev1_out_sa pcn: 0 pn: 0<1 valid_count: 1 trans_cnt: 2 | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0xe93161bd for esp.0@192.1.2.45 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI e9 31 61 bd | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ESP): 32 | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 1 (0x1) | ESP transform ID: ESP_3DES (0x3) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | emitting length of ISAKMP Transform Payload (ESP): 28 | emitting length of ISAKMP Proposal Payload: 72 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 84 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Ni into ISAKMP Nonce Payload | Ni 4e 45 8a 60 86 9a dc 93 53 b4 06 a2 6d 2d 97 58 | Ni 37 80 5a ae 79 fc ec f0 bb cb 3b 79 6f 30 34 7d | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value a6 83 63 46 84 f6 19 b9 6a 82 3d 80 d2 a0 3d f7 | keyex value 38 64 19 31 45 1d 4b 24 7b ee 3b af 2f c9 dd 7c | keyex value de 98 25 93 2f 40 9a 76 14 86 4e a5 67 1d 2d c8 | keyex value 13 e3 c4 b7 9f 11 ba 88 6f 5a ac 3c 7e c0 d0 f1 | keyex value 0f be c6 9d e0 02 85 99 83 62 85 26 59 47 60 99 | keyex value 00 68 4e 47 16 51 af b9 34 6d 29 6e 7a 24 92 40 | keyex value 20 65 0b ad 18 00 c7 1f cd b4 5d 10 d4 8e 76 69 | keyex value 1f 6b 6c 8f f6 f3 c0 96 55 a8 f4 4b 7b 9c 7e c0 | keyex value 65 93 fc 54 0b a5 6b a7 ac 2d ba 9c ae f2 25 11 | keyex value 49 a6 a0 83 dd c5 01 e5 6b 16 0a 2e 49 92 fe ca | keyex value 08 de 68 f5 9d 7c b7 09 8e 53 83 f6 bb 99 ee 34 | keyex value 53 11 8b 3e 66 8f b0 af 94 ef 97 23 fd ab c0 e4 | keyex value 63 ba b3 aa 34 06 1e d4 29 ee f1 72 61 ab 2b bb | keyex value 47 06 34 cf 30 93 d4 e2 99 10 d1 40 92 62 b7 56 | keyex value ff 1b ce 0c e1 5c 4b 02 67 99 69 b1 0f 61 ce 29 | keyex value 58 db a0 e2 36 b9 8e 45 7d ef c1 0b 7a 1b 24 e6 | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of client network into ISAKMP Identification Payload (IPsec DOI) | client network c0 00 01 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of client network into ISAKMP Identification Payload (IPsec DOI) | client network c0 00 02 f4 | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | outI1 HASH(1): | 8e 75 8b 1b a4 5c 71 95 2d 11 8e 2e 5a c7 0e 29 | 8c 9f 5a b5 a2 05 3e 2a 04 8b d2 7f 65 ae 28 e0 | emitting 8 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 476 | sending 476 bytes for reply packet from quick_outI1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #3) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 38 f9 05 49 00 00 01 dc 2a e0 e1 97 | 24 90 9a 43 5e f9 b3 75 74 62 24 a4 47 da 76 c4 | 74 1a c1 b8 17 9b 1d 09 f3 6b 16 c3 43 1d 09 87 | 2f b4 9c 81 99 35 fb 4c 5f 0e 42 06 c4 a3 cc cf | fa 89 e5 d4 21 05 c1 37 7e 5f eb 65 75 6c ba 61 | da 16 ff f4 87 c6 c2 6a ff b4 73 79 dc 8b bb 0b | 61 44 fe c0 23 bc 6e cc 84 86 23 50 4d 43 98 b5 | a7 29 69 27 04 ad e5 60 35 a7 f8 5b d8 29 24 56 | 99 fa 4a e6 84 26 b2 eb fc 22 fe 3e a3 6f 09 63 | d1 00 a6 9e ea 4e b2 53 db 67 1e 94 d0 d4 34 77 | 91 10 33 29 1d b9 92 d0 b3 22 09 d2 41 53 6d 66 | 5a 92 f1 cf ed 6b 31 ab db 35 f0 0a ca e9 b5 5d | 38 85 14 12 69 95 49 4a d2 aa 33 75 49 9d de 45 | be bf 3b 12 6a aa c6 79 87 fd 60 de 2b 88 f6 57 | b0 67 50 f1 86 5a 3d 30 18 17 ff 3e df 35 e4 6d | 6f 84 24 07 aa 83 ba d5 db f0 77 a0 6f e7 c9 85 | c0 48 1a 5e 9b 50 15 d2 86 76 e3 91 2d 3d c4 09 | 96 65 29 a6 71 bd b8 3b 8d 53 c7 24 98 95 51 b1 | 6a 92 68 c3 2d 20 bd 6e 09 16 c7 fe 40 b7 78 c2 | 01 8f cb 22 20 75 14 bb 22 44 33 49 75 6a 44 f7 | 60 f4 9d 4d 68 d3 79 29 1d 57 92 20 57 a6 dd ac | 65 43 a6 ff e2 e9 9f 06 51 f4 04 7a 76 85 7e 75 | 9d fe df f0 8e 91 6b 3b 22 8a 87 e0 84 71 b1 e6 | 7a 63 6e ff eb a6 60 e3 5a a6 64 73 60 ec 60 27 | c5 b0 f9 f6 8e 26 54 4c 2c 8a c2 cf 57 65 93 0d | e8 d2 01 0b 93 db 98 90 23 98 b6 eb 80 d1 1b 43 | a2 c3 7f c5 42 37 c9 f1 c7 3c 91 5b c4 f5 d7 40 | 43 0e be ae 6d 15 f4 1c f9 ee d4 43 b0 5b 01 b8 | 3c e3 de 71 26 4b 19 45 f3 6a ff 21 | state #3 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f3e80001f78 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f3e8c004218 "TUNNEL-B" #3: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x7f3e8c004218 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #3 | libevent_malloc: new ptr-libevent@0x5596176e5868 size 128 | #3 STATE_QUICK_I1: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.30891 | resume sending helper answer for #3 suppresed complete_v1_state_transition() | #3 spent 0.405 milliseconds in resume sending helper answer | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e84002888 | spent 0.00231 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 444 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 38 f9 05 49 00 00 01 bc d3 40 62 11 | 6b 5e 72 88 9a ce 00 e1 0a 75 b6 77 5d 00 86 f2 | 03 e6 88 1b 17 a9 99 c2 df 68 b5 88 f7 91 ef 5e | 59 37 a9 a6 fb 11 2a 5a c0 2d 9b d2 74 8a 66 5c | 85 b7 e3 10 fb 0c e2 21 58 89 71 ee 65 fb bb 0a | aa 6b 84 28 e0 0d b0 93 06 63 24 65 36 af ed 88 | 6d b6 1b 39 a9 e7 aa af 27 3f b1 b0 34 8a 39 7a | 98 3c f0 aa f3 8d 17 05 4c 16 9b d3 50 13 10 c6 | 09 84 1e 96 3f bc a5 05 8f 0f c4 fb a4 66 70 37 | ae 42 0e 6d 47 f9 11 1c a6 3b 09 ca fd a6 f5 2d | fc ed 03 cd 1c 29 ac f4 6b 40 3d e9 2e 9e de a8 | 17 bc 7d e2 72 15 c5 7c 6d bb 48 5d 91 c5 f5 07 | f0 ff bd 85 d7 ad 38 bd e6 2f 41 97 9d fd 09 b2 | 91 7d 13 7c 1d fd cd 32 24 39 ac 2a 9f 94 46 e4 | d3 6c 66 0b 20 cd 9e 4f a8 07 5f 87 6d b5 3e 1c | 8a e3 55 0f 2f 88 45 34 b8 6d 5d 2b 59 6e 36 5a | 68 a9 37 de 42 9f 75 f4 2d 7a 0a 31 0b 57 6b 0b | 7d aa 45 16 01 4f ff 6c 30 40 6d 89 a3 d2 96 fd | 46 c8 6f b4 f9 12 48 cb a7 4f 1d 59 00 58 bc c1 | bf 59 6d ca 89 60 a7 87 a5 aa 2c 34 ba ea 15 0b | 2c fe 45 51 0c 2f c8 c0 92 51 1f 55 6f 1d 0c 00 | 19 ec 05 d2 cb 84 63 4c 0b fc 2c 35 63 b4 83 44 | d3 57 e1 93 b7 2e 2c 59 ec 3f 79 c3 d0 9e 77 da | b6 29 1b b2 91 83 57 ea bc 5f d6 eb 51 81 20 cf | eb b3 3f cc 6c 8a 40 d6 79 6e 3f 81 05 36 ce d9 | de ec 41 d7 72 bc 95 59 14 4a f1 09 e1 c0 b9 11 | 31 79 ba 5c a4 3b 4b 65 f9 1e 24 06 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 955843913 (0x38f90549) | length: 444 (0x1bc) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #3 in QUICK_I1 (find_state_ikev1) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1633) | #3 is idle | #3 idle | received encrypted packet from 192.1.2.23:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 36 (0x24) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 260 (0x104) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 01 fe | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 02 f4 | removing 4 bytes of padding | quick_inR1_outI2 HASH(2): | e2 2c 9f 13 e4 b4 3e 23 ab 5e e2 55 62 f3 f5 52 | ab ef 55 6b ab cb ad d7 b5 23 38 9c 3e 70 c1 92 | received 'quick_inR1_outI2' message HASH(2) data ok | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI 23 10 b1 06 | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outI2 DH work-order 6 for state #3 | state #3 requesting EVENT_RETRANSMIT to be deleted | #3 STATE_QUICK_I1: retransmits: cleared | libevent_free: release ptr-libevent@0x5596176e5868 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f3e8c004218 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f3e8c004218 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #3 | libevent_malloc: new ptr-libevent@0x7f3e84002888 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #3 and saving MD | #3 is busy; has a suspended MD | #3 spent 0.0974 milliseconds in process_packet_tail() | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.246 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 6 resuming | crypto helper 6 starting work-order 6 for state #3 | crypto helper 6 doing compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 6 | crypto helper 6 finished compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 6 time elapsed 0.000552 seconds | (#3) spent 0.553 milliseconds in crypto helper computing work-order 6: quick outI2 DH (pcr) | crypto helper 6 sending results from work-order 6 for state #3 to event queue | scheduling resume sending helper answer for #3 | libevent_malloc: new ptr-libevent@0x7f3e78001f78 size 128 | crypto helper 6 waiting (nothing to do) | processing resume sending helper answer for #3 | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 6 replies to request ID 6 | calling continuation function 0x559617387b50 | quick_inR1_outI2_continue for #3: calculated ke+nonce, calculating DH | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 955843913 (0x38f90549) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 01 fe | our client is 192.0.1.254/32 | our client protocol/port is 0/0 | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 02 f4 | peer client is 192.0.2.244/32 | peer client protocol/port is 0/0 | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | quick_inR1_outI2 HASH(3): | ae ad de 7a a9 da 1f d5 4b 84 5c d3 c8 f1 68 ad | 37 af e2 9a 91 ab ad 38 07 bd a3 3c ac 14 ce 8d | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | install_ipsec_sa() for #3: inbound and outbound | could_route called for TUNNEL-B (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: NULL; eroute owner: NULL | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-B' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.2310b106@192.1.2.23 included non-error error | set up outgoing SA, ref=0/0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-B' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.e93161bd@192.1.2.45 included non-error error | priority calculation of connection "TUNNEL-B" is 0xfdfdf | add inbound eroute 192.0.2.244/32:0 --0-> 192.0.1.254/32:0 => tun.10000@192.1.2.45 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | set up incoming SA, ref=0/0 | sr for #3: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: NULL; eroute owner: NULL | route_and_eroute with c: TUNNEL-B (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #3 | priority calculation of connection "TUNNEL-B" is 0xfdfdf | eroute_connection add eroute 192.0.1.254/32:0 --0-> 192.0.2.244/32:0 => tun.0@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-client | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_ | popen cmd is 1295 chars long | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=C: | cmd( 160):A, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libre: | cmd( 240):swan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PL: | cmd( 320):UTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_: | cmd( 400):PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_: | cmd( 480):PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Te: | cmd( 560):st Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org': | cmd( 640): PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO_PE: | cmd( 720):ER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: | cmd( 800):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+E: | cmd( 880):NCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' P: | cmd( 960):LUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_: | cmd(1040):IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BA: | cmd(1120):NNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IF: | cmd(1200):ACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x2310b106 SPI_OUT=0xe93161bd ips: | cmd(1280):ec _updown 2>&1: | route_and_eroute: firewall_notified: true | running updown command "ipsec _updown" for verb prepare | command executing prepare-client | executing prepare-client: PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANE | popen cmd is 1300 chars long | cmd( 0):PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.: | cmd( 240):libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' P: | cmd( 480):LUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, : | cmd( 560):OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan: | cmd( 640):.org' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLU: | cmd( 720):TO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0: | cmd( 800):' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSA: | cmd( 880):SIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_: | cmd( 960):NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 P: | cmd(1040):LUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PE: | cmd(1120):ER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' V: | cmd(1200):TI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x2310b106 SPI_OUT=0xe93161b: | cmd(1280):d ipsec _updown 2>&1: | running updown command "ipsec _updown" for verb route | command executing route-client | executing route-client: PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' | popen cmd is 1298 chars long | cmd( 0):PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_: | cmd( 80):INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID=': | cmd( 160):C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.li: | cmd( 240):breswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32': | cmd( 320): PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_: | cmd( 400):MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLU: | cmd( 480):TO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU: | cmd( 560):=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.o: | cmd( 640):rg' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO: | cmd( 720):_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' : | cmd( 800):PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASI: | cmd( 880):G+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO: | cmd( 960):' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLU: | cmd(1040):TO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER: | cmd(1120):_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI: | cmd(1200):_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x2310b106 SPI_OUT=0xe93161bd : | cmd(1280):ipsec _updown 2>&1: | route_and_eroute: instance "TUNNEL-B", setting eroute_owner {spd=0x5596176d0a98,sr=0x5596176d0a98} to #3 (was #0) (newest_ipsec_sa=#0) | #1 spent 1.3 milliseconds in install_ipsec_sa() | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 76 | inR1_outI2: instance TUNNEL-B[0], setting IKEv1 newest_ipsec_sa to #3 (was #0) (spd.eroute=#3) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #3 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_I1 to state STATE_QUICK_I2 | child state #3: QUICK_I1(established CHILD SA) => QUICK_I2(established CHILD SA) | event_already_set, deleting event | state #3 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f3e84002888 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f3e8c004218 | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | sending 76 bytes for STATE_QUICK_I1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #3) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 38 f9 05 49 00 00 00 4c 8b b5 47 88 | f3 dd fd 66 8f a9 dc 7c be 47 20 86 06 29 00 ca | 96 b1 d1 9b 32 55 a1 9f 58 3e 95 18 08 08 c7 9d | 5a ef dd 10 e2 de 15 f8 90 9d b7 9e | !event_already_set at reschedule | event_schedule: new EVENT_v1_SA_REPLACE_IF_USED-pe@0x7f3e8c004218 | inserting event EVENT_v1_SA_REPLACE_IF_USED, timeout in 27838 seconds for #3 | libevent_malloc: new ptr-libevent@0x5596176e5868 size 128 | pstats #3 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-B" #3: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0x2310b106 <0xe93161bd xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | close_any(fd@24) (in release_whack() at state.c:654) | resume sending helper answer for #3 suppresed complete_v1_state_transition() | #3 spent 1.64 milliseconds in resume sending helper answer | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e78001f78 | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00372 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00201 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00193 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | dup_any(fd@16) -> fd@23 (in whack_process() at rcv_whack.c:590) | FOR_EACH_CONNECTION_... in conn_by_name | start processing: connection "TUNNEL-C" (in initiate_a_connection() at initiate.c:186) | empty esp_info, returning defaults for ENCRYPT | connection 'TUNNEL-C' +POLICY_UP | dup_any(fd@23) -> fd@24 (in initiate_a_connection() at initiate.c:342) | FOR_EACH_STATE_... in find_phase1_state | creating state object #4 at 0x5596176eeb18 | State DB: adding IKEv1 state #4 in UNDEFINED | pstats #4 ikev1.ipsec started | duplicating state object #1 "TUNNEL-A" as #4 for IPSEC SA | #4 setting local endpoint to 192.1.2.45:500 from #1.st_localport (in duplicate_state() at state.c:1484) | in connection_discard for connection TUNNEL-A | suspend processing: connection "TUNNEL-C" (in quick_outI1() at ikev1_quick.c:685) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:685) | child state #4: UNDEFINED(ignore) => QUICK_I1(established CHILD SA) "TUNNEL-C" #4: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO {using isakmp#1 msgid:af958306 proposal=defaults pfsgroup=MODP2048} | adding quick_outI1 KE work-order 7 for state #4 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f3e84002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #4 | libevent_malloc: new ptr-libevent@0x7f3e78001f78 size 128 | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in quick_outI1() at ikev1_quick.c:764) | resume processing: connection "TUNNEL-C" (in quick_outI1() at ikev1_quick.c:764) | crypto helper 5 resuming | crypto helper 5 starting work-order 7 for state #4 | stop processing: connection "TUNNEL-C" (in initiate_a_connection() at initiate.c:349) | crypto helper 5 doing build KE and nonce (quick_outI1 KE); request ID 7 | close_any(fd@23) (in initiate_connection() at initiate.c:372) | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.258 milliseconds in whack | crypto helper 5 finished build KE and nonce (quick_outI1 KE); request ID 7 time elapsed 0.001144 seconds | (#4) spent 1.15 milliseconds in crypto helper computing work-order 7: quick_outI1 KE (pcr) | crypto helper 5 sending results from work-order 7 for state #4 to event queue | scheduling resume sending helper answer for #4 | libevent_malloc: new ptr-libevent@0x7f3e7c002888 size 128 | crypto helper 5 waiting (nothing to do) | processing resume sending helper answer for #4 | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 5 replies to request ID 7 | calling continuation function 0x559617387b50 | quick_outI1_continue for #4: calculated ke+nonce, sending I1 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2945811206 (0xaf958306) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | emitting quick defaults using policy none | empty esp_info, returning defaults for ENCRYPT | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ikev1_out_sa pcn: 0 has 1 valid proposals | ikev1_out_sa pcn: 0 pn: 0<1 valid_count: 1 trans_cnt: 2 | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 2 (0x2) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | netlink_get_spi: allocated 0x2605d62c for esp.0@192.1.2.45 | emitting 4 raw bytes of SPI into ISAKMP Proposal Payload | SPI 26 05 d6 2c | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_T (0x3) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | emitting length of ISAKMP Transform Payload (ESP): 32 | *****emit ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ESP transform number: 1 (0x1) | ESP transform ID: ESP_3DES (0x3) | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is ISAKMP_NEXT_T (0x3) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******emit ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | emitting length of ISAKMP Transform Payload (ESP): 28 | emitting length of ISAKMP Proposal Payload: 72 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ESP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 84 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | next payload chain: ignoring supplied 'ISAKMP Nonce Payload'.'next payload type' value 4:ISAKMP_NEXT_KE | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Ni into ISAKMP Nonce Payload | Ni 1a ef 7c 86 71 9b d3 93 4e d5 e9 81 54 5c 96 4e | Ni 34 3d e5 a3 64 d7 82 99 82 d4 a1 3e 57 6e 97 fa | emitting length of ISAKMP Nonce Payload: 36 | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value 52 12 7f 71 42 a7 43 2f c4 17 ac d0 0c 83 b2 cf | keyex value af 08 5f 52 07 a0 ec 78 9c d2 10 28 30 11 be 33 | keyex value 0e ed 83 d5 6c 13 06 18 e9 60 92 13 d8 e1 37 0a | keyex value 44 05 04 a3 3f 52 d7 7d 42 9a 23 31 73 af 38 b2 | keyex value 97 59 e4 fc 80 cd 06 8f a8 ab 10 59 ef 7b 9d 23 | keyex value 04 d9 d7 ca 5d 5d b0 65 17 77 ab b1 22 7c 14 e5 | keyex value 4b 00 ec 8b d9 a0 a0 3c 69 18 bd 6a f4 dd 47 05 | keyex value 9b 6b 2c e4 e1 43 0b ed 3a eb f3 83 79 93 44 61 | keyex value ee 3a 74 48 f7 c3 b3 02 51 18 04 cc 7d b5 7c 37 | keyex value 2a b8 f2 c9 1a e7 47 8f ca dd 9a 5e 87 e9 f8 cb | keyex value d9 bd 35 28 35 39 ab 21 56 50 3a b1 ba 87 76 5c | keyex value e9 f6 8d 44 45 eb 53 09 9f 8e b4 97 96 eb 63 15 | keyex value 36 99 0e 4b bb b8 5b 98 97 2b 26 96 bf 1b 48 06 | keyex value 42 74 a7 94 dc 85 4c dc 91 65 3a fc 62 dd 34 d5 | keyex value 15 29 0d 03 e0 4a 19 6c ab 42 65 78 84 02 8c 0b | keyex value db 16 a5 bc e8 e6 18 16 8b 57 b3 ec 37 98 70 fc | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 5:ISAKMP_NEXT_ID | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of client network into ISAKMP Identification Payload (IPsec DOI) | client network c0 00 01 fe | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 4 raw bytes of client network into ISAKMP Identification Payload (IPsec DOI) | client network c0 00 02 ea | emitting length of ISAKMP Identification Payload (IPsec DOI): 12 | outI1 HASH(1): | b2 0f c5 e3 9e 1a a3 8a 55 ae ee 98 fe 16 e9 94 | d7 7a c2 80 d1 4a e0 55 ce e4 12 dc 94 27 1d db | emitting 8 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 476 | sending 476 bytes for reply packet from quick_outI1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #4) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 af 95 83 06 00 00 01 dc ba 77 0e 5c | f4 5c 31 5e ac 7c 4c 33 7f 07 f6 63 47 48 7a 2d | fc de f0 40 22 31 c5 f7 cd 25 ce ab 22 3d 0e e8 | c6 ec 28 2c 42 5d 67 4b 5a d2 46 84 cd f9 83 57 | cf c6 6a 92 d7 8a ba 0b f9 da 0f 5b b9 93 2b ad | 88 ae 62 e1 33 cd 9c 32 91 64 4b 47 70 77 7d 0c | 95 40 ef 14 56 25 56 3b 46 79 d2 71 e9 1a c5 6d | 6b 83 17 49 ca 0f 14 ec 80 d0 a5 12 12 9e 40 bc | 2e bc b5 51 8f 1e 3f 0c 8c 26 b5 bb 4a 71 2c 86 | 90 19 9f 19 25 ec bb b3 8a 8b d0 49 83 91 a6 5b | 11 28 ef bb c9 4f 3d 3e 8f aa 8a f8 d2 b8 e0 b2 | e6 4d 58 54 10 41 5c e6 f9 c9 a3 32 4d fe 26 5e | 51 f3 c9 1d 76 5a 46 72 2c 22 26 6e df 0b 77 8d | a4 87 6f a5 91 a7 d2 0a 43 79 53 f4 f2 db 14 95 | d8 76 08 12 f6 08 b0 3d b8 5f 25 09 fa e6 a0 6d | 96 28 dd 6e aa 45 f4 50 bf 0f 3c 61 4c c4 16 f9 | ec b0 52 2d bc 16 a3 fc 37 97 46 bf d8 9a 65 02 | 6a 85 5e 98 14 59 9e ff d6 20 b1 cf e0 d7 5e e0 | e0 9e a9 a7 de 6f 7a 21 62 af cf 47 08 fe 26 65 | d4 e8 1c 1a e3 f9 77 b5 ed f7 89 8f 07 2b 95 3f | 9f 65 04 96 79 87 c0 3c 3c dd 45 d4 68 de c8 17 | eb f4 34 1d d3 c5 8f 7b 04 a5 52 c5 26 6d 23 4b | fd 3a 5a da fb 7d ac 8d 4c 24 13 6f 0f 2e 3b 93 | 2f a5 b4 bf 40 df 7a 9c f4 e8 3e e0 b3 3f 99 9d | f0 10 df b7 a2 a6 44 a0 e8 87 84 74 a0 01 02 36 | fe 81 11 0e 5d 50 e4 74 4c 5b 47 47 9b e0 1c c8 | 9c 69 11 d3 75 63 91 4b 70 76 33 c0 47 69 ef da | a5 28 be 2b d2 1a 89 48 ed 29 d0 39 57 0e 59 a2 | 83 3a d6 5f 7e 88 e7 2a 53 5b 14 68 | state #4 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f3e78001f78 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f3e84002b78 "TUNNEL-C" #4: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x7f3e84002b78 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #4 | libevent_malloc: new ptr-libevent@0x5596176dd778 size 128 | #4 STATE_QUICK_I1: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11182.403962 | resume sending helper answer for #4 suppresed complete_v1_state_transition() | #4 spent 0.728 milliseconds in resume sending helper answer | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e7c002888 | spent 0.00709 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 444 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 af 95 83 06 00 00 01 bc 81 05 12 11 | 70 6d 7a ad 63 67 b1 c6 46 84 15 a5 a4 d7 80 e4 | 0e 72 d6 b4 24 71 2d 9b d5 53 59 af 26 a2 14 cd | 6e db 51 88 db b6 f5 c3 33 3e 2c d3 7b 6e 9b 0d | 95 b8 e0 0b 57 26 7d d3 ad 21 19 0f ae 99 f5 48 | a6 f4 19 7a 89 ed e4 dc 70 b2 d8 30 df 87 0f 70 | 37 58 ad 30 3b 3b 8c 05 c2 25 c9 68 5c 81 cc 91 | 77 63 aa 23 e5 24 ad 1e cf e6 6a 62 80 be 89 fb | 71 23 15 8b 37 a5 a1 35 6b 44 ad 94 28 79 73 16 | 7a 3c aa 01 1c ef 03 69 8f 56 b2 9b 9d bd 77 7b | 9b 85 fc 36 ee 1e 52 08 42 bd 5e a6 94 9e 75 28 | c0 27 d1 3c 5a 95 5d 07 2c ca 83 5d e2 59 d3 41 | 88 01 8b e2 00 82 8f 3c 63 b9 a9 3a aa 4f 3f be | a4 8f b9 7c 82 f9 29 af 0b 26 1e 2f 17 b9 45 1b | 60 ba b7 6a c1 cc 23 75 48 d3 30 ad e9 b3 24 cf | 69 c8 4d 8f 4a 53 ae d3 21 37 3c 15 94 62 fd a3 | 70 81 d4 09 4c d1 7e 6f c3 05 d0 40 33 e5 de 4d | bb da 6e 37 92 97 3d be 9f 39 6d f6 ab 22 4a 90 | c8 c7 af 9e 69 16 be 82 ca cc b6 27 45 40 0b 80 | 50 59 60 9c c6 77 f5 bf a2 7a 47 b2 e9 46 b0 e5 | 2b 16 51 13 2f 8b f5 4f 5a 03 85 d0 c8 44 43 0f | 6b b2 71 fe 36 d2 4d 89 51 96 e4 08 53 0c 8c d7 | d9 e8 94 32 40 47 f8 45 32 d3 14 ad 34 08 df 4c | e3 3c 47 87 66 1f 92 15 c8 da 17 ad 03 77 7a 7b | 15 9f 58 a2 1f 71 ef a1 41 9e 58 ac 50 98 c6 43 | aa a2 be 0a bd 1e d6 87 aa cd 38 4e 81 99 f1 ab | 1b 31 27 cc 4b ea fb 09 4b 98 32 d2 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2945811206 (0xaf958306) | length: 444 (0x1bc) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_QUICK (32) | State DB: found IKEv1 state #4 in QUICK_I1 (find_state_ikev1) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1633) | #4 is idle | #4 idle | received encrypted packet from 192.1.2.23:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x502 opt: 0x200030 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_SA (0x1) | length: 36 (0x24) | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x402 opt: 0x200030 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 56 (0x38) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x200030 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_KE (0x4) | length: 36 (0x24) | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_ID (0x5) | length: 260 (0x104) | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_ID (0x5) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 01 fe | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x0 opt: 0x200030 | ***parse ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 12 (0xc) | ID type: ID_IPV4_ADDR (0x1) | Protocol ID: 0 (0x0) | port: 0 (0x0) | obj: c0 00 02 ea | removing 4 bytes of padding | quick_inR1_outI2 HASH(2): | c2 e6 4b 4b 06 45 46 62 0d f5 28 7c c4 6f fb c0 | a4 ea f6 7d b5 38 e3 76 4a 93 3f f8 80 a6 82 0f | received 'quick_inR1_outI2' message HASH(2) data ok | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 44 (0x2c) | proposal number: 0 (0x0) | protocol ID: PROTO_IPSEC_ESP (0x3) | SPI size: 4 (0x4) | number of transforms: 1 (0x1) | parsing 4 raw bytes of ISAKMP Proposal Payload into SPI | SPI 58 b8 5b c4 | *****parse ISAKMP Transform Payload (ESP): | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 32 (0x20) | ESP transform number: 0 (0x0) | ESP transform ID: ESP_AES (0xc) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+GROUP_DESCRIPTION (0x8003) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+ENCAPSULATION_MODE (0x8004) | length/value: 1 (0x1) | [1 is ENCAPSULATION_MODE_TUNNEL] | NAT-T non-encap: Installing IPsec SA without ENCAP, st->hidden_variables.st_nat_traversal is none | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_TYPE (0x8001) | length/value: 1 (0x1) | [1 is SA_LIFE_TYPE_SECONDS] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+SA_LIFE_DURATION (variable length) (0x8002) | length/value: 28800 (0x7080) | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+AUTH_ALGORITHM (0x8005) | length/value: 2 (0x2) | [2 is AUTH_ALGORITHM_HMAC_SHA1] | ******parse ISAKMP IPsec DOI attribute: | af+type: AF+KEY_LENGTH (0x8006) | length/value: 128 (0x80) | ESP IPsec Transform verified unconditionally; no alg_info to check against | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding quick outI2 DH work-order 8 for state #4 | state #4 requesting EVENT_RETRANSMIT to be deleted | #4 STATE_QUICK_I1: retransmits: cleared | libevent_free: release ptr-libevent@0x5596176dd778 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f3e84002b78 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f3e84002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #4 | libevent_malloc: new ptr-libevent@0x7f3e7c002888 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #4 and saving MD | #4 is busy; has a suspended MD | #4 spent 0.304 milliseconds in process_packet_tail() | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.754 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 0 resuming | crypto helper 0 starting work-order 8 for state #4 | crypto helper 0 doing compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 8 | crypto helper 0 finished compute dh (V1 Phase 2 PFS) (quick outI2 DH); request ID 8 time elapsed 0.001563 seconds | (#4) spent 1.56 milliseconds in crypto helper computing work-order 8: quick outI2 DH (pcr) | crypto helper 0 sending results from work-order 8 for state #4 to event queue | scheduling resume sending helper answer for #4 | libevent_malloc: new ptr-libevent@0x7f3e900027d8 size 128 | crypto helper 0 waiting (nothing to do) | processing resume sending helper answer for #4 | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in resume_handler() at server.c:797) | crypto helper 0 replies to request ID 8 | calling continuation function 0x559617387b50 | quick_inR1_outI2_continue for #4: calculated ke+nonce, calculating DH | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_QUICK (0x20) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2945811206 (0xaf958306) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 01 fe | our client is 192.0.1.254/32 | our client protocol/port is 0/0 | parsing 4 raw bytes of ISAKMP Identification Payload (IPsec DOI) into ID address | ID address c0 00 02 ea | peer client is 192.0.2.234/32 | peer client protocol/port is 0/0 | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'reply packet' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | quick_inR1_outI2 HASH(3): | a8 f4 9b 50 32 59 7e b3 4c ce 5b 42 b8 03 20 34 | ac c7 b7 e9 8e ef 5a 74 b2 24 78 7e d7 71 8a ae | compute_proto_keymat: needed_len (after ESP enc)=16 | compute_proto_keymat: needed_len (after ESP auth)=36 | install_ipsec_sa() for #4: inbound and outbound | could_route called for TUNNEL-C (kind=CK_PERMANENT) | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: NULL; eroute owner: NULL | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-C' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.58b85bc4@192.1.2.23 included non-error error | set up outgoing SA, ref=0/0 | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA1_96 | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 | st->st_esp.keymat_len=36 is encrypt_keymat_size=16 + integ_keymat_size=20 | setting IPsec SA replay-window to 32 | NIC esp-hw-offload not for connection 'TUNNEL-C' not available on interface eth1 | netlink: enabling tunnel mode | netlink: setting IPsec SA replay-window to 32 using old-style req | netlink: esp-hw-offload not set for IPsec SA | netlink response for Add SA esp.2605d62c@192.1.2.45 included non-error error | priority calculation of connection "TUNNEL-C" is 0xfdfdf | add inbound eroute 192.0.2.234/32:0 --0-> 192.0.1.254/32:0 => tun.10000@192.1.2.45 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | set up incoming SA, ref=0/0 | sr for #4: unrouted | route_and_eroute() for proto 0, and source port 0 dest port 0 | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: NULL; eroute owner: NULL | route_and_eroute with c: TUNNEL-C (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #4 | priority calculation of connection "TUNNEL-C" is 0xfdfdf | eroute_connection add eroute 192.0.1.254/32:0 --0-> 192.0.2.234/32:0 => tun.0@192.1.2.23 (raw_eroute) | IPsec Sa SPD priority set to 1040351 | raw_eroute result=success | running updown command "ipsec _updown" for verb up | command executing up-client | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_ | popen cmd is 1295 chars long | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INT: | cmd( 80):ERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=C: | cmd( 160):A, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libre: | cmd( 240):swan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PL: | cmd( 320):UTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_: | cmd( 400):PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_: | cmd( 480):PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Te: | cmd( 560):st Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org': | cmd( 640): PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO_PE: | cmd( 720):ER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: | cmd( 800):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+E: | cmd( 880):NCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' P: | cmd( 960):LUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_: | cmd(1040):IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BA: | cmd(1120):NNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IF: | cmd(1200):ACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x58b85bc4 SPI_OUT=0x2605d62c ips: | cmd(1280):ec _updown 2>&1: | route_and_eroute: firewall_notified: true | running updown command "ipsec _updown" for verb prepare | command executing prepare-client | executing prepare-client: PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANE | popen cmd is 1300 chars long | cmd( 0):PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.: | cmd( 240):libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' P: | cmd( 480):LUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, : | cmd( 560):OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan: | cmd( 640):.org' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLU: | cmd( 720):TO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0: | cmd( 800):' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSA: | cmd( 880):SIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_: | cmd( 960):NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 P: | cmd(1040):LUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PE: | cmd(1120):ER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' V: | cmd(1200):TI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x58b85bc4 SPI_OUT=0x2605d62: | cmd(1280):c ipsec _updown 2>&1: | running updown command "ipsec _updown" for verb route | command executing route-client | executing route-client: PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' | popen cmd is 1298 chars long | cmd( 0):PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_: | cmd( 80):INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID=': | cmd( 160):C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.li: | cmd( 240):breswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32': | cmd( 320): PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_: | cmd( 400):MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLU: | cmd( 480):TO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU: | cmd( 560):=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.o: | cmd( 640):rg' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO: | cmd( 720):_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' : | cmd( 800):PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASI: | cmd( 880):G+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO: | cmd( 960):' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLU: | cmd(1040):TO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER: | cmd(1120):_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI: | cmd(1200):_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x58b85bc4 SPI_OUT=0x2605d62c : | cmd(1280):ipsec _updown 2>&1: | route_and_eroute: instance "TUNNEL-C", setting eroute_owner {spd=0x5596176cafc8,sr=0x5596176cafc8} to #4 (was #0) (newest_ipsec_sa=#0) | #1 spent 3.4 milliseconds in install_ipsec_sa() | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 76 | inR1_outI2: instance TUNNEL-C[0], setting IKEv1 newest_ipsec_sa to #4 (was #0) (spd.eroute=#4) cloned from #1 | DPD: dpd_init() called on IPsec SA | DPD: Peer does not support Dead Peer Detection | complete v1 state transition with STF_OK | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in complete_v1_state_transition() at ikev1.c:2673) | #4 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_QUICK_I1 to state STATE_QUICK_I2 | child state #4: QUICK_I1(established CHILD SA) => QUICK_I2(established CHILD SA) | event_already_set, deleting event | state #4 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x7f3e7c002888 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f3e84002b78 | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | sending 76 bytes for STATE_QUICK_I1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #4) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 20 01 af 95 83 06 00 00 00 4c 17 7f 41 57 | ad 57 85 50 32 cf 98 76 38 37 ce 22 f3 9f c4 17 | f9 4e 38 37 25 2f 8b a1 e8 91 d5 57 9e 9c 21 8b | fc 76 d1 43 bf e8 a5 c4 1f 7c 76 71 | !event_already_set at reschedule | event_schedule: new EVENT_v1_SA_REPLACE_IF_USED-pe@0x7f3e84002b78 | inserting event EVENT_v1_SA_REPLACE_IF_USED, timeout in 27829 seconds for #4 | libevent_malloc: new ptr-libevent@0x5596176e6978 size 128 | pstats #4 ikev1.ipsec established | NAT-T: encaps is 'auto' "TUNNEL-C" #4: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0x58b85bc4 <0x2605d62c xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | close_any(fd@24) (in release_whack() at state.c:654) | resume sending helper answer for #4 suppresed complete_v1_state_transition() | #4 spent 4.07 milliseconds in resume sending helper answer | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e900027d8 | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00536 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00326 milliseconds in signal handler PLUTO_SIGCHLD | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00315 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | FOR_EACH_STATE_... in sort_states | get_sa_info esp.f384cffa@192.1.2.45 | get_sa_info esp.ac88167e@192.1.2.23 | get_sa_info esp.e93161bd@192.1.2.45 | get_sa_info esp.2310b106@192.1.2.23 | get_sa_info esp.2605d62c@192.1.2.45 | get_sa_info esp.58b85bc4@192.1.2.23 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.552 milliseconds in whack | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.0129 milliseconds in global timer EVENT_SHUNT_SCAN | spent 0.00417 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.0167 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00174 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.00693 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00157 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.00606 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_NAT_T_KEEPALIVE | FOR_EACH_STATE_... in nat_traversal_ka_event (for_each_state) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#4) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #4) | ff | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-B | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#3) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #3) | ff | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#2) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #2) | ff | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1577) | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | spent 0.131 milliseconds in global timer EVENT_NAT_T_KEEPALIVE | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.0031 milliseconds in global timer EVENT_SHUNT_SCAN | spent 0.00273 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.011 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00151 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.00611 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00112 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.00523 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_NAT_T_KEEPALIVE | FOR_EACH_STATE_... in nat_traversal_ka_event (for_each_state) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#4) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #4) | ff | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-B | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#3) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #3) | ff | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#2) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #2) | ff | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1577) | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | spent 0.105 milliseconds in global timer EVENT_NAT_T_KEEPALIVE | spent 0.00286 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 792 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 7a 3e ee d8 64 fe 14 54 00 00 00 00 00 00 00 00 | 01 10 02 00 00 00 00 00 00 00 03 18 0d 00 02 84 | 00 00 00 01 00 00 00 01 00 00 02 78 00 01 00 12 | 03 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 01 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 04 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 02 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 06 | 80 03 00 03 80 04 00 0e 80 0e 01 00 03 00 00 24 | 03 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 06 80 03 00 03 80 04 00 0e 80 0e 00 80 | 03 00 00 24 04 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 02 80 03 00 03 80 04 00 0e | 80 0e 01 00 03 00 00 24 05 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 02 80 03 00 03 | 80 04 00 0e 80 0e 00 80 03 00 00 24 06 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 04 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 07 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 04 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 24 08 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 06 80 03 00 03 80 04 00 05 | 80 0e 01 00 03 00 00 24 09 01 00 00 80 0b 00 01 | 80 0c 00 3c 80 01 00 07 80 02 00 06 80 03 00 03 | 80 04 00 05 80 0e 00 80 03 00 00 24 0a 01 00 00 | 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 02 | 80 03 00 03 80 04 00 05 80 0e 01 00 03 00 00 24 | 0b 01 00 00 80 0b 00 01 80 0c 00 3c 80 01 00 07 | 80 02 00 02 80 03 00 03 80 04 00 05 80 0e 00 80 | 03 00 00 20 0c 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 0e | 03 00 00 20 0d 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 0e | 03 00 00 20 0e 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 0e | 03 00 00 20 0f 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 04 80 03 00 03 80 04 00 05 | 03 00 00 20 10 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 06 80 03 00 03 80 04 00 05 | 00 00 00 20 11 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 05 80 02 00 02 80 03 00 03 80 04 00 05 | 0d 00 00 14 40 48 b7 d5 6e bc e8 85 25 e7 de 7f | 00 d6 c2 d3 0d 00 00 14 af ca d7 13 68 a1 f1 c9 | 6b 86 96 fc 77 57 01 00 0d 00 00 14 4a 13 1c 81 | 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 00 14 | 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 9d 56 | 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 | ec 42 7b 1f 00 00 00 14 cd 60 46 43 35 df 21 f8 | 7c fd b2 fc 68 b6 a4 48 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | 00 00 00 00 00 00 00 00 | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 792 (0x318) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: IKEv1 state not found (find_state_ikev1_init) | #null state always idle | got payload 0x2 (ISAKMP_NEXT_SA) needed: 0x2 opt: 0x2080 | ***parse ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 644 (0x284) | DOI: ISAKMP_DOI_IPSEC (0x1) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | length: 20 (0x14) | got payload 0x2000 (ISAKMP_NEXT_VID) needed: 0x0 opt: 0x2080 | ***parse ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 20 (0x14) | message 'main_inI1_outR1' HASH payload not checked early | received Vendor ID payload [FRAGMENTATION] | received Vendor ID payload [Dead Peer Detection] | quirks.qnat_traversal_vid set to=117 [RFC 3947] | received Vendor ID payload [RFC 3947] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] | Ignoring older NAT-T Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] | in statetime_start() with no state | find_host_connection local=192.1.2.45:500 remote=192.1.2.23:500 policy=IKEV1_ALLOW but ignoring ports | find_host_pair: comparing 192.1.2.45:500 to 192.1.2.23:500 but ignoring ports | find_next_host_connection policy=IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (TUNNEL-B) | find_next_host_connection returns TUNNEL-B | find_next_host_connection policy=IKEV1_ALLOW | found policy = RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (TUNNEL-A) | find_next_host_connection returns TUNNEL-A | creating state object #5 at 0x5596176e8cd8 | State DB: adding IKEv1 state #5 in UNDEFINED | pstats #5 ikev1.isakmp started | #5 updating local interface from to 192.1.2.45:500 using md->iface (in update_ike_endpoints() at state.c:2669) | start processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in main_inI1_outR1() at ikev1_main.c:667) | parent state #5: UNDEFINED(ignore) => MAIN_R0(half-open IKE SA) | sender checking NAT-T: enabled; VID 117 | returning NAT-T method NAT_TRAVERSAL_METHOD_IETF_RFC | enabling possible NAT-traversal with method RFC 3947 (NAT-Traversal) "TUNNEL-A" #5: responding to Main Mode | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_SA (0x1) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 1:ISAKMP_NEXT_SA | ***emit ISAKMP Security Association Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | DOI: ISAKMP_DOI_IPSEC (0x1) | next payload chain: ignoring supplied 'ISAKMP Security Association Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Security Association Payload (1:ISAKMP_NEXT_SA) | next payload chain: saving location 'ISAKMP Security Association Payload'.'next payload type' in 'reply packet' | ****parse IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****parse ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 632 (0x278) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 18 (0x12) | *****parse ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_T (0x3) | length: 36 (0x24) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_TYPE (0x800b) | length/value: 1 (0x1) | [1 is OAKLEY_LIFE_SECONDS] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_LIFE_DURATION (variable length) (0x800c) | length/value: 60 (0x3c) | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_ENCRYPTION_ALGORITHM (0x8001) | length/value: 7 (0x7) | [7 is OAKLEY_AES_CBC] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_HASH_ALGORITHM (0x8002) | length/value: 4 (0x4) | [4 is OAKLEY_SHA2_256] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_AUTHENTICATION_METHOD (0x8003) | length/value: 3 (0x3) | [3 is OAKLEY_RSA_SIG] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_GROUP_DESCRIPTION (0x8004) | length/value: 14 (0xe) | [14 is OAKLEY_GROUP_MODP2048] | ******parse ISAKMP Oakley attribute: | af+type: AF+OAKLEY_KEY_LENGTH (0x800e) | length/value: 256 (0x100) | OAKLEY proposal verified unconditionally; no alg_info to check against | Oakley Transform 0 accepted | ****emit IPsec DOI SIT: | IPsec DOI SIT: SIT_IDENTITY_ONLY (0x1) | ****emit ISAKMP Proposal Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | proposal number: 0 (0x0) | protocol ID: PROTO_ISAKMP (0x1) | SPI size: 0 (0x0) | number of transforms: 1 (0x1) | last substructure: saving location 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' | *****emit ISAKMP Transform Payload (ISAKMP): | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP transform number: 0 (0x0) | ISAKMP transform ID: KEY_IKE (0x1) | last substructure: saving location 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' | emitting 28 raw bytes of attributes into ISAKMP Transform Payload (ISAKMP) | attributes 80 0b 00 01 80 0c 00 3c 80 01 00 07 80 02 00 04 | attributes 80 03 00 03 80 04 00 0e 80 0e 01 00 | emitting length of ISAKMP Transform Payload (ISAKMP): 36 | emitting length of ISAKMP Proposal Payload: 44 | last substructure: checking 'ISAKMP Proposal Payload'.'ISAKMP Transform Payload (ISAKMP)'.'next payload type' is 0 | emitting length of ISAKMP Security Association Payload: 56 | last substructure: checking 'ISAKMP Security Association Payload'.'ISAKMP Proposal Payload'.'next payload type' is 0 | out_vid(): sending [FRAGMENTATION] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_VID (0xd) | next payload chain: ignoring supplied 'ISAKMP Vendor ID Payload'.'next payload type' value 13:ISAKMP_NEXT_VID | next payload chain: setting previous 'ISAKMP Security Association Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 40 48 b7 d5 6e bc e8 85 25 e7 de 7f 00 d6 c2 d3 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [Dead Peer Detection] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 | emitting length of ISAKMP Vendor ID Payload: 20 | out_vid(): sending [RFC 3947] | ***emit ISAKMP Vendor ID Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Vendor ID Payload'.'next payload type' to current ISAKMP Vendor ID Payload (13:ISAKMP_NEXT_VID) | next payload chain: saving location 'ISAKMP Vendor ID Payload'.'next payload type' in 'reply packet' | emitting 16 raw bytes of V_ID into ISAKMP Vendor ID Payload | V_ID 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | emitting length of ISAKMP Vendor ID Payload: 20 | no IKEv1 message padding required | emitting length of ISAKMP Message: 144 | complete v1 state transition with STF_OK | [RE]START processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in complete_v1_state_transition() at ikev1.c:2673) | #5 is idle | doing_xauth:no, t_xauth_client_done:no | peer supports fragmentation | peer supports DPD | IKEv1: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1 | parent state #5: MAIN_R0(half-open IKE SA) => MAIN_R1(open IKE SA) | event_already_set, deleting event | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | sending 144 bytes for STATE_MAIN_R0 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 01 10 02 00 00 00 00 00 00 00 00 90 0d 00 00 38 | 00 00 00 01 00 00 00 01 00 00 00 2c 00 01 00 01 | 00 00 00 24 00 01 00 00 80 0b 00 01 80 0c 00 3c | 80 01 00 07 80 02 00 04 80 03 00 03 80 04 00 0e | 80 0e 01 00 0d 00 00 14 40 48 b7 d5 6e bc e8 85 | 25 e7 de 7f 00 d6 c2 d3 0d 00 00 14 af ca d7 13 | 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 00 00 00 14 | 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f | !event_already_set at reschedule | event_schedule: new EVENT_SO_DISCARD-pe@0x7f3e7c002b78 | inserting event EVENT_SO_DISCARD, timeout in 60 seconds for #5 | libevent_malloc: new ptr-libevent@0x7f3e900027d8 size 128 "TUNNEL-A" #5: STATE_MAIN_R1: sent MR1, expecting MI2 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.459 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00203 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 396 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | 72 00 a6 90 bb 47 cf e3 82 52 93 43 d3 93 44 76 | 37 19 13 c7 95 fd 00 29 5f a9 11 8a 7c 73 ad d7 | dc a7 5a 8e 3e d1 cd ef f3 56 e3 9f cd 76 5f 0a | 34 31 a4 3d 3c 63 16 19 1a a9 28 8e d2 9a ef 7a | 18 01 ec 8d 65 34 a7 8e 5e 35 50 91 98 b4 2f 03 | 67 a4 9a 4e b8 10 5e 58 5c f6 46 7f 26 eb 44 c8 | f2 7c 19 be 0e 46 e8 40 2f 3f 7d 05 b3 5f 29 c7 | ec 6a c6 56 29 7c 6b af 35 55 41 79 d1 82 ba cb | 17 57 cb 6e a9 b0 a2 89 b9 9e 22 a3 af b9 d0 ad | 12 be 27 01 94 da f6 be 70 36 30 59 f6 73 d4 83 | 94 1b 30 0c be 9c cf 7d 58 4c 09 9e 2c 34 1d 61 | e9 d7 9c 24 ee 8a 41 69 d4 13 f4 4c 08 fd da 70 | 60 a3 3e c9 6a 42 8b fa df 5c 30 7d dc f0 94 0f | 60 0f b7 a7 cb 11 5b 19 95 ef ca 2d 18 38 73 01 | 1c b0 29 58 80 d8 fc 4c 1e 71 76 9b 82 6c b2 31 | da dd c7 70 7c d7 02 1a 2a 50 70 58 0b 7c ba 13 | 14 00 00 24 fd 29 12 2e ca 58 1d 2b d6 ce af 60 | 38 ee c6 4a fd da 0f b7 bb a3 78 06 b0 60 24 94 | 7c 8c 30 e7 14 00 00 24 f0 c8 e4 b4 19 d1 3c 20 | da 9d 32 e8 6d 48 38 93 e8 f5 8d 02 e5 0e 9b aa | 5c d0 71 65 a1 8b 17 83 00 00 00 24 f9 1f 2a 23 | a1 68 7b e1 bd 80 68 ae cd bf 8f 98 ac ef f5 82 | c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_KE (0x4) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | length: 396 (0x18c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #5 in MAIN_R1 (find_state_ikev1) | start processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in process_v1_packet() at ikev1.c:1459) | #5 is idle | #5 idle | got payload 0x10 (ISAKMP_NEXT_KE) needed: 0x410 opt: 0x102080 | ***parse ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | length: 260 (0x104) | got payload 0x400 (ISAKMP_NEXT_NONCE) needed: 0x400 opt: 0x102080 | ***parse ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | length: 36 (0x24) | got payload 0x100000 (ISAKMP_NEXT_NATD_RFC) needed: 0x0 opt: 0x102080 | ***parse ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 36 (0x24) | message 'main_inI2_outR2' HASH payload not checked early | init checking NAT-T: enabled; RFC 3947 (NAT-Traversal) | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | natd_hash: hash= e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | natd_hash: hash= ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | expected NAT-D(me): f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | expected NAT-D(me): e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | expected NAT-D(him): | f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | received NAT-D: f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | received NAT-D: e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | received NAT-D: f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | received NAT-D: ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | NAT_TRAVERSAL encaps using auto-detect | NAT_TRAVERSAL this end is NOT behind NAT | NAT_TRAVERSAL that end is NOT behind NAT | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.23 | NAT-Traversal: Result using RFC 3947 (NAT-Traversal) sender port 500: no NAT detected | NAT_T_WITH_KA detected | adding inI2_outR2 KE work-order 9 for state #5 | state #5 requesting EVENT_SO_DISCARD to be deleted | libevent_free: release ptr-libevent@0x7f3e900027d8 | free_event_entry: release EVENT_SO_DISCARD-pe@0x7f3e7c002b78 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f3e7c002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #5 | libevent_malloc: new ptr-libevent@0x5596176e9dd8 size 128 | complete v1 state transition with STF_SUSPEND | [RE]START processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in complete_v1_state_transition() at ikev1.c:2648) | suspending state #5 and saving MD | #5 is busy; has a suspended MD | #5 spent 0.0797 milliseconds in process_packet_tail() | crypto helper 1 resuming | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | crypto helper 1 starting work-order 9 for state #5 | stop processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | crypto helper 1 doing build KE and nonce (inI2_outR2 KE); request ID 9 | spent 0.188 milliseconds in comm_handle_cb() reading and processing packet | crypto helper 1 finished build KE and nonce (inI2_outR2 KE); request ID 9 time elapsed 0.00087 seconds | (#5) spent 0.879 milliseconds in crypto helper computing work-order 9: inI2_outR2 KE (pcr) | crypto helper 1 sending results from work-order 9 for state #5 to event queue | scheduling resume sending helper answer for #5 | libevent_malloc: new ptr-libevent@0x7f3e88004fd8 size 128 | crypto helper 1 waiting (nothing to do) | processing resume sending helper answer for #5 | start processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in resume_handler() at server.c:797) | crypto helper 1 replies to request ID 9 | calling continuation function 0x559617387b50 | main_inI2_outR2_continue for #5: calculated ke+nonce, sending R2 | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: none (0x0) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Key Exchange Payload: | next payload type: ISAKMP_NEXT_NONCE (0xa) | next payload chain: ignoring supplied 'ISAKMP Key Exchange Payload'.'next payload type' value 10:ISAKMP_NEXT_NONCE | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Key Exchange Payload (4:ISAKMP_NEXT_KE) | next payload chain: saving location 'ISAKMP Key Exchange Payload'.'next payload type' in 'reply packet' | emitting 256 raw bytes of keyex value into ISAKMP Key Exchange Payload | keyex value a1 44 47 96 63 aa 6d b2 d9 3b b6 c3 df 4f 20 eb | keyex value cb 86 40 67 d5 b7 94 ab 41 61 f4 e3 ba d5 c3 52 | keyex value 6d 85 e0 dc bf cb 07 33 99 c6 db f6 64 d8 75 36 | keyex value ad 1b 33 f5 53 11 9f c9 1e 30 92 18 97 c5 fe d2 | keyex value f7 77 e7 6f 6b 11 96 48 29 20 d3 d7 ed d1 0a 03 | keyex value f3 2a 41 b3 fa d5 65 c3 bd 1a bd 19 3e 25 5a 53 | keyex value 84 ab eb 40 9c cd 00 ed 47 f1 e3 46 d8 f1 73 f9 | keyex value 90 a2 f7 10 f1 ee e2 bd 15 f5 58 1a 7b 8a 45 90 | keyex value 7a c8 36 fe 2c a5 0b 5f db 02 4e 29 6b 99 a0 42 | keyex value e9 a7 c6 14 4f 68 6f fa 48 d8 1f f2 f0 9f d5 28 | keyex value 3b 08 25 2e 0a 6d 82 d1 85 de f2 ed 36 a4 5b 3e | keyex value d7 c7 c1 ad 55 55 b9 ff c5 8a 32 1f 55 e9 33 5a | keyex value 1d 68 04 3d 93 fd 79 fe f0 99 63 fe ec bb 26 a1 | keyex value 04 c4 7a e0 66 bb ce a9 e0 7e 17 89 4d d6 72 20 | keyex value 3c d9 a2 c7 ab 48 cb 82 47 c9 04 2a 13 8b 01 da | keyex value 11 9c 26 ab f5 09 96 3c 5f 95 14 8a 68 9b 27 2b | emitting length of ISAKMP Key Exchange Payload: 260 | ***emit ISAKMP Nonce Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Key Exchange Payload'.'next payload type' to current ISAKMP Nonce Payload (10:ISAKMP_NEXT_NONCE) | next payload chain: saving location 'ISAKMP Nonce Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of Nr into ISAKMP Nonce Payload | Nr 1e d8 ac 0c 47 18 82 5e c4 b0 b1 43 b8 51 90 14 | Nr 2e d0 e2 11 45 4e 26 b2 14 a1 99 83 34 b4 6a 9a | emitting length of ISAKMP Nonce Payload: 36 | sending NAT-D payloads | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 17 | natd_hash: port=500 | natd_hash: hash= f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | natd_hash: hash= ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NATD_RFC (0x14) | next payload chain: ignoring supplied 'ISAKMP NAT-D Payload'.'next payload type' value 20:ISAKMP_NEXT_NATD_RFC | next payload chain: setting previous 'ISAKMP Nonce Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D f9 1f 2a 23 a1 68 7b e1 bd 80 68 ae cd bf 8f 98 | NAT-D ac ef f5 82 c6 80 31 e3 d8 0a ec eb 67 7a 29 39 | emitting length of ISAKMP NAT-D Payload: 36 | natd_hash: hasher=0x55961745cca0(32) | natd_hash: icookie= 7a 3e ee d8 64 fe 14 54 | natd_hash: rcookie= d3 7b 19 72 3b a4 45 7b | natd_hash: ip= c0 01 02 2d | natd_hash: port=500 | natd_hash: hash= f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | natd_hash: hash= e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | ***emit ISAKMP NAT-D Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP NAT-D Payload'.'next payload type' to current ISAKMP NAT-D Payload (20:ISAKMP_NEXT_NATD_RFC) | next payload chain: saving location 'ISAKMP NAT-D Payload'.'next payload type' in 'reply packet' | emitting 32 raw bytes of NAT-D into ISAKMP NAT-D Payload | NAT-D f0 c8 e4 b4 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 | NAT-D e8 f5 8d 02 e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | emitting length of ISAKMP NAT-D Payload: 36 | no IKEv1 message padding required | emitting length of ISAKMP Message: 396 | main inI2_outR2: starting async DH calculation (group=14) | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | actually looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_PSK | line 0: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | line 1: key type PKK_PSK(C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org) to type PKK_RSA | concluding with best_match=000 best=(nil) (lineno=-1) | no PreShared Key Found | adding main_inI2_outR2_tail work-order 10 for state #5 | state #5 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5596176e9dd8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f3e7c002b78 | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x7f3e7c002b78 | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #5 | libevent_malloc: new ptr-libevent@0x5596176efba8 size 128 | #5 main_inI2_outR2_continue1_tail:1165 st->st_calculating = FALSE; | complete v1 state transition with STF_OK | [RE]START processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in complete_v1_state_transition() at ikev1.c:2673) | #5 is idle; has background offloaded task | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2 | parent state #5: MAIN_R1(open IKE SA) => MAIN_R2(open IKE SA) | event_already_set, deleting event | state #5 requesting EVENT_CRYPTO_TIMEOUT to be deleted | libevent_free: release ptr-libevent@0x5596176efba8 | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x7f3e7c002b78 | crypto helper 2 resuming | crypto helper 2 starting work-order 10 for state #5 | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | crypto helper 2 doing compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 10 | sending 396 bytes for STATE_MAIN_R1 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 04 10 02 00 00 00 00 00 00 00 01 8c 0a 00 01 04 | a1 44 47 96 63 aa 6d b2 d9 3b b6 c3 df 4f 20 eb | cb 86 40 67 d5 b7 94 ab 41 61 f4 e3 ba d5 c3 52 | 6d 85 e0 dc bf cb 07 33 99 c6 db f6 64 d8 75 36 | ad 1b 33 f5 53 11 9f c9 1e 30 92 18 97 c5 fe d2 | f7 77 e7 6f 6b 11 96 48 29 20 d3 d7 ed d1 0a 03 | f3 2a 41 b3 fa d5 65 c3 bd 1a bd 19 3e 25 5a 53 | 84 ab eb 40 9c cd 00 ed 47 f1 e3 46 d8 f1 73 f9 | 90 a2 f7 10 f1 ee e2 bd 15 f5 58 1a 7b 8a 45 90 | 7a c8 36 fe 2c a5 0b 5f db 02 4e 29 6b 99 a0 42 | e9 a7 c6 14 4f 68 6f fa 48 d8 1f f2 f0 9f d5 28 | 3b 08 25 2e 0a 6d 82 d1 85 de f2 ed 36 a4 5b 3e | d7 c7 c1 ad 55 55 b9 ff c5 8a 32 1f 55 e9 33 5a | 1d 68 04 3d 93 fd 79 fe f0 99 63 fe ec bb 26 a1 | 04 c4 7a e0 66 bb ce a9 e0 7e 17 89 4d d6 72 20 | 3c d9 a2 c7 ab 48 cb 82 47 c9 04 2a 13 8b 01 da | 11 9c 26 ab f5 09 96 3c 5f 95 14 8a 68 9b 27 2b | 14 00 00 24 1e d8 ac 0c 47 18 82 5e c4 b0 b1 43 | b8 51 90 14 2e d0 e2 11 45 4e 26 b2 14 a1 99 83 | 34 b4 6a 9a 14 00 00 24 f9 1f 2a 23 a1 68 7b e1 | bd 80 68 ae cd bf 8f 98 ac ef f5 82 c6 80 31 e3 | d8 0a ec eb 67 7a 29 39 00 00 00 24 f0 c8 e4 b4 | 19 d1 3c 20 da 9d 32 e8 6d 48 38 93 e8 f5 8d 02 | e5 0e 9b aa 5c d0 71 65 a1 8b 17 83 | !event_already_set at reschedule "TUNNEL-A" #5: IMPAIR: suppressing retransmits; scheduling timeout in 60 seconds | event_schedule: new EVENT_RETRANSMIT-pe@0x7f3e7c002b78 | inserting event EVENT_RETRANSMIT, timeout in 60 seconds for #5 | libevent_malloc: new ptr-libevent@0x5596176efba8 size 128 | #5 STATE_MAIN_R2: retransmits: first event in 60 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 11241.171031 "TUNNEL-A" #5: STATE_MAIN_R2: sent MR2, expecting MI3 | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | resume sending helper answer for #5 suppresed complete_v1_state_transition() | #5 spent 0.386 milliseconds in resume sending helper answer | stop processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e88004fd8 | crypto helper 2 finished compute dh+iv (V1 Phase 1) (main_inI2_outR2_tail); request ID 10 time elapsed 0.000778 seconds | (#5) spent 0.783 milliseconds in crypto helper computing work-order 10: main_inI2_outR2_tail (pcr) | crypto helper 2 sending results from work-order 10 for state #5 to event queue | scheduling resume sending helper answer for #5 | libevent_malloc: new ptr-libevent@0x7f3e8c00bcf8 size 128 | crypto helper 2 waiting (nothing to do) | processing resume sending helper answer for #5 | start processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in resume_handler() at server.c:797) | crypto helper 2 replies to request ID 10 | calling continuation function 0x559617387b50 | main_inI2_outR2_calcdone for #5: calculate DH finished | [RE]START processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1015) | stop processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in main_inI2_outR2_continue2() at ikev1_main.c:1028) | resume sending helper answer for #5 suppresed complete_v1_state_transition() | #5 spent 0.0134 milliseconds in resume sending helper answer | processing: STOP state #0 (in resume_handler() at server.c:833) | libevent_free: release ptr-libevent@0x7f3e8c00bcf8 | spent 0.00271 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 1884 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 05 10 02 01 00 00 00 00 00 00 07 5c 9e aa 71 29 | ad 1e e5 00 d4 ad 93 93 8a 03 70 24 fb c4 a7 18 | f6 98 c5 9e aa 43 9f 23 bf cd d6 8d 6c 20 c9 ec | be e2 1b 33 e4 e5 ec 19 b6 31 9e 24 f2 e7 bd f4 | ec 3e 82 d6 42 b2 c8 2f 9e 2b 7b 2b c6 c3 75 e1 | b7 3d 24 a8 22 e0 a2 e3 ad 19 30 57 c9 13 74 08 | 11 26 8f f6 06 92 7d dd 31 62 2a 0e 71 09 92 34 | 3a f6 79 9d d2 53 c7 24 73 51 0a 6e 5d 62 64 e9 | 50 13 bc 9c 78 62 35 63 a6 52 17 1d 91 1e b2 c4 | 90 6a 47 6d 21 ab 04 46 bd 4b 02 11 ad aa 7e d7 | 76 84 fc 5d f6 c3 2c 74 4a c6 06 0b db 02 c8 de | a7 f8 84 bf e4 bb 1b 56 5b f5 58 8b e9 60 ec 09 | b5 8a f0 53 fe 5e 8a aa 07 fd 82 ea 10 20 23 41 | b5 ef 1b a2 25 aa 83 85 50 1c e8 7a 18 1a 64 7c | 85 a4 88 45 75 33 ed ec db 4b fe 6e f9 f1 e8 ea | fb 8b 78 f3 a8 de 08 e2 24 97 fa 1c 9e c4 c9 65 | e0 96 5a 13 67 1c 12 ed 82 89 59 e6 9c 55 49 f3 | a1 12 c4 fe 1d db 9a fd db cb 01 65 e7 6e c1 65 | 4b 49 95 95 8a 63 66 a7 ca 10 a7 9c 0c d9 74 22 | 97 4d cb 5d df 1e 02 06 b1 ed 0e b9 23 c9 1b c5 | d0 bf 11 5c 2f ac d0 c4 b8 4c 9f 65 e3 8f 49 10 | 64 4a 30 b2 5c 53 24 ac ce 90 50 a8 db 2f 8f 43 | 13 25 31 f1 a4 5d 7f 0f fa 2f 4b 52 88 0f 65 96 | 3a a4 d6 ce b1 60 48 42 30 54 c7 1e db 60 5b 6f | 70 3a f7 47 1c cc 9f 2a cd 7f df b7 98 b3 7c 11 | 04 da ab 87 3d 42 8b 9e cf 04 57 51 70 4b 1c 75 | 4c 08 0a b8 46 48 a2 f3 32 d0 45 75 8a 93 38 95 | 6d 4c e6 90 18 85 52 be 3c 26 d3 c4 78 13 28 1e | 91 8c 1f 59 2d 9f 79 00 43 41 93 75 4d 49 e9 a3 | 84 59 a0 8b 8c 49 55 76 93 65 84 2c 2e 76 c9 b5 | 7e 4b f0 74 73 47 12 63 a3 0f e8 87 ff 1c fd c4 | 84 d3 42 bb 24 b5 f3 5e 1e 42 6c c5 5e 04 c9 3d | 86 6e 5b 26 31 81 16 27 92 a7 18 63 a0 35 36 82 | 90 50 98 7e 75 54 da f2 ea e7 66 26 b9 53 36 2a | 75 46 55 86 1f 4d bf e6 cf d2 7b 44 c3 3b 0b 62 | 80 a2 12 3a 34 1d 65 ef 9a e6 7f 6a aa de 2f 57 | 3b c7 dc 41 e5 8a 97 f5 00 9b 9b dc 66 a8 1e 05 | 7a cc 17 20 fa a1 07 e8 c2 bd 0c 80 8d ee b5 dd | 6a 58 d9 6e e3 cd 8d 44 7f 1a 5f 51 f4 cb b7 49 | 16 39 d6 29 c0 57 f4 23 16 08 6d 15 6e b8 ca 97 | 76 da 03 14 bb 32 ba 82 03 bd bf a8 f5 37 3c 4a | 82 61 7e 3a 6e 8a bc 6c 56 18 17 ab dd a3 d0 3f | b3 31 80 7e 2f 70 42 69 8f 29 d0 c0 c6 d5 d4 3a | 8d 0c ad 58 72 16 cd 99 32 9d 2d c4 02 52 c4 2f | 2d 0a d7 f3 a7 71 50 d3 3d f2 41 b2 c5 22 fd bc | 93 7d f6 b8 b7 fc e1 ab 14 71 d2 c8 fa 15 fb 2e | ef 28 d5 a7 8a 8e b4 04 24 81 ac fa f5 36 90 df | 03 6b 61 49 25 2a e5 bb ad 67 d8 9f 76 88 f1 06 | 32 6a 86 79 fc d0 0f d8 8f 0f f9 48 fb f9 e3 f5 | 3e 65 7e f1 5d 2e 00 2f 8f 14 35 38 c3 6d 25 3f | 67 d2 d4 79 e4 ed 5c 3d 03 ab 6d d8 0a b5 38 2e | 4c 3f c3 0f 27 ee d3 20 98 21 7c b6 ff aa 18 42 | 6d 5f fc 0e b3 bb 87 40 c1 b6 bd 99 06 37 e4 88 | 1f ea 0f 03 60 c0 16 89 90 43 f1 90 1c cb 93 25 | 63 8b 7e 3c 59 76 8a 21 89 7b 3a 82 60 76 ed 0f | fe 2a 20 a3 19 3e 12 28 e6 02 85 d4 31 75 27 5d | 5a 46 c0 05 c9 93 69 12 79 22 86 a7 11 70 73 d4 | d6 34 18 45 78 30 f4 e0 f3 64 52 72 f1 6f a4 2c | a7 33 5b f6 1c 8c b9 96 1d 35 ec 04 cd fa 6e e1 | 92 1f c8 01 f6 6e bd c1 79 aa 82 ec fd 5e 50 68 | 20 2e 87 d7 c3 5f b9 a8 58 e1 77 7f 8c b6 c8 fc | 39 78 73 5c fd 53 c8 82 e5 56 d1 12 a5 7f d4 3f | 58 b0 0b c0 b2 f2 55 8e 29 36 cf fd fd ac 22 7e | fd 7e 04 2a 50 39 11 b8 cd b6 20 70 8f 1d c2 9f | 67 49 a3 6e 7f c7 f9 91 dc 49 e1 30 88 90 70 bc | c1 66 3d 70 15 a4 7c 5c 7b c9 b8 c6 b8 74 c7 40 | 06 cf 4d 8a c1 f5 b4 94 9f eb ef 28 f3 a7 38 b6 | 11 fb 86 81 2b 08 9a 6a 15 ec 76 13 3b d6 e7 03 | 9e bc 06 91 66 d3 bf 66 d3 01 db 4f 03 98 06 7b | 5e b4 58 d4 96 51 eb a0 36 2a 08 f2 5b 8f 88 49 | 54 66 53 7a 05 34 8b 6e 3b c2 24 d8 5d 7c a6 c2 | f6 e9 dc 42 1c 32 a8 15 64 15 07 d2 09 12 b4 3d | 1c 52 3f 31 93 de 89 29 40 5d 0c c8 74 64 04 7d | 42 ed 8b 19 e4 cc f4 d4 f1 45 20 32 f5 f8 1d 24 | 79 8c 5f c0 39 68 56 3d 15 e4 02 da d4 ad e1 c8 | 5c aa 4a 24 ca 13 c1 27 01 0a 54 b9 0b 9c 96 8c | d6 c3 92 4e 52 dd 4c af 9e 76 ad 42 68 4f 48 51 | c3 4d 92 d7 4a 5c 9b 92 23 5c cd 0a 71 18 88 07 | d3 c2 3f 13 bc 95 62 d6 21 9d f5 f6 30 60 3e 89 | e8 45 ed 13 3f 8a de 4f e4 0b a5 28 2e 14 e6 70 | 49 a3 48 a4 37 4c 60 e6 d8 4a 5e 53 c7 90 1b f3 | d3 9e e3 39 8d b2 63 16 6b 75 db 12 3e d3 01 9c | f1 12 e6 ab 93 a1 c8 22 15 1f 37 72 09 5a 94 3b | 05 4f 1c 37 39 03 ee 4e 43 a1 55 df 24 a5 1b ea | 79 82 1e 3e 19 07 e2 b1 d9 88 f4 04 71 3e 60 4f | 43 92 cf 6f 34 d5 9a 7c 54 72 49 55 d5 d9 af 0f | b5 cc 3d e0 d4 32 05 4c a9 c8 b6 10 64 a8 51 19 | d7 67 88 ca e7 f9 45 df d9 5d 8b 61 91 ba 46 91 | 7b 2d bd aa de 61 9c 7a b6 9c b6 6f a0 8f 0f 72 | 44 50 84 82 3c 9d 93 60 82 97 30 79 ed 58 3f e6 | 43 30 78 08 3e 40 44 4c fe cd e8 a3 c1 25 71 e4 | 92 eb 7a 51 a1 21 c0 ab 72 e0 24 04 eb b7 9c fd | 89 64 6d f2 94 7a 8b 5f 6d a9 94 00 f3 14 3a bf | 94 bc 27 c8 f9 7f 72 a9 4a 6e bd 17 90 38 da 9f | b5 0a 62 55 89 db a7 18 35 d4 15 65 2b 49 ae 97 | 5f b3 e9 fb 64 ef 2c e7 39 a5 c6 fc e1 bb 88 dd | 80 0f e4 8c 51 f2 31 5a a4 61 32 06 93 b9 d1 9e | 1e 02 31 54 1f d3 8e 63 2f ae c0 f0 ab f8 fb c7 | 93 76 5d 10 b9 4d 61 2e d9 58 fd b4 a8 66 25 f9 | e2 b6 59 f6 6f d2 92 52 7a 97 67 83 3f 43 0b 43 | 61 bb 4c ff 72 cf 21 78 90 b9 9b 3c b0 56 97 9a | 92 0f 37 e7 d9 7a 56 5e d3 1e 47 7a 48 45 17 a2 | 84 ed 09 14 8e cd 3f d7 52 2f b7 45 38 95 24 75 | 6b 9e 7b 05 c1 03 3c 72 0a f9 89 d1 aa 54 79 d5 | b8 93 b5 57 f7 7b 23 d6 08 af b9 50 9e f6 f3 66 | 22 2a 7e a6 53 62 01 84 fb 78 58 88 01 fb 49 46 | 1a cb 14 8f a0 41 d1 18 69 d9 9d be 62 59 79 70 | 22 ca 87 d3 87 30 3e c2 04 9e 23 22 88 24 ad 8f | f7 8b ec 6e ea 0d b7 4a 08 3a c9 35 bc 48 c7 3d | 7b 53 ca d0 84 08 28 7e b0 82 c9 4b c6 59 da fd | 26 b9 83 21 18 06 56 4e 12 8c e4 2d 82 c1 88 fb | 9b c9 49 b6 c6 b9 ea 92 57 13 86 9d a2 44 cb 0f | 65 43 0d 4c 18 f8 a9 85 f2 92 99 11 2d 72 6c 75 | 6f 92 16 9f 70 dc ac b7 64 da dd ba e6 92 ca 88 | 9f 4d 14 05 6d 15 78 12 46 e9 32 fe a5 9d 78 06 | 6b d6 4a f0 70 3c b6 04 59 15 e0 5a ae 4d da 52 | e0 dc 10 6c 0e c4 50 3b 67 7e 25 47 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | length: 1884 (0x75c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_IDPROT (2) | State DB: found IKEv1 state #5 in MAIN_R2 (find_state_ikev1) | start processing: state #5 connection "TUNNEL-A" from 192.1.2.23:500 (in process_v1_packet() at ikev1.c:1459) | #5 is idle | #5 idle | received encrypted packet from 192.1.2.23:500 | got payload 0x20 (ISAKMP_NEXT_ID) needed: 0x220 opt: 0x20c0 | ***parse ISAKMP Identification Payload: | next payload type: ISAKMP_NEXT_CERT (0x6) | length: 191 (0xbf) | ID type: ID_DER_ASN1_DN (0x9) | DOI specific A: 0 (0x0) | DOI specific B: 0 (0x0) | obj: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | obj: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | obj: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | obj: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | obj: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | obj: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | obj: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | obj: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | obj: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | obj: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | obj: 77 61 6e 2e 6f 72 67 | got payload 0x40 (ISAKMP_NEXT_CERT) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_CR (0x7) | length: 1265 (0x4f1) | cert encoding: CERT_X509_SIGNATURE (0x4) | got payload 0x80 (ISAKMP_NEXT_CR) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Certificate RequestPayload: | next payload type: ISAKMP_NEXT_SIG (0x9) | length: 5 (0x5) | cert type: CERT_X509_SIGNATURE (0x4) | got payload 0x200 (ISAKMP_NEXT_SIG) needed: 0x200 opt: 0x20c0 | ***parse ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 388 (0x184) | removing 7 bytes of padding | message 'main_inI3_outR3' HASH payload not checked early | DER ASN1 DN: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | DER ASN1 DN: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | DER ASN1 DN: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | DER ASN1 DN: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "TUNNEL-A" #5: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds | #5 spent 0.00353 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #5 spent 0.0642 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for mainca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #5 spent 0.114 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec | certificate is valid (profile IPsec) | #5 spent 0.0877 milliseconds in find_and_verify_certs() calling verify_end_cert() "TUNNEL-A" #5: certificate verified OK: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176ff8e8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176fef28 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176fed78 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176fe3b8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176fe208 | unreference key: 0x5596176e1888 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | #5 spent 0.224 milliseconds in decode_certs() calling add_pubkey_from_nss_cert() | #5 spent 0.517 milliseconds in decode_certs() | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' needs further ID comparison against 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' matched our ID | SAN ID matched, updating that.cert | X509: CERT and ID matches current connection | CR | requested CA: '%any' | refine_host_connection for IKEv1: starting with "TUNNEL-A" | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-A" against "TUNNEL-B", best=(none) with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-A against TUNNEL-B, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | refine_host_connection: picking new best "TUNNEL-B" (wild=0, peer_pathlen=7/our=0) | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-A" against "TUNNEL-A", best=TUNNEL-B with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-A against TUNNEL-A, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-A" against "TUNNEL-C", best=TUNNEL-B with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-A against TUNNEL-C, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | refine going into 2nd loop allowing instantiated conns as well | returning since no better match than original best_found | offered CA: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' "TUNNEL-A" #5: switched from "TUNNEL-A" to "TUNNEL-B" | in connection_discard for connection TUNNEL-A | retrying ike_decode_peer_id() with new conn | DER ASN1 DN: 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | DER ASN1 DN: 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | DER ASN1 DN: 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | DER ASN1 DN: 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | DER ASN1 DN: 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | DER ASN1 DN: 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | DER ASN1 DN: 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 65 61 73 | DER ASN1 DN: 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | DER ASN1 DN: 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 65 61 73 | DER ASN1 DN: 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | DER ASN1 DN: 77 61 6e 2e 6f 72 67 "TUNNEL-B" #5: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | global one-shot timer EVENT_FREE_ROOT_CERTS scheduled in 300 seconds | #5 spent 0.00269 milliseconds in find_and_verify_certs() calling get_root_certs() | checking for known CERT payloads | saving certificate of type 'X509_SIGNATURE' | decoded cert: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #5 spent 0.0286 milliseconds in find_and_verify_certs() calling decode_cert_payloads() | cert_issuer_has_current_crl: looking for a CRL issued by E=testing@libreswan.org,CN=Libreswan test CA for mainca,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | #5 spent 0.0353 milliseconds in find_and_verify_certs() calling crl_update_check() | missing or expired CRL | crl_strict: 0, ocsp: 0, ocsp_strict: 0, ocsp_post: 0 | verify_end_cert trying profile IPsec | certificate is valid (profile IPsec) | #5 spent 0.0597 milliseconds in find_and_verify_certs() calling verify_end_cert() "TUNNEL-B" #5: certificate verified OK: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA | unreference key: 0x559617700348 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x559617700fd8 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176fff58 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176fe158 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176fd798 | get_pluto_gn_from_nss_cert: allocated pluto_gn 0x5596176ff6f8 | unreference key: 0x5596176ff788 192.1.2.23 cnt 1-- | unreference key: 0x5596176fe258 east@testing.libreswan.org cnt 1-- | unreference key: 0x5596176e9f88 @east.testing.libreswan.org cnt 1-- | unreference key: 0x5596176fb048 user-east@testing.libreswan.org cnt 1-- | unreference key: 0x559617700438 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | #5 spent 0.212 milliseconds in decode_certs() calling add_pubkey_from_nss_cert() | #5 spent 0.359 milliseconds in decode_certs() | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' needs further ID comparison against 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | ID_DER_ASN1_DN 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' matched our ID | SAN ID matched, updating that.cert | X509: CERT and ID matches current connection | CR | requested CA: '%any' | refine_host_connection for IKEv1: starting with "TUNNEL-B" | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-B" against "TUNNEL-B", best=(none) with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-B against TUNNEL-B, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | refine_host_connection: picking new best "TUNNEL-B" (wild=0, peer_pathlen=7/our=0) | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-B" against "TUNNEL-A", best=TUNNEL-B with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-B against TUNNEL-A, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | match_id a=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | b=C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org | results matched | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | refine_host_connection: checking "TUNNEL-B" against "TUNNEL-C", best=TUNNEL-B with match=1(id=1(0)/ca=1(7)/reqca=1(0)) | Warning: not switching back to template of current instance | No IDr payload received from peer | refine_host_connection: checked TUNNEL-B against TUNNEL-C, now for see if best | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | refine going into 2nd loop allowing instantiated conns as well | returning since no better match than original best_found | offered CA: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | required RSA CA is '%any' | checking RSA keyid 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' for match with 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' | trusted_ca_nss: trustee A = 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | key issuer CA is 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' | an RSA Sig check passed with *AwEAAbEef [remote certificates] | #5 spent 0.0955 milliseconds in try_all_RSA_keys() trying a pubkey "TUNNEL-B" #5: Authenticated using RSA | thinking about whether to send my certificate: | I have RSA key: OAKLEY_RSA_SIG cert.type: CERT_X509_SIGNATURE | sendcert: CERT_ALWAYSSEND and I did not get a certificate request | so send cert. | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_ID (0x5) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_IDPROT (0x2) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 0 (0x0) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | next payload chain: ignoring supplied 'ISAKMP Message'.'next payload type' value 5:ISAKMP_NEXT_ID | ***emit ISAKMP Identification Payload (IPsec DOI): | next payload type: ISAKMP_NEXT_CERT (0x6) | ID type: ID_DER_ASN1_DN (0x9) | Protocol ID: 0 (0x0) | port: 0 (0x0) | next payload chain: ignoring supplied 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' value 6:ISAKMP_NEXT_CERT | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Identification Payload (IPsec DOI) (5:ISAKMP_NEXT_ID) | next payload chain: saving location 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' in 'reply packet' | emitting 183 raw bytes of my identity into ISAKMP Identification Payload (IPsec DOI) | my identity 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 43 41 | my identity 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 | my identity 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 | my identity 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c | my identity 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 | my identity 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 | my identity 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 65 73 | my identity 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a 86 48 | my identity 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 65 73 | my identity 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 | my identity 77 61 6e 2e 6f 72 67 | emitting length of ISAKMP Identification Payload (IPsec DOI): 191 "TUNNEL-B" #5: I am sending my cert | ***emit ISAKMP Certificate Payload: | next payload type: ISAKMP_NEXT_SIG (0x9) | cert encoding: CERT_X509_SIGNATURE (0x4) | next payload chain: ignoring supplied 'ISAKMP Certificate Payload'.'next payload type' value 9:ISAKMP_NEXT_SIG | next payload chain: setting previous 'ISAKMP Identification Payload (IPsec DOI)'.'next payload type' to current ISAKMP Certificate Payload (6:ISAKMP_NEXT_CERT) | next payload chain: saving location 'ISAKMP Certificate Payload'.'next payload type' in 'reply packet' | emitting 1260 raw bytes of CERT into ISAKMP Certificate Payload | CERT 30 82 04 e8 30 82 04 51 a0 03 02 01 02 02 01 04 | CERT 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 | CERT 81 ac 31 0b 30 09 06 03 55 04 06 13 02 43 41 31 | CERT 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 61 72 69 | CERT 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 6f 72 6f | CERT 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c 09 4c 69 | CERT 62 72 65 73 77 61 6e 31 18 30 16 06 03 55 04 0b | CERT 0c 0f 54 65 73 74 20 44 65 70 61 72 74 6d 65 6e | CERT 74 31 25 30 23 06 03 55 04 03 0c 1c 4c 69 62 72 | CERT 65 73 77 61 6e 20 74 65 73 74 20 43 41 20 66 6f | CERT 72 20 6d 61 69 6e 63 61 31 24 30 22 06 09 2a 86 | CERT 48 86 f7 0d 01 09 01 16 15 74 65 73 74 69 6e 67 | CERT 40 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 30 22 | CERT 18 0f 32 30 31 39 30 38 32 34 30 39 30 37 35 33 | CERT 5a 18 0f 32 30 32 32 30 38 32 33 30 39 30 37 35 | CERT 33 5a 30 81 b4 31 0b 30 09 06 03 55 04 06 13 02 | CERT 43 41 31 10 30 0e 06 03 55 04 08 0c 07 4f 6e 74 | CERT 61 72 69 6f 31 10 30 0e 06 03 55 04 07 0c 07 54 | CERT 6f 72 6f 6e 74 6f 31 12 30 10 06 03 55 04 0a 0c | CERT 09 4c 69 62 72 65 73 77 61 6e 31 18 30 16 06 03 | CERT 55 04 0b 0c 0f 54 65 73 74 20 44 65 70 61 72 74 | CERT 6d 65 6e 74 31 23 30 21 06 03 55 04 03 0c 1a 77 | CERT 65 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 31 2e 30 2c 06 09 2a | CERT 86 48 86 f7 0d 01 09 01 16 1f 75 73 65 72 2d 77 | CERT 65 73 74 40 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 30 82 01 a2 30 0d 06 | CERT 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 8f | CERT 00 30 82 01 8a 02 82 01 81 00 97 74 bf cb bf e4 | CERT ee 91 0b d4 69 75 82 f9 89 a4 7c 61 ad 72 9f 63 | CERT d0 cb a1 44 70 27 f4 d2 b4 6f 56 97 f1 84 ea 4c | CERT 56 ce 73 39 bf bb e3 7d 19 bb ee d9 e7 3f e9 a3 | CERT ec 1e 7f fa 04 93 a9 f7 14 2b fb 47 74 66 5b 2f | CERT ba 23 9f b2 22 b3 ce 07 5f b7 14 41 a8 53 69 ef | CERT 37 e1 2d 74 09 ef 9b f4 67 d4 33 3b 42 39 c7 68 | CERT 67 08 db 58 d8 23 26 3e 92 ee ff 68 d8 2a 34 08 | CERT 21 ea df 77 b6 5c 62 26 96 f1 23 7f c8 86 ee eb | CERT 94 9e 86 61 b9 da 39 ca 7f f7 10 7c b3 03 d9 6f | CERT 91 e6 ef 40 ed e9 26 c1 c7 ba c4 d6 9b d1 e4 06 | CERT 54 d5 de b4 27 d7 70 a5 60 57 5f ad 31 66 fd 5e | CERT e6 b5 f8 0b 4c ad 97 4b 90 2a 92 25 9d ea 79 62 | CERT c8 36 40 41 ab 5d ae 18 c1 9c 2a 99 3e ad 19 82 | CERT 92 00 bf d9 f0 df 40 43 59 3a 87 2c 2d 96 1d e5 | CERT a8 66 34 2d df d4 0e de cd fa 4d 34 d0 1f 81 f2 | CERT 7a 2e 4c c2 e2 ae c9 df 0c b7 94 23 be b9 23 d9 | CERT ab 34 80 52 c3 61 81 01 b6 04 f3 9b 95 27 59 d1 | CERT f4 c2 a5 01 ab fa 14 fa 5b e2 93 00 fd 52 77 87 | CERT 44 20 37 b7 72 c3 92 ac e2 13 a5 01 a8 72 43 39 | CERT 43 82 fc 82 95 74 22 7a 16 f7 fa 61 86 d0 22 35 | CERT c5 d6 4d ad b8 ef de f7 aa ed e4 dc 17 42 fa 6d | CERT 10 ff c2 4f b1 8b 93 5a 98 68 57 c8 0b 31 f5 49 | CERT c6 00 d4 fc 2b a1 d4 7b 37 31 97 f9 12 31 89 1c | CERT 0a dc ad a3 4b 06 4c e6 90 03 02 03 01 00 01 a3 | CERT 82 01 06 30 82 01 02 30 09 06 03 55 1d 13 04 02 | CERT 30 00 30 47 06 03 55 1d 11 04 40 30 3e 82 1a 77 | CERT 65 73 74 2e 74 65 73 74 69 6e 67 2e 6c 69 62 72 | CERT 65 73 77 61 6e 2e 6f 72 67 81 1a 77 65 73 74 40 | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 87 04 c0 01 02 2d 30 0b 06 03 55 | CERT 1d 0f 04 04 03 02 07 80 30 1d 06 03 55 1d 25 04 | CERT 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b | CERT 06 01 05 05 07 03 02 30 41 06 08 2b 06 01 05 05 | CERT 07 01 01 04 35 30 33 30 31 06 08 2b 06 01 05 05 | CERT 07 30 01 86 25 68 74 74 70 3a 2f 2f 6e 69 63 2e | CERT 74 65 73 74 69 6e 67 2e 6c 69 62 72 65 73 77 61 | CERT 6e 2e 6f 72 67 3a 32 35 36 30 30 3d 06 03 55 1d | CERT 1f 04 36 30 34 30 32 a0 30 a0 2e 86 2c 68 74 74 | CERT 70 3a 2f 2f 6e 69 63 2e 74 65 73 74 69 6e 67 2e | CERT 6c 69 62 72 65 73 77 61 6e 2e 6f 72 67 2f 72 65 | CERT 76 6f 6b 65 64 2e 63 72 6c 30 0d 06 09 2a 86 48 | CERT 86 f7 0d 01 01 0b 05 00 03 81 81 00 5a 67 23 b0 | CERT 7e 6d 1b fc ee 9b 1f bf 83 f2 7f ee 5e 9c 9a d9 | CERT 50 b1 fa 36 e8 9b d1 a0 ed 86 39 a8 ab e3 df 81 | CERT b6 ce aa e6 ce 9f 15 04 03 59 de a4 f5 8b bd 05 | CERT 79 82 a5 ca 1b dd d5 d9 8f e4 62 19 1f 75 9e 8b | CERT 8b c6 ed b7 26 83 a8 15 16 64 a8 60 bf d4 c6 f6 | CERT 40 f9 e1 b2 d9 a2 fa 48 87 d5 07 80 36 d3 c8 53 | CERT 3f a8 cd 6a 53 7a d6 14 2c 4a cb 91 8e 53 79 3b | CERT c7 82 ad 80 1c 13 54 12 a2 86 ea 29 | emitting length of ISAKMP Certificate Payload: 1265 | started looking for secret for C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org->C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org of kind PKK_RSA | searching for certificate PKK_RSA:AwEAAZd0v vs PKK_RSA:AwEAAZd0v | ***emit ISAKMP Signature Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Certificate Payload'.'next payload type' to current ISAKMP Signature Payload (9:ISAKMP_NEXT_SIG) | next payload chain: saving location 'ISAKMP Signature Payload'.'next payload type' in 'reply packet' | emitting 384 raw bytes of SIG_R into ISAKMP Signature Payload | SIG_R 90 75 ec 1e ec 6e c0 76 9a 68 17 07 5c c2 b7 ee | SIG_R 79 d1 66 6f 60 4e c3 9b 5e ea 5d 94 d3 0a be 2c | SIG_R 32 52 69 05 ad 52 20 1b 60 76 ac 58 a2 7c 9b 27 | SIG_R 3f e0 29 76 8e db 48 e5 df d3 65 f5 6a 88 02 fd | SIG_R e2 4e 7a a8 4a 00 76 3b 4b e8 a2 c7 83 3f 44 4a | SIG_R a3 51 bc 8b 20 ef 0c d3 15 a9 33 12 a2 b5 4f 24 | SIG_R 55 e1 c7 7a 5b 53 83 c8 81 e4 07 89 a5 f7 f9 e3 | SIG_R 76 1e f5 6c 0e 8b b2 32 eb b5 24 c8 a1 75 e5 c8 | SIG_R 1a ef db d9 2d 03 3e 8c eb 23 ed a0 df b8 f4 c8 | SIG_R df 43 66 f3 f5 11 85 3a 17 8d bf 9d 1e 46 65 cb | SIG_R 62 51 0d ee 9d 72 6d 41 89 4b 44 3b d2 83 ff 0a | SIG_R f9 2b 51 c5 35 cf 7f 74 dc 60 b5 73 9c 31 87 a3 | SIG_R 23 b4 c3 4c df 88 cb 64 be 19 fc 0d 5b 98 db 5e | SIG_R e5 c1 99 8f 4d 38 36 74 f9 78 db 42 dd 78 d8 2b | SIG_R ca 4b 89 b9 e5 71 a4 64 f2 3a 78 11 f8 51 07 57 | SIG_R d7 fa 48 90 85 91 d8 08 0b d6 c4 8a 15 ab 74 bb | SIG_R 6a 0f 6b d8 cf ac 92 af 82 0e 1d e5 71 e9 e8 d3 | SIG_R df c9 08 04 4b a9 fa 03 a1 48 37 d0 9d e2 c3 df | SIG_R 26 3c a6 b9 75 8a 8f 41 a4 46 14 e2 14 02 9d 8d | SIG_R f6 1b cd 5d d1 2f 5c 69 d2 c4 43 d1 fd a0 d3 5b | SIG_R 93 4f 75 8c 2e fe df 11 d5 68 70 e6 e9 c1 ca 47 | SIG_R 97 37 2e ff a6 31 81 2a f5 c5 81 92 93 c2 71 2b | SIG_R 6c 0f 59 c6 9f 60 26 6d e5 3d c1 44 d8 d3 fe c2 | SIG_R 7a 57 f5 16 9d ab 72 c8 c9 e6 97 4c 09 e5 33 b3 | emitting length of ISAKMP Signature Payload: 388 | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 1884 | FOR_EACH_CONNECTION_... in ISAKMP_SA_established | complete v1 state transition with STF_OK | [RE]START processing: state #5 connection "TUNNEL-B" from 192.1.2.23:500 (in complete_v1_state_transition() at ikev1.c:2673) | #5 is idle | doing_xauth:no, t_xauth_client_done:no | IKEv1: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3 | parent state #5: MAIN_R2(open IKE SA) => MAIN_R3(established IKE SA) | event_already_set, deleting event | state #5 requesting EVENT_RETRANSMIT to be deleted | #5 STATE_MAIN_R3: retransmits: cleared | libevent_free: release ptr-libevent@0x5596176efba8 | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f3e7c002b78 | sending reply packet to 192.1.2.23:500 (from 192.1.2.45:500) | sending 1884 bytes for STATE_MAIN_R2 through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 05 10 02 01 00 00 00 00 00 00 07 5c 5f ae 07 51 | 17 78 00 ef c1 fe d5 b2 1c 9f 4f b7 97 07 fd 4d | d0 98 1f 4d cc 49 e7 01 d0 ff a8 36 a3 12 dc 50 | 30 04 2f 2b fd 05 ef 6a 5e 08 8d e4 15 c5 6e ed | d2 5c cb bb 7b 59 e4 1b 91 d1 24 32 b9 3b 95 c4 | 01 3a 57 c5 1e b6 f3 d2 0d 5b 1f 12 95 49 bd 4d | fa eb 7a cd 87 3b f8 91 03 1a 28 e5 71 70 5d bb | 04 23 93 de 52 36 2c e7 a7 84 bf d3 00 ef 78 c0 | 57 ac 9d 96 79 0e e3 1f a4 b1 38 a2 d3 af ca a5 | aa 90 c1 43 88 de 50 b7 4b 97 8c 3b bf e3 53 8d | f4 ba f1 d2 95 1a d0 5a ec 7c 6f 9f ba 7a b8 cd | e9 c0 da 5a b7 f0 6d 1f 11 04 13 0d 14 26 46 2b | 85 79 a0 cc 21 ab b2 49 96 d8 2e 87 0a 25 5e 77 | a0 c1 2a 0d c3 25 ea aa 18 94 37 13 6c 01 11 98 | 5c 7e 8e 39 aa b7 42 50 39 cc 81 88 a5 bd 76 fe | 8f a0 2d 40 0e 6f ac 25 c7 8d 7e 48 8d 65 8a 36 | 22 fb a7 b3 a4 e0 0f 5c d0 d5 d7 78 7b c5 87 74 | 15 78 14 72 ca ff cc 8b 2c ca c8 62 92 27 b7 7c | fd 31 89 83 81 fd 45 de ac 36 ce 0e cb 95 af c4 | 59 2e 36 c7 dd 6c 2c 51 f5 1d b0 e8 74 38 53 d7 | 7c 5f 05 a5 b4 2e 05 8e 3b 71 8d 01 f2 a7 e3 17 | e3 aa 64 b5 4d ad 4e 0e a0 85 6e 6f 56 08 03 ac | ce d7 4b 56 41 c8 13 c9 df 18 d6 a5 42 25 af 2b | 50 d6 7d 3a 7b 5a 66 ae 22 f3 1b 5f 55 27 d5 86 | 6d 80 58 02 4e d1 71 d4 af 40 46 ef 1a 1a 3e c4 | c5 7e 45 91 c9 dc 2a 9c c5 0e 54 8d 58 08 f9 34 | 50 0e c9 bc 8f e3 3d 3f 51 35 1e 16 e1 03 dc 1c | dd 87 70 1c 9e bd c5 d2 02 d2 fe 9f 5c 4a ff fd | 76 ae 6e 08 bc b5 65 23 32 8f de 6d 94 06 e2 09 | 2e c6 e3 a0 91 90 3c f7 b3 38 24 f6 02 60 14 b2 | bf 41 3b 6d ca 0d 2e 1f 2b d4 50 06 e0 d9 60 54 | e3 e3 83 d6 df 2c 64 67 d9 c8 ed 73 d5 59 24 5d | 09 4a 10 ab 9a 1b c1 30 ec 7c c5 a4 6e 09 7d 49 | 92 36 d3 67 1b 2e 4c bc 4d f7 9a 23 84 79 68 f3 | d5 9b da 9d 71 6c 48 c8 f6 00 e9 05 be bc da af | 9a a2 8b 78 0f c5 d9 70 1a 08 21 c0 e3 0c 4c f1 | d0 51 93 40 a3 99 26 aa a3 53 27 98 1a e9 0a 93 | 2a ad 67 4d 0c cf b6 99 f5 d3 03 88 dc 41 57 61 | 70 27 af d7 61 1b 65 f8 a4 fb 01 46 2f c4 8c f9 | 8e 6e 10 91 7c a3 c0 48 27 1c f5 d9 e6 e1 37 f8 | f1 a7 50 f2 9c fe 22 da 9f 82 b0 e3 69 35 49 bc | 2c 3f d3 ef e9 88 0f 28 8f ea 02 a9 53 a7 7c 86 | 0b be 92 8a 17 69 81 20 75 ce c0 0d c0 00 69 d8 | 65 6f e2 e1 5a 93 6e 89 e4 5e 76 70 f1 b9 a0 88 | bb e2 82 b3 e8 0e 5a 7c 64 36 b8 61 d9 08 24 3f | c3 98 40 0c b9 8e 11 65 99 2e 23 6f 39 80 24 a8 | 0e 65 4b 41 dd 28 f9 db d3 5e 28 00 7b 11 14 96 | aa f2 03 59 3c 9f ad 36 7b 6b a0 7a a6 5e f0 1a | 39 8b 78 12 e3 96 2a 25 03 65 74 73 26 24 d8 b4 | 63 3c 84 76 ed 44 91 e9 22 df 7c 45 5b 5d cb c3 | 64 fd 1b 4f 93 96 12 67 a7 18 f5 05 56 11 83 6f | b5 a8 22 5f 7a 27 20 0e 32 4f 92 91 40 4f 90 b0 | b9 ad 26 4b 29 99 a9 ea 6f 61 c5 4e 66 bd 4f f2 | a8 d9 20 c7 f9 8a 21 af 14 e2 7c 8a 32 19 e8 ea | 5a d6 53 b6 78 16 fa b4 c5 e2 60 b9 e4 34 d4 10 | 45 8a 0e 4e 7d 57 8c 15 c0 a9 b5 27 21 45 95 66 | fe c4 5e ee 1a ea 01 3d a2 3b a6 51 fa 74 e1 85 | 0e f3 1e 6c d2 74 e7 69 b9 18 b0 2c 23 03 8d 9e | 4d b8 07 a9 ff 16 85 be bb fc 7b 12 be 84 c6 e6 | 8d 60 6e 15 da 2b c6 ce 93 8b 2a 1b e6 8e 75 32 | e6 55 d5 62 da 26 55 6d 96 cf 9e 9e c4 59 56 e0 | fe 5f 94 d0 87 37 e0 c4 99 b1 17 ef ee de ae 07 | 41 1f a1 06 16 8e 1f 59 45 cf e0 f7 06 25 dd d1 | 75 a5 c2 54 0f 83 dd da 03 16 cf a4 07 a7 3a ac | 96 11 cb b8 38 4e 6b de d4 fe 68 0c 49 2a 16 58 | 62 01 be 23 29 db fb 7d 51 fc e9 7c 41 71 a4 96 | 41 c0 10 31 7d 0e f3 e7 3d 8d 2b 56 0a e5 00 0b | e2 e2 f7 58 3e db 18 d7 f6 32 6f b0 53 ef 14 d0 | a5 68 3f f5 9e a4 1c 62 db 03 d6 63 2f 18 2e d3 | ef 00 ec e3 22 14 5b 3f d2 e1 2d 63 b0 1f 76 86 | b1 63 72 6a fb 4e 82 bf 51 35 dd 6d 40 d0 0c fe | 67 8d 72 12 35 e5 37 56 4b ff 87 c6 7e 11 c9 78 | 6e c5 6f 6c 57 15 e6 46 9f 3b db 9a 0a e6 67 54 | 5e 67 b1 f8 70 f8 32 93 74 47 8b 02 41 7e 77 f5 | 5b 54 aa 81 67 59 9e e6 5f e5 ef 8a e1 71 c1 0e | 1a b2 2f e3 67 32 4f 50 25 23 97 d9 58 d9 09 de | 8b eb ea 8b 8c 86 bb 09 1e f4 41 c4 ae 61 34 94 | 80 a0 67 ca 3d fc a4 e2 5a 38 cb 99 fd 11 f3 e7 | 2d ca df 3a d2 17 31 9f bf b3 69 51 cd 88 4d 97 | be a4 b6 eb 3f 82 b8 ec ae ae 7a ae 0e 61 3c d8 | 0d 94 22 90 85 2e 7d 86 24 5a 28 18 12 f7 42 c2 | 6b f5 4f 52 da 9c c3 83 fc e7 bb df 9e 23 da a1 | e4 23 72 4d 3e 66 a7 61 3d 7e 0d 3d e0 05 f7 69 | f4 42 7c d0 4f f4 01 1f 49 ae 00 bb 9d 04 82 1c | ef 12 4f 5a 85 b4 55 ac db 79 0c 9a d2 a6 a1 fc | b2 46 f8 75 6b dc c6 d0 dd a8 ee a5 cc 21 e0 f9 | d7 89 e7 38 e0 e0 70 22 f7 2d ce 99 25 4f ce 61 | e2 12 65 39 2d a7 11 f7 5c a8 12 85 ea 05 00 d5 | 53 44 68 fe 5d dd 38 ce ee a5 c4 0f 3f 1a 15 04 | fc 5f bd 9f c6 d5 50 e5 51 0b 8a 68 55 19 31 37 | 81 f4 7c fe 3a 0a fd 87 ae 06 66 1c fc 71 7e 1b | c7 71 ba ad 9b 0c 18 00 37 4b 27 61 41 3b 2c e7 | 4c e4 b3 2a 55 70 cc f5 cc 99 59 26 4d e5 d0 ee | f6 a3 71 6c 07 c1 80 8b 89 d6 6f 1b f0 b0 2b 15 | 50 20 02 27 36 bf 47 ec 3e 61 c2 34 50 d4 92 69 | 9f 9e d5 55 67 5e 41 31 e8 f1 65 a0 27 f9 96 02 | e1 c6 c1 c1 dc ad 87 2e 0c 44 2c 8c 99 2a e5 7d | e6 a4 b2 fe 81 a1 d8 6d 37 75 d1 20 47 fb 3b 3f | 73 09 5f 95 d4 c9 0d 1d 2b f5 47 f5 bf 35 00 e6 | a0 0a 56 98 8c 1d 77 74 65 ee ed f0 20 07 ab ae | 69 8d 53 c1 6e fe 15 d6 c8 c8 0d 52 de 6d 3b a1 | 1f d6 92 df 23 82 df 94 ce 2e e3 e1 eb 0f 9a 7a | 6f 49 27 5d f9 99 0b 50 55 d3 c2 2a e7 96 9c 6b | ef 30 c0 64 2b c2 03 2a 25 58 28 15 73 92 17 44 | 03 e4 0c 84 00 37 84 20 c7 86 9a 2f a5 da 6d f5 | 36 5b 09 d1 dc 06 94 a7 b4 62 91 43 c4 4f 03 36 | a4 81 87 aa bf d7 3d 00 ef 2d ef 09 de be 50 7c | 3f 01 7e 58 aa 3c 95 6f 3f 0d 2b 6e 1b 59 4b 75 | 09 96 0a be af 20 37 cb 30 9b a5 8a 14 4f 40 7b | 4c cc 2b d6 fc 86 ea 63 55 f8 c2 21 86 74 3a 87 | d0 d0 d1 64 e7 5f 17 ed da 86 d0 5f bc e2 10 8f | 6d 48 41 c6 a3 98 b0 0c 30 95 5b e4 3c 09 20 3c | d3 31 61 25 e9 95 ab b7 fb 51 4c 50 f6 87 51 17 | 68 82 30 9e 84 f6 84 f5 a4 f2 db ce e8 72 65 da | 6c e6 f2 d3 51 be 96 65 06 4f a2 b4 08 00 b1 19 | 53 bc 27 78 4a e2 af f6 64 8e 37 ae 6b bc 45 b7 | cc 36 e0 23 f2 26 40 0b a1 9b 6c 19 | !event_already_set at reschedule | event_schedule: new EVENT_SA_EXPIRE-pe@0x7f3e7c002b78 | inserting event EVENT_SA_EXPIRE, timeout in 60 seconds for #5 | libevent_malloc: new ptr-libevent@0x7f3e88004fd8 size 128 | pstats #5 ikev1.isakmp established "TUNNEL-B" #5: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP2048} | DPD: dpd_init() called on ISAKMP SA | DPD: Peer supports Dead Peer Detection | DPD: not initializing DPD because DPD is disabled locally | modecfg pull: noquirk policy:push not-client | phase 1 is done, looking for phase 2 to unpend | unpending state #5 | #5 spent 6.27 milliseconds | #5 spent 7.76 milliseconds in process_packet_tail() | stop processing: from 192.1.2.23:500 (BACKGROUND) (in process_md() at demux.c:380) | stop processing: state #5 connection "TUNNEL-B" from 192.1.2.23:500 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 8.02 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_PENDING_DDNS | FOR_EACH_CONNECTION_... in connection_check_ddns | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | elapsed time in connection_check_ddns for hostname lookup 0.000005 | spent 0.00856 milliseconds in global timer EVENT_PENDING_DDNS | processing global timer EVENT_SHUNT_SCAN | expiring aged bare shunts from shunt table | spent 0.00211 milliseconds in global timer EVENT_SHUNT_SCAN | spent 0.00302 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.00897 milliseconds in comm_handle_cb() reading and processing packet | processing global timer EVENT_NAT_T_KEEPALIVE | FOR_EACH_STATE_... in nat_traversal_ka_event (for_each_state) | start processing: state #5 connection "TUNNEL-B" from 192.1.2.23:500 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-B | stop processing: state #5 connection "TUNNEL-B" from 192.1.2.23:500 (in for_each_state() at state.c:1577) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-C | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#4) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #4) | ff | stop processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-B | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#3) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #3) | ff | stop processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:774) | ka_event: send NAT-KA to 192.1.2.23:500 (state=#2) | sending NAT-T Keep Alive | sending 1 bytes for NAT-T Keep Alive through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #2) | ff | stop processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in nat_traversal_send_ka() at nat_traversal.c:786) | processing: STOP state #0 (in for_each_state() at state.c:1577) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1575) | not behind NAT: no NAT-T KEEP-ALIVE required for conn TUNNEL-A | stop processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in for_each_state() at state.c:1577) | global one-shot timer EVENT_NAT_T_KEEPALIVE scheduled in 20 seconds | spent 0.0837 milliseconds in global timer EVENT_NAT_T_KEEPALIVE | spent 0.00186 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.00619 milliseconds in comm_handle_cb() reading and processing packet | spent 0.000964 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | NAT-T keep-alive (bogus ?) should not reach this point. Ignored. Sender: 192.1.2.23:500 | spent 0.0036 milliseconds in comm_handle_cb() reading and processing packet | spent 0.00265 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 92 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 05 01 84 e9 26 58 00 00 00 5c b3 18 ba 44 | 5f 81 00 01 57 1e 25 45 79 23 97 29 b5 91 f3 19 | fc dc bd 5b 96 72 5a 95 67 0c 1d 40 25 3f 92 a9 | f0 53 78 20 cd 67 5c ba ee ba 85 03 23 3d 4a 0e | a1 bc d4 a6 12 76 fc ee 74 78 06 67 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 2229872216 (0x84e92658) | length: 92 (0x5c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_INFO (5) | peer and cookies match on #4; msgid=00000000 st_msgid=af958306 st_msgid_phase15=00000000 | peer and cookies match on #3; msgid=00000000 st_msgid=38f90549 st_msgid_phase15=00000000 | peer and cookies match on #2; msgid=00000000 st_msgid=6218486d st_msgid_phase15=00000000 | peer and cookies match on #1; msgid=00000000 st_msgid=00000000 st_msgid_phase15=00000000 | p15 state object #1 found, in STATE_MAIN_I4 | State DB: found IKEv1 state #1 in MAIN_I4 (find_v1_info_state) | start processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in process_v1_packet() at ikev1.c:1479) | #1 is idle | #1 idle | received encrypted packet from 192.1.2.23:500 | got payload 0x100 (ISAKMP_NEXT_HASH) needed: 0x100 opt: 0x0 | ***parse ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_D (0xc) | length: 36 (0x24) | got payload 0x1000 (ISAKMP_NEXT_D) needed: 0x0 opt: 0x0 | ***parse ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | length: 28 (0x1c) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 16 (0x10) | number of SPIs: 1 (0x1) | informational HASH(1): | 6c 8a 5a b4 0a 71 cb 66 29 ae ff 51 5f 4d ce c9 | a7 6f 79 af 17 98 35 d3 04 86 3e e9 40 35 b0 44 | received 'informational' message HASH(1) data ok | parsing 8 raw bytes of ISAKMP Delete Payload into iCookie | iCookie 13 ce 9d 4e da e6 3a 63 | parsing 8 raw bytes of ISAKMP Delete Payload into rCookie | rCookie 77 51 4f 24 9b f8 4c 14 | State DB: found IKEv1 state #1 in MAIN_I4 (find_state_ikev1) | del: "TUNNEL-A" #1: received Delete SA payload: self-deleting ISAKMP State #1 | pstats #1 ikev1.isakmp deleted completed | [RE]START processing: state #1 connection "TUNNEL-A" from 192.1.2.23 (in delete_state() at state.c:879) "TUNNEL-A" #1: deleting state (STATE_MAIN_I4) aged 60.052s and sending notification | parent state #1: MAIN_I4(established IKE SA) => delete | #1 send IKEv1 delete notification for STATE_MAIN_I4 | **emit ISAKMP Message: | initiator cookie: | 13 ce 9d 4e da e6 3a 63 | responder cookie: | 77 51 4f 24 9b f8 4c 14 | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1502093745 (0x598821b1) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'delete msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 16 (0x10) | number of SPIs: 1 (0x1) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Delete Payload (12:ISAKMP_NEXT_D) | next payload chain: saving location 'ISAKMP Delete Payload'.'next payload type' in 'delete msg' | emitting 8 raw bytes of initiator SPI into ISAKMP Delete Payload | initiator SPI 13 ce 9d 4e da e6 3a 63 | emitting 8 raw bytes of responder SPI into ISAKMP Delete Payload | responder SPI 77 51 4f 24 9b f8 4c 14 | emitting length of ISAKMP Delete Payload: 28 | send delete HASH(1): | 37 b7 e7 88 61 51 84 0f 64 10 31 c1 71 a6 63 59 | 8a a0 8b 56 17 b4 04 3a 6d 83 b0 aa 3d a1 38 2b | no IKEv1 message padding required | emitting length of ISAKMP Message: 92 | sending 92 bytes for delete notify through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #1) | 13 ce 9d 4e da e6 3a 63 77 51 4f 24 9b f8 4c 14 | 08 10 05 01 59 88 21 b1 00 00 00 5c d6 7c 76 92 | 0b f4 1e 8d 52 4c 06 82 62 a8 56 ce d3 ea 35 ff | bc f4 d2 a5 8d cf b9 04 08 3e 57 31 71 b9 ed e8 | 21 88 b2 23 4e c0 1b 9f 4f 47 da 99 0a 55 f0 96 | 35 8e 9e 58 99 6b 00 9c be 9b 1c 50 | state #1 requesting EVENT_SA_EXPIRE to be deleted | libevent_free: release ptr-libevent@0x5596176e1318 | free_event_entry: release EVENT_SA_EXPIRE-pe@0x5596176d6618 | State DB: IKEv1 state not found (flush_incomplete_children) | in connection_discard for connection TUNNEL-A | State DB: deleting IKEv1 state #1 in MAIN_I4 | parent state #1: MAIN_I4(established IKE SA) => UNDEFINED(ignore) | unreference key: 0x5596176d52b8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 2-- | stop processing: state #1 from 192.1.2.23 (in delete_state() at state.c:1143) | unreference key: 0x5596176d52b8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | unreference key: 0x5596176df768 user-east@testing.libreswan.org cnt 1-- | unreference key: 0x5596176df9b8 @east.testing.libreswan.org cnt 1-- | unreference key: 0x5596176e14c8 east@testing.libreswan.org cnt 1-- | unreference key: 0x5596176e1a88 192.1.2.23 cnt 1-- | in statetime_start() with no state | complete v1 state transition with STF_IGNORE | stop processing: from 192.1.2.23:500 (in process_md() at demux.c:380) | processing: STOP state #0 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.359 milliseconds in comm_handle_cb() reading and processing packet | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | FOR_EACH_STATE_... in sort_states | get_sa_info esp.f384cffa@192.1.2.45 | get_sa_info esp.ac88167e@192.1.2.23 | get_sa_info esp.e93161bd@192.1.2.45 | get_sa_info esp.2310b106@192.1.2.23 | get_sa_info esp.2605d62c@192.1.2.45 | get_sa_info esp.58b85bc4@192.1.2.23 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.751 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | start processing: connection "TUNNEL-B" (in terminate_a_connection() at terminate.c:69) "TUNNEL-B": terminating SAs using this connection | connection 'TUNNEL-B' -POLICY_UP | FOR_EACH_STATE_... in shared_phase1_connection | connection not shared - terminating IKE and IPsec SA | Deleting states for connection - not including other IPsec SA's | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #5 | state #4 | state #3 | suspend processing: connection "TUNNEL-B" (in foreach_state_by_connection_func_delete() at state.c:1310) | start processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in foreach_state_by_connection_func_delete() at state.c:1310) | pstats #3 ikev1.ipsec deleted completed | [RE]START processing: state #3 connection "TUNNEL-B" from 192.1.2.23 (in delete_state() at state.c:879) "TUNNEL-B" #3: deleting state (STATE_QUICK_I2) aged 70.039s and sending notification | child state #3: QUICK_I2(established CHILD SA) => delete | get_sa_info esp.2310b106@192.1.2.23 | get_sa_info esp.e93161bd@192.1.2.45 "TUNNEL-B" #3: ESP traffic information: in=336B out=336B | #3 send IKEv1 delete notification for STATE_QUICK_I2 | FOR_EACH_STATE_... in find_phase1_state | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 1403168251 (0x53a2a5fb) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'delete msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 3 (0x3) | SPI size: 4 (0x4) | number of SPIs: 1 (0x1) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Delete Payload (12:ISAKMP_NEXT_D) | next payload chain: saving location 'ISAKMP Delete Payload'.'next payload type' in 'delete msg' | emitting 4 raw bytes of delete payload into ISAKMP Delete Payload | delete payload e9 31 61 bd | emitting length of ISAKMP Delete Payload: 16 | send delete HASH(1): | d9 44 51 87 5b 50 b4 cf 25 94 30 75 63 6a a2 28 | de ec a7 2d ac 73 28 a8 bb 26 23 0c db cc d5 ff | emitting 12 zero bytes of encryption padding into ISAKMP Message | no IKEv1 message padding required | emitting length of ISAKMP Message: 92 | sending 92 bytes for delete notify through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 53 a2 a5 fb 00 00 00 5c a8 42 fb 6e | 82 30 01 4f e8 04 2d 7c c1 9b 7a 6f da 26 60 d6 | a7 3b cf 1a ca 6e b6 26 73 17 e5 d1 34 bc 7b 43 | 69 42 a3 af 11 bc b9 4e 0d e7 5d 4a 31 ea 8b da | 16 13 20 36 c7 28 87 34 8c 71 75 80 | state #3 requesting EVENT_v1_SA_REPLACE_IF_USED to be deleted | libevent_free: release ptr-libevent@0x5596176e5868 | free_event_entry: release EVENT_v1_SA_REPLACE_IF_USED-pe@0x7f3e8c004218 | running updown command "ipsec _updown" for verb down | command executing down-client | executing down-client: PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANE | popen cmd is 1303 chars long | cmd( 0):PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_I: | cmd( 80):NTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C: | cmd( 160):=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.lib: | cmd( 240):reswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_M: | cmd( 400):Y_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='ESP' PLUT: | cmd( 480):O_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=: | cmd( 560):Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.or: | cmd( 640):g' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO_: | cmd( 720):PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: | cmd( 800):LUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLIC: | cmd( 880):Y='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+E: | cmd( 960):SN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=: | cmd(1040):0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO: | cmd(1120):_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0: | cmd(1200):' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x2310b106 SPI_OUT=0xe931: | cmd(1280):61bd ipsec _updown 2>&1: | shunt_eroute() called for connection 'TUNNEL-B' to 'replace with shunt' for rt_kind 'prospective erouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-B" is 0xfdfdf | IPsec Sa SPD priority set to 1040351 | delete esp.2310b106@192.1.2.23 | netlink response for Del SA esp.2310b106@192.1.2.23 included non-error error | priority calculation of connection "TUNNEL-B" is 0xfdfdf | delete inbound eroute 192.0.2.244/32:0 --0-> 192.0.1.254/32:0 => unk255.10000@192.1.2.45 (raw_eroute) | raw_eroute result=success | delete esp.e93161bd@192.1.2.45 | netlink response for Del SA esp.e93161bd@192.1.2.45 included non-error error | stop processing: connection "TUNNEL-B" (BACKGROUND) (in update_state_connection() at connections.c:4076) | start processing: connection NULL (in update_state_connection() at connections.c:4077) | in connection_discard for connection TUNNEL-B | State DB: deleting IKEv1 state #3 in QUICK_I2 | child state #3: QUICK_I2(established CHILD SA) => UNDEFINED(ignore) | stop processing: state #3 from 192.1.2.23 (in delete_state() at state.c:1143) | processing: STOP state #0 (in foreach_state_by_connection_func_delete() at state.c:1312) | state #2 | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #5 | start processing: state #5 connection "TUNNEL-B" from 192.1.2.23:500 (in foreach_state_by_connection_func_delete() at state.c:1310) | pstats #5 ikev1.isakmp deleted completed | [RE]START processing: state #5 connection "TUNNEL-B" from 192.1.2.23:500 (in delete_state() at state.c:879) "TUNNEL-B" #5: deleting state (STATE_MAIN_R3) aged 11.191s and sending notification | parent state #5: MAIN_R3(established IKE SA) => delete | #5 send IKEv1 delete notification for STATE_MAIN_R3 | **emit ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_NONE (0x0) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 475806770 (0x1c5c3c32) | next payload chain: saving message location 'ISAKMP Message'.'next payload type' | ***emit ISAKMP Hash Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current ISAKMP Hash Payload (8:ISAKMP_NEXT_HASH) | next payload chain: saving location 'ISAKMP Hash Payload'.'next payload type' in 'delete msg' | emitting 32 zero bytes of HASH DATA into ISAKMP Hash Payload | emitting length of ISAKMP Hash Payload: 36 | ***emit ISAKMP Delete Payload: | next payload type: ISAKMP_NEXT_NONE (0x0) | DOI: ISAKMP_DOI_IPSEC (0x1) | protocol ID: 1 (0x1) | SPI size: 16 (0x10) | number of SPIs: 1 (0x1) | next payload chain: setting previous 'ISAKMP Hash Payload'.'next payload type' to current ISAKMP Delete Payload (12:ISAKMP_NEXT_D) | next payload chain: saving location 'ISAKMP Delete Payload'.'next payload type' in 'delete msg' | emitting 8 raw bytes of initiator SPI into ISAKMP Delete Payload | initiator SPI 7a 3e ee d8 64 fe 14 54 | emitting 8 raw bytes of responder SPI into ISAKMP Delete Payload | responder SPI d3 7b 19 72 3b a4 45 7b | emitting length of ISAKMP Delete Payload: 28 | send delete HASH(1): | a9 91 02 f8 52 75 01 68 e5 82 61 e9 21 f2 4b 24 | c8 d8 c7 3c 3f cc 25 ee 40 1c 6e e9 90 de 1d 4d | no IKEv1 message padding required | emitting length of ISAKMP Message: 92 | sending 92 bytes for delete notify through eth1 from 192.1.2.45:500 to 192.1.2.23:500 (using #5) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 1c 5c 3c 32 00 00 00 5c 68 6e 66 1b | db b6 08 72 89 51 54 f5 d8 e8 af d0 ab 73 cd 58 | 80 36 a8 6c 0a 83 12 eb fe 05 44 58 6a b2 7b e1 | ce 12 65 93 40 68 80 96 9f fb 3e e2 a9 8e 2b dc | bd b1 57 bb 8e 85 5e d3 27 64 53 ff | state #5 requesting EVENT_SA_EXPIRE to be deleted | libevent_free: release ptr-libevent@0x7f3e88004fd8 | free_event_entry: release EVENT_SA_EXPIRE-pe@0x7f3e7c002b78 | State DB: IKEv1 state not found (flush_incomplete_children) | in connection_discard for connection TUNNEL-B | State DB: deleting IKEv1 state #5 in MAIN_R3 | parent state #5: MAIN_R3(established IKE SA) => UNDEFINED(ignore) | unreference key: 0x5596176fb048 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 2-- | stop processing: state #5 from 192.1.2.23:500 (in delete_state() at state.c:1143) | unreference key: 0x5596176fb048 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org cnt 1-- | unreference key: 0x5596176e9f88 user-east@testing.libreswan.org cnt 1-- | unreference key: 0x5596176fe258 @east.testing.libreswan.org cnt 1-- | unreference key: 0x5596176ff788 east@testing.libreswan.org cnt 1-- | unreference key: 0x5596176e1888 192.1.2.23 cnt 1-- | processing: STOP state #0 (in foreach_state_by_connection_func_delete() at state.c:1312) | state #4 | state #2 | processing: STOP connection NULL (in terminate_a_connection() at terminate.c:87) | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 1.42 milliseconds in whack | spent 0.00149 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 92 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 09 e8 99 75 00 00 00 5c 55 27 7f f0 | c6 19 ca 76 a2 85 48 d0 af 06 77 8d c9 f8 09 3a | c9 a1 0e 73 b6 57 c1 d6 29 1b 61 f9 1f 64 9a e4 | 3d 6e ce 91 e5 7f 1e 8e 34 33 27 36 2a 76 76 b6 | 42 a6 a7 24 61 42 18 fb 03 3c 07 4f | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 166238581 (0x9e89975) | length: 92 (0x5c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_INFO (5) | State DB: IKEv1 state not found (find_v1_info_state) | State DB: IKEv1 state not found (find_state_ikev1_init) | Informational Exchange is for an unknown (expired?) SA with MSGID:0x09e89975 | - unknown SA's md->hdr.isa_ike_initiator_spi.bytes: | 7a 3e ee d8 64 fe 14 54 | - unknown SA's md->hdr.isa_ike_responder_spi.bytes: | d3 7b 19 72 3b a4 45 7b | stop processing: from 192.1.2.23:500 (in process_md() at demux.c:380) | processing: STOP state #0 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.0814 milliseconds in comm_handle_cb() reading and processing packet | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00439 milliseconds in signal handler PLUTO_SIGCHLD | spent 0.00211 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() | *received 92 bytes from 192.1.2.23:500 on eth1 (192.1.2.45:500) | 7a 3e ee d8 64 fe 14 54 d3 7b 19 72 3b a4 45 7b | 08 10 05 01 b7 c9 e6 a5 00 00 00 5c 45 1b 48 17 | 44 ee f1 cc 42 26 2f 7d 62 a8 50 7b 76 9e 6f 26 | fe 2b 2d e3 47 87 83 bc 80 79 0f f0 38 be 60 c7 | 1b 70 d9 75 e4 bd 08 24 f5 9f fc 2b 6c a8 34 ee | f5 1c 07 4d 7b 2f 19 21 60 ed 30 a2 | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) | **parse ISAKMP Message: | initiator cookie: | 7a 3e ee d8 64 fe 14 54 | responder cookie: | d3 7b 19 72 3b a4 45 7b | next payload type: ISAKMP_NEXT_HASH (0x8) | ISAKMP version: ISAKMP Version 1.0 (rfc2407) (0x10) | exchange type: ISAKMP_XCHG_INFO (0x5) | flags: ISAKMP_FLAG_v1_ENCRYPTION (0x1) | Message ID: 3083462309 (0xb7c9e6a5) | length: 92 (0x5c) | processing version=1.0 packet with exchange type=ISAKMP_XCHG_INFO (5) | State DB: IKEv1 state not found (find_v1_info_state) | State DB: IKEv1 state not found (find_state_ikev1_init) | Informational Exchange is for an unknown (expired?) SA with MSGID:0xb7c9e6a5 | - unknown SA's md->hdr.isa_ike_initiator_spi.bytes: | 7a 3e ee d8 64 fe 14 54 | - unknown SA's md->hdr.isa_ike_responder_spi.bytes: | d3 7b 19 72 3b a4 45 7b | stop processing: from 192.1.2.23:500 (in process_md() at demux.c:380) | processing: STOP state #0 (in process_md() at demux.c:382) | processing: STOP connection NULL (in process_md() at demux.c:383) | spent 0.0681 milliseconds in comm_handle_cb() reading and processing packet | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | FOR_EACH_STATE_... in sort_states | get_sa_info esp.f384cffa@192.1.2.45 | get_sa_info esp.ac88167e@192.1.2.23 | get_sa_info esp.2605d62c@192.1.2.45 | get_sa_info esp.58b85bc4@192.1.2.23 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.477 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in conn_by_name | start processing: connection "TUNNEL-B" (in terminate_a_connection() at terminate.c:69) "TUNNEL-B": terminating SAs using this connection | connection 'TUNNEL-B' -POLICY_UP | connection not shared - terminating IKE and IPsec SA | Deleting states for connection - not including other IPsec SA's | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #4 | state #2 | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #4 | state #2 | stop processing: connection "TUNNEL-B" (in terminate_a_connection() at terminate.c:87) | FOR_EACH_CONNECTION_... in conn_by_name | start processing: connection "TUNNEL-B" (in delete_connection() at connections.c:189) | Deleting states for connection - not including other IPsec SA's | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #4 | state #2 | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #4 | state #2 | shunt_eroute() called for connection 'TUNNEL-B' to 'delete' for rt_kind 'unrouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-B" is 0xfdfdf | priority calculation of connection "TUNNEL-B" is 0xfdfdf | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-B mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-B mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-B" unrouted: NULL | running updown command "ipsec _updown" for verb unroute | command executing unroute-client | executing unroute-client: PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='none' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT | popen cmd is 1284 chars long | cmd( 0):PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-B' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.: | cmd( 240):libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16396' PLUTO_SA_TYPE='none' : | cmd( 480):PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan,: | cmd( 560): OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswa: | cmd( 640):n.org' PLUTO_PEER_CLIENT='192.0.2.244/32' PLUTO_PEER_CLIENT_NET='192.0.2.244' PL: | cmd( 720):UTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL=': | cmd( 800):0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RS: | cmd( 880):ASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO: | cmd( 960):' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLU: | cmd(1040):TO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER: | cmd(1120):_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI: | cmd(1200):_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x0 SPI_OUT=0x0 ipsec _updown : | cmd(1280):2>&1: "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. "TUNNEL-B": unroute-client output: Error: Peer netns reference is invalid. | flush revival: connection 'TUNNEL-B' wasn't on the list | stop processing: connection "TUNNEL-B" (in discard_connection() at connections.c:249) | FOR_EACH_CONNECTION_... in conn_by_name | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 1.02 milliseconds in whack | processing signal PLUTO_SIGCHLD | waitpid returned ECHILD (no child processes left) | spent 0.00321 milliseconds in signal handler PLUTO_SIGCHLD | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | FOR_EACH_STATE_... in sort_states | get_sa_info esp.f384cffa@192.1.2.45 | get_sa_info esp.ac88167e@192.1.2.23 | get_sa_info esp.2605d62c@192.1.2.45 | get_sa_info esp.58b85bc4@192.1.2.23 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.545 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_CONNECTION_... in show_connections_status | FOR_EACH_STATE_... in show_states_status (sort_states) | FOR_EACH_STATE_... in sort_states | get_sa_info esp.f384cffa@192.1.2.45 | get_sa_info esp.ac88167e@192.1.2.23 | get_sa_info esp.2605d62c@192.1.2.45 | get_sa_info esp.58b85bc4@192.1.2.23 | close_any(fd@16) (in whack_process() at rcv_whack.c:700) | spent 0.364 milliseconds in whack | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) shutting down | processing: RESET whack log_fd (was fd@16) (in exit_pluto() at plutomain.c:1825) destroying root certificate cache | certs and keys locked by 'free_preshared_secrets' forgetting secrets | certs and keys unlocked by 'free_preshared_secrets' | unreference key: 0x5596176d18a8 C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org cnt 1-- | unreference key: 0x5596176d1378 user-west@testing.libreswan.org cnt 1-- | unreference key: 0x5596176cff88 @west.testing.libreswan.org cnt 1-- | unreference key: 0x5596176ccb88 west@testing.libreswan.org cnt 1-- | unreference key: 0x5596176d2af8 192.1.2.45 cnt 1-- | start processing: connection "TUNNEL-C" (in delete_connection() at connections.c:189) | Deleting states for connection - including all other IPsec SA's of this IKE SA | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #4 | suspend processing: connection "TUNNEL-C" (in foreach_state_by_connection_func_delete() at state.c:1310) | start processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in foreach_state_by_connection_func_delete() at state.c:1310) | pstats #4 ikev1.ipsec deleted completed | [RE]START processing: state #4 connection "TUNNEL-C" from 192.1.2.23 (in delete_state() at state.c:879) "TUNNEL-C" #4: deleting state (STATE_QUICK_I2) aged 72.261s and sending notification | child state #4: QUICK_I2(established CHILD SA) => delete | get_sa_info esp.58b85bc4@192.1.2.23 | get_sa_info esp.2605d62c@192.1.2.45 "TUNNEL-C" #4: ESP traffic information: in=336B out=336B | #4 send IKEv1 delete notification for STATE_QUICK_I2 | FOR_EACH_STATE_... in find_phase1_state | no Phase 1 state for Delete | state #4 requesting EVENT_v1_SA_REPLACE_IF_USED to be deleted | libevent_free: release ptr-libevent@0x5596176e6978 | free_event_entry: release EVENT_v1_SA_REPLACE_IF_USED-pe@0x7f3e84002b78 | running updown command "ipsec _updown" for verb down | command executing down-client | executing down-client: PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERM | popen cmd is 1306 chars long | cmd( 0):PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_I: | cmd( 80):NTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C: | cmd( 160):=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.lib: | cmd( 240):reswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_M: | cmd( 400):Y_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUT: | cmd( 480):O_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=: | cmd( 560):Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.or: | cmd( 640):g' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO_: | cmd( 720):PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: | cmd( 800):LUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLIC: | cmd( 880):Y='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLO: | cmd( 960):W+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAIL: | cmd(1040):ED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PL: | cmd(1120):UTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED: | cmd(1200):='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x58b85bc4 SPI_OUT=0x2: | cmd(1280):605d62c ipsec _updown 2>&1: | shunt_eroute() called for connection 'TUNNEL-C' to 'replace with shunt' for rt_kind 'prospective erouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-C" is 0xfdfdf | IPsec Sa SPD priority set to 1040351 | delete esp.58b85bc4@192.1.2.23 | netlink response for Del SA esp.58b85bc4@192.1.2.23 included non-error error | priority calculation of connection "TUNNEL-C" is 0xfdfdf | delete inbound eroute 192.0.2.234/32:0 --0-> 192.0.1.254/32:0 => unk255.10000@192.1.2.45 (raw_eroute) | raw_eroute result=success | delete esp.2605d62c@192.1.2.45 | netlink response for Del SA esp.2605d62c@192.1.2.45 included non-error error | stop processing: connection "TUNNEL-C" (BACKGROUND) (in update_state_connection() at connections.c:4076) | start processing: connection NULL (in update_state_connection() at connections.c:4077) | in connection_discard for connection TUNNEL-C | State DB: deleting IKEv1 state #4 in QUICK_I2 | child state #4: QUICK_I2(established CHILD SA) => UNDEFINED(ignore) | stop processing: state #4 from 192.1.2.23 (in delete_state() at state.c:1143) | processing: STOP state #0 (in foreach_state_by_connection_func_delete() at state.c:1312) | state #2 | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #2 | shunt_eroute() called for connection 'TUNNEL-C' to 'delete' for rt_kind 'unrouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-C" is 0xfdfdf | priority calculation of connection "TUNNEL-C" is 0xfdfdf | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-C mark 0/00000000, 0/00000000 | conn TUNNEL-C mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-C" unrouted: NULL | running updown command "ipsec _updown" for verb unroute | command executing unroute-client | executing unroute-client: PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='none' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMAN | popen cmd is 1287 chars long | cmd( 0):PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-C' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.: | cmd( 240):libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='none' : | cmd( 480):PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan,: | cmd( 560): OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswa: | cmd( 640):n.org' PLUTO_PEER_CLIENT='192.0.2.234/32' PLUTO_PEER_CLIENT_NET='192.0.2.234' PL: | cmd( 720):UTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL=': | cmd( 800):0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RS: | cmd( 880):ASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN: | cmd( 960):_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 : | cmd(1040):PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_P: | cmd(1120):EER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' : | cmd(1200):VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x0 SPI_OUT=0x0 ipsec _updo: | cmd(1280):wn 2>&1: unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. | flush revival: connection 'TUNNEL-C' wasn't on the list | processing: STOP connection NULL (in discard_connection() at connections.c:249) | start processing: connection "TUNNEL-A" (in delete_connection() at connections.c:189) | Deleting states for connection - including all other IPsec SA's of this IKE SA | pass 0 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | state #2 | suspend processing: connection "TUNNEL-A" (in foreach_state_by_connection_func_delete() at state.c:1310) | start processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in foreach_state_by_connection_func_delete() at state.c:1310) | pstats #2 ikev1.ipsec deleted completed | [RE]START processing: state #2 connection "TUNNEL-A" from 192.1.2.23 (in delete_state() at state.c:879) "TUNNEL-A" #2: deleting state (STATE_QUICK_I2) aged 72.526s and sending notification | child state #2: QUICK_I2(established CHILD SA) => delete | get_sa_info esp.ac88167e@192.1.2.23 | get_sa_info esp.f384cffa@192.1.2.45 "TUNNEL-A" #2: ESP traffic information: in=336B out=336B | #2 send IKEv1 delete notification for STATE_QUICK_I2 | FOR_EACH_STATE_... in find_phase1_state | no Phase 1 state for Delete | state #2 requesting EVENT_v1_SA_REPLACE_IF_USED to be deleted | libevent_free: release ptr-libevent@0x5596176e57b8 | free_event_entry: release EVENT_v1_SA_REPLACE_IF_USED-pe@0x5596176d4778 | running updown command "ipsec _updown" for verb down | command executing down-client | executing down-client: PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERM | popen cmd is 1306 chars long | cmd( 0):PLUTO_VERB='down-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_I: | cmd( 80):NTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C: | cmd( 160):=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.lib: | cmd( 240):reswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' : | cmd( 320):PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_M: | cmd( 400):Y_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='ESP' PLUT: | cmd( 480):O_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=: | cmd( 560):Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.or: | cmd( 640):g' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO_: | cmd( 720):PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: | cmd( 800):LUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='1566825896' PLUTO_CONN_POLIC: | cmd( 880):Y='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLO: | cmd( 960):W+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAIL: | cmd(1040):ED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PL: | cmd(1120):UTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED: | cmd(1200):='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xac88167e SPI_OUT=0xf: | cmd(1280):384cffa ipsec _updown 2>&1: | shunt_eroute() called for connection 'TUNNEL-A' to 'replace with shunt' for rt_kind 'prospective erouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-A" is 0xfdfdf | IPsec Sa SPD priority set to 1040351 | delete esp.ac88167e@192.1.2.23 | netlink response for Del SA esp.ac88167e@192.1.2.23 included non-error error | priority calculation of connection "TUNNEL-A" is 0xfdfdf | delete inbound eroute 192.0.2.254/32:0 --0-> 192.0.1.254/32:0 => unk255.10000@192.1.2.45 (raw_eroute) | raw_eroute result=success | delete esp.f384cffa@192.1.2.45 | netlink response for Del SA esp.f384cffa@192.1.2.45 included non-error error | stop processing: connection "TUNNEL-A" (BACKGROUND) (in update_state_connection() at connections.c:4076) | start processing: connection NULL (in update_state_connection() at connections.c:4077) | in connection_discard for connection TUNNEL-A | State DB: deleting IKEv1 state #2 in QUICK_I2 | child state #2: QUICK_I2(established CHILD SA) => UNDEFINED(ignore) | stop processing: state #2 from 192.1.2.23 (in delete_state() at state.c:1143) | processing: STOP state #0 (in foreach_state_by_connection_func_delete() at state.c:1312) | pass 1 | FOR_EACH_STATE_... in foreach_state_by_connection_func_delete | shunt_eroute() called for connection 'TUNNEL-A' to 'delete' for rt_kind 'unrouted' using protoports 0--0->-0 | netlink_shunt_eroute for proto 0, and source port 0 dest port 0 | priority calculation of connection "TUNNEL-A" is 0xfdfdf | priority calculation of connection "TUNNEL-A" is 0xfdfdf | FOR_EACH_CONNECTION_... in route_owner | conn TUNNEL-A mark 0/00000000, 0/00000000 vs | conn TUNNEL-A mark 0/00000000, 0/00000000 | route owner of "TUNNEL-A" unrouted: NULL | running updown command "ipsec _updown" for verb unroute | command executing unroute-client | executing unroute-client: PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/32' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='none' PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PLUTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMAN | popen cmd is 1287 chars long | cmd( 0):PLUTO_VERB='unroute-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='TUNNEL-A' PLUT: | cmd( 80):O_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.23' PLUTO_ME='192.1.2.45' PLUTO_MY_ID: | cmd( 160):='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=west.testing.: | cmd( 240):libreswan.org, E=user-west@testing.libreswan.org' PLUTO_MY_CLIENT='192.0.1.254/3: | cmd( 320):2' PLUTO_MY_CLIENT_NET='192.0.1.254' PLUTO_MY_CLIENT_MASK='255.255.255.255' PLUT: | cmd( 400):O_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16392' PLUTO_SA_TYPE='none' : | cmd( 480):PLUTO_PEER='192.1.2.23' PLUTO_PEER_ID='C=CA, ST=Ontario, L=Toronto, O=Libreswan,: | cmd( 560): OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswa: | cmd( 640):n.org' PLUTO_PEER_CLIENT='192.0.2.254/32' PLUTO_PEER_CLIENT_NET='192.0.2.254' PL: | cmd( 720):UTO_PEER_CLIENT_MASK='255.255.255.255' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL=': | cmd( 800):0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RS: | cmd( 880):ASIG+ENCRYPT+TUNNEL+PFS+DONT_REKEY+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN: | cmd( 960):_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 : | cmd(1040):PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_P: | cmd(1120):EER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' : | cmd(1200):VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x0 SPI_OUT=0x0 ipsec _updo: | cmd(1280):wn 2>&1: unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. unroute-client output: Error: Peer netns reference is invalid. | free hp@0x5596176d2438 | flush revival: connection 'TUNNEL-A' wasn't on the list | processing: STOP connection NULL (in discard_connection() at connections.c:249) | crl fetch request list locked by 'free_crl_fetch' | crl fetch request list unlocked by 'free_crl_fetch' shutting down interface lo/lo 127.0.0.1:4500 shutting down interface lo/lo 127.0.0.1:500 shutting down interface eth0/eth0 192.0.1.254:4500 shutting down interface eth0/eth0 192.0.1.254:500 shutting down interface eth1/eth1 192.1.2.45:4500 shutting down interface eth1/eth1 192.1.2.45:500 | FOR_EACH_STATE_... in delete_states_dead_interfaces | libevent_free: release ptr-libevent@0x5596176be6d8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca5c8 | libevent_free: release ptr-libevent@0x559617664ee8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca678 | libevent_free: release ptr-libevent@0x559617664808 | free_event_entry: release EVENT_NULL-pe@0x5596176ca728 | libevent_free: release ptr-libevent@0x55961766c0c8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca7d8 | libevent_free: release ptr-libevent@0x55961766c1c8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca888 | libevent_free: release ptr-libevent@0x55961766c2c8 | free_event_entry: release EVENT_NULL-pe@0x5596176ca938 | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations | libevent_free: release ptr-libevent@0x5596176be788 | free_event_entry: release EVENT_NULL-pe@0x5596176b28a8 | libevent_free: release ptr-libevent@0x559617664e38 | free_event_entry: release EVENT_NULL-pe@0x5596176b2408 | libevent_free: release ptr-libevent@0x5596176ab3e8 | free_event_entry: release EVENT_NULL-pe@0x55961766c378 | global timer EVENT_REINIT_SECRET uninitialized | global timer EVENT_SHUNT_SCAN uninitialized | global timer EVENT_PENDING_DDNS uninitialized | global timer EVENT_PENDING_PHASE2 uninitialized | global timer EVENT_CHECK_CRLS uninitialized | global timer EVENT_REVIVE_CONNS uninitialized | global timer EVENT_FREE_ROOT_CERTS uninitialized | global timer EVENT_RESET_LOG_RATE_LIMIT uninitialized | global timer EVENT_NAT_T_KEEPALIVE uninitialized | libevent_free: release ptr-libevent@0x559617670948 | signal event handler PLUTO_SIGCHLD uninstalled | libevent_free: release ptr-libevent@0x5596175ee7b8 | signal event handler PLUTO_SIGTERM uninstalled | libevent_free: release ptr-libevent@0x5596176c9da8 | signal event handler PLUTO_SIGHUP uninstalled | libevent_free: release ptr-libevent@0x5596176c9fe8 | signal event handler PLUTO_SIGSYS uninstalled | releasing event base | libevent_free: release ptr-libevent@0x5596176c9eb8 | libevent_free: release ptr-libevent@0x5596176accc8 | libevent_free: release ptr-libevent@0x5596176acc78 | libevent_free: release ptr-libevent@0x5596176cb508 | libevent_free: release ptr-libevent@0x5596176acc38 | libevent_free: release ptr-libevent@0x5596176c9a78 | libevent_free: release ptr-libevent@0x5596176c9ce8 | libevent_free: release ptr-libevent@0x5596176ace78 | libevent_free: release ptr-libevent@0x5596176b2478 | libevent_free: release ptr-libevent@0x5596176b20d8 | libevent_free: release ptr-libevent@0x5596176ca9a8 | libevent_free: release ptr-libevent@0x5596176ca8f8 | libevent_free: release ptr-libevent@0x5596176ca848 | libevent_free: release ptr-libevent@0x5596176ca798 | libevent_free: release ptr-libevent@0x5596176ca6e8 | libevent_free: release ptr-libevent@0x5596176ca638 | libevent_free: release ptr-libevent@0x5596175eda68 | libevent_free: release ptr-libevent@0x5596176c9d68 | libevent_free: release ptr-libevent@0x5596176c9d28 | libevent_free: release ptr-libevent@0x5596176c9be8 | libevent_free: release ptr-libevent@0x5596176c9e78 | libevent_free: release ptr-libevent@0x5596176c9ab8 | libevent_free: release ptr-libevent@0x5596176724d8 | libevent_free: release ptr-libevent@0x559617672458 | libevent_free: release ptr-libevent@0x5596175eddd8 | releasing global libevent data | libevent_free: release ptr-libevent@0x559617672658 | libevent_free: release ptr-libevent@0x5596176725d8 | libevent_free: release ptr-libevent@0x559617672558 leak detective found no leaks