--- road.console.txt 2019-08-24 18:12:56.167677661 +0000 +++ OUTPUT/road.console.txt 2019-08-26 13:13:02.254439461 +0000 @@ -71,11 +71,29 @@ ../../pluto/bin/ipsec-look.sh road NOW XFRM state: +src 192.1.2.23 dst 192.1.3.209 + proto esp spi 0xSPISPI reqid REQID mode tunnel + replay-window 32 flag af-unspec + aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 + encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 +src 192.1.3.209 dst 192.1.2.23 + proto esp spi 0xSPISPI reqid REQID mode tunnel + replay-window 32 flag af-unspec + aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 + encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 XFRM policy: +src 0.0.0.0/0 dst 192.0.2.100/32 + dir fwd priority 1040383 ptype main + tmpl src 192.1.2.23 dst 192.1.3.209 + proto esp reqid REQID mode tunnel +src 0.0.0.0/0 dst 192.0.2.100/32 + dir in priority 1040383 ptype main + tmpl src 192.1.2.23 dst 192.1.3.209 + proto esp reqid REQID mode tunnel src 192.0.2.100/32 dst 0.0.0.0/0 dir out priority 1040383 ptype main - tmpl src 0.0.0.0 dst 0.0.0.0 - proto esp reqid REQID mode transport + tmpl src 192.1.3.209 dst 192.1.2.23 + proto esp reqid REQID mode tunnel XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES @@ -105,8 +123,7 @@ ping -q -n -c 4 -I 192.0.2.100 192.1.2.23 PING 192.1.2.23 (192.1.2.23) from 192.0.2.100 : 56(84) bytes of data. --- 192.1.2.23 ping statistics --- -4 packets transmitted, 4 received, 0% packet loss, time XXXX -rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms +4 packets transmitted, 0 received, 100% packet loss, time XXXX road # echo done done