Aug 26 13:09:59.274842: FIPS Product: YES Aug 26 13:09:59.274936: FIPS Kernel: NO Aug 26 13:09:59.274939: FIPS Mode: NO Aug 26 13:09:59.274942: NSS DB directory: sql:/etc/ipsec.d Aug 26 13:09:59.275083: Initializing NSS Aug 26 13:09:59.275090: Opening NSS database "sql:/etc/ipsec.d" read-only Aug 26 13:09:59.317430: NSS initialized Aug 26 13:09:59.317448: NSS crypto library initialized Aug 26 13:09:59.317453: FIPS HMAC integrity support [enabled] Aug 26 13:09:59.317455: FIPS mode disabled for pluto daemon Aug 26 13:09:59.399221: FIPS HMAC integrity verification self-test FAILED Aug 26 13:09:59.399718: libcap-ng support [enabled] Aug 26 13:09:59.399735: Linux audit support [enabled] Aug 26 13:09:59.400107: Linux audit activated Aug 26 13:09:59.400117: Starting Pluto (Libreswan Version v3.28-685-gbfd5aef521-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:13183 Aug 26 13:09:59.400120: core dump dir: /tmp Aug 26 13:09:59.400122: secrets file: /etc/ipsec.secrets Aug 26 13:09:59.400125: leak-detective enabled Aug 26 13:09:59.400127: NSS crypto [enabled] Aug 26 13:09:59.400129: XAUTH PAM support [enabled] Aug 26 13:09:59.400208: | libevent is using pluto's memory allocator Aug 26 13:09:59.400216: Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) Aug 26 13:09:59.400235: | libevent_malloc: new ptr-libevent@0x55e277676138 size 40 Aug 26 13:09:59.400240: | libevent_malloc: new ptr-libevent@0x55e277670cd8 size 40 Aug 26 13:09:59.400243: | libevent_malloc: new ptr-libevent@0x55e277670dd8 size 40 Aug 26 13:09:59.400246: | creating event base Aug 26 13:09:59.400249: | libevent_malloc: new ptr-libevent@0x55e2776f5408 size 56 Aug 26 13:09:59.400254: | libevent_malloc: new ptr-libevent@0x55e277699c88 size 664 Aug 26 13:09:59.400266: | libevent_malloc: new ptr-libevent@0x55e2776f5478 size 24 Aug 26 13:09:59.400270: | libevent_malloc: new ptr-libevent@0x55e2776f54c8 size 384 Aug 26 13:09:59.400281: | libevent_malloc: new ptr-libevent@0x55e2776f53c8 size 16 Aug 26 13:09:59.400286: | libevent_malloc: new ptr-libevent@0x55e277670908 size 40 Aug 26 13:09:59.400292: | libevent_malloc: new ptr-libevent@0x55e277670d38 size 48 Aug 26 13:09:59.400301: | libevent_realloc: new ptr-libevent@0x55e277699918 size 256 Aug 26 13:09:59.400304: | libevent_malloc: new ptr-libevent@0x55e2776f5678 size 16 Aug 26 13:09:59.400311: | libevent_free: release ptr-libevent@0x55e2776f5408 Aug 26 13:09:59.400315: | libevent initialized Aug 26 13:09:59.400320: | libevent_realloc: new ptr-libevent@0x55e2776f5408 size 64 Aug 26 13:09:59.400324: | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds Aug 26 13:09:59.400344: | init_nat_traversal() initialized with keep_alive=0s Aug 26 13:09:59.400347: NAT-Traversal support [enabled] Aug 26 13:09:59.400351: | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized Aug 26 13:09:59.400357: | global one-shot timer EVENT_FREE_ROOT_CERTS initialized Aug 26 13:09:59.400361: | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds Aug 26 13:09:59.400398: | global one-shot timer EVENT_REVIVE_CONNS initialized Aug 26 13:09:59.400403: | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds Aug 26 13:09:59.400407: | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Aug 26 13:09:59.400457: Encryption algorithms: Aug 26 13:09:59.400467: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c Aug 26 13:09:59.400472: AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b Aug 26 13:09:59.400477: AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a Aug 26 13:09:59.400481: 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des Aug 26 13:09:59.400484: CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} Aug 26 13:09:59.400495: CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia Aug 26 13:09:59.400500: AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c Aug 26 13:09:59.400504: AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b Aug 26 13:09:59.400507: AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a Aug 26 13:09:59.400511: AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr Aug 26 13:09:59.400515: AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes Aug 26 13:09:59.400519: SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent Aug 26 13:09:59.400523: TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish Aug 26 13:09:59.400527: TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh Aug 26 13:09:59.400530: NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac Aug 26 13:09:59.400534: NULL IKEv1: ESP IKEv2: ESP [] Aug 26 13:09:59.400537: CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Aug 26 13:09:59.400545: Hash algorithms: Aug 26 13:09:59.400548: MD5 IKEv1: IKE IKEv2: Aug 26 13:09:59.400551: SHA1 IKEv1: IKE IKEv2: FIPS sha Aug 26 13:09:59.400555: SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 Aug 26 13:09:59.400558: SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 Aug 26 13:09:59.400560: SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 Aug 26 13:09:59.400574: PRF algorithms: Aug 26 13:09:59.400578: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 Aug 26 13:09:59.400581: HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 Aug 26 13:09:59.400585: HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 Aug 26 13:09:59.400588: HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 Aug 26 13:09:59.400592: HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 Aug 26 13:09:59.400595: AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Aug 26 13:09:59.400620: Integrity algorithms: Aug 26 13:09:59.400625: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 Aug 26 13:09:59.400630: HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 Aug 26 13:09:59.400634: HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 Aug 26 13:09:59.400638: HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 Aug 26 13:09:59.400642: HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 Aug 26 13:09:59.400645: HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH Aug 26 13:09:59.400649: AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 Aug 26 13:09:59.400652: AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac Aug 26 13:09:59.400656: NONE IKEv1: ESP IKEv2: IKE ESP FIPS null Aug 26 13:09:59.400668: DH algorithms: Aug 26 13:09:59.400672: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 Aug 26 13:09:59.400675: MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 Aug 26 13:09:59.400678: MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 Aug 26 13:09:59.400685: MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 Aug 26 13:09:59.400689: MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 Aug 26 13:09:59.400692: MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 Aug 26 13:09:59.400695: MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 Aug 26 13:09:59.400699: DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 Aug 26 13:09:59.400702: DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 Aug 26 13:09:59.400706: DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 Aug 26 13:09:59.400709: DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 Aug 26 13:09:59.400712: testing CAMELLIA_CBC: Aug 26 13:09:59.400715: Camellia: 16 bytes with 128-bit key Aug 26 13:09:59.400842: Camellia: 16 bytes with 128-bit key Aug 26 13:09:59.400875: Camellia: 16 bytes with 256-bit key Aug 26 13:09:59.400908: Camellia: 16 bytes with 256-bit key Aug 26 13:09:59.400940: testing AES_GCM_16: Aug 26 13:09:59.400944: empty string Aug 26 13:09:59.400975: one block Aug 26 13:09:59.401002: two blocks Aug 26 13:09:59.401030: two blocks with associated data Aug 26 13:09:59.401060: testing AES_CTR: Aug 26 13:09:59.401064: Encrypting 16 octets using AES-CTR with 128-bit key Aug 26 13:09:59.401093: Encrypting 32 octets using AES-CTR with 128-bit key Aug 26 13:09:59.401125: Encrypting 36 octets using AES-CTR with 128-bit key Aug 26 13:09:59.401160: Encrypting 16 octets using AES-CTR with 192-bit key Aug 26 13:09:59.401190: Encrypting 32 octets using AES-CTR with 192-bit key Aug 26 13:09:59.401221: Encrypting 36 octets using AES-CTR with 192-bit key Aug 26 13:09:59.401252: Encrypting 16 octets using AES-CTR with 256-bit key Aug 26 13:09:59.401282: Encrypting 32 octets using AES-CTR with 256-bit key Aug 26 13:09:59.401317: Encrypting 36 octets using AES-CTR with 256-bit key Aug 26 13:09:59.401353: testing AES_CBC: Aug 26 13:09:59.401358: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Aug 26 13:09:59.401387: Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Aug 26 13:09:59.401420: Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Aug 26 13:09:59.401452: Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key Aug 26 13:09:59.401489: testing AES_XCBC: Aug 26 13:09:59.401494: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input Aug 26 13:09:59.401622: RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input Aug 26 13:09:59.401763: RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input Aug 26 13:09:59.401896: RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input Aug 26 13:09:59.402031: RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input Aug 26 13:09:59.402168: RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input Aug 26 13:09:59.402310: RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input Aug 26 13:09:59.402612: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) Aug 26 13:09:59.402747: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) Aug 26 13:09:59.402894: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) Aug 26 13:09:59.403152: testing HMAC_MD5: Aug 26 13:09:59.403159: RFC 2104: MD5_HMAC test 1 Aug 26 13:09:59.403346: RFC 2104: MD5_HMAC test 2 Aug 26 13:09:59.403515: RFC 2104: MD5_HMAC test 3 Aug 26 13:09:59.403768: 8 CPU cores online Aug 26 13:09:59.403774: starting up 7 crypto helpers Aug 26 13:09:59.403808: started thread for crypto helper 0 Aug 26 13:09:59.403832: started thread for crypto helper 1 Aug 26 13:09:59.403838: | starting up helper thread 1 Aug 26 13:09:59.403852: | status value returned by setting the priority of this thread (crypto helper 1) 22 Aug 26 13:09:59.403856: | crypto helper 1 waiting (nothing to do) Aug 26 13:09:59.403858: started thread for crypto helper 2 Aug 26 13:09:59.404078: started thread for crypto helper 3 Aug 26 13:09:59.404102: started thread for crypto helper 4 Aug 26 13:09:59.404109: | starting up helper thread 4 Aug 26 13:09:59.404120: | status value returned by setting the priority of this thread (crypto helper 4) 22 Aug 26 13:09:59.404124: started thread for crypto helper 5 Aug 26 13:09:59.404156: started thread for crypto helper 6 Aug 26 13:09:59.404161: | checking IKEv1 state table Aug 26 13:09:59.404170: | MAIN_R0: category: half-open IKE SA flags: 0: Aug 26 13:09:59.404174: | -> MAIN_R1 EVENT_SO_DISCARD Aug 26 13:09:59.404177: | MAIN_I1: category: half-open IKE SA flags: 0: Aug 26 13:09:59.404180: | -> MAIN_I2 EVENT_RETRANSMIT Aug 26 13:09:59.404182: | MAIN_R1: category: open IKE SA flags: 200: Aug 26 13:09:59.404185: | -> MAIN_R2 EVENT_RETRANSMIT Aug 26 13:09:59.404188: | -> UNDEFINED EVENT_RETRANSMIT Aug 26 13:09:59.404190: | -> UNDEFINED EVENT_RETRANSMIT Aug 26 13:09:59.404193: | MAIN_I2: category: open IKE SA flags: 0: Aug 26 13:09:59.404196: | -> MAIN_I3 EVENT_RETRANSMIT Aug 26 13:09:59.404198: | -> UNDEFINED EVENT_RETRANSMIT Aug 26 13:09:59.404201: | -> UNDEFINED EVENT_RETRANSMIT Aug 26 13:09:59.404204: | MAIN_R2: category: open IKE SA flags: 0: Aug 26 13:09:59.404206: | -> MAIN_R3 EVENT_SA_REPLACE Aug 26 13:09:59.404209: | -> MAIN_R3 EVENT_SA_REPLACE Aug 26 13:09:59.404211: | -> UNDEFINED EVENT_SA_REPLACE Aug 26 13:09:59.404214: | MAIN_I3: category: open IKE SA flags: 0: Aug 26 13:09:59.404217: | -> MAIN_I4 EVENT_SA_REPLACE Aug 26 13:09:59.404219: | -> MAIN_I4 EVENT_SA_REPLACE Aug 26 13:09:59.404222: | -> UNDEFINED EVENT_SA_REPLACE Aug 26 13:09:59.404225: | MAIN_R3: category: established IKE SA flags: 200: Aug 26 13:09:59.404227: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404230: | MAIN_I4: category: established IKE SA flags: 0: Aug 26 13:09:59.404233: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404236: | AGGR_R0: category: half-open IKE SA flags: 0: Aug 26 13:09:59.404238: | -> AGGR_R1 EVENT_SO_DISCARD Aug 26 13:09:59.404241: | AGGR_I1: category: half-open IKE SA flags: 0: Aug 26 13:09:59.404244: | -> AGGR_I2 EVENT_SA_REPLACE Aug 26 13:09:59.404246: | -> AGGR_I2 EVENT_SA_REPLACE Aug 26 13:09:59.404249: | AGGR_R1: category: open IKE SA flags: 200: Aug 26 13:09:59.404252: | -> AGGR_R2 EVENT_SA_REPLACE Aug 26 13:09:59.404254: | -> AGGR_R2 EVENT_SA_REPLACE Aug 26 13:09:59.404257: | AGGR_I2: category: established IKE SA flags: 200: Aug 26 13:09:59.404259: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404263: | AGGR_R2: category: established IKE SA flags: 0: Aug 26 13:09:59.404265: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404268: | QUICK_R0: category: established CHILD SA flags: 0: Aug 26 13:09:59.404271: | -> QUICK_R1 EVENT_RETRANSMIT Aug 26 13:09:59.404274: | QUICK_I1: category: established CHILD SA flags: 0: Aug 26 13:09:59.404276: | -> QUICK_I2 EVENT_SA_REPLACE Aug 26 13:09:59.404279: | QUICK_R1: category: established CHILD SA flags: 0: Aug 26 13:09:59.404282: | -> QUICK_R2 EVENT_SA_REPLACE Aug 26 13:09:59.404284: | QUICK_I2: category: established CHILD SA flags: 200: Aug 26 13:09:59.404287: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404296: | QUICK_R2: category: established CHILD SA flags: 0: Aug 26 13:09:59.404299: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404302: | INFO: category: informational flags: 0: Aug 26 13:09:59.404310: | starting up helper thread 6 Aug 26 13:09:59.404321: | status value returned by setting the priority of this thread (crypto helper 6) 22 Aug 26 13:09:59.404305: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404331: | INFO_PROTECTED: category: informational flags: 0: Aug 26 13:09:59.404333: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404336: | XAUTH_R0: category: established IKE SA flags: 0: Aug 26 13:09:59.404339: | -> XAUTH_R1 EVENT_NULL Aug 26 13:09:59.404342: | XAUTH_R1: category: established IKE SA flags: 0: Aug 26 13:09:59.404350: | -> MAIN_R3 EVENT_SA_REPLACE Aug 26 13:09:59.404354: | MODE_CFG_R0: category: informational flags: 0: Aug 26 13:09:59.404357: | -> MODE_CFG_R1 EVENT_SA_REPLACE Aug 26 13:09:59.404360: | MODE_CFG_R1: category: established IKE SA flags: 0: Aug 26 13:09:59.404362: | -> MODE_CFG_R2 EVENT_SA_REPLACE Aug 26 13:09:59.404365: | MODE_CFG_R2: category: established IKE SA flags: 0: Aug 26 13:09:59.404368: | -> UNDEFINED EVENT_NULL Aug 26 13:09:59.404371: | MODE_CFG_I1: category: established IKE SA flags: 0: Aug 26 13:09:59.404373: | -> MAIN_I4 EVENT_SA_REPLACE Aug 26 13:09:59.404376: | XAUTH_I0: category: established IKE SA flags: 0: Aug 26 13:09:59.404379: | -> XAUTH_I1 EVENT_RETRANSMIT Aug 26 13:09:59.404382: | XAUTH_I1: category: established IKE SA flags: 0: Aug 26 13:09:59.404384: | -> MAIN_I4 EVENT_RETRANSMIT Aug 26 13:09:59.404390: | checking IKEv2 state table Aug 26 13:09:59.404398: | PARENT_I0: category: ignore flags: 0: Aug 26 13:09:59.404401: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) Aug 26 13:09:59.404404: | PARENT_I1: category: half-open IKE SA flags: 0: Aug 26 13:09:59.404407: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) Aug 26 13:09:59.404410: | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) Aug 26 13:09:59.404413: | PARENT_I2: category: open IKE SA flags: 0: Aug 26 13:09:59.404416: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) Aug 26 13:09:59.404419: | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) Aug 26 13:09:59.404422: | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) Aug 26 13:09:59.404425: | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) Aug 26 13:09:59.404428: | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) Aug 26 13:09:59.404431: | PARENT_I3: category: established IKE SA flags: 0: Aug 26 13:09:59.404434: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) Aug 26 13:09:59.404437: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) Aug 26 13:09:59.404440: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) Aug 26 13:09:59.404443: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) Aug 26 13:09:59.404446: | PARENT_R0: category: half-open IKE SA flags: 0: Aug 26 13:09:59.404449: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) Aug 26 13:09:59.404452: | PARENT_R1: category: half-open IKE SA flags: 0: Aug 26 13:09:59.404455: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) Aug 26 13:09:59.404458: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) Aug 26 13:09:59.404461: | PARENT_R2: category: established IKE SA flags: 0: Aug 26 13:09:59.404464: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) Aug 26 13:09:59.404467: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) Aug 26 13:09:59.404470: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) Aug 26 13:09:59.404473: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) Aug 26 13:09:59.404476: | V2_CREATE_I0: category: established IKE SA flags: 0: Aug 26 13:09:59.404478: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) Aug 26 13:09:59.404482: | V2_CREATE_I: category: established IKE SA flags: 0: Aug 26 13:09:59.404485: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) Aug 26 13:09:59.404488: | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: Aug 26 13:09:59.404491: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) Aug 26 13:09:59.404494: | V2_REKEY_IKE_I: category: established IKE SA flags: 0: Aug 26 13:09:59.404497: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) Aug 26 13:09:59.404503: | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: Aug 26 13:09:59.404506: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) Aug 26 13:09:59.404509: | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: Aug 26 13:09:59.404512: | V2_CREATE_R: category: established IKE SA flags: 0: Aug 26 13:09:59.404515: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) Aug 26 13:09:59.404518: | V2_REKEY_IKE_R: category: established IKE SA flags: 0: Aug 26 13:09:59.404521: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) Aug 26 13:09:59.404525: | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: Aug 26 13:09:59.404528: | V2_IPSEC_I: category: established CHILD SA flags: 0: Aug 26 13:09:59.404531: | V2_IPSEC_R: category: established CHILD SA flags: 0: Aug 26 13:09:59.404534: | IKESA_DEL: category: established IKE SA flags: 0: Aug 26 13:09:59.404537: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) Aug 26 13:09:59.404540: | CHILDSA_DEL: category: informational flags: 0: Aug 26 13:09:59.404553: Using Linux XFRM/NETKEY IPsec interface code on 5.1.18-200.fc29.x86_64 Aug 26 13:09:59.404979: | Hard-wiring algorithms Aug 26 13:09:59.404985: | adding AES_CCM_16 to kernel algorithm db Aug 26 13:09:59.404990: | adding AES_CCM_12 to kernel algorithm db Aug 26 13:09:59.404993: | adding AES_CCM_8 to kernel algorithm db Aug 26 13:09:59.404995: | adding 3DES_CBC to kernel algorithm db Aug 26 13:09:59.404998: | adding CAMELLIA_CBC to kernel algorithm db Aug 26 13:09:59.405001: | adding AES_GCM_16 to kernel algorithm db Aug 26 13:09:59.405004: | adding AES_GCM_12 to kernel algorithm db Aug 26 13:09:59.405006: | adding AES_GCM_8 to kernel algorithm db Aug 26 13:09:59.405009: | adding AES_CTR to kernel algorithm db Aug 26 13:09:59.405011: | adding AES_CBC to kernel algorithm db Aug 26 13:09:59.405014: | adding SERPENT_CBC to kernel algorithm db Aug 26 13:09:59.405017: | adding TWOFISH_CBC to kernel algorithm db Aug 26 13:09:59.405020: | adding NULL_AUTH_AES_GMAC to kernel algorithm db Aug 26 13:09:59.405023: | adding NULL to kernel algorithm db Aug 26 13:09:59.405026: | adding CHACHA20_POLY1305 to kernel algorithm db Aug 26 13:09:59.405029: | adding HMAC_MD5_96 to kernel algorithm db Aug 26 13:09:59.405031: | adding HMAC_SHA1_96 to kernel algorithm db Aug 26 13:09:59.405034: | adding HMAC_SHA2_512_256 to kernel algorithm db Aug 26 13:09:59.405036: | adding HMAC_SHA2_384_192 to kernel algorithm db Aug 26 13:09:59.405039: | adding HMAC_SHA2_256_128 to kernel algorithm db Aug 26 13:09:59.405042: | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db Aug 26 13:09:59.405044: | adding AES_XCBC_96 to kernel algorithm db Aug 26 13:09:59.405047: | adding AES_CMAC_96 to kernel algorithm db Aug 26 13:09:59.405049: | adding NONE to kernel algorithm db Aug 26 13:09:59.405072: | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes Aug 26 13:09:59.405080: | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds Aug 26 13:09:59.405083: | setup kernel fd callback Aug 26 13:09:59.405087: | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x55e2776fa048 Aug 26 13:09:59.405092: | libevent_malloc: new ptr-libevent@0x55e2776de4a8 size 128 Aug 26 13:09:59.405096: | libevent_malloc: new ptr-libevent@0x55e2776fa158 size 16 Aug 26 13:09:59.405103: | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x55e2776fab88 Aug 26 13:09:59.405108: | libevent_malloc: new ptr-libevent@0x55e27769b0d8 size 128 Aug 26 13:09:59.405111: | libevent_malloc: new ptr-libevent@0x55e2776fab48 size 16 Aug 26 13:09:59.405353: | global one-shot timer EVENT_CHECK_CRLS initialized Aug 26 13:09:59.405366: selinux support is enabled. Aug 26 13:09:59.404124: | crypto helper 4 waiting (nothing to do) Aug 26 13:09:59.406071: | unbound context created - setting debug level to 5 Aug 26 13:09:59.406105: | /etc/hosts lookups activated Aug 26 13:09:59.406124: | /etc/resolv.conf usage activated Aug 26 13:09:59.406190: | outgoing-port-avoid set 0-65535 Aug 26 13:09:59.406222: | outgoing-port-permit set 32768-60999 Aug 26 13:09:59.406226: | Loading dnssec root key from:/var/lib/unbound/root.key Aug 26 13:09:59.406230: | No additional dnssec trust anchors defined via dnssec-trusted= option Aug 26 13:09:59.406233: | Setting up events, loop start Aug 26 13:09:59.406237: | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x55e2776fabf8 Aug 26 13:09:59.406240: | libevent_malloc: new ptr-libevent@0x55e277706e08 size 128 Aug 26 13:09:59.406244: | libevent_malloc: new ptr-libevent@0x55e2777120d8 size 16 Aug 26 13:09:59.406251: | libevent_realloc: new ptr-libevent@0x55e277712118 size 256 Aug 26 13:09:59.406255: | libevent_malloc: new ptr-libevent@0x55e277712248 size 8 Aug 26 13:09:59.406259: | libevent_realloc: new ptr-libevent@0x55e277712288 size 144 Aug 26 13:09:59.406262: | libevent_malloc: new ptr-libevent@0x55e27769a7e8 size 152 Aug 26 13:09:59.406266: | libevent_malloc: new ptr-libevent@0x55e277712348 size 16 Aug 26 13:09:59.406270: | signal event handler PLUTO_SIGCHLD installed Aug 26 13:09:59.406274: | libevent_malloc: new ptr-libevent@0x55e277712388 size 8 Aug 26 13:09:59.406277: | libevent_malloc: new ptr-libevent@0x55e2776a5678 size 152 Aug 26 13:09:59.406280: | signal event handler PLUTO_SIGTERM installed Aug 26 13:09:59.406283: | libevent_malloc: new ptr-libevent@0x55e2777123c8 size 8 Aug 26 13:09:59.406287: | libevent_malloc: new ptr-libevent@0x55e27769d498 size 152 Aug 26 13:09:59.406297: | signal event handler PLUTO_SIGHUP installed Aug 26 13:09:59.406300: | libevent_malloc: new ptr-libevent@0x55e277712408 size 8 Aug 26 13:09:59.406303: | libevent_realloc: release ptr-libevent@0x55e277712288 Aug 26 13:09:59.406307: | libevent_realloc: new ptr-libevent@0x55e277712448 size 256 Aug 26 13:09:59.406310: | libevent_malloc: new ptr-libevent@0x55e277712578 size 152 Aug 26 13:09:59.406313: | signal event handler PLUTO_SIGSYS installed Aug 26 13:09:59.406661: | created addconn helper (pid:13352) using fork+execve Aug 26 13:09:59.406677: | forked child 13352 Aug 26 13:09:59.406725: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.407066: listening for IKE messages Aug 26 13:09:59.407159: | Inspecting interface lo Aug 26 13:09:59.407168: | found lo with address 127.0.0.1 Aug 26 13:09:59.407171: | Inspecting interface eth0 Aug 26 13:09:59.407176: | found eth0 with address 192.0.2.254 Aug 26 13:09:59.407181: | Inspecting interface eth0 Aug 26 13:09:59.407186: | found eth0 with address 192.0.22.251 Aug 26 13:09:59.407189: | Inspecting interface eth0 Aug 26 13:09:59.407193: | found eth0 with address 192.0.22.254 Aug 26 13:09:59.407196: | Inspecting interface eth0 Aug 26 13:09:59.407200: | found eth0 with address 192.0.2.251 Aug 26 13:09:59.407203: | Inspecting interface eth1 Aug 26 13:09:59.407207: | found eth1 with address 192.1.2.23 Aug 26 13:09:59.407468: Kernel supports NIC esp-hw-offload Aug 26 13:09:59.407487: adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.2.23:500 Aug 26 13:09:59.407544: | NAT-Traversal: Trying sockopt style NAT-T Aug 26 13:09:59.407551: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Aug 26 13:09:59.407555: adding interface eth1/eth1 192.1.2.23:4500 Aug 26 13:09:59.407585: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.2.251:500 Aug 26 13:09:59.407609: | NAT-Traversal: Trying sockopt style NAT-T Aug 26 13:09:59.407615: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Aug 26 13:09:59.407619: adding interface eth0/eth0 192.0.2.251:4500 Aug 26 13:09:59.407647: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.22.254:500 Aug 26 13:09:59.407671: | NAT-Traversal: Trying sockopt style NAT-T Aug 26 13:09:59.407677: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Aug 26 13:09:59.407685: adding interface eth0/eth0 192.0.22.254:4500 Aug 26 13:09:59.407714: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.22.251:500 Aug 26 13:09:59.407738: | NAT-Traversal: Trying sockopt style NAT-T Aug 26 13:09:59.407744: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Aug 26 13:09:59.407748: adding interface eth0/eth0 192.0.22.251:4500 Aug 26 13:09:59.407776: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.2.254:500 Aug 26 13:09:59.407801: | NAT-Traversal: Trying sockopt style NAT-T Aug 26 13:09:59.407807: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Aug 26 13:09:59.407811: adding interface eth0/eth0 192.0.2.254:4500 Aug 26 13:09:59.407847: adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 Aug 26 13:09:59.407871: | NAT-Traversal: Trying sockopt style NAT-T Aug 26 13:09:59.407877: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Aug 26 13:09:59.407881: adding interface lo/lo 127.0.0.1:4500 Aug 26 13:09:59.407970: | no interfaces to sort Aug 26 13:09:59.407976: | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations Aug 26 13:09:59.407990: | add_fd_read_event_handler: new ethX-pe@0x55e277712e68 Aug 26 13:09:59.407994: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:09:59.407998: | libevent_malloc: new ptr-libevent@0x55e277712ed8 size 16 Aug 26 13:09:59.408005: | setup callback for interface lo 127.0.0.1:4500 fd 28 Aug 26 13:09:59.408009: | add_fd_read_event_handler: new ethX-pe@0x55e277712f18 Aug 26 13:09:59.408015: | libevent_malloc: new ptr-libevent@0x55e27769ca88 size 128 Aug 26 13:09:59.408019: | libevent_malloc: new ptr-libevent@0x55e277712f88 size 16 Aug 26 13:09:59.408024: | setup callback for interface lo 127.0.0.1:500 fd 27 Aug 26 13:09:59.408027: | add_fd_read_event_handler: new ethX-pe@0x55e277712fc8 Aug 26 13:09:59.408034: | libevent_malloc: new ptr-libevent@0x55e27769d2f8 size 128 Aug 26 13:09:59.408038: | libevent_malloc: new ptr-libevent@0x55e277713038 size 16 Aug 26 13:09:59.408043: | setup callback for interface eth0 192.0.2.254:4500 fd 26 Aug 26 13:09:59.408047: | add_fd_read_event_handler: new ethX-pe@0x55e2777136f8 Aug 26 13:09:59.408050: | libevent_malloc: new ptr-libevent@0x55e277670ba8 size 128 Aug 26 13:09:59.408053: | libevent_malloc: new ptr-libevent@0x55e277713768 size 16 Aug 26 13:09:59.408058: | setup callback for interface eth0 192.0.2.254:500 fd 25 Aug 26 13:09:59.408061: | add_fd_read_event_handler: new ethX-pe@0x55e2777137a8 Aug 26 13:09:59.408064: | libevent_malloc: new ptr-libevent@0x55e2776714e8 size 128 Aug 26 13:09:59.408067: | libevent_malloc: new ptr-libevent@0x55e277713818 size 16 Aug 26 13:09:59.408072: | setup callback for interface eth0 192.0.22.251:4500 fd 24 Aug 26 13:09:59.408076: | add_fd_read_event_handler: new ethX-pe@0x55e277713858 Aug 26 13:09:59.408078: | libevent_malloc: new ptr-libevent@0x55e2776711d8 size 128 Aug 26 13:09:59.408081: | libevent_malloc: new ptr-libevent@0x55e2777138c8 size 16 Aug 26 13:09:59.408087: | setup callback for interface eth0 192.0.22.251:500 fd 23 Aug 26 13:09:59.408090: | add_fd_read_event_handler: new ethX-pe@0x55e277713908 Aug 26 13:09:59.408093: | libevent_malloc: new ptr-libevent@0x55e277713978 size 128 Aug 26 13:09:59.408096: | libevent_malloc: new ptr-libevent@0x55e277713a28 size 16 Aug 26 13:09:59.408101: | setup callback for interface eth0 192.0.22.254:4500 fd 22 Aug 26 13:09:59.408104: | add_fd_read_event_handler: new ethX-pe@0x55e277713a68 Aug 26 13:09:59.408107: | libevent_malloc: new ptr-libevent@0x55e277713ad8 size 128 Aug 26 13:09:59.408110: | libevent_malloc: new ptr-libevent@0x55e277713b88 size 16 Aug 26 13:09:59.408115: | setup callback for interface eth0 192.0.22.254:500 fd 21 Aug 26 13:09:59.408119: | add_fd_read_event_handler: new ethX-pe@0x55e277713bc8 Aug 26 13:09:59.408122: | libevent_malloc: new ptr-libevent@0x55e277713c38 size 128 Aug 26 13:09:59.408125: | libevent_malloc: new ptr-libevent@0x55e277713ce8 size 16 Aug 26 13:09:59.408133: | setup callback for interface eth0 192.0.2.251:4500 fd 20 Aug 26 13:09:59.408136: | add_fd_read_event_handler: new ethX-pe@0x55e277713d28 Aug 26 13:09:59.408139: | libevent_malloc: new ptr-libevent@0x55e277713d98 size 128 Aug 26 13:09:59.408142: | libevent_malloc: new ptr-libevent@0x55e277713e48 size 16 Aug 26 13:09:59.408147: | setup callback for interface eth0 192.0.2.251:500 fd 19 Aug 26 13:09:59.408150: | add_fd_read_event_handler: new ethX-pe@0x55e277713e88 Aug 26 13:09:59.408153: | libevent_malloc: new ptr-libevent@0x55e277713ef8 size 128 Aug 26 13:09:59.408156: | libevent_malloc: new ptr-libevent@0x55e277713fa8 size 16 Aug 26 13:09:59.408161: | setup callback for interface eth1 192.1.2.23:4500 fd 18 Aug 26 13:09:59.408167: | add_fd_read_event_handler: new ethX-pe@0x55e277713fe8 Aug 26 13:09:59.408170: | libevent_malloc: new ptr-libevent@0x55e277714058 size 128 Aug 26 13:09:59.408173: | libevent_malloc: new ptr-libevent@0x55e277714108 size 16 Aug 26 13:09:59.408178: | setup callback for interface eth1 192.1.2.23:500 fd 17 Aug 26 13:09:59.408184: | certs and keys locked by 'free_preshared_secrets' Aug 26 13:09:59.408188: | certs and keys unlocked by 'free_preshared_secrets' Aug 26 13:09:59.408207: loading secrets from "/etc/ipsec.secrets" Aug 26 13:09:59.408227: | saving Modulus Aug 26 13:09:59.408235: | saving PublicExponent Aug 26 13:09:59.408239: | ignoring PrivateExponent Aug 26 13:09:59.408243: | ignoring Prime1 Aug 26 13:09:59.408246: | ignoring Prime2 Aug 26 13:09:59.408250: | ignoring Exponent1 Aug 26 13:09:59.408253: | ignoring Exponent2 Aug 26 13:09:59.408256: | ignoring Coefficient Aug 26 13:09:59.408260: | ignoring CKAIDNSS Aug 26 13:09:59.408304: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Aug 26 13:09:59.408311: | computed rsa CKAID 8a 82 25 f1 Aug 26 13:09:59.408316: loaded private key for keyid: PKK_RSA:AQO9bJbr3 Aug 26 13:09:59.408324: | certs and keys locked by 'process_secret' Aug 26 13:09:59.408331: | certs and keys unlocked by 'process_secret' Aug 26 13:09:59.408342: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.408351: | spent 1.46 milliseconds in whack Aug 26 13:09:59.408366: | crypto helper 6 waiting (nothing to do) Aug 26 13:09:59.408382: | starting up helper thread 5 Aug 26 13:09:59.408389: | status value returned by setting the priority of this thread (crypto helper 5) 22 Aug 26 13:09:59.408395: | crypto helper 5 waiting (nothing to do) Aug 26 13:09:59.408405: | starting up helper thread 3 Aug 26 13:09:59.408411: | status value returned by setting the priority of this thread (crypto helper 3) 22 Aug 26 13:09:59.408413: | crypto helper 3 waiting (nothing to do) Aug 26 13:09:59.404305: | starting up helper thread 2 Aug 26 13:09:59.410359: | status value returned by setting the priority of this thread (crypto helper 2) 22 Aug 26 13:09:59.410368: | crypto helper 2 waiting (nothing to do) Aug 26 13:09:59.419319: | starting up helper thread 0 Aug 26 13:09:59.419346: | status value returned by setting the priority of this thread (crypto helper 0) 22 Aug 26 13:09:59.419350: | crypto helper 0 waiting (nothing to do) Aug 26 13:09:59.467526: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.467758: | FOR_EACH_CONNECTION_... in show_connections_status Aug 26 13:09:59.467774: | FOR_EACH_STATE_... in show_states_status (sort_states) Aug 26 13:09:59.467786: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.467795: | spent 0.277 milliseconds in whack Aug 26 13:09:59.555446: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.555476: | FOR_EACH_CONNECTION_... in conn_by_name Aug 26 13:09:59.555481: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Aug 26 13:09:59.555484: | FOR_EACH_CONNECTION_... in conn_by_name Aug 26 13:09:59.555487: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Aug 26 13:09:59.555497: | FOR_EACH_CONNECTION_... in conn_by_name Aug 26 13:09:59.555506: | Added new connection north-eastnets/0x1 with policy ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Aug 26 13:09:59.555510: | No AUTH policy was set - defaulting to RSASIG Aug 26 13:09:59.555538: | ike (phase1) algorithm values: AES_CBC_256-HMAC_SHA2_256-MODP2048 Aug 26 13:09:59.555543: | from whack: got --esp=aes128-sha2_512;modp3072 Aug 26 13:09:59.555560: | ESP/AH string values: AES_CBC_128-HMAC_SHA2_512_256-MODP3072 Aug 26 13:09:59.555566: | counting wild cards for @north is 0 Aug 26 13:09:59.555570: | counting wild cards for @east is 0 Aug 26 13:09:59.555581: | connect_to_host_pair: 192.1.2.23:500 192.1.3.33:500 -> hp@(nil): none Aug 26 13:09:59.555585: | new hp@0x55e277714c48 Aug 26 13:09:59.555591: added connection description "north-eastnets/0x1" Aug 26 13:09:59.555600: | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Aug 26 13:09:59.555612: | 192.0.2.0/24===192.1.2.23<192.1.2.23>[@east]...192.1.3.33<192.1.3.33>[@north]===192.0.3.0/24 Aug 26 13:09:59.555620: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.555627: | spent 0.191 milliseconds in whack Aug 26 13:09:59.555680: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.555691: add keyid @north Aug 26 13:09:59.555696: | add pubkey 01 03 e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab Aug 26 13:09:59.555699: | add pubkey 7f ec 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 Aug 26 13:09:59.555701: | add pubkey 93 9e 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 Aug 26 13:09:59.555704: | add pubkey 01 03 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 Aug 26 13:09:59.555707: | add pubkey 10 84 b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 Aug 26 13:09:59.555709: | add pubkey f4 6b 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f Aug 26 13:09:59.555712: | add pubkey 25 b4 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e Aug 26 13:09:59.555714: | add pubkey c8 16 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 Aug 26 13:09:59.555717: | add pubkey cc 92 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 Aug 26 13:09:59.555720: | add pubkey 13 0f 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 Aug 26 13:09:59.555722: | add pubkey 39 f9 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d Aug 26 13:09:59.555725: | add pubkey 9e ca 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 Aug 26 13:09:59.555727: | add pubkey ba 64 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 Aug 26 13:09:59.555730: | add pubkey 9c 85 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 Aug 26 13:09:59.555732: | add pubkey 61 eb 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 Aug 26 13:09:59.555735: | add pubkey 83 c2 d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca Aug 26 13:09:59.555737: | add pubkey f5 38 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 Aug 26 13:09:59.555740: | add pubkey c7 5e a5 99 Aug 26 13:09:59.555764: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Aug 26 13:09:59.555768: | computed rsa CKAID 88 aa 7c 5d Aug 26 13:09:59.555777: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.555783: | spent 0.106 milliseconds in whack Aug 26 13:09:59.555826: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.555836: add keyid @east Aug 26 13:09:59.555841: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Aug 26 13:09:59.555843: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Aug 26 13:09:59.555846: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Aug 26 13:09:59.555849: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Aug 26 13:09:59.555851: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Aug 26 13:09:59.555854: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Aug 26 13:09:59.555859: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Aug 26 13:09:59.555862: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Aug 26 13:09:59.555865: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Aug 26 13:09:59.555868: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Aug 26 13:09:59.555870: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Aug 26 13:09:59.555873: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Aug 26 13:09:59.555875: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Aug 26 13:09:59.555878: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Aug 26 13:09:59.555880: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Aug 26 13:09:59.555883: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Aug 26 13:09:59.555885: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Aug 26 13:09:59.555888: | add pubkey 51 51 48 ef Aug 26 13:09:59.555897: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Aug 26 13:09:59.555900: | computed rsa CKAID 8a 82 25 f1 Aug 26 13:09:59.555908: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.555914: | spent 0.0915 milliseconds in whack Aug 26 13:09:59.555953: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.555964: | FOR_EACH_CONNECTION_... in conn_by_name Aug 26 13:09:59.555968: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Aug 26 13:09:59.555971: | FOR_EACH_CONNECTION_... in conn_by_name Aug 26 13:09:59.555974: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Aug 26 13:09:59.555977: | FOR_EACH_CONNECTION_... in conn_by_name Aug 26 13:09:59.555982: | Added new connection north-eastnets/0x2 with policy ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Aug 26 13:09:59.555986: | No AUTH policy was set - defaulting to RSASIG Aug 26 13:09:59.556002: | ike (phase1) algorithm values: AES_CBC_256-HMAC_SHA2_256-MODP2048 Aug 26 13:09:59.556006: | from whack: got --esp=aes128-sha2_512;modp3072 Aug 26 13:09:59.556024: | ESP/AH string values: AES_CBC_128-HMAC_SHA2_512_256-MODP3072 Aug 26 13:09:59.556029: | counting wild cards for @north is 0 Aug 26 13:09:59.556033: | counting wild cards for @east is 0 Aug 26 13:09:59.556040: | find_host_pair: comparing 192.1.2.23:500 to 192.1.3.33:500 but ignoring ports Aug 26 13:09:59.556046: | connect_to_host_pair: 192.1.2.23:500 192.1.3.33:500 -> hp@0x55e277714c48: north-eastnets/0x1 Aug 26 13:09:59.556049: added connection description "north-eastnets/0x2" Aug 26 13:09:59.556057: | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Aug 26 13:09:59.556068: | 192.0.22.0/24===192.1.2.23<192.1.2.23>[@east]...192.1.3.33<192.1.3.33>[@north]===192.0.3.0/24 Aug 26 13:09:59.556074: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.556080: | spent 0.129 milliseconds in whack Aug 26 13:09:59.556125: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.556135: add keyid @north Aug 26 13:09:59.556140: | unreference key: 0x55e27766cc48 @north cnt 1-- Aug 26 13:09:59.556145: | add pubkey 01 03 e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab Aug 26 13:09:59.556148: | add pubkey 7f ec 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 Aug 26 13:09:59.556151: | add pubkey 93 9e 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 Aug 26 13:09:59.556153: | add pubkey 01 03 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 Aug 26 13:09:59.556156: | add pubkey 10 84 b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 Aug 26 13:09:59.556158: | add pubkey f4 6b 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f Aug 26 13:09:59.556161: | add pubkey 25 b4 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e Aug 26 13:09:59.556164: | add pubkey c8 16 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 Aug 26 13:09:59.556170: | add pubkey cc 92 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 Aug 26 13:09:59.556173: | add pubkey 13 0f 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 Aug 26 13:09:59.556175: | add pubkey 39 f9 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d Aug 26 13:09:59.556178: | add pubkey 9e ca 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 Aug 26 13:09:59.556180: | add pubkey ba 64 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 Aug 26 13:09:59.556183: | add pubkey 9c 85 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 Aug 26 13:09:59.556186: | add pubkey 61 eb 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 Aug 26 13:09:59.556188: | add pubkey 83 c2 d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca Aug 26 13:09:59.556191: | add pubkey f5 38 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 Aug 26 13:09:59.556193: | add pubkey c7 5e a5 99 Aug 26 13:09:59.556205: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Aug 26 13:09:59.556209: | computed rsa CKAID 88 aa 7c 5d Aug 26 13:09:59.556216: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.556222: | spent 0.0999 milliseconds in whack Aug 26 13:09:59.556264: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.556273: add keyid @east Aug 26 13:09:59.556278: | unreference key: 0x55e277714fb8 @east cnt 1-- Aug 26 13:09:59.556283: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Aug 26 13:09:59.556285: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Aug 26 13:09:59.556291: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Aug 26 13:09:59.556297: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Aug 26 13:09:59.556300: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Aug 26 13:09:59.556303: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Aug 26 13:09:59.556305: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Aug 26 13:09:59.556308: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Aug 26 13:09:59.556310: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Aug 26 13:09:59.556313: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Aug 26 13:09:59.556315: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Aug 26 13:09:59.556318: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Aug 26 13:09:59.556320: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Aug 26 13:09:59.556323: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Aug 26 13:09:59.556325: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Aug 26 13:09:59.556328: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Aug 26 13:09:59.556331: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Aug 26 13:09:59.556333: | add pubkey 51 51 48 ef Aug 26 13:09:59.556342: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Aug 26 13:09:59.556345: | computed rsa CKAID 8a 82 25 f1 Aug 26 13:09:59.556352: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.556358: | spent 0.0945 milliseconds in whack Aug 26 13:09:59.556397: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.556408: listening for IKE messages Aug 26 13:09:59.556440: | Inspecting interface lo Aug 26 13:09:59.556447: | found lo with address 127.0.0.1 Aug 26 13:09:59.556451: | Inspecting interface eth0 Aug 26 13:09:59.556455: | found eth0 with address 192.0.2.254 Aug 26 13:09:59.556458: | Inspecting interface eth0 Aug 26 13:09:59.556462: | found eth0 with address 192.0.22.251 Aug 26 13:09:59.556465: | Inspecting interface eth0 Aug 26 13:09:59.556469: | found eth0 with address 192.0.22.254 Aug 26 13:09:59.556471: | Inspecting interface eth0 Aug 26 13:09:59.556476: | found eth0 with address 192.0.2.251 Aug 26 13:09:59.556482: | Inspecting interface eth1 Aug 26 13:09:59.556486: | found eth1 with address 192.1.2.23 Aug 26 13:09:59.556551: | no interfaces to sort Aug 26 13:09:59.556562: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:09:59.556567: | free_event_entry: release EVENT_NULL-pe@0x55e277712e68 Aug 26 13:09:59.556571: | add_fd_read_event_handler: new ethX-pe@0x55e277712e68 Aug 26 13:09:59.556575: | libevent_malloc: new ptr-libevent@0x55e277716228 size 128 Aug 26 13:09:59.556582: | setup callback for interface lo 127.0.0.1:4500 fd 28 Aug 26 13:09:59.556586: | libevent_free: release ptr-libevent@0x55e27769ca88 Aug 26 13:09:59.556590: | free_event_entry: release EVENT_NULL-pe@0x55e277712f18 Aug 26 13:09:59.556593: | add_fd_read_event_handler: new ethX-pe@0x55e277712f18 Aug 26 13:09:59.556596: | libevent_malloc: new ptr-libevent@0x55e27769ca88 size 128 Aug 26 13:09:59.556601: | setup callback for interface lo 127.0.0.1:500 fd 27 Aug 26 13:09:59.556606: | libevent_free: release ptr-libevent@0x55e27769d2f8 Aug 26 13:09:59.556609: | free_event_entry: release EVENT_NULL-pe@0x55e277712fc8 Aug 26 13:09:59.556612: | add_fd_read_event_handler: new ethX-pe@0x55e277712fc8 Aug 26 13:09:59.556615: | libevent_malloc: new ptr-libevent@0x55e27769d2f8 size 128 Aug 26 13:09:59.556621: | setup callback for interface eth0 192.0.2.254:4500 fd 26 Aug 26 13:09:59.556625: | libevent_free: release ptr-libevent@0x55e277670ba8 Aug 26 13:09:59.556628: | free_event_entry: release EVENT_NULL-pe@0x55e2777136f8 Aug 26 13:09:59.556631: | add_fd_read_event_handler: new ethX-pe@0x55e2777136f8 Aug 26 13:09:59.556634: | libevent_malloc: new ptr-libevent@0x55e277670ba8 size 128 Aug 26 13:09:59.556639: | setup callback for interface eth0 192.0.2.254:500 fd 25 Aug 26 13:09:59.556643: | libevent_free: release ptr-libevent@0x55e2776714e8 Aug 26 13:09:59.556646: | free_event_entry: release EVENT_NULL-pe@0x55e2777137a8 Aug 26 13:09:59.556649: | add_fd_read_event_handler: new ethX-pe@0x55e2777137a8 Aug 26 13:09:59.556652: | libevent_malloc: new ptr-libevent@0x55e2776714e8 size 128 Aug 26 13:09:59.556657: | setup callback for interface eth0 192.0.22.251:4500 fd 24 Aug 26 13:09:59.556662: | libevent_free: release ptr-libevent@0x55e2776711d8 Aug 26 13:09:59.556665: | free_event_entry: release EVENT_NULL-pe@0x55e277713858 Aug 26 13:09:59.556667: | add_fd_read_event_handler: new ethX-pe@0x55e277713858 Aug 26 13:09:59.556670: | libevent_malloc: new ptr-libevent@0x55e2776711d8 size 128 Aug 26 13:09:59.556676: | setup callback for interface eth0 192.0.22.251:500 fd 23 Aug 26 13:09:59.556680: | libevent_free: release ptr-libevent@0x55e277713978 Aug 26 13:09:59.556683: | free_event_entry: release EVENT_NULL-pe@0x55e277713908 Aug 26 13:09:59.556686: | add_fd_read_event_handler: new ethX-pe@0x55e277713908 Aug 26 13:09:59.556689: | libevent_malloc: new ptr-libevent@0x55e277713978 size 128 Aug 26 13:09:59.556694: | setup callback for interface eth0 192.0.22.254:4500 fd 22 Aug 26 13:09:59.556699: | libevent_free: release ptr-libevent@0x55e277713ad8 Aug 26 13:09:59.556702: | free_event_entry: release EVENT_NULL-pe@0x55e277713a68 Aug 26 13:09:59.556705: | add_fd_read_event_handler: new ethX-pe@0x55e277713a68 Aug 26 13:09:59.556707: | libevent_malloc: new ptr-libevent@0x55e277713ad8 size 128 Aug 26 13:09:59.556713: | setup callback for interface eth0 192.0.22.254:500 fd 21 Aug 26 13:09:59.556717: | libevent_free: release ptr-libevent@0x55e277713c38 Aug 26 13:09:59.556720: | free_event_entry: release EVENT_NULL-pe@0x55e277713bc8 Aug 26 13:09:59.556723: | add_fd_read_event_handler: new ethX-pe@0x55e277713bc8 Aug 26 13:09:59.556726: | libevent_malloc: new ptr-libevent@0x55e277713c38 size 128 Aug 26 13:09:59.556732: | setup callback for interface eth0 192.0.2.251:4500 fd 20 Aug 26 13:09:59.556736: | libevent_free: release ptr-libevent@0x55e277713d98 Aug 26 13:09:59.556738: | free_event_entry: release EVENT_NULL-pe@0x55e277713d28 Aug 26 13:09:59.556741: | add_fd_read_event_handler: new ethX-pe@0x55e277713d28 Aug 26 13:09:59.556744: | libevent_malloc: new ptr-libevent@0x55e277713d98 size 128 Aug 26 13:09:59.556752: | setup callback for interface eth0 192.0.2.251:500 fd 19 Aug 26 13:09:59.556757: | libevent_free: release ptr-libevent@0x55e277713ef8 Aug 26 13:09:59.556760: | free_event_entry: release EVENT_NULL-pe@0x55e277713e88 Aug 26 13:09:59.556763: | add_fd_read_event_handler: new ethX-pe@0x55e277713e88 Aug 26 13:09:59.556766: | libevent_malloc: new ptr-libevent@0x55e277713ef8 size 128 Aug 26 13:09:59.556771: | setup callback for interface eth1 192.1.2.23:4500 fd 18 Aug 26 13:09:59.556775: | libevent_free: release ptr-libevent@0x55e277714058 Aug 26 13:09:59.556778: | free_event_entry: release EVENT_NULL-pe@0x55e277713fe8 Aug 26 13:09:59.556781: | add_fd_read_event_handler: new ethX-pe@0x55e277713fe8 Aug 26 13:09:59.556784: | libevent_malloc: new ptr-libevent@0x55e277714058 size 128 Aug 26 13:09:59.556789: | setup callback for interface eth1 192.1.2.23:500 fd 17 Aug 26 13:09:59.556793: | certs and keys locked by 'free_preshared_secrets' Aug 26 13:09:59.556795: forgetting secrets Aug 26 13:09:59.556802: | certs and keys unlocked by 'free_preshared_secrets' Aug 26 13:09:59.556819: loading secrets from "/etc/ipsec.secrets" Aug 26 13:09:59.556835: | saving Modulus Aug 26 13:09:59.556839: | saving PublicExponent Aug 26 13:09:59.556843: | ignoring PrivateExponent Aug 26 13:09:59.556847: | ignoring Prime1 Aug 26 13:09:59.556850: | ignoring Prime2 Aug 26 13:09:59.556854: | ignoring Exponent1 Aug 26 13:09:59.556857: | ignoring Exponent2 Aug 26 13:09:59.556860: | ignoring Coefficient Aug 26 13:09:59.556864: | ignoring CKAIDNSS Aug 26 13:09:59.556875: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Aug 26 13:09:59.556878: | computed rsa CKAID 8a 82 25 f1 Aug 26 13:09:59.556882: loaded private key for keyid: PKK_RSA:AQO9bJbr3 Aug 26 13:09:59.556888: | certs and keys locked by 'process_secret' Aug 26 13:09:59.556891: | certs and keys unlocked by 'process_secret' Aug 26 13:09:59.556899: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.556904: | spent 0.51 milliseconds in whack Aug 26 13:09:59.556949: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:722) Aug 26 13:09:59.556960: | FOR_EACH_CONNECTION_... in conn_by_name Aug 26 13:09:59.556964: initiating all conns with alias='north-eastnets' Aug 26 13:09:59.556969: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Aug 26 13:09:59.556975: | start processing: connection "north-eastnets/0x2" (in initiate_a_connection() at initiate.c:186) Aug 26 13:09:59.556979: | connection 'north-eastnets/0x2' +POLICY_UP Aug 26 13:09:59.556982: | dup_any(fd@-1) -> fd@-1 (in initiate_a_connection() at initiate.c:342) Aug 26 13:09:59.556985: | FOR_EACH_STATE_... in find_phase1_state Aug 26 13:09:59.557001: | creating state object #1 at 0x55e2777162d8 Aug 26 13:09:59.557006: | State DB: adding IKEv2 state #1 in UNDEFINED Aug 26 13:09:59.557014: | pstats #1 ikev2.ike started Aug 26 13:09:59.557019: | Message ID: init #1: msgid=0 lastack=4294967295 nextuse=0 lastrecv=4294967295 lastreplied=0 Aug 26 13:09:59.557023: | parent state #1: UNDEFINED(ignore) => PARENT_I0(ignore) Aug 26 13:09:59.557029: | Message ID: init_ike #1; ike: initiator.sent=0->-1 initiator.recv=0->-1 responder.sent=0->-1 responder.recv=0->-1 wip.initiator=0->-1 wip.responder=0->-1 Aug 26 13:09:59.557037: | suspend processing: connection "north-eastnets/0x2" (in ikev2_parent_outI1() at ikev2_parent.c:535) Aug 26 13:09:59.557043: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_parent_outI1() at ikev2_parent.c:535) Aug 26 13:09:59.557047: | dup_any(fd@-1) -> fd@-1 (in ikev2_parent_outI1() at ikev2_parent.c:551) Aug 26 13:09:59.557051: | Queuing pending IPsec SA negotiating with 192.1.3.33 "north-eastnets/0x2" IKE SA #1 "north-eastnets/0x2" Aug 26 13:09:59.557056: "north-eastnets/0x2" #1: initiating v2 parent SA Aug 26 13:09:59.557064: | constructing local IKE proposals for north-eastnets/0x2 (IKE SA initiator selecting KE) Aug 26 13:09:59.557069: | converting ike_info AES_CBC_256-HMAC_SHA2_256-MODP2048 to ikev2 ... Aug 26 13:09:59.557078: | ... ikev2_proposal: 1:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_256;INTEG=HMAC_SHA2_256_128;DH=MODP2048 Aug 26 13:09:59.557084: "north-eastnets/0x2": constructed local IKE proposals for north-eastnets/0x2 (IKE SA initiator selecting KE): 1:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_256;INTEG=HMAC_SHA2_256_128;DH=MODP2048 Aug 26 13:09:59.557093: | adding ikev2_outI1 KE work-order 1 for state #1 Aug 26 13:09:59.557097: | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x55e277714d28 Aug 26 13:09:59.557102: | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 Aug 26 13:09:59.557105: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:09:59.557118: | #1 spent 0.143 milliseconds in ikev2_parent_outI1() Aug 26 13:09:59.557122: | processing: RESET whack log_fd (was fd@16) (in ikev2_parent_outI1() at ikev2_parent.c:610) Aug 26 13:09:59.557128: | RESET processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_parent_outI1() at ikev2_parent.c:610) Aug 26 13:09:59.557131: | RESET processing: connection "north-eastnets/0x2" (in ikev2_parent_outI1() at ikev2_parent.c:610) Aug 26 13:09:59.557134: | processing: STOP connection NULL (in initiate_a_connection() at initiate.c:349) Aug 26 13:09:59.557139: | start processing: connection "north-eastnets/0x1" (in initiate_a_connection() at initiate.c:186) Aug 26 13:09:59.557142: | connection 'north-eastnets/0x1' +POLICY_UP Aug 26 13:09:59.557146: | dup_any(fd@-1) -> fd@-1 (in initiate_a_connection() at initiate.c:342) Aug 26 13:09:59.557148: | FOR_EACH_STATE_... in find_phase1_state Aug 26 13:09:59.557153: | Queuing pending IPsec SA negotiating with 192.1.3.33 "north-eastnets/0x1" IKE SA #1 "north-eastnets/0x2" Aug 26 13:09:59.557157: | stop processing: connection "north-eastnets/0x1" (in initiate_a_connection() at initiate.c:349) Aug 26 13:09:59.557163: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Aug 26 13:09:59.557168: | spent 0.222 milliseconds in whack Aug 26 13:09:59.557307: | crypto helper 1 resuming Aug 26 13:09:59.557320: | crypto helper 1 starting work-order 1 for state #1 Aug 26 13:09:59.557324: | crypto helper 1 doing build KE and nonce (ikev2_outI1 KE); request ID 1 Aug 26 13:09:59.558241: | crypto helper 1 finished build KE and nonce (ikev2_outI1 KE); request ID 1 time elapsed 0.000916 seconds Aug 26 13:09:59.558252: | (#1) spent 0.926 milliseconds in crypto helper computing work-order 1: ikev2_outI1 KE (pcr) Aug 26 13:09:59.558256: | crypto helper 1 sending results from work-order 1 for state #1 to event queue Aug 26 13:09:59.558259: | scheduling resume sending helper answer for #1 Aug 26 13:09:59.558262: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:09:59.558270: | crypto helper 1 waiting (nothing to do) Aug 26 13:09:59.558458: | processing resume sending helper answer for #1 Aug 26 13:09:59.558469: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in resume_handler() at server.c:797) Aug 26 13:09:59.558475: | crypto helper 1 replies to request ID 1 Aug 26 13:09:59.558478: | calling continuation function 0x55e2755a6b50 Aug 26 13:09:59.558481: | ikev2_parent_outI1_continue for #1 Aug 26 13:09:59.558511: | **emit ISAKMP Message: Aug 26 13:09:59.558516: | initiator cookie: Aug 26 13:09:59.558519: | 8b 87 d7 26 c3 30 6b 14 Aug 26 13:09:59.558522: | responder cookie: Aug 26 13:09:59.558524: | 00 00 00 00 00 00 00 00 Aug 26 13:09:59.558528: | next payload type: ISAKMP_NEXT_NONE (0x0) Aug 26 13:09:59.558531: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Aug 26 13:09:59.558534: | exchange type: ISAKMP_v2_IKE_SA_INIT (0x22) Aug 26 13:09:59.558537: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Aug 26 13:09:59.558540: | Message ID: 0 (0x0) Aug 26 13:09:59.558544: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Aug 26 13:09:59.558551: | using existing local IKE proposals for connection north-eastnets/0x2 (IKE SA initiator emitting local proposals): 1:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_256;INTEG=HMAC_SHA2_256_128;DH=MODP2048 Aug 26 13:09:59.558557: | Emitting ikev2_proposals ... Aug 26 13:09:59.558561: | ***emit IKEv2 Security Association Payload: Aug 26 13:09:59.558564: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:09:59.558567: | flags: none (0x0) Aug 26 13:09:59.558571: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Security Association Payload (33:ISAKMP_NEXT_v2SA) Aug 26 13:09:59.558574: | next payload chain: saving location 'IKEv2 Security Association Payload'.'next payload type' in 'reply packet' Aug 26 13:09:59.558578: | ****emit IKEv2 Proposal Substructure Payload: Aug 26 13:09:59.558581: | last proposal: v2_PROPOSAL_LAST (0x0) Aug 26 13:09:59.558584: | prop #: 1 (0x1) Aug 26 13:09:59.558586: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Aug 26 13:09:59.558589: | spi size: 0 (0x0) Aug 26 13:09:59.558592: | # transforms: 4 (0x4) Aug 26 13:09:59.558595: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Aug 26 13:09:59.558598: | *****emit IKEv2 Transform Substructure Payload: Aug 26 13:09:59.558601: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:09:59.558604: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Aug 26 13:09:59.558606: | IKEv2 transform ID: AES_CBC (0xc) Aug 26 13:09:59.558609: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:09:59.558613: | ******emit IKEv2 Attribute Substructure Payload: Aug 26 13:09:59.558616: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Aug 26 13:09:59.558618: | length/value: 256 (0x100) Aug 26 13:09:59.558622: | emitting length of IKEv2 Transform Substructure Payload: 12 Aug 26 13:09:59.558624: | *****emit IKEv2 Transform Substructure Payload: Aug 26 13:09:59.558627: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:09:59.558630: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Aug 26 13:09:59.558633: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Aug 26 13:09:59.558636: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:09:59.558639: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:09:59.558642: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:09:59.558645: | *****emit IKEv2 Transform Substructure Payload: Aug 26 13:09:59.558648: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:09:59.558651: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Aug 26 13:09:59.558654: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Aug 26 13:09:59.558657: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:09:59.558660: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:09:59.558663: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:09:59.558666: | *****emit IKEv2 Transform Substructure Payload: Aug 26 13:09:59.558668: | last transform: v2_TRANSFORM_LAST (0x0) Aug 26 13:09:59.558671: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Aug 26 13:09:59.558673: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Aug 26 13:09:59.558677: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:09:59.558680: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:09:59.558683: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:09:59.558686: | emitting length of IKEv2 Proposal Substructure Payload: 44 Aug 26 13:09:59.558693: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Aug 26 13:09:59.558697: | emitting length of IKEv2 Security Association Payload: 48 Aug 26 13:09:59.558700: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is 0 Aug 26 13:09:59.558703: | ***emit IKEv2 Key Exchange Payload: Aug 26 13:09:59.558706: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:09:59.558709: | flags: none (0x0) Aug 26 13:09:59.558712: | DH group: OAKLEY_GROUP_MODP2048 (0xe) Aug 26 13:09:59.558715: | next payload chain: setting previous 'IKEv2 Security Association Payload'.'next payload type' to current IKEv2 Key Exchange Payload (34:ISAKMP_NEXT_v2KE) Aug 26 13:09:59.558718: | next payload chain: saving location 'IKEv2 Key Exchange Payload'.'next payload type' in 'reply packet' Aug 26 13:09:59.558722: | emitting 256 raw bytes of ikev2 g^x into IKEv2 Key Exchange Payload Aug 26 13:09:59.558725: | ikev2 g^x 46 49 8e 2c e9 3f 06 93 46 99 ca 74 e5 f7 3b 1d Aug 26 13:09:59.558728: | ikev2 g^x b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f 3c 10 62 1a Aug 26 13:09:59.558730: | ikev2 g^x b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 1d 3b 5a a6 Aug 26 13:09:59.558733: | ikev2 g^x 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 7f f0 7b 13 Aug 26 13:09:59.558736: | ikev2 g^x f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 b7 c0 36 06 Aug 26 13:09:59.558738: | ikev2 g^x c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 e4 a1 34 c0 Aug 26 13:09:59.558741: | ikev2 g^x a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf aa 16 cd 7a Aug 26 13:09:59.558744: | ikev2 g^x aa 0e ac c5 77 39 e1 e4 0b a9 41 4d 5f 3a e2 86 Aug 26 13:09:59.558746: | ikev2 g^x 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 58 4b e1 f3 Aug 26 13:09:59.558749: | ikev2 g^x 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 b4 4a f4 ec Aug 26 13:09:59.558751: | ikev2 g^x 62 a0 69 1e bf b2 18 95 6e a1 e4 ea 57 65 65 59 Aug 26 13:09:59.558754: | ikev2 g^x 06 9d b6 56 e0 42 69 72 08 5e 18 d1 c1 a1 0e bc Aug 26 13:09:59.558756: | ikev2 g^x ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 10 56 e8 5c Aug 26 13:09:59.558759: | ikev2 g^x 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 fb f9 e5 c8 Aug 26 13:09:59.558762: | ikev2 g^x 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 c1 a7 a9 a4 Aug 26 13:09:59.558764: | ikev2 g^x ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 95 8f 9d a9 Aug 26 13:09:59.558767: | emitting length of IKEv2 Key Exchange Payload: 264 Aug 26 13:09:59.558770: | ***emit IKEv2 Nonce Payload: Aug 26 13:09:59.558773: | next payload type: ISAKMP_NEXT_v2N (0x29) Aug 26 13:09:59.558776: | flags: none (0x0) Aug 26 13:09:59.558779: | next payload chain: ignoring supplied 'IKEv2 Nonce Payload'.'next payload type' value 41:ISAKMP_NEXT_v2N Aug 26 13:09:59.558782: | next payload chain: setting previous 'IKEv2 Key Exchange Payload'.'next payload type' to current IKEv2 Nonce Payload (40:ISAKMP_NEXT_v2Ni) Aug 26 13:09:59.558786: | next payload chain: saving location 'IKEv2 Nonce Payload'.'next payload type' in 'reply packet' Aug 26 13:09:59.558789: | emitting 32 raw bytes of IKEv2 nonce into IKEv2 Nonce Payload Aug 26 13:09:59.558792: | IKEv2 nonce 68 52 d7 6f 01 ea 94 77 db 29 2a 9b 81 9b 32 73 Aug 26 13:09:59.558794: | IKEv2 nonce d9 a3 6c 68 4d 1f 9b 48 71 1a 23 51 51 45 55 e1 Aug 26 13:09:59.558797: | emitting length of IKEv2 Nonce Payload: 36 Aug 26 13:09:59.558800: | Adding a v2N Payload Aug 26 13:09:59.558803: | ***emit IKEv2 Notify Payload: Aug 26 13:09:59.558806: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:09:59.558809: | flags: none (0x0) Aug 26 13:09:59.558812: | Protocol ID: PROTO_v2_RESERVED (0x0) Aug 26 13:09:59.558815: | SPI size: 0 (0x0) Aug 26 13:09:59.558818: | Notify Message Type: v2N_IKEV2_FRAGMENTATION_SUPPORTED (0x402e) Aug 26 13:09:59.558821: | next payload chain: setting previous 'IKEv2 Nonce Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Aug 26 13:09:59.558824: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Aug 26 13:09:59.558829: | emitting length of IKEv2 Notify Payload: 8 Aug 26 13:09:59.558833: | NAT-Traversal support [enabled] add v2N payloads. Aug 26 13:09:59.558836: | natd_hash: rcookie is zero Aug 26 13:09:59.558846: | natd_hash: hasher=0x55e27567b800(20) Aug 26 13:09:59.558850: | natd_hash: icookie= 8b 87 d7 26 c3 30 6b 14 Aug 26 13:09:59.558853: | natd_hash: rcookie= 00 00 00 00 00 00 00 00 Aug 26 13:09:59.558856: | natd_hash: ip= c0 01 02 17 Aug 26 13:09:59.558858: | natd_hash: port=500 Aug 26 13:09:59.558861: | natd_hash: hash= 3f f9 28 7c b6 d3 bd 80 a1 39 c1 36 60 63 78 f5 Aug 26 13:09:59.558864: | natd_hash: hash= 52 e4 d5 f2 Aug 26 13:09:59.558866: | Adding a v2N Payload Aug 26 13:09:59.558869: | ***emit IKEv2 Notify Payload: Aug 26 13:09:59.558872: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:09:59.558875: | flags: none (0x0) Aug 26 13:09:59.558877: | Protocol ID: PROTO_v2_RESERVED (0x0) Aug 26 13:09:59.558880: | SPI size: 0 (0x0) Aug 26 13:09:59.558883: | Notify Message Type: v2N_NAT_DETECTION_SOURCE_IP (0x4004) Aug 26 13:09:59.558886: | next payload chain: setting previous 'IKEv2 Notify Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Aug 26 13:09:59.558890: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Aug 26 13:09:59.558893: | emitting 20 raw bytes of Notify data into IKEv2 Notify Payload Aug 26 13:09:59.558896: | Notify data 3f f9 28 7c b6 d3 bd 80 a1 39 c1 36 60 63 78 f5 Aug 26 13:09:59.558899: | Notify data 52 e4 d5 f2 Aug 26 13:09:59.558902: | emitting length of IKEv2 Notify Payload: 28 Aug 26 13:09:59.558904: | natd_hash: rcookie is zero Aug 26 13:09:59.558912: | natd_hash: hasher=0x55e27567b800(20) Aug 26 13:09:59.558916: | natd_hash: icookie= 8b 87 d7 26 c3 30 6b 14 Aug 26 13:09:59.558918: | natd_hash: rcookie= 00 00 00 00 00 00 00 00 Aug 26 13:09:59.558921: | natd_hash: ip= c0 01 03 21 Aug 26 13:09:59.558923: | natd_hash: port=500 Aug 26 13:09:59.558926: | natd_hash: hash= 73 33 01 04 6c b2 8b fd 31 a2 0e f6 48 b2 81 c8 Aug 26 13:09:59.558928: | natd_hash: hash= 29 fc 94 50 Aug 26 13:09:59.558931: | Adding a v2N Payload Aug 26 13:09:59.558934: | ***emit IKEv2 Notify Payload: Aug 26 13:09:59.558937: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:09:59.558939: | flags: none (0x0) Aug 26 13:09:59.558942: | Protocol ID: PROTO_v2_RESERVED (0x0) Aug 26 13:09:59.558945: | SPI size: 0 (0x0) Aug 26 13:09:59.558948: | Notify Message Type: v2N_NAT_DETECTION_DESTINATION_IP (0x4005) Aug 26 13:09:59.558951: | next payload chain: setting previous 'IKEv2 Notify Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Aug 26 13:09:59.558954: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Aug 26 13:09:59.558957: | emitting 20 raw bytes of Notify data into IKEv2 Notify Payload Aug 26 13:09:59.558960: | Notify data 73 33 01 04 6c b2 8b fd 31 a2 0e f6 48 b2 81 c8 Aug 26 13:09:59.558963: | Notify data 29 fc 94 50 Aug 26 13:09:59.558965: | emitting length of IKEv2 Notify Payload: 28 Aug 26 13:09:59.558968: | emitting length of ISAKMP Message: 440 Aug 26 13:09:59.558976: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_parent_outI1_common() at ikev2_parent.c:817) Aug 26 13:09:59.558987: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in complete_v2_state_transition() at ikev2.c:3379) Aug 26 13:09:59.558991: | #1 complete_v2_state_transition() PARENT_I0->PARENT_I1 with status STF_OK Aug 26 13:09:59.558995: | IKEv2: transition from state STATE_PARENT_I0 to state STATE_PARENT_I1 Aug 26 13:09:59.558998: | parent state #1: PARENT_I0(ignore) => PARENT_I1(half-open IKE SA) Aug 26 13:09:59.559002: | Message ID: updating counters for #1 to 4294967295 after switching state Aug 26 13:09:59.559005: | Message ID: IKE #1 skipping update_recv as MD is fake Aug 26 13:09:59.559012: | Message ID: sent #1 request 0; ike: initiator.sent=-1->0 initiator.recv=-1 responder.sent=-1 responder.recv=-1 wip.initiator=-1->0 wip.responder=-1 Aug 26 13:09:59.559016: "north-eastnets/0x2" #1: STATE_PARENT_I1: sent v2I1, expected v2R1 Aug 26 13:09:59.559022: | sending V2 reply packet to 192.1.3.33:500 (from 192.1.2.23:500) Aug 26 13:09:59.559032: | sending 440 bytes for STATE_PARENT_I0 through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:09:59.559035: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:09:59.559038: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:09:59.559041: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:09:59.559043: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:09:59.559046: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:09:59.559048: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:09:59.559051: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:09:59.559053: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:09:59.559056: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:09:59.559059: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:09:59.559061: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:09:59.559064: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:09:59.559066: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:09:59.559069: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:09:59.559071: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:09:59.559074: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:09:59.559076: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:09:59.559079: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:09:59.559081: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:09:59.559084: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:09:59.559086: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:09:59.559089: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:09:59.559092: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:09:59.559094: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:09:59.559097: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:09:59.559099: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:09:59.559102: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:09:59.559104: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:09:59.559172: | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted Aug 26 13:09:59.559178: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:09:59.559182: | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x55e277714d28 Aug 26 13:09:59.559185: | success_v2_state_transition scheduling EVENT_RETRANSMIT of c->r_interval=50ms Aug 26 13:09:59.559190: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:09:59.559194: | inserting event EVENT_RETRANSMIT, timeout in 0.05 seconds for #1 Aug 26 13:09:59.559198: | libevent_malloc: new ptr-libevent@0x55e277716f18 size 128 Aug 26 13:09:59.559219: | #1 STATE_PARENT_I1: retransmits: first event in 0.05 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 10285.301656 Aug 26 13:09:59.559225: | resume sending helper answer for #1 suppresed complete_v2_state_transition() and stole MD Aug 26 13:09:59.559231: | #1 spent 0.699 milliseconds in resume sending helper answer Aug 26 13:09:59.559237: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in resume_handler() at server.c:833) Aug 26 13:09:59.559240: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:09:59.559250: | processing signal PLUTO_SIGCHLD Aug 26 13:09:59.559259: | waitpid returned pid 13352 (exited with status 0) Aug 26 13:09:59.559262: | reaped addconn helper child (status 0) Aug 26 13:09:59.559267: | waitpid returned ECHILD (no child processes left) Aug 26 13:09:59.559274: | spent 0.0187 milliseconds in signal handler PLUTO_SIGCHLD Aug 26 13:09:59.613712: | timer_event_cb: processing event@0x55e277714d28 Aug 26 13:09:59.613736: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:09:59.613746: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:09:59.613750: | IKEv2 retransmit event Aug 26 13:09:59.613756: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:09:59.613761: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:09:59.613766: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:09:59.613773: | retransmits: current time 10285.356236; retransmit count 0 exceeds limit? NO; deltatime 0.05 exceeds limit? NO; monotime 0.05458 exceeds limit? NO Aug 26 13:09:59.613778: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:09:59.613782: | inserting event EVENT_RETRANSMIT, timeout in 0.05 seconds for #1 Aug 26 13:09:59.613786: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:09:59.613792: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 0.05 seconds for response Aug 26 13:09:59.613802: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:09:59.613806: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:09:59.613808: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:09:59.613811: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:09:59.613814: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:09:59.613816: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:09:59.613819: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:09:59.613821: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:09:59.613824: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:09:59.613826: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:09:59.613829: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:09:59.613831: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:09:59.613834: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:09:59.613836: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:09:59.613839: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:09:59.613841: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:09:59.613844: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:09:59.613846: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:09:59.613849: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:09:59.613851: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:09:59.613854: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:09:59.613856: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:09:59.613859: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:09:59.613861: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:09:59.613864: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:09:59.613866: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:09:59.613869: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:09:59.613871: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:09:59.613874: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:09:59.613890: | libevent_free: release ptr-libevent@0x55e277716f18 Aug 26 13:09:59.613895: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:09:59.613903: | #1 spent 0.193 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:09:59.613909: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:09:59.664348: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:09:59.664378: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:09:59.664388: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:09:59.664393: | IKEv2 retransmit event Aug 26 13:09:59.664398: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:09:59.664403: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:09:59.664408: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 2 Aug 26 13:09:59.664415: | retransmits: current time 10285.406878; retransmit count 1 exceeds limit? NO; deltatime 0.1 exceeds limit? NO; monotime 0.105222 exceeds limit? NO Aug 26 13:09:59.664420: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:09:59.664424: | inserting event EVENT_RETRANSMIT, timeout in 0.1 seconds for #1 Aug 26 13:09:59.664428: | libevent_malloc: new ptr-libevent@0x55e277716f18 size 128 Aug 26 13:09:59.664434: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 0.1 seconds for response Aug 26 13:09:59.664442: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:09:59.664445: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:09:59.664448: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:09:59.664450: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:09:59.664453: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:09:59.664455: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:09:59.664458: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:09:59.664460: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:09:59.664462: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:09:59.664465: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:09:59.664468: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:09:59.664470: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:09:59.664473: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:09:59.664476: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:09:59.664478: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:09:59.664481: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:09:59.664483: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:09:59.664486: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:09:59.664488: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:09:59.664491: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:09:59.664493: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:09:59.664495: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:09:59.664498: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:09:59.664500: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:09:59.664503: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:09:59.664505: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:09:59.664507: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:09:59.664510: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:09:59.664512: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:09:59.664898: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:09:59.664905: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:09:59.664913: | #1 spent 0.555 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:09:59.664920: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:09:59.766104: | timer_event_cb: processing event@0x55e277714d28 Aug 26 13:09:59.766126: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:09:59.766139: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:09:59.766145: | IKEv2 retransmit event Aug 26 13:09:59.766150: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:09:59.766155: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:09:59.766160: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 3 Aug 26 13:09:59.766167: | retransmits: current time 10285.50863; retransmit count 2 exceeds limit? NO; deltatime 0.2 exceeds limit? NO; monotime 0.206974 exceeds limit? NO Aug 26 13:09:59.766172: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:09:59.766176: | inserting event EVENT_RETRANSMIT, timeout in 0.2 seconds for #1 Aug 26 13:09:59.766180: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:09:59.766186: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 0.2 seconds for response Aug 26 13:09:59.766194: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:09:59.766198: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:09:59.766201: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:09:59.766203: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:09:59.766206: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:09:59.766208: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:09:59.766211: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:09:59.766213: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:09:59.766215: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:09:59.766218: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:09:59.766220: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:09:59.766223: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:09:59.766225: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:09:59.766228: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:09:59.766230: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:09:59.766233: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:09:59.766235: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:09:59.766238: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:09:59.766240: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:09:59.766243: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:09:59.766245: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:09:59.766248: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:09:59.766251: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:09:59.766253: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:09:59.766255: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:09:59.766258: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:09:59.766260: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:09:59.766263: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:09:59.766265: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:09:59.766305: | libevent_free: release ptr-libevent@0x55e277716f18 Aug 26 13:09:59.766313: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:09:59.766322: | #1 spent 0.196 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:09:59.766328: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:09:59.966555: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:09:59.966571: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:09:59.966580: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:09:59.966585: | IKEv2 retransmit event Aug 26 13:09:59.966593: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:09:59.966598: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:09:59.966602: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 4 Aug 26 13:09:59.966609: | retransmits: current time 10285.709073; retransmit count 3 exceeds limit? NO; deltatime 0.4 exceeds limit? NO; monotime 0.407417 exceeds limit? NO Aug 26 13:09:59.966613: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:09:59.966618: | inserting event EVENT_RETRANSMIT, timeout in 0.4 seconds for #1 Aug 26 13:09:59.966621: | libevent_malloc: new ptr-libevent@0x55e277716f18 size 128 Aug 26 13:09:59.966626: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 0.4 seconds for response Aug 26 13:09:59.966634: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:09:59.966637: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:09:59.966640: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:09:59.966642: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:09:59.966645: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:09:59.966648: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:09:59.966650: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:09:59.966652: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:09:59.966655: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:09:59.966658: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:09:59.966660: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:09:59.966663: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:09:59.966665: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:09:59.966668: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:09:59.966670: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:09:59.966673: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:09:59.966675: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:09:59.966678: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:09:59.966680: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:09:59.966683: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:09:59.966685: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:09:59.966688: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:09:59.966690: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:09:59.966693: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:09:59.966695: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:09:59.966698: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:09:59.966700: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:09:59.966703: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:09:59.966705: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:09:59.966721: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:09:59.966725: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:09:59.966731: | #1 spent 0.177 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:09:59.966737: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:00.370938: | timer_event_cb: processing event@0x55e277714d28 Aug 26 13:10:00.370956: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:10:00.370966: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:00.370971: | IKEv2 retransmit event Aug 26 13:10:00.370976: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:00.370986: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:10:00.370991: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 5 Aug 26 13:10:00.370998: | retransmits: current time 10286.113461; retransmit count 4 exceeds limit? NO; deltatime 0.8 exceeds limit? NO; monotime 0.811805 exceeds limit? NO Aug 26 13:10:00.371003: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:00.371007: | inserting event EVENT_RETRANSMIT, timeout in 0.8 seconds for #1 Aug 26 13:10:00.371012: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:10:00.371017: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 0.8 seconds for response Aug 26 13:10:00.371025: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:00.371029: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:10:00.371031: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:10:00.371034: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:10:00.371036: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:10:00.371039: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:10:00.371041: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:10:00.371044: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:10:00.371046: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:10:00.371048: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:10:00.371051: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:10:00.371053: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:10:00.371056: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:10:00.371059: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:10:00.371061: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:10:00.371063: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:10:00.371066: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:10:00.371069: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:10:00.371071: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:10:00.371074: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:10:00.371076: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:10:00.371079: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:10:00.371081: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:10:00.371084: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:10:00.371086: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:10:00.371088: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:10:00.371091: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:10:00.371093: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:10:00.371095: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:10:00.371136: | libevent_free: release ptr-libevent@0x55e277716f18 Aug 26 13:10:00.371142: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:10:00.371150: | #1 spent 0.191 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:00.371156: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:01.171602: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:01.171618: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:10:01.171628: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:01.171633: | IKEv2 retransmit event Aug 26 13:10:01.171638: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:01.171643: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:10:01.171652: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 6 Aug 26 13:10:01.171660: | retransmits: current time 10286.914123; retransmit count 5 exceeds limit? NO; deltatime 1.6 exceeds limit? NO; monotime 1.612467 exceeds limit? NO Aug 26 13:10:01.171665: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:10:01.171670: | inserting event EVENT_RETRANSMIT, timeout in 1.6 seconds for #1 Aug 26 13:10:01.171674: | libevent_malloc: new ptr-libevent@0x55e277716f18 size 128 Aug 26 13:10:01.171679: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 1.6 seconds for response Aug 26 13:10:01.171687: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:01.171691: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:10:01.171694: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:10:01.171696: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:10:01.171699: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:10:01.171701: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:10:01.171704: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:10:01.171706: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:10:01.171709: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:10:01.171711: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:10:01.171714: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:10:01.171716: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:10:01.171719: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:10:01.171721: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:10:01.171724: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:10:01.171726: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:10:01.171729: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:10:01.171731: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:10:01.171734: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:10:01.171736: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:10:01.171738: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:10:01.171741: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:10:01.171744: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:10:01.171746: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:10:01.171748: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:10:01.171751: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:10:01.171753: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:10:01.171756: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:10:01.171758: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:10:01.171798: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:10:01.171804: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:01.171813: | #1 spent 0.19 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:01.171818: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:02.773327: | timer_event_cb: processing event@0x55e277714d28 Aug 26 13:10:02.773362: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:10:02.773370: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:02.773373: | IKEv2 retransmit event Aug 26 13:10:02.773378: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:02.773383: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:10:02.773387: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 7 Aug 26 13:10:02.773397: | retransmits: current time 10288.515861; retransmit count 6 exceeds limit? NO; deltatime 3.2 exceeds limit? NO; monotime 3.214205 exceeds limit? NO Aug 26 13:10:02.773401: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:02.773405: | inserting event EVENT_RETRANSMIT, timeout in 3.2 seconds for #1 Aug 26 13:10:02.773408: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:10:02.773414: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 3.2 seconds for response Aug 26 13:10:02.773421: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:02.773423: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:10:02.773426: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:10:02.773428: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:10:02.773431: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:10:02.773433: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:10:02.773435: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:10:02.773438: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:10:02.773440: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:10:02.773443: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:10:02.773445: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:10:02.773447: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:10:02.773450: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:10:02.773452: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:10:02.773454: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:10:02.773457: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:10:02.773459: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:10:02.773462: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:10:02.773464: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:10:02.773466: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:10:02.773469: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:10:02.773471: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:10:02.773473: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:10:02.773476: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:10:02.773478: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:10:02.773481: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:10:02.773483: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:10:02.773485: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:10:02.773488: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:10:02.773895: | libevent_free: release ptr-libevent@0x55e277716f18 Aug 26 13:10:02.773902: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:10:02.773910: | #1 spent 0.575 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:02.773916: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:05.974442: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:05.974456: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:10:05.974462: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:05.974465: | IKEv2 retransmit event Aug 26 13:10:05.974468: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:05.974471: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:10:05.974474: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 8 Aug 26 13:10:05.974479: | retransmits: current time 10291.716943; retransmit count 7 exceeds limit? NO; deltatime 6.4 exceeds limit? NO; monotime 6.415287 exceeds limit? NO Aug 26 13:10:05.974484: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:10:05.974487: | inserting event EVENT_RETRANSMIT, timeout in 6.4 seconds for #1 Aug 26 13:10:05.974490: | libevent_malloc: new ptr-libevent@0x55e277716f18 size 128 Aug 26 13:10:05.974494: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 6.4 seconds for response Aug 26 13:10:05.974499: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:05.974501: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:10:05.974503: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:10:05.974504: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:10:05.974506: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:10:05.974508: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:10:05.974509: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:10:05.974511: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:10:05.974512: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:10:05.974514: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:10:05.974516: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:10:05.974517: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:10:05.974519: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:10:05.974520: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:10:05.974522: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:10:05.974523: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:10:05.974525: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:10:05.974527: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:10:05.974528: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:10:05.974530: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:10:05.974531: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:10:05.974533: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:10:05.974535: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:10:05.974536: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:10:05.974538: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:10:05.974539: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:10:05.974541: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:10:05.974543: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:10:05.974544: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:10:05.974582: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:10:05.974586: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:05.974592: | #1 spent 0.13 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:05.974595: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:12.380355: | timer_event_cb: processing event@0x55e277714d28 Aug 26 13:10:12.380381: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:10:12.380387: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:12.380390: | IKEv2 retransmit event Aug 26 13:10:12.380393: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:12.380396: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:10:12.380398: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 9 Aug 26 13:10:12.380403: | retransmits: current time 10298.122867; retransmit count 8 exceeds limit? NO; deltatime 12.8 exceeds limit? NO; monotime 12.821211 exceeds limit? NO Aug 26 13:10:12.380405: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:12.380408: | inserting event EVENT_RETRANSMIT, timeout in 12.8 seconds for #1 Aug 26 13:10:12.380413: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:10:12.380416: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 12.8 seconds for response Aug 26 13:10:12.380421: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:12.380423: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:10:12.380425: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:10:12.380426: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:10:12.380428: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:10:12.380446: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:10:12.380449: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:10:12.380452: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:10:12.380455: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:10:12.380458: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:10:12.380461: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:10:12.380464: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:10:12.380480: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:10:12.380483: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:10:12.380485: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:10:12.380488: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:10:12.380490: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:10:12.380491: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:10:12.380493: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:10:12.380494: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:10:12.380495: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:10:12.380497: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:10:12.380498: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:10:12.380500: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:10:12.380501: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:10:12.380503: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:10:12.380504: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:10:12.380506: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:10:12.380507: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:10:12.380548: | libevent_free: release ptr-libevent@0x55e277716f18 Aug 26 13:10:12.380551: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:10:12.380557: | #1 spent 0.182 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:12.380560: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:19.412318: | processing global timer EVENT_SHUNT_SCAN Aug 26 13:10:19.412344: | expiring aged bare shunts from shunt table Aug 26 13:10:19.412353: | spent 0.00646 milliseconds in global timer EVENT_SHUNT_SCAN Aug 26 13:10:25.185309: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:25.185335: | handling event EVENT_RETRANSMIT for parent state #1 Aug 26 13:10:25.185341: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:25.185344: | IKEv2 retransmit event Aug 26 13:10:25.185347: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:25.185350: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #1 attempt 2 of 0 Aug 26 13:10:25.185353: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 10 Aug 26 13:10:25.185358: | retransmits: current time 10310.927822; retransmit count 9 exceeds limit? NO; deltatime 25.6 exceeds limit? NO; monotime 25.626166 exceeds limit? NO Aug 26 13:10:25.185361: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:10:25.185367: | inserting event EVENT_RETRANSMIT, timeout in 25.6 seconds for #1 Aug 26 13:10:25.185369: | libevent_malloc: new ptr-libevent@0x55e277716f18 size 128 Aug 26 13:10:25.185373: "north-eastnets/0x2" #1: STATE_PARENT_I1: retransmission; will wait 25.6 seconds for response Aug 26 13:10:25.185378: | sending 440 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:25.185380: | 8b 87 d7 26 c3 30 6b 14 00 00 00 00 00 00 00 00 Aug 26 13:10:25.185382: | 21 20 22 08 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:10:25.185383: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:10:25.185385: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:10:25.185386: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:10:25.185388: | 00 0e 00 00 46 49 8e 2c e9 3f 06 93 46 99 ca 74 Aug 26 13:10:25.185389: | e5 f7 3b 1d b1 a2 0a 03 c9 67 c4 9e 16 bb 5c 7f Aug 26 13:10:25.185391: | 3c 10 62 1a b6 71 0b 74 cb b9 e1 7b 30 b4 f2 57 Aug 26 13:10:25.185392: | 1d 3b 5a a6 4b f1 d2 52 20 75 1a 57 9f 4e fe d9 Aug 26 13:10:25.185394: | 7f f0 7b 13 f5 45 2c 02 a3 02 c6 07 8f 08 d7 f5 Aug 26 13:10:25.185395: | b7 c0 36 06 c1 6d 3e 0f 5b ca 2b ad f2 b5 47 f0 Aug 26 13:10:25.185397: | e4 a1 34 c0 a4 c6 03 34 ed c8 ec 45 4d 9c c0 cf Aug 26 13:10:25.185398: | aa 16 cd 7a aa 0e ac c5 77 39 e1 e4 0b a9 41 4d Aug 26 13:10:25.185400: | 5f 3a e2 86 93 b6 92 94 a1 2c 1b 26 b6 39 9a 53 Aug 26 13:10:25.185401: | 58 4b e1 f3 28 9e 07 53 ae 55 d2 59 8e a5 dd 36 Aug 26 13:10:25.185403: | b4 4a f4 ec 62 a0 69 1e bf b2 18 95 6e a1 e4 ea Aug 26 13:10:25.185404: | 57 65 65 59 06 9d b6 56 e0 42 69 72 08 5e 18 d1 Aug 26 13:10:25.185406: | c1 a1 0e bc ff e0 6a f8 9f f1 cb 5c b9 7f 72 53 Aug 26 13:10:25.185407: | 10 56 e8 5c 8a 0c 16 89 03 a7 cd 8a 2d 48 c4 86 Aug 26 13:10:25.185409: | fb f9 e5 c8 17 0b dd 97 f7 99 95 a3 9a a3 2b 30 Aug 26 13:10:25.185410: | c1 a7 a9 a4 ed 6f 1d 35 33 80 73 2e 2f 59 4e 55 Aug 26 13:10:25.185412: | 95 8f 9d a9 29 00 00 24 68 52 d7 6f 01 ea 94 77 Aug 26 13:10:25.185413: | db 29 2a 9b 81 9b 32 73 d9 a3 6c 68 4d 1f 9b 48 Aug 26 13:10:25.185415: | 71 1a 23 51 51 45 55 e1 29 00 00 08 00 00 40 2e Aug 26 13:10:25.185416: | 29 00 00 1c 00 00 40 04 3f f9 28 7c b6 d3 bd 80 Aug 26 13:10:25.185418: | a1 39 c1 36 60 63 78 f5 52 e4 d5 f2 00 00 00 1c Aug 26 13:10:25.185419: | 00 00 40 05 73 33 01 04 6c b2 8b fd 31 a2 0e f6 Aug 26 13:10:25.185421: | 48 b2 81 c8 29 fc 94 50 Aug 26 13:10:25.185490: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:10:25.185509: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:25.185515: | #1 spent 0.161 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:25.185518: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:27.188457: | spent 0.00301 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() Aug 26 13:10:27.188478: | *received 440 bytes from 192.1.3.33:500 on eth1 (192.1.2.23:500) Aug 26 13:10:27.188481: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.188483: | 21 20 22 20 00 00 00 00 00 00 01 b8 22 00 00 30 Aug 26 13:10:27.188485: | 00 00 00 2c 01 01 00 04 03 00 00 0c 01 00 00 0c Aug 26 13:10:27.188486: | 80 0e 01 00 03 00 00 08 02 00 00 05 03 00 00 08 Aug 26 13:10:27.188488: | 03 00 00 0c 00 00 00 08 04 00 00 0e 28 00 01 08 Aug 26 13:10:27.188489: | 00 0e 00 00 5f 75 e5 d5 c6 db 40 39 2a 0e 43 f2 Aug 26 13:10:27.188491: | 29 02 40 6e 2e b6 2e e8 59 fc 05 3f d9 e4 bd 50 Aug 26 13:10:27.188492: | 1d 91 0e 17 72 de f4 33 58 4e a0 78 38 32 58 39 Aug 26 13:10:27.188494: | ca 75 d8 5f 4a 13 32 1f ab ea e6 14 0e 3b 41 ef Aug 26 13:10:27.188495: | 70 97 32 a2 26 79 9d 4c b1 42 99 58 86 d8 71 17 Aug 26 13:10:27.188497: | de 97 6a 79 41 10 a7 fd bf 7c d7 67 a4 1f 89 7c Aug 26 13:10:27.188501: | 50 c6 fd 60 ac 43 68 e3 44 24 b5 c1 30 46 8d cf Aug 26 13:10:27.188503: | 68 d1 b3 39 e9 92 bf 9c d6 f0 78 8a 24 47 da 06 Aug 26 13:10:27.188505: | ce fc ef 2a 52 ba 0e bc 8b 75 e7 40 a6 06 c7 13 Aug 26 13:10:27.188506: | 48 f3 5f ea fa df 2f c5 fb 06 a4 ea 2d 5c 01 3a Aug 26 13:10:27.188508: | 9e 6d 38 6e 65 9e 92 72 3a e6 45 48 e9 2d 49 8a Aug 26 13:10:27.188509: | a9 ad 68 45 65 d6 04 3e ce eb 39 a3 00 87 09 8b Aug 26 13:10:27.188511: | e8 96 fb 81 05 c2 a6 30 80 f3 2c 5b 64 65 1e 53 Aug 26 13:10:27.188512: | a8 e1 5d 90 57 65 bf 47 b9 b9 23 8e e4 05 5f 67 Aug 26 13:10:27.188514: | 74 a3 0a e8 2e 8d 8f a0 3a 61 c0 ca 5c f7 c5 9d Aug 26 13:10:27.188515: | 03 93 87 3c 7d 7b 8a 27 80 b9 4b e5 61 5f 23 ef Aug 26 13:10:27.188517: | 76 f3 23 a4 29 00 00 24 28 c4 6e 45 bf e1 9f 2b Aug 26 13:10:27.188518: | 6a c5 4f c5 a8 d0 68 b6 3f cf 73 7b c4 da 77 f4 Aug 26 13:10:27.188520: | 53 cd ae 54 73 26 e3 c6 29 00 00 08 00 00 40 2e Aug 26 13:10:27.188521: | 29 00 00 1c 00 00 40 04 9b 28 99 9a 12 57 bf c4 Aug 26 13:10:27.188523: | ed ee f8 52 09 04 95 90 7e 59 18 59 00 00 00 1c Aug 26 13:10:27.188524: | 00 00 40 05 44 a5 8b 90 40 7e aa 0d 14 c0 4d d7 Aug 26 13:10:27.188526: | ee 49 1a 16 b5 85 4f 2c Aug 26 13:10:27.188529: | start processing: from 192.1.3.33:500 (in process_md() at demux.c:378) Aug 26 13:10:27.188532: | **parse ISAKMP Message: Aug 26 13:10:27.188534: | initiator cookie: Aug 26 13:10:27.188536: | 8b 87 d7 26 c3 30 6b 14 Aug 26 13:10:27.188537: | responder cookie: Aug 26 13:10:27.188539: | 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.188541: | next payload type: ISAKMP_NEXT_v2SA (0x21) Aug 26 13:10:27.188543: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Aug 26 13:10:27.188545: | exchange type: ISAKMP_v2_IKE_SA_INIT (0x22) Aug 26 13:10:27.188546: | flags: ISAKMP_FLAG_v2_MSG_RESPONSE (0x20) Aug 26 13:10:27.188548: | Message ID: 0 (0x0) Aug 26 13:10:27.188550: | length: 440 (0x1b8) Aug 26 13:10:27.188552: | processing version=2.0 packet with exchange type=ISAKMP_v2_IKE_SA_INIT (34) Aug 26 13:10:27.188555: | I am the IKE SA Original Initiator receiving an IKEv2 IKE_SA_INIT response Aug 26 13:10:27.188557: | State DB: found IKEv2 state #1 in PARENT_I1 (find_v2_ike_sa_by_initiator_spi) Aug 26 13:10:27.188562: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_process_packet() at ikev2.c:2016) Aug 26 13:10:27.188565: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ike_process_packet() at ikev2.c:2062) Aug 26 13:10:27.188567: | #1 is idle Aug 26 13:10:27.188569: | #1 idle Aug 26 13:10:27.188570: | unpacking clear payload Aug 26 13:10:27.188572: | Now let's proceed with payload (ISAKMP_NEXT_v2SA) Aug 26 13:10:27.188574: | ***parse IKEv2 Security Association Payload: Aug 26 13:10:27.188576: | next payload type: ISAKMP_NEXT_v2KE (0x22) Aug 26 13:10:27.188578: | flags: none (0x0) Aug 26 13:10:27.188579: | length: 48 (0x30) Aug 26 13:10:27.188581: | processing payload: ISAKMP_NEXT_v2SA (len=44) Aug 26 13:10:27.188583: | Now let's proceed with payload (ISAKMP_NEXT_v2KE) Aug 26 13:10:27.188585: | ***parse IKEv2 Key Exchange Payload: Aug 26 13:10:27.188586: | next payload type: ISAKMP_NEXT_v2Ni (0x28) Aug 26 13:10:27.188588: | flags: none (0x0) Aug 26 13:10:27.188589: | length: 264 (0x108) Aug 26 13:10:27.188591: | DH group: OAKLEY_GROUP_MODP2048 (0xe) Aug 26 13:10:27.188593: | processing payload: ISAKMP_NEXT_v2KE (len=256) Aug 26 13:10:27.188594: | Now let's proceed with payload (ISAKMP_NEXT_v2Ni) Aug 26 13:10:27.188596: | ***parse IKEv2 Nonce Payload: Aug 26 13:10:27.188598: | next payload type: ISAKMP_NEXT_v2N (0x29) Aug 26 13:10:27.188599: | flags: none (0x0) Aug 26 13:10:27.188601: | length: 36 (0x24) Aug 26 13:10:27.188602: | processing payload: ISAKMP_NEXT_v2Ni (len=32) Aug 26 13:10:27.188604: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Aug 26 13:10:27.188607: | ***parse IKEv2 Notify Payload: Aug 26 13:10:27.188609: | next payload type: ISAKMP_NEXT_v2N (0x29) Aug 26 13:10:27.188610: | flags: none (0x0) Aug 26 13:10:27.188612: | length: 8 (0x8) Aug 26 13:10:27.188614: | Protocol ID: PROTO_v2_RESERVED (0x0) Aug 26 13:10:27.188615: | SPI size: 0 (0x0) Aug 26 13:10:27.188617: | Notify Message Type: v2N_IKEV2_FRAGMENTATION_SUPPORTED (0x402e) Aug 26 13:10:27.188619: | processing payload: ISAKMP_NEXT_v2N (len=0) Aug 26 13:10:27.188620: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Aug 26 13:10:27.188622: | ***parse IKEv2 Notify Payload: Aug 26 13:10:27.188624: | next payload type: ISAKMP_NEXT_v2N (0x29) Aug 26 13:10:27.188625: | flags: none (0x0) Aug 26 13:10:27.188627: | length: 28 (0x1c) Aug 26 13:10:27.188628: | Protocol ID: PROTO_v2_RESERVED (0x0) Aug 26 13:10:27.188630: | SPI size: 0 (0x0) Aug 26 13:10:27.188631: | Notify Message Type: v2N_NAT_DETECTION_SOURCE_IP (0x4004) Aug 26 13:10:27.188633: | processing payload: ISAKMP_NEXT_v2N (len=20) Aug 26 13:10:27.188635: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Aug 26 13:10:27.188636: | ***parse IKEv2 Notify Payload: Aug 26 13:10:27.188638: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:27.188639: | flags: none (0x0) Aug 26 13:10:27.188641: | length: 28 (0x1c) Aug 26 13:10:27.188642: | Protocol ID: PROTO_v2_RESERVED (0x0) Aug 26 13:10:27.188644: | SPI size: 0 (0x0) Aug 26 13:10:27.188646: | Notify Message Type: v2N_NAT_DETECTION_DESTINATION_IP (0x4005) Aug 26 13:10:27.188647: | processing payload: ISAKMP_NEXT_v2N (len=20) Aug 26 13:10:27.188649: | State DB: re-hashing IKEv2 state #1 IKE SPIi and SPI[ir] Aug 26 13:10:27.188652: | #1 in state PARENT_I1: sent v2I1, expected v2R1 Aug 26 13:10:27.188654: | selected state microcode Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH Aug 26 13:10:27.188656: | Now let's proceed with state specific processing Aug 26 13:10:27.188658: | calling processor Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH Aug 26 13:10:27.188660: | ikev2 parent inR1: calculating g^{xy} in order to send I2 Aug 26 13:10:27.188666: | using existing local IKE proposals for connection north-eastnets/0x2 (IKE SA initiator accepting remote proposal): 1:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_256;INTEG=HMAC_SHA2_256_128;DH=MODP2048 Aug 26 13:10:27.188668: | Comparing remote proposals against IKE initiator (accepting) 1 local proposals Aug 26 13:10:27.188674: | local proposal 1 type ENCR has 1 transforms Aug 26 13:10:27.188675: | local proposal 1 type PRF has 1 transforms Aug 26 13:10:27.188677: | local proposal 1 type INTEG has 1 transforms Aug 26 13:10:27.188679: | local proposal 1 type DH has 1 transforms Aug 26 13:10:27.188681: | local proposal 1 type ESN has 0 transforms Aug 26 13:10:27.188683: | local proposal 1 transforms: required: ENCR+PRF+INTEG+DH; optional: none Aug 26 13:10:27.188685: | ****parse IKEv2 Proposal Substructure Payload: Aug 26 13:10:27.188687: | last proposal: v2_PROPOSAL_LAST (0x0) Aug 26 13:10:27.188689: | length: 44 (0x2c) Aug 26 13:10:27.188690: | prop #: 1 (0x1) Aug 26 13:10:27.188692: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Aug 26 13:10:27.188693: | spi size: 0 (0x0) Aug 26 13:10:27.188695: | # transforms: 4 (0x4) Aug 26 13:10:27.188697: | Comparing remote proposal 1 containing 4 transforms against local proposal [1..1] of 1 local proposals Aug 26 13:10:27.188699: | *****parse IKEv2 Transform Substructure Payload: Aug 26 13:10:27.188701: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:27.188703: | length: 12 (0xc) Aug 26 13:10:27.188704: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Aug 26 13:10:27.188706: | IKEv2 transform ID: AES_CBC (0xc) Aug 26 13:10:27.188708: | ******parse IKEv2 Attribute Substructure Payload: Aug 26 13:10:27.188709: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Aug 26 13:10:27.188711: | length/value: 256 (0x100) Aug 26 13:10:27.188714: | remote proposal 1 transform 0 (ENCR=AES_CBC_256) matches local proposal 1 type 1 (ENCR) transform 0 Aug 26 13:10:27.188717: | *****parse IKEv2 Transform Substructure Payload: Aug 26 13:10:27.188719: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:27.188720: | length: 8 (0x8) Aug 26 13:10:27.188722: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Aug 26 13:10:27.188724: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Aug 26 13:10:27.188726: | remote proposal 1 transform 1 (PRF=HMAC_SHA2_256) matches local proposal 1 type 2 (PRF) transform 0 Aug 26 13:10:27.188728: | *****parse IKEv2 Transform Substructure Payload: Aug 26 13:10:27.188729: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:27.188731: | length: 8 (0x8) Aug 26 13:10:27.188732: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Aug 26 13:10:27.188734: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Aug 26 13:10:27.188736: | remote proposal 1 transform 2 (INTEG=HMAC_SHA2_256_128) matches local proposal 1 type 3 (INTEG) transform 0 Aug 26 13:10:27.188738: | *****parse IKEv2 Transform Substructure Payload: Aug 26 13:10:27.188740: | last transform: v2_TRANSFORM_LAST (0x0) Aug 26 13:10:27.188741: | length: 8 (0x8) Aug 26 13:10:27.188743: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Aug 26 13:10:27.188744: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Aug 26 13:10:27.188747: | remote proposal 1 transform 3 (DH=MODP2048) matches local proposal 1 type 4 (DH) transform 0 Aug 26 13:10:27.188749: | remote proposal 1 proposed transforms: ENCR+PRF+INTEG+DH; matched: ENCR+PRF+INTEG+DH; unmatched: none Aug 26 13:10:27.188752: | comparing remote proposal 1 containing ENCR+PRF+INTEG+DH transforms to local proposal 1; required: ENCR+PRF+INTEG+DH; optional: none; matched: ENCR+PRF+INTEG+DH Aug 26 13:10:27.188754: | remote proposal 1 matches local proposal 1 Aug 26 13:10:27.188756: | remote accepted the proposal 1:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_256;INTEG=HMAC_SHA2_256_128;DH=MODP2048[first-match] Aug 26 13:10:27.188758: | converting proposal to internal trans attrs Aug 26 13:10:27.188772: | natd_hash: hasher=0x55e27567b800(20) Aug 26 13:10:27.188774: | natd_hash: icookie= 8b 87 d7 26 c3 30 6b 14 Aug 26 13:10:27.188776: | natd_hash: rcookie= 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.188777: | natd_hash: ip= c0 01 02 17 Aug 26 13:10:27.188779: | natd_hash: port=500 Aug 26 13:10:27.188781: | natd_hash: hash= 44 a5 8b 90 40 7e aa 0d 14 c0 4d d7 ee 49 1a 16 Aug 26 13:10:27.188782: | natd_hash: hash= b5 85 4f 2c Aug 26 13:10:27.188786: | natd_hash: hasher=0x55e27567b800(20) Aug 26 13:10:27.188788: | natd_hash: icookie= 8b 87 d7 26 c3 30 6b 14 Aug 26 13:10:27.188789: | natd_hash: rcookie= 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.188791: | natd_hash: ip= c0 01 03 21 Aug 26 13:10:27.188792: | natd_hash: port=500 Aug 26 13:10:27.188794: | natd_hash: hash= 9b 28 99 9a 12 57 bf c4 ed ee f8 52 09 04 95 90 Aug 26 13:10:27.188795: | natd_hash: hash= 7e 59 18 59 Aug 26 13:10:27.188797: | NAT_TRAVERSAL encaps using auto-detect Aug 26 13:10:27.188799: | NAT_TRAVERSAL this end is NOT behind NAT Aug 26 13:10:27.188800: | NAT_TRAVERSAL that end is NOT behind NAT Aug 26 13:10:27.188802: | NAT_TRAVERSAL nat-keepalive enabled 192.1.3.33 Aug 26 13:10:27.188807: | offloading IKEv2 SKEYSEED using prf=HMAC_SHA2_256 integ=HMAC_SHA2_256_128 cipherkey=AES_CBC Aug 26 13:10:27.188810: | adding ikev2_inR1outI2 KE work-order 2 for state #1 Aug 26 13:10:27.188812: | state #1 requesting EVENT_RETRANSMIT to be deleted Aug 26 13:10:27.188814: | #1 STATE_PARENT_I1: retransmits: cleared Aug 26 13:10:27.188817: | libevent_free: release ptr-libevent@0x55e277716f18 Aug 26 13:10:27.188819: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277714d28 Aug 26 13:10:27.188821: | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x55e277714d28 Aug 26 13:10:27.188823: | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 Aug 26 13:10:27.188825: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:10:27.188834: | #1 spent 0.173 milliseconds in processing: Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH in ikev2_process_state_packet() Aug 26 13:10:27.188839: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in complete_v2_state_transition() at ikev2.c:3379) Aug 26 13:10:27.188842: | #1 complete_v2_state_transition() PARENT_I1->PARENT_I2 with status STF_SUSPEND Aug 26 13:10:27.188842: | crypto helper 4 resuming Aug 26 13:10:27.188858: | crypto helper 4 starting work-order 2 for state #1 Aug 26 13:10:27.188865: | crypto helper 4 doing compute dh (V2) (ikev2_inR1outI2 KE); request ID 2 Aug 26 13:10:27.188844: | suspending state #1 and saving MD Aug 26 13:10:27.188871: | #1 is busy; has a suspended MD Aug 26 13:10:27.188875: | [RE]START processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in log_stf_suspend() at ikev2.c:3269) Aug 26 13:10:27.188878: | "north-eastnets/0x2" #1 complete v2 state STATE_PARENT_I1 transition with STF_SUSPEND suspended from complete_v2_state_transition:3451 Aug 26 13:10:27.188881: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_process_packet() at ikev2.c:2018) Aug 26 13:10:27.188884: | #1 spent 0.408 milliseconds in ikev2_process_packet() Aug 26 13:10:27.188887: | stop processing: from 192.1.3.33:500 (in process_md() at demux.c:380) Aug 26 13:10:27.188889: | processing: STOP state #0 (in process_md() at demux.c:382) Aug 26 13:10:27.188891: | processing: STOP connection NULL (in process_md() at demux.c:383) Aug 26 13:10:27.188893: | spent 0.418 milliseconds in comm_handle_cb() reading and processing packet Aug 26 13:10:27.189722: | calculating skeyseed using prf=sha2_256 integ=sha2_256 cipherkey-size=32 salt-size=0 Aug 26 13:10:27.190189: | crypto helper 4 finished compute dh (V2) (ikev2_inR1outI2 KE); request ID 2 time elapsed 0.001325 seconds Aug 26 13:10:27.190198: | (#1) spent 1.32 milliseconds in crypto helper computing work-order 2: ikev2_inR1outI2 KE (pcr) Aug 26 13:10:27.190200: | crypto helper 4 sending results from work-order 2 for state #1 to event queue Aug 26 13:10:27.190202: | scheduling resume sending helper answer for #1 Aug 26 13:10:27.190205: | libevent_malloc: new ptr-libevent@0x7f046800a868 size 128 Aug 26 13:10:27.190212: | crypto helper 4 waiting (nothing to do) Aug 26 13:10:27.190222: | processing resume sending helper answer for #1 Aug 26 13:10:27.190234: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in resume_handler() at server.c:797) Aug 26 13:10:27.190238: | crypto helper 4 replies to request ID 2 Aug 26 13:10:27.190240: | calling continuation function 0x55e2755a6b50 Aug 26 13:10:27.190242: | ikev2_parent_inR1outI2_continue for #1: calculating g^{xy}, sending I2 Aug 26 13:10:27.190249: | creating state object #2 at 0x55e27771a758 Aug 26 13:10:27.190251: | State DB: adding IKEv2 state #2 in UNDEFINED Aug 26 13:10:27.190254: | pstats #2 ikev2.child started Aug 26 13:10:27.190256: | duplicating state object #1 "north-eastnets/0x2" as #2 for IPSEC SA Aug 26 13:10:27.190260: | #2 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1484) Aug 26 13:10:27.190264: | Message ID: init_child #1.#2; ike: initiator.sent=0 initiator.recv=-1 responder.sent=-1 responder.recv=-1; child: wip.initiator=0->-1 wip.responder=0->-1 Aug 26 13:10:27.190268: | Message ID: switch-from #1 response 0; ike: initiator.sent=0 initiator.recv=-1 responder.sent=-1 responder.recv=-1 wip.initiator=0->-1 wip.responder=-1 Aug 26 13:10:27.190272: | Message ID: switch-to #1.#2 response 0; ike: initiator.sent=0 initiator.recv=-1 responder.sent=-1 responder.recv=-1; child: wip.initiator=-1->0 wip.responder=-1 Aug 26 13:10:27.190274: | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted Aug 26 13:10:27.190276: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:10:27.190278: | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x55e277714d28 Aug 26 13:10:27.190280: | event_schedule: new EVENT_SA_REPLACE-pe@0x55e277714d28 Aug 26 13:10:27.190283: | inserting event EVENT_SA_REPLACE, timeout in 60 seconds for #1 Aug 26 13:10:27.190285: | libevent_malloc: new ptr-libevent@0x7f0470002888 size 128 Aug 26 13:10:27.190312: | parent state #1: PARENT_I1(half-open IKE SA) => PARENT_I2(open IKE SA) Aug 26 13:10:27.190321: | **emit ISAKMP Message: Aug 26 13:10:27.190324: | initiator cookie: Aug 26 13:10:27.190325: | 8b 87 d7 26 c3 30 6b 14 Aug 26 13:10:27.190327: | responder cookie: Aug 26 13:10:27.190328: | 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.190330: | next payload type: ISAKMP_NEXT_NONE (0x0) Aug 26 13:10:27.190332: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Aug 26 13:10:27.190334: | exchange type: ISAKMP_v2_IKE_AUTH (0x23) Aug 26 13:10:27.190336: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Aug 26 13:10:27.190338: | Message ID: 1 (0x1) Aug 26 13:10:27.190340: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Aug 26 13:10:27.190342: | ***emit IKEv2 Encryption Payload: Aug 26 13:10:27.190344: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:27.190346: | flags: none (0x0) Aug 26 13:10:27.190348: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Encryption Payload (46:ISAKMP_NEXT_v2SK) Aug 26 13:10:27.190350: | next payload chain: saving location 'IKEv2 Encryption Payload'.'next payload type' in 'reply packet' Aug 26 13:10:27.190352: | emitting 16 zero bytes of IV into IKEv2 Encryption Payload Aug 26 13:10:27.190359: | IKEv2 CERT: send a certificate? Aug 26 13:10:27.190361: | IKEv2 CERT: no certificate to send Aug 26 13:10:27.190362: | IDr payload will be sent Aug 26 13:10:27.190374: | ****emit IKEv2 Identification - Initiator - Payload: Aug 26 13:10:27.190376: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:27.190378: | flags: none (0x0) Aug 26 13:10:27.190379: | ID type: ID_FQDN (0x2) Aug 26 13:10:27.190382: | next payload chain: setting previous 'IKEv2 Encryption Payload'.'next payload type' to current IKEv2 Identification - Initiator - Payload (35:ISAKMP_NEXT_v2IDi) Aug 26 13:10:27.190384: | next payload chain: saving location 'IKEv2 Identification - Initiator - Payload'.'next payload type' in 'reply packet' Aug 26 13:10:27.190386: | emitting 4 raw bytes of my identity into IKEv2 Identification - Initiator - Payload Aug 26 13:10:27.190388: | my identity 65 61 73 74 Aug 26 13:10:27.190389: | emitting length of IKEv2 Identification - Initiator - Payload: 12 Aug 26 13:10:27.190395: | ****emit IKEv2 Identification - Responder - Payload: Aug 26 13:10:27.190397: | next payload type: ISAKMP_NEXT_v2AUTH (0x27) Aug 26 13:10:27.190399: | flags: none (0x0) Aug 26 13:10:27.190400: | ID type: ID_FQDN (0x2) Aug 26 13:10:27.190402: | next payload chain: ignoring supplied 'IKEv2 Identification - Responder - Payload'.'next payload type' value 39:ISAKMP_NEXT_v2AUTH Aug 26 13:10:27.190404: | next payload chain: setting previous 'IKEv2 Identification - Initiator - Payload'.'next payload type' to current IKEv2 Identification - Responder - Payload (36:ISAKMP_NEXT_v2IDr) Aug 26 13:10:27.190406: | next payload chain: saving location 'IKEv2 Identification - Responder - Payload'.'next payload type' in 'reply packet' Aug 26 13:10:27.190408: | emitting 5 raw bytes of IDr into IKEv2 Identification - Responder - Payload Aug 26 13:10:27.190410: | IDr 6e 6f 72 74 68 Aug 26 13:10:27.190411: | emitting length of IKEv2 Identification - Responder - Payload: 13 Aug 26 13:10:27.190413: | not sending INITIAL_CONTACT Aug 26 13:10:27.190415: | ****emit IKEv2 Authentication Payload: Aug 26 13:10:27.190417: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:27.190418: | flags: none (0x0) Aug 26 13:10:27.190420: | auth method: IKEv2_AUTH_RSA (0x1) Aug 26 13:10:27.190422: | next payload chain: setting previous 'IKEv2 Identification - Responder - Payload'.'next payload type' to current IKEv2 Authentication Payload (39:ISAKMP_NEXT_v2AUTH) Aug 26 13:10:27.190424: | next payload chain: saving location 'IKEv2 Authentication Payload'.'next payload type' in 'reply packet' Aug 26 13:10:27.190428: | started looking for secret for @east->@north of kind PKK_RSA Aug 26 13:10:27.190432: | actually looking for secret for @east->@north of kind PKK_RSA Aug 26 13:10:27.190434: | line 1: key type PKK_RSA(@east) to type PKK_RSA Aug 26 13:10:27.190437: | 1: compared key (none) to @east / @north -> 002 Aug 26 13:10:27.190438: | 2: compared key (none) to @east / @north -> 002 Aug 26 13:10:27.190440: | line 1: match=002 Aug 26 13:10:27.190442: | match 002 beats previous best_match 000 match=0x55e27766cb58 (line=1) Aug 26 13:10:27.190444: | concluding with best_match=002 best=0x55e27766cb58 (lineno=1) Aug 26 13:10:27.193884: | #1 spent 3.41 milliseconds in ikev2_calculate_rsa_hash() calling sign_hash_RSA() Aug 26 13:10:27.193897: | emitting 274 raw bytes of rsa signature into IKEv2 Authentication Payload Aug 26 13:10:27.193902: | rsa signature 29 f5 a9 44 14 73 41 ce 64 f0 44 6b 1d 5f 58 8e Aug 26 13:10:27.193904: | rsa signature 87 73 83 64 80 29 16 80 23 02 57 c3 2d 2d 9e 29 Aug 26 13:10:27.193907: | rsa signature 94 c1 9c 8e b9 10 ca 02 da 81 c0 61 3b ca 4b fd Aug 26 13:10:27.193908: | rsa signature 34 34 0c c2 ba 1b 7c f2 17 65 f1 67 88 90 cc d8 Aug 26 13:10:27.193910: | rsa signature 2a 13 58 ad a2 5e 4d ee d3 43 d4 80 ef 34 98 b6 Aug 26 13:10:27.193911: | rsa signature cb 05 6b 27 84 e8 db d1 d9 39 2e b9 83 c3 fe c4 Aug 26 13:10:27.193913: | rsa signature d8 a2 de 0a c1 f5 f1 34 c2 d7 84 94 a7 dc 12 ef Aug 26 13:10:27.193914: | rsa signature 14 5b a0 ce 4a e4 34 25 80 8a f0 5d e0 3c 12 df Aug 26 13:10:27.193916: | rsa signature c7 6a 3e a0 5d 71 75 0d 50 f9 94 4c 20 f9 10 c5 Aug 26 13:10:27.193917: | rsa signature 3b 67 17 ca 2e e2 df da f4 1a b1 39 3f 76 45 26 Aug 26 13:10:27.193919: | rsa signature 55 7d 7b da 62 62 bf 35 df 28 fb 83 78 27 9b 88 Aug 26 13:10:27.193920: | rsa signature 6b a7 b2 0c fd 63 c3 d4 00 b1 a2 c3 2c d1 65 59 Aug 26 13:10:27.193922: | rsa signature b9 cd f1 de 7f 16 26 e9 d1 19 65 89 5d 1e b7 04 Aug 26 13:10:27.193923: | rsa signature f2 1a b7 e1 c3 ce 56 b4 3b b9 d4 89 22 e1 45 73 Aug 26 13:10:27.193925: | rsa signature e4 3a 20 02 71 87 a2 85 ea 5d f6 6d 84 ff 53 5a Aug 26 13:10:27.193926: | rsa signature e6 bf c8 ab 30 07 a5 ed 4d 15 69 27 cb bf 3f 62 Aug 26 13:10:27.193928: | rsa signature 70 bd 2d bc 96 b7 ff 47 ad 65 17 2b 63 bd 4e 9f Aug 26 13:10:27.193929: | rsa signature c3 2b Aug 26 13:10:27.193932: | #1 spent 3.49 milliseconds in ikev2_calculate_rsa_hash() Aug 26 13:10:27.193935: | emitting length of IKEv2 Authentication Payload: 282 Aug 26 13:10:27.193936: | getting first pending from state #1 Aug 26 13:10:27.193939: | Switching Child connection for #2 to "north-eastnets/0x1" from "north-eastnets/0x2" Aug 26 13:10:27.193942: | in connection_discard for connection north-eastnets/0x2 Aug 26 13:10:27.193961: | netlink_get_spi: allocated 0xf3b8aff7 for esp.0@192.1.2.23 Aug 26 13:10:27.193964: | constructing ESP/AH proposals with all DH removed for north-eastnets/0x1 (IKE SA initiator emitting ESP/AH proposals) Aug 26 13:10:27.193968: | converting proposal AES_CBC_128-HMAC_SHA2_512_256-MODP3072 to ikev2 ... Aug 26 13:10:27.193973: | ... ikev2_proposal: 1:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;DH=NONE;ESN=DISABLED Aug 26 13:10:27.193976: "north-eastnets/0x1": constructed local ESP/AH proposals for north-eastnets/0x1 (IKE SA initiator emitting ESP/AH proposals): 1:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;DH=NONE;ESN=DISABLED Aug 26 13:10:27.193978: | Emitting ikev2_proposals ... Aug 26 13:10:27.193980: | ****emit IKEv2 Security Association Payload: Aug 26 13:10:27.193982: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:27.193984: | flags: none (0x0) Aug 26 13:10:27.193987: | next payload chain: setting previous 'IKEv2 Authentication Payload'.'next payload type' to current IKEv2 Security Association Payload (33:ISAKMP_NEXT_v2SA) Aug 26 13:10:27.193989: | next payload chain: saving location 'IKEv2 Security Association Payload'.'next payload type' in 'reply packet' Aug 26 13:10:27.193990: | discarding DH=NONE Aug 26 13:10:27.193992: | *****emit IKEv2 Proposal Substructure Payload: Aug 26 13:10:27.193997: | last proposal: v2_PROPOSAL_LAST (0x0) Aug 26 13:10:27.193999: | prop #: 1 (0x1) Aug 26 13:10:27.194000: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Aug 26 13:10:27.194002: | spi size: 4 (0x4) Aug 26 13:10:27.194003: | # transforms: 3 (0x3) Aug 26 13:10:27.194005: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Aug 26 13:10:27.194007: | emitting 4 raw bytes of our spi into IKEv2 Proposal Substructure Payload Aug 26 13:10:27.194009: | our spi f3 b8 af f7 Aug 26 13:10:27.194011: | ******emit IKEv2 Transform Substructure Payload: Aug 26 13:10:27.194012: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:27.194014: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Aug 26 13:10:27.194016: | IKEv2 transform ID: AES_CBC (0xc) Aug 26 13:10:27.194017: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:10:27.194019: | *******emit IKEv2 Attribute Substructure Payload: Aug 26 13:10:27.194021: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Aug 26 13:10:27.194023: | length/value: 128 (0x80) Aug 26 13:10:27.194025: | emitting length of IKEv2 Transform Substructure Payload: 12 Aug 26 13:10:27.194026: | ******emit IKEv2 Transform Substructure Payload: Aug 26 13:10:27.194028: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:27.194029: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Aug 26 13:10:27.194031: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Aug 26 13:10:27.194033: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:27.194036: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:10:27.194039: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:10:27.194040: | discarding DH=NONE Aug 26 13:10:27.194042: | ******emit IKEv2 Transform Substructure Payload: Aug 26 13:10:27.194044: | last transform: v2_TRANSFORM_LAST (0x0) Aug 26 13:10:27.194045: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Aug 26 13:10:27.194047: | IKEv2 transform ID: ESN_DISABLED (0x0) Aug 26 13:10:27.194049: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:27.194050: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:10:27.194052: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:10:27.194054: | emitting length of IKEv2 Proposal Substructure Payload: 40 Aug 26 13:10:27.194056: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Aug 26 13:10:27.194057: | emitting length of IKEv2 Security Association Payload: 44 Aug 26 13:10:27.194059: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is 0 Aug 26 13:10:27.194061: | ****emit IKEv2 Traffic Selector - Initiator - Payload: Aug 26 13:10:27.194063: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:27.194065: | flags: none (0x0) Aug 26 13:10:27.194066: | number of TS: 1 (0x1) Aug 26 13:10:27.194068: | next payload chain: setting previous 'IKEv2 Security Association Payload'.'next payload type' to current IKEv2 Traffic Selector - Initiator - Payload (44:ISAKMP_NEXT_v2TSi) Aug 26 13:10:27.194070: | next payload chain: saving location 'IKEv2 Traffic Selector - Initiator - Payload'.'next payload type' in 'reply packet' Aug 26 13:10:27.194072: | *****emit IKEv2 Traffic Selector: Aug 26 13:10:27.194074: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Aug 26 13:10:27.194075: | IP Protocol ID: 0 (0x0) Aug 26 13:10:27.194077: | start port: 0 (0x0) Aug 26 13:10:27.194079: | end port: 65535 (0xffff) Aug 26 13:10:27.194082: | emitting 4 raw bytes of ipv4 start into IKEv2 Traffic Selector Aug 26 13:10:27.194083: | ipv4 start c0 00 02 00 Aug 26 13:10:27.194085: | emitting 4 raw bytes of ipv4 end into IKEv2 Traffic Selector Aug 26 13:10:27.194087: | ipv4 end c0 00 02 ff Aug 26 13:10:27.194088: | emitting length of IKEv2 Traffic Selector: 16 Aug 26 13:10:27.194090: | emitting length of IKEv2 Traffic Selector - Initiator - Payload: 24 Aug 26 13:10:27.194092: | ****emit IKEv2 Traffic Selector - Responder - Payload: Aug 26 13:10:27.194093: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:27.194095: | flags: none (0x0) Aug 26 13:10:27.194096: | number of TS: 1 (0x1) Aug 26 13:10:27.194098: | next payload chain: setting previous 'IKEv2 Traffic Selector - Initiator - Payload'.'next payload type' to current IKEv2 Traffic Selector - Responder - Payload (45:ISAKMP_NEXT_v2TSr) Aug 26 13:10:27.194100: | next payload chain: saving location 'IKEv2 Traffic Selector - Responder - Payload'.'next payload type' in 'reply packet' Aug 26 13:10:27.194102: | *****emit IKEv2 Traffic Selector: Aug 26 13:10:27.194103: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Aug 26 13:10:27.194105: | IP Protocol ID: 0 (0x0) Aug 26 13:10:27.194106: | start port: 0 (0x0) Aug 26 13:10:27.194108: | end port: 65535 (0xffff) Aug 26 13:10:27.194110: | emitting 4 raw bytes of ipv4 start into IKEv2 Traffic Selector Aug 26 13:10:27.194111: | ipv4 start c0 00 03 00 Aug 26 13:10:27.194113: | emitting 4 raw bytes of ipv4 end into IKEv2 Traffic Selector Aug 26 13:10:27.194114: | ipv4 end c0 00 03 ff Aug 26 13:10:27.194116: | emitting length of IKEv2 Traffic Selector: 16 Aug 26 13:10:27.194117: | emitting length of IKEv2 Traffic Selector - Responder - Payload: 24 Aug 26 13:10:27.194119: | Initiator child policy is tunnel mode, NOT sending v2N_USE_TRANSPORT_MODE Aug 26 13:10:27.194121: | Initiator child policy is compress=no, NOT sending v2N_IPCOMP_SUPPORTED Aug 26 13:10:27.194123: | adding 1 bytes of padding (including 1 byte padding-length) Aug 26 13:10:27.194125: | emitting 1 0x00 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:27.194127: | emitting 16 zero bytes of length of truncated HMAC/KEY into IKEv2 Encryption Payload Aug 26 13:10:27.194129: | emitting length of IKEv2 Encryption Payload: 436 Aug 26 13:10:27.194131: | emitting length of ISAKMP Message: 464 Aug 26 13:10:27.194159: | data being hmac: 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.194162: | data being hmac: 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:27.194163: | data being hmac: 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:27.194165: | data being hmac: 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:27.194166: | data being hmac: 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:27.194168: | data being hmac: 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:27.194169: | data being hmac: 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:27.194171: | data being hmac: c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:27.194172: | data being hmac: 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:27.194174: | data being hmac: dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:27.194175: | data being hmac: 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:27.194177: | data being hmac: b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:27.194178: | data being hmac: 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:27.194180: | data being hmac: 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:27.194181: | data being hmac: 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:27.194183: | data being hmac: be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:27.194184: | data being hmac: aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:27.194187: | data being hmac: 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:27.194189: | data being hmac: 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:27.194190: | data being hmac: 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:27.194192: | data being hmac: fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:27.194193: | data being hmac: ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:27.194195: | data being hmac: ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:27.194196: | data being hmac: 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:27.194198: | data being hmac: 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:27.194199: | data being hmac: 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:27.194201: | data being hmac: 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:27.194202: | data being hmac: 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:27.194204: | out calculated auth: Aug 26 13:10:27.194205: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:27.194211: | suspend processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in complete_v2_state_transition() at ikev2.c:3379) Aug 26 13:10:27.194214: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in complete_v2_state_transition() at ikev2.c:3379) Aug 26 13:10:27.194217: | #2 complete_v2_state_transition() md.from_state=PARENT_I1 md.svm.state[from]=PARENT_I1 UNDEFINED->PARENT_I2 with status STF_OK Aug 26 13:10:27.194220: | IKEv2: transition from state STATE_PARENT_I1 to state STATE_PARENT_I2 Aug 26 13:10:27.194222: | child state #2: UNDEFINED(ignore) => PARENT_I2(open IKE SA) Aug 26 13:10:27.194224: | Message ID: updating counters for #2 to 0 after switching state Aug 26 13:10:27.194227: | Message ID: recv #1.#2 response 0; ike: initiator.sent=0 initiator.recv=-1->0 responder.sent=-1 responder.recv=-1; child: wip.initiator=0->-1 wip.responder=-1 Aug 26 13:10:27.194230: | Message ID: sent #1.#2 request 1; ike: initiator.sent=0->1 initiator.recv=0 responder.sent=-1 responder.recv=-1; child: wip.initiator=-1->1 wip.responder=-1 Aug 26 13:10:27.194234: "north-eastnets/0x1" #2: STATE_PARENT_I2: sent v2I2, expected v2R2 {auth=IKEv2 cipher=AES_CBC_256 integ=HMAC_SHA2_256_128 prf=HMAC_SHA2_256 group=MODP2048} Aug 26 13:10:27.194237: | sending V2 reply packet to 192.1.3.33:500 (from 192.1.2.23:500) Aug 26 13:10:27.194241: | sending 464 bytes for STATE_PARENT_I1 through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:27.194242: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.194244: | 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:27.194245: | 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:27.194247: | 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:27.194248: | 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:27.194250: | 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:27.194251: | 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:27.194253: | c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:27.194254: | 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:27.194256: | dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:27.194257: | 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:27.194259: | b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:27.194260: | 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:27.194262: | 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:27.194263: | 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:27.194264: | be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:27.194266: | aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:27.194267: | 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:27.194270: | 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:27.194271: | 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:27.194273: | fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:27.194274: | ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:27.194276: | ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:27.194277: | 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:27.194279: | 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:27.194280: | 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:27.194282: | 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:27.194283: | 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:27.194285: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:27.194380: | success_v2_state_transition scheduling EVENT_RETRANSMIT of c->r_interval=50ms Aug 26 13:10:27.194387: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:27.194390: | inserting event EVENT_RETRANSMIT, timeout in 0.05 seconds for #2 Aug 26 13:10:27.194393: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:10:27.194397: | #2 STATE_PARENT_I2: retransmits: first event in 0.05 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 10312.936853 Aug 26 13:10:27.194400: | resume sending helper answer for #1 suppresed complete_v2_state_transition() Aug 26 13:10:27.194404: | #1 spent 4.05 milliseconds in resume sending helper answer Aug 26 13:10:27.194407: | stop processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in resume_handler() at server.c:833) Aug 26 13:10:27.194410: | libevent_free: release ptr-libevent@0x7f046800a868 Aug 26 13:10:27.244504: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:27.244519: | handling event EVENT_RETRANSMIT for child state #2 Aug 26 13:10:27.244526: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:27.244529: | IKEv2 retransmit event Aug 26 13:10:27.244532: | [RE]START processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:27.244535: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x1" #2 attempt 2 of 0 Aug 26 13:10:27.244538: | and parent for 192.1.3.33 "north-eastnets/0x1" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:27.244543: | retransmits: current time 10312.987008; retransmit count 0 exceeds limit? NO; deltatime 0.05 exceeds limit? NO; monotime 0.050155 exceeds limit? NO Aug 26 13:10:27.244546: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277716ea8 Aug 26 13:10:27.244549: | inserting event EVENT_RETRANSMIT, timeout in 0.05 seconds for #2 Aug 26 13:10:27.244551: | libevent_malloc: new ptr-libevent@0x7f046800a868 size 128 Aug 26 13:10:27.244555: "north-eastnets/0x1" #2: STATE_PARENT_I2: retransmission; will wait 0.05 seconds for response Aug 26 13:10:27.244560: | sending 464 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:27.244562: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.244564: | 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:27.244565: | 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:27.244567: | 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:27.244568: | 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:27.244570: | 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:27.244571: | 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:27.244573: | c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:27.244574: | 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:27.244576: | dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:27.244577: | 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:27.244579: | b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:27.244583: | 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:27.244585: | 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:27.244586: | 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:27.244588: | be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:27.244589: | aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:27.244591: | 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:27.244592: | 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:27.244594: | 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:27.244596: | fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:27.244597: | ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:27.244599: | ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:27.244600: | 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:27.244602: | 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:27.244603: | 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:27.244605: | 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:27.244606: | 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:27.244608: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:27.244659: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:10:27.244676: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:27.244698: | #2 spent 0.15 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:27.244703: | stop processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:27.295861: | timer_event_cb: processing event@0x55e277716ea8 Aug 26 13:10:27.295873: | handling event EVENT_RETRANSMIT for child state #2 Aug 26 13:10:27.295880: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:27.295882: | IKEv2 retransmit event Aug 26 13:10:27.295886: | [RE]START processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:27.295889: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x1" #2 attempt 2 of 0 Aug 26 13:10:27.295892: | and parent for 192.1.3.33 "north-eastnets/0x1" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:27.295896: | retransmits: current time 10313.038361; retransmit count 1 exceeds limit? NO; deltatime 0.1 exceeds limit? NO; monotime 0.101508 exceeds limit? NO Aug 26 13:10:27.295899: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:27.295902: | inserting event EVENT_RETRANSMIT, timeout in 0.1 seconds for #2 Aug 26 13:10:27.295904: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:10:27.295908: "north-eastnets/0x1" #2: STATE_PARENT_I2: retransmission; will wait 0.1 seconds for response Aug 26 13:10:27.295913: | sending 464 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:27.295915: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.295916: | 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:27.295918: | 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:27.295919: | 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:27.295921: | 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:27.295922: | 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:27.295924: | 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:27.295925: | c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:27.295927: | 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:27.295928: | dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:27.295930: | 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:27.295931: | b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:27.295933: | 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:27.295937: | 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:27.295938: | 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:27.295940: | be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:27.295941: | aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:27.295943: | 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:27.295944: | 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:27.295946: | 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:27.295947: | fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:27.295949: | ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:27.295950: | ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:27.295952: | 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:27.295953: | 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:27.295955: | 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:27.295956: | 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:27.295957: | 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:27.295959: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:27.296011: | libevent_free: release ptr-libevent@0x7f046800a868 Aug 26 13:10:27.296017: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277716ea8 Aug 26 13:10:27.296025: | #2 spent 0.134 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:27.296030: | stop processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:27.397206: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:27.397218: | handling event EVENT_RETRANSMIT for child state #2 Aug 26 13:10:27.397224: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:27.397226: | IKEv2 retransmit event Aug 26 13:10:27.397230: | [RE]START processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:27.397233: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x1" #2 attempt 2 of 0 Aug 26 13:10:27.397249: | and parent for 192.1.3.33 "north-eastnets/0x1" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:27.397254: | retransmits: current time 10313.139718; retransmit count 2 exceeds limit? NO; deltatime 0.2 exceeds limit? NO; monotime 0.202865 exceeds limit? NO Aug 26 13:10:27.397257: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277716ea8 Aug 26 13:10:27.397259: | inserting event EVENT_RETRANSMIT, timeout in 0.2 seconds for #2 Aug 26 13:10:27.397262: | libevent_malloc: new ptr-libevent@0x7f046800a868 size 128 Aug 26 13:10:27.397265: "north-eastnets/0x1" #2: STATE_PARENT_I2: retransmission; will wait 0.2 seconds for response Aug 26 13:10:27.397270: | sending 464 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:27.397272: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.397274: | 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:27.397275: | 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:27.397277: | 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:27.397278: | 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:27.397280: | 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:27.397281: | 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:27.397283: | c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:27.397284: | 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:27.397286: | dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:27.397291: | 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:27.397294: | b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:27.397297: | 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:27.397302: | 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:27.397304: | 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:27.397306: | be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:27.397307: | aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:27.397309: | 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:27.397310: | 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:27.397312: | 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:27.397313: | fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:27.397315: | ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:27.397316: | ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:27.397318: | 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:27.397319: | 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:27.397321: | 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:27.397322: | 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:27.397337: | 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:27.397338: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:27.397391: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:10:27.397394: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:27.397412: | #2 spent 0.172 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:27.397416: | stop processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:27.597639: | timer_event_cb: processing event@0x55e277716ea8 Aug 26 13:10:27.597653: | handling event EVENT_RETRANSMIT for child state #2 Aug 26 13:10:27.597661: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:27.597666: | IKEv2 retransmit event Aug 26 13:10:27.597671: | [RE]START processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:27.597676: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x1" #2 attempt 2 of 0 Aug 26 13:10:27.597678: | and parent for 192.1.3.33 "north-eastnets/0x1" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:27.597683: | retransmits: current time 10313.340148; retransmit count 3 exceeds limit? NO; deltatime 0.4 exceeds limit? NO; monotime 0.403295 exceeds limit? NO Aug 26 13:10:27.597686: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:27.597689: | inserting event EVENT_RETRANSMIT, timeout in 0.4 seconds for #2 Aug 26 13:10:27.597692: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:10:27.597695: "north-eastnets/0x1" #2: STATE_PARENT_I2: retransmission; will wait 0.4 seconds for response Aug 26 13:10:27.597700: | sending 464 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:27.597702: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.597704: | 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:27.597706: | 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:27.597707: | 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:27.597709: | 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:27.597710: | 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:27.597712: | 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:27.597713: | c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:27.597715: | 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:27.597716: | dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:27.597718: | 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:27.597719: | b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:27.597721: | 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:27.597725: | 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:27.597727: | 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:27.597728: | be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:27.597730: | aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:27.597731: | 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:27.597733: | 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:27.597734: | 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:27.597736: | fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:27.597737: | ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:27.597739: | ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:27.597740: | 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:27.597742: | 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:27.597743: | 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:27.597745: | 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:27.597746: | 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:27.597748: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:27.598112: | libevent_free: release ptr-libevent@0x7f046800a868 Aug 26 13:10:27.598122: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277716ea8 Aug 26 13:10:27.598130: | #2 spent 0.462 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:27.598138: | stop processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:27.998308: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:27.998328: | handling event EVENT_RETRANSMIT for child state #2 Aug 26 13:10:27.998335: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:27.998338: | IKEv2 retransmit event Aug 26 13:10:27.998342: | [RE]START processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:27.998345: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x1" #2 attempt 2 of 0 Aug 26 13:10:27.998347: | and parent for 192.1.3.33 "north-eastnets/0x1" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:27.998352: | retransmits: current time 10313.740817; retransmit count 4 exceeds limit? NO; deltatime 0.8 exceeds limit? NO; monotime 0.803964 exceeds limit? NO Aug 26 13:10:27.998355: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e277716ea8 Aug 26 13:10:27.998357: | inserting event EVENT_RETRANSMIT, timeout in 0.8 seconds for #2 Aug 26 13:10:27.998360: | libevent_malloc: new ptr-libevent@0x7f046800a868 size 128 Aug 26 13:10:27.998363: "north-eastnets/0x1" #2: STATE_PARENT_I2: retransmission; will wait 0.8 seconds for response Aug 26 13:10:27.998369: | sending 464 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:27.998370: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:27.998372: | 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:27.998374: | 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:27.998375: | 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:27.998377: | 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:27.998378: | 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:27.998380: | 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:27.998381: | c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:27.998383: | 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:27.998384: | dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:27.998386: | 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:27.998387: | b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:27.998389: | 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:27.998390: | 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:27.998396: | 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:27.998398: | be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:27.998399: | aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:27.998401: | 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:27.998402: | 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:27.998404: | 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:27.998405: | fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:27.998407: | ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:27.998408: | ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:27.998410: | 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:27.998412: | 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:27.998413: | 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:27.998415: | 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:27.998416: | 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:27.998418: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:27.998460: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:10:27.998463: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:27.998469: | #2 spent 0.139 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:27.998472: | stop processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:28.799336: | timer_event_cb: processing event@0x55e277716ea8 Aug 26 13:10:28.799366: | handling event EVENT_RETRANSMIT for child state #2 Aug 26 13:10:28.799372: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:28.799375: | IKEv2 retransmit event Aug 26 13:10:28.799394: | [RE]START processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:28.799397: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x1" #2 attempt 2 of 0 Aug 26 13:10:28.799400: | and parent for 192.1.3.33 "north-eastnets/0x1" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:28.799404: | retransmits: current time 10314.541869; retransmit count 5 exceeds limit? NO; deltatime 1.6 exceeds limit? NO; monotime 1.605016 exceeds limit? NO Aug 26 13:10:28.799407: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:28.799410: | inserting event EVENT_RETRANSMIT, timeout in 1.6 seconds for #2 Aug 26 13:10:28.799413: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:10:28.799416: "north-eastnets/0x1" #2: STATE_PARENT_I2: retransmission; will wait 1.6 seconds for response Aug 26 13:10:28.799421: | sending 464 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:28.799423: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:28.799437: | 2e 20 23 08 00 00 00 01 00 00 01 d0 23 00 01 b4 Aug 26 13:10:28.799439: | 66 f4 89 12 1b 52 ab 97 78 a5 e4 83 35 7b 8c ba Aug 26 13:10:28.799440: | 91 4a 3c 78 bf 27 ba 51 59 78 2f 4b 59 79 14 30 Aug 26 13:10:28.799441: | 63 3f 42 23 99 e4 5e a0 72 d6 5a 6c 54 4a f0 2a Aug 26 13:10:28.799443: | 6f 45 53 98 4b 85 96 ce eb 85 ce fa 0a b1 76 0b Aug 26 13:10:28.799444: | 92 5a 4e 0c 3c a0 4d cc 8f f6 a2 4e e0 94 a7 1c Aug 26 13:10:28.799446: | c4 2f fa 97 1d 27 87 8f 60 e4 6b 8b 47 5a da c3 Aug 26 13:10:28.799447: | 0d 27 b0 31 67 e2 43 76 e0 79 c2 ad 7a cc 1f 41 Aug 26 13:10:28.799449: | dd 45 55 c1 76 f5 b8 17 ac 0b 75 d8 6d 1c f6 6f Aug 26 13:10:28.799450: | 94 ff b6 69 46 5f 91 d6 0d 51 a3 11 44 bd d8 83 Aug 26 13:10:28.799452: | b3 0d 06 7b b2 d8 57 36 da ca 19 7a 91 59 e2 ab Aug 26 13:10:28.799453: | 43 04 de b7 41 f9 27 e2 ec 66 5f 39 28 24 d1 6a Aug 26 13:10:28.799455: | 77 28 86 d4 cf d6 5f 19 8d 18 dd 0a 7e af 23 84 Aug 26 13:10:28.799459: | 72 d0 d4 0e 3b 80 cd 82 90 1d 76 69 9b 63 e6 be Aug 26 13:10:28.799460: | be e0 e2 e9 71 f6 4c bf 00 d6 28 bf a1 21 8a 7f Aug 26 13:10:28.799462: | aa 7a 44 25 4f 21 85 6e 27 5d 4e 05 45 14 d7 e9 Aug 26 13:10:28.799463: | 0e 19 d5 29 e9 6a d1 bd 3f b0 0b 9e 11 6a d8 a1 Aug 26 13:10:28.799465: | 1f 36 e2 08 f8 dc 75 bb ce ac 16 40 92 b6 a6 65 Aug 26 13:10:28.799467: | 7b 8b 3f 55 2b 2c ed d3 d8 0a fe 6b 71 f1 0e 08 Aug 26 13:10:28.799470: | fe 0d a8 5f c1 26 e9 5f ba 7f db 63 40 b2 74 20 Aug 26 13:10:28.799472: | ec 06 74 f7 e2 ea 58 83 fe 90 0b eb 53 e6 63 21 Aug 26 13:10:28.799474: | ff da 69 9a 2d 2b 23 ee 6b f2 50 69 54 d9 bd 4f Aug 26 13:10:28.799477: | 0b 5b e1 3e ab f7 5b 9e 7c 6e 55 29 70 5e f3 dc Aug 26 13:10:28.799479: | 42 8e 12 b6 3f a3 74 c8 bd 22 f5 cc 17 16 56 c9 Aug 26 13:10:28.799482: | 3f dc 2b 88 11 e2 e0 da 28 fe 17 d0 84 3f 98 3e Aug 26 13:10:28.799484: | 90 cc 76 04 05 a9 81 58 36 1d da d1 27 0b 67 0d Aug 26 13:10:28.799487: | 4c 2f 5e f4 38 ce 13 7d b3 4f 76 6c 27 8a 4a 84 Aug 26 13:10:28.799490: | 4d 75 fa 68 62 a2 f4 0f db 61 c5 3a 44 18 d9 d5 Aug 26 13:10:28.799851: | libevent_free: release ptr-libevent@0x7f046800a868 Aug 26 13:10:28.799856: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e277716ea8 Aug 26 13:10:28.799862: | #2 spent 0.504 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:28.799866: | stop processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:29.225618: | spent 0.00282 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() Aug 26 13:10:29.225637: | *received 464 bytes from 192.1.3.33:500 on eth1 (192.1.2.23:500) Aug 26 13:10:29.225640: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.225642: | 2e 20 23 20 00 00 00 01 00 00 01 d0 24 00 01 b4 Aug 26 13:10:29.225644: | d5 c9 98 85 fb c1 5d de 0a 87 45 67 58 93 83 c2 Aug 26 13:10:29.225645: | 87 a0 ea 17 f0 fb 24 be d8 e6 39 d6 3f 13 8a 02 Aug 26 13:10:29.225647: | 79 2a 6f a0 30 12 71 ba 0e 7c 9a 28 2a 5e 54 e1 Aug 26 13:10:29.225649: | fa 4a 0f 96 78 c9 24 da 04 23 b2 f7 96 9a 80 af Aug 26 13:10:29.225650: | 5b 04 3e 55 fb 00 1b e8 ae 05 87 dc 66 8b 77 d8 Aug 26 13:10:29.225652: | 51 13 4f c4 82 d3 01 11 94 77 54 8d 42 47 d4 3d Aug 26 13:10:29.225653: | 73 db 68 1a bf 8b 9a 19 14 59 08 ce 6b 0d 5f 06 Aug 26 13:10:29.225655: | fe d5 eb 58 6a 7e 9c d4 d0 4f e3 f3 0a 67 49 a7 Aug 26 13:10:29.225656: | 76 b1 bb a5 cc 5d 35 36 d9 6b 37 76 1e 42 75 24 Aug 26 13:10:29.225658: | 5e ed 2d 3e 7c bd f0 73 aa 78 fb c5 4a b7 b3 45 Aug 26 13:10:29.225660: | c7 2d 96 96 b0 38 ec 25 3a 79 c6 60 ca f8 77 83 Aug 26 13:10:29.225661: | c5 4a 28 4b 98 c4 ae 48 09 9f 58 b2 96 b4 3a 60 Aug 26 13:10:29.225663: | 46 91 ff 4c 49 21 58 aa 69 a5 1b 36 95 26 cc 09 Aug 26 13:10:29.225664: | 76 48 ff f5 3c 1f 80 8b ab 94 f5 27 0c db ef 73 Aug 26 13:10:29.225666: | c5 23 ec 1a eb 73 3e d1 70 eb f4 1d 38 1c 0f 20 Aug 26 13:10:29.225667: | 5f 46 f7 00 17 31 20 46 26 c8 4c 6e ae 8f 8a 76 Aug 26 13:10:29.225669: | 5a 7f 21 ad 15 5f bf 65 e1 0b 05 fd d2 d5 24 d2 Aug 26 13:10:29.225670: | 9c 93 e4 3a 09 13 75 ef 76 4f e1 41 ef b0 02 80 Aug 26 13:10:29.225672: | 69 b1 e3 3b 86 c0 7e 5d 33 17 ef 25 00 a6 22 dc Aug 26 13:10:29.225673: | f5 6f 9f b6 45 4a 16 d5 1e 2a fa 59 e9 67 e9 96 Aug 26 13:10:29.225675: | c4 34 54 99 a0 56 94 23 bd 28 7a ae df d0 46 a6 Aug 26 13:10:29.225676: | 4a 28 ef df b4 2e 57 be 23 3a 8b 55 a0 e7 64 a5 Aug 26 13:10:29.225678: | 0a 30 24 d4 de bc 96 c2 54 16 22 b5 28 45 e4 a7 Aug 26 13:10:29.225679: | 75 a0 f7 b4 5d 91 e6 47 77 3c 50 81 01 e6 be e9 Aug 26 13:10:29.225681: | 49 d3 2b da f3 be 8c 21 16 4d 86 98 a3 36 c8 d7 Aug 26 13:10:29.225682: | da 94 22 9b cd 49 78 cb 19 0a d0 83 e0 34 32 4e Aug 26 13:10:29.225684: | c3 82 70 74 d3 15 98 d5 23 90 ad 3f db da d3 e6 Aug 26 13:10:29.225687: | start processing: from 192.1.3.33:500 (in process_md() at demux.c:378) Aug 26 13:10:29.225692: | **parse ISAKMP Message: Aug 26 13:10:29.225694: | initiator cookie: Aug 26 13:10:29.225696: | 8b 87 d7 26 c3 30 6b 14 Aug 26 13:10:29.225697: | responder cookie: Aug 26 13:10:29.225699: | 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.225701: | next payload type: ISAKMP_NEXT_v2SK (0x2e) Aug 26 13:10:29.225703: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Aug 26 13:10:29.225705: | exchange type: ISAKMP_v2_IKE_AUTH (0x23) Aug 26 13:10:29.225706: | flags: ISAKMP_FLAG_v2_MSG_RESPONSE (0x20) Aug 26 13:10:29.225708: | Message ID: 1 (0x1) Aug 26 13:10:29.225710: | length: 464 (0x1d0) Aug 26 13:10:29.225712: | processing version=2.0 packet with exchange type=ISAKMP_v2_IKE_AUTH (35) Aug 26 13:10:29.225714: | I am the IKE SA Original Initiator receiving an IKEv2 IKE_AUTH response Aug 26 13:10:29.225718: | State DB: found IKEv2 state #1 in PARENT_I2 (find_v2_ike_sa) Aug 26 13:10:29.225722: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_process_packet() at ikev2.c:2016) Aug 26 13:10:29.225725: | State DB: found IKEv2 state #2 in PARENT_I2 (find_v2_sa_by_initiator_wip) Aug 26 13:10:29.225728: | suspend processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in ike_process_packet() at ikev2.c:2062) Aug 26 13:10:29.225731: | start processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in ike_process_packet() at ikev2.c:2062) Aug 26 13:10:29.225733: | #2 is idle Aug 26 13:10:29.225734: | #2 idle Aug 26 13:10:29.225736: | unpacking clear payload Aug 26 13:10:29.225738: | Now let's proceed with payload (ISAKMP_NEXT_v2SK) Aug 26 13:10:29.225740: | ***parse IKEv2 Encryption Payload: Aug 26 13:10:29.225742: | next payload type: ISAKMP_NEXT_v2IDr (0x24) Aug 26 13:10:29.225744: | flags: none (0x0) Aug 26 13:10:29.225745: | length: 436 (0x1b4) Aug 26 13:10:29.225747: | processing payload: ISAKMP_NEXT_v2SK (len=432) Aug 26 13:10:29.225749: | #2 in state PARENT_I2: sent v2I2, expected v2R2 Aug 26 13:10:29.225772: | data for hmac: 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.225775: | data for hmac: 2e 20 23 20 00 00 00 01 00 00 01 d0 24 00 01 b4 Aug 26 13:10:29.225777: | data for hmac: d5 c9 98 85 fb c1 5d de 0a 87 45 67 58 93 83 c2 Aug 26 13:10:29.225778: | data for hmac: 87 a0 ea 17 f0 fb 24 be d8 e6 39 d6 3f 13 8a 02 Aug 26 13:10:29.225780: | data for hmac: 79 2a 6f a0 30 12 71 ba 0e 7c 9a 28 2a 5e 54 e1 Aug 26 13:10:29.225781: | data for hmac: fa 4a 0f 96 78 c9 24 da 04 23 b2 f7 96 9a 80 af Aug 26 13:10:29.225783: | data for hmac: 5b 04 3e 55 fb 00 1b e8 ae 05 87 dc 66 8b 77 d8 Aug 26 13:10:29.225785: | data for hmac: 51 13 4f c4 82 d3 01 11 94 77 54 8d 42 47 d4 3d Aug 26 13:10:29.225786: | data for hmac: 73 db 68 1a bf 8b 9a 19 14 59 08 ce 6b 0d 5f 06 Aug 26 13:10:29.225788: | data for hmac: fe d5 eb 58 6a 7e 9c d4 d0 4f e3 f3 0a 67 49 a7 Aug 26 13:10:29.225790: | data for hmac: 76 b1 bb a5 cc 5d 35 36 d9 6b 37 76 1e 42 75 24 Aug 26 13:10:29.225791: | data for hmac: 5e ed 2d 3e 7c bd f0 73 aa 78 fb c5 4a b7 b3 45 Aug 26 13:10:29.225793: | data for hmac: c7 2d 96 96 b0 38 ec 25 3a 79 c6 60 ca f8 77 83 Aug 26 13:10:29.225795: | data for hmac: c5 4a 28 4b 98 c4 ae 48 09 9f 58 b2 96 b4 3a 60 Aug 26 13:10:29.225798: | data for hmac: 46 91 ff 4c 49 21 58 aa 69 a5 1b 36 95 26 cc 09 Aug 26 13:10:29.225800: | data for hmac: 76 48 ff f5 3c 1f 80 8b ab 94 f5 27 0c db ef 73 Aug 26 13:10:29.225803: | data for hmac: c5 23 ec 1a eb 73 3e d1 70 eb f4 1d 38 1c 0f 20 Aug 26 13:10:29.225805: | data for hmac: 5f 46 f7 00 17 31 20 46 26 c8 4c 6e ae 8f 8a 76 Aug 26 13:10:29.225807: | data for hmac: 5a 7f 21 ad 15 5f bf 65 e1 0b 05 fd d2 d5 24 d2 Aug 26 13:10:29.225808: | data for hmac: 9c 93 e4 3a 09 13 75 ef 76 4f e1 41 ef b0 02 80 Aug 26 13:10:29.225810: | data for hmac: 69 b1 e3 3b 86 c0 7e 5d 33 17 ef 25 00 a6 22 dc Aug 26 13:10:29.225811: | data for hmac: f5 6f 9f b6 45 4a 16 d5 1e 2a fa 59 e9 67 e9 96 Aug 26 13:10:29.225814: | data for hmac: c4 34 54 99 a0 56 94 23 bd 28 7a ae df d0 46 a6 Aug 26 13:10:29.225816: | data for hmac: 4a 28 ef df b4 2e 57 be 23 3a 8b 55 a0 e7 64 a5 Aug 26 13:10:29.225817: | data for hmac: 0a 30 24 d4 de bc 96 c2 54 16 22 b5 28 45 e4 a7 Aug 26 13:10:29.225819: | data for hmac: 75 a0 f7 b4 5d 91 e6 47 77 3c 50 81 01 e6 be e9 Aug 26 13:10:29.225821: | data for hmac: 49 d3 2b da f3 be 8c 21 16 4d 86 98 a3 36 c8 d7 Aug 26 13:10:29.225822: | data for hmac: da 94 22 9b cd 49 78 cb 19 0a d0 83 e0 34 32 4e Aug 26 13:10:29.225824: | calculated auth: c3 82 70 74 d3 15 98 d5 23 90 ad 3f db da d3 e6 Aug 26 13:10:29.225826: | provided auth: c3 82 70 74 d3 15 98 d5 23 90 ad 3f db da d3 e6 Aug 26 13:10:29.225827: | authenticator matched Aug 26 13:10:29.225834: | #2 ikev2 ISAKMP_v2_IKE_AUTH decrypt success Aug 26 13:10:29.225836: | Now let's proceed with payload (ISAKMP_NEXT_v2IDr) Aug 26 13:10:29.225839: | **parse IKEv2 Identification - Responder - Payload: Aug 26 13:10:29.225840: | next payload type: ISAKMP_NEXT_v2AUTH (0x27) Aug 26 13:10:29.225842: | flags: none (0x0) Aug 26 13:10:29.225844: | length: 13 (0xd) Aug 26 13:10:29.225845: | ID type: ID_FQDN (0x2) Aug 26 13:10:29.225847: | processing payload: ISAKMP_NEXT_v2IDr (len=5) Aug 26 13:10:29.225849: | Now let's proceed with payload (ISAKMP_NEXT_v2AUTH) Aug 26 13:10:29.225851: | **parse IKEv2 Authentication Payload: Aug 26 13:10:29.225852: | next payload type: ISAKMP_NEXT_v2SA (0x21) Aug 26 13:10:29.225854: | flags: none (0x0) Aug 26 13:10:29.225855: | length: 282 (0x11a) Aug 26 13:10:29.225857: | auth method: IKEv2_AUTH_RSA (0x1) Aug 26 13:10:29.225859: | processing payload: ISAKMP_NEXT_v2AUTH (len=274) Aug 26 13:10:29.225860: | Now let's proceed with payload (ISAKMP_NEXT_v2SA) Aug 26 13:10:29.225862: | **parse IKEv2 Security Association Payload: Aug 26 13:10:29.225863: | next payload type: ISAKMP_NEXT_v2TSi (0x2c) Aug 26 13:10:29.225865: | flags: none (0x0) Aug 26 13:10:29.225866: | length: 44 (0x2c) Aug 26 13:10:29.225868: | processing payload: ISAKMP_NEXT_v2SA (len=40) Aug 26 13:10:29.225870: | Now let's proceed with payload (ISAKMP_NEXT_v2TSi) Aug 26 13:10:29.225871: | **parse IKEv2 Traffic Selector - Initiator - Payload: Aug 26 13:10:29.225873: | next payload type: ISAKMP_NEXT_v2TSr (0x2d) Aug 26 13:10:29.225874: | flags: none (0x0) Aug 26 13:10:29.225876: | length: 24 (0x18) Aug 26 13:10:29.225877: | number of TS: 1 (0x1) Aug 26 13:10:29.225879: | processing payload: ISAKMP_NEXT_v2TSi (len=16) Aug 26 13:10:29.225881: | Now let's proceed with payload (ISAKMP_NEXT_v2TSr) Aug 26 13:10:29.225882: | **parse IKEv2 Traffic Selector - Responder - Payload: Aug 26 13:10:29.225884: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:29.225885: | flags: none (0x0) Aug 26 13:10:29.225887: | length: 24 (0x18) Aug 26 13:10:29.225888: | number of TS: 1 (0x1) Aug 26 13:10:29.225890: | processing payload: ISAKMP_NEXT_v2TSr (len=16) Aug 26 13:10:29.225892: | selected state microcode Initiator: process IKE_AUTH response Aug 26 13:10:29.225893: | Now let's proceed with state specific processing Aug 26 13:10:29.225895: | calling processor Initiator: process IKE_AUTH response Aug 26 13:10:29.225899: | offered CA: '%none' Aug 26 13:10:29.225902: "north-eastnets/0x1" #2: IKEv2 mode peer ID is ID_FQDN: '@north' Aug 26 13:10:29.225913: | verifying AUTH payload Aug 26 13:10:29.225923: | required RSA CA is '%any' Aug 26 13:10:29.225926: | checking RSA keyid '@east' for match with '@north' Aug 26 13:10:29.225928: | checking RSA keyid '@north' for match with '@north' Aug 26 13:10:29.225929: | key issuer CA is '%any' Aug 26 13:10:29.225970: | an RSA Sig check passed with *AQPl33O2P [preloaded key] Aug 26 13:10:29.225975: | #1 spent 0.042 milliseconds in try_all_RSA_keys() trying a pubkey Aug 26 13:10:29.225977: "north-eastnets/0x1" #2: Authenticated using RSA Aug 26 13:10:29.225980: | #1 spent 0.0633 milliseconds in ikev2_verify_rsa_hash() Aug 26 13:10:29.225986: | parent state #1: PARENT_I2(open IKE SA) => PARENT_I3(established IKE SA) Aug 26 13:10:29.225989: | #1 will start re-keying in 2607 seconds with margin of 993 seconds (attempting re-key) Aug 26 13:10:29.225991: | state #1 requesting EVENT_SA_REPLACE to be deleted Aug 26 13:10:29.225994: | libevent_free: release ptr-libevent@0x7f0470002888 Aug 26 13:10:29.225996: | free_event_entry: release EVENT_SA_REPLACE-pe@0x55e277714d28 Aug 26 13:10:29.225998: | event_schedule: new EVENT_SA_REKEY-pe@0x55e277714d28 Aug 26 13:10:29.226000: | inserting event EVENT_SA_REKEY, timeout in 2607 seconds for #1 Aug 26 13:10:29.226002: | libevent_malloc: new ptr-libevent@0x7f046800a868 size 128 Aug 26 13:10:29.226082: | pstats #1 ikev2.ike established Aug 26 13:10:29.226089: | TSi: parsing 1 traffic selectors Aug 26 13:10:29.226093: | ***parse IKEv2 Traffic Selector: Aug 26 13:10:29.226097: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Aug 26 13:10:29.226100: | IP Protocol ID: 0 (0x0) Aug 26 13:10:29.226102: | length: 16 (0x10) Aug 26 13:10:29.226105: | start port: 0 (0x0) Aug 26 13:10:29.226107: | end port: 65535 (0xffff) Aug 26 13:10:29.226110: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS low Aug 26 13:10:29.226112: | TS low c0 00 02 00 Aug 26 13:10:29.226115: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS high Aug 26 13:10:29.226117: | TS high c0 00 02 ff Aug 26 13:10:29.226120: | TSi: parsed 1 traffic selectors Aug 26 13:10:29.226122: | TSr: parsing 1 traffic selectors Aug 26 13:10:29.226124: | ***parse IKEv2 Traffic Selector: Aug 26 13:10:29.226127: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Aug 26 13:10:29.226130: | IP Protocol ID: 0 (0x0) Aug 26 13:10:29.226132: | length: 16 (0x10) Aug 26 13:10:29.226134: | start port: 0 (0x0) Aug 26 13:10:29.226136: | end port: 65535 (0xffff) Aug 26 13:10:29.226138: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS low Aug 26 13:10:29.226141: | TS low c0 00 03 00 Aug 26 13:10:29.226143: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS high Aug 26 13:10:29.226145: | TS high c0 00 03 ff Aug 26 13:10:29.226147: | TSr: parsed 1 traffic selectors Aug 26 13:10:29.226153: | evaluating our conn="north-eastnets/0x1" I=192.0.2.0/24:0/0 R=192.0.3.0/24:0/0 to their: Aug 26 13:10:29.226159: | TSi[0] .net=192.0.2.0-192.0.2.255 .iporotoid=0 .{start,end}port=0..65535 Aug 26 13:10:29.226164: | match address end->client=192.0.2.0/24 == TSi[0]net=192.0.2.0-192.0.2.255: YES fitness 32 Aug 26 13:10:29.226167: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Aug 26 13:10:29.226169: | TSi[0] port match: YES fitness 65536 Aug 26 13:10:29.226172: | narrow protocol end=*0 == TSi[0]=*0: 0 Aug 26 13:10:29.226175: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Aug 26 13:10:29.226178: | TSr[0] .net=192.0.3.0-192.0.3.255 .iporotoid=0 .{start,end}port=0..65535 Aug 26 13:10:29.226183: | match address end->client=192.0.3.0/24 == TSr[0]net=192.0.3.0-192.0.3.255: YES fitness 32 Aug 26 13:10:29.226186: | narrow port end=0..65535 == TSr[0]=0..65535: 0 Aug 26 13:10:29.226188: | TSr[0] port match: YES fitness 65536 Aug 26 13:10:29.226191: | narrow protocol end=*0 == TSr[0]=*0: 0 Aug 26 13:10:29.226194: | match end->protocol=*0 == TSr[0].ipprotoid=*0: YES fitness 255 Aug 26 13:10:29.226196: | best fit so far: TSi[0] TSr[0] Aug 26 13:10:29.226199: | found an acceptable TSi/TSr Traffic Selector Aug 26 13:10:29.226201: | printing contents struct traffic_selector Aug 26 13:10:29.226203: | ts_type: IKEv2_TS_IPV6_ADDR_RANGE Aug 26 13:10:29.226206: | ipprotoid: 0 Aug 26 13:10:29.226208: | port range: 0-65535 Aug 26 13:10:29.226212: | ip range: 192.0.2.0-192.0.2.255 Aug 26 13:10:29.226214: | printing contents struct traffic_selector Aug 26 13:10:29.226216: | ts_type: IKEv2_TS_IPV6_ADDR_RANGE Aug 26 13:10:29.226219: | ipprotoid: 0 Aug 26 13:10:29.226221: | port range: 0-65535 Aug 26 13:10:29.226225: | ip range: 192.0.3.0-192.0.3.255 Aug 26 13:10:29.226236: | using existing local ESP/AH proposals for north-eastnets/0x1 (IKE_AUTH initiator accepting remote ESP/AH proposal): 1:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;DH=NONE;ESN=DISABLED Aug 26 13:10:29.226240: | Comparing remote proposals against IKE_AUTH initiator accepting remote ESP/AH proposal 1 local proposals Aug 26 13:10:29.226243: | local proposal 1 type ENCR has 1 transforms Aug 26 13:10:29.226246: | local proposal 1 type PRF has 0 transforms Aug 26 13:10:29.226249: | local proposal 1 type INTEG has 1 transforms Aug 26 13:10:29.226251: | local proposal 1 type DH has 1 transforms Aug 26 13:10:29.226254: | local proposal 1 type ESN has 1 transforms Aug 26 13:10:29.226257: | local proposal 1 transforms: required: ENCR+INTEG+ESN; optional: DH Aug 26 13:10:29.226261: | ***parse IKEv2 Proposal Substructure Payload: Aug 26 13:10:29.226264: | last proposal: v2_PROPOSAL_LAST (0x0) Aug 26 13:10:29.226266: | length: 40 (0x28) Aug 26 13:10:29.226268: | prop #: 1 (0x1) Aug 26 13:10:29.226271: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Aug 26 13:10:29.226274: | spi size: 4 (0x4) Aug 26 13:10:29.226276: | # transforms: 3 (0x3) Aug 26 13:10:29.226279: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Aug 26 13:10:29.226282: | remote SPI 94 e2 35 67 Aug 26 13:10:29.226285: | Comparing remote proposal 1 containing 3 transforms against local proposal [1..1] of 1 local proposals Aug 26 13:10:29.226292: | ****parse IKEv2 Transform Substructure Payload: Aug 26 13:10:29.226312: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.226314: | length: 12 (0xc) Aug 26 13:10:29.226319: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Aug 26 13:10:29.226335: | IKEv2 transform ID: AES_CBC (0xc) Aug 26 13:10:29.226338: | *****parse IKEv2 Attribute Substructure Payload: Aug 26 13:10:29.226340: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Aug 26 13:10:29.226343: | length/value: 128 (0x80) Aug 26 13:10:29.226348: | remote proposal 1 transform 0 (ENCR=AES_CBC_128) matches local proposal 1 type 1 (ENCR) transform 0 Aug 26 13:10:29.226351: | ****parse IKEv2 Transform Substructure Payload: Aug 26 13:10:29.226354: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.226356: | length: 8 (0x8) Aug 26 13:10:29.226359: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Aug 26 13:10:29.226362: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Aug 26 13:10:29.226366: | remote proposal 1 transform 1 (INTEG=HMAC_SHA2_512_256) matches local proposal 1 type 3 (INTEG) transform 0 Aug 26 13:10:29.226368: | ****parse IKEv2 Transform Substructure Payload: Aug 26 13:10:29.226372: | last transform: v2_TRANSFORM_LAST (0x0) Aug 26 13:10:29.226374: | length: 8 (0x8) Aug 26 13:10:29.226377: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Aug 26 13:10:29.226380: | IKEv2 transform ID: ESN_DISABLED (0x0) Aug 26 13:10:29.226383: | remote proposal 1 transform 2 (ESN=DISABLED) matches local proposal 1 type 5 (ESN) transform 0 Aug 26 13:10:29.226387: | remote proposal 1 proposed transforms: ENCR+INTEG+ESN; matched: ENCR+INTEG+ESN; unmatched: none Aug 26 13:10:29.226392: | comparing remote proposal 1 containing ENCR+INTEG+ESN transforms to local proposal 1; required: ENCR+INTEG+ESN; optional: DH; matched: ENCR+INTEG+ESN Aug 26 13:10:29.226396: | remote proposal 1 matches local proposal 1 Aug 26 13:10:29.226399: | remote accepted the proposal 1:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;ESN=DISABLED[first-match] Aug 26 13:10:29.226405: | IKE_AUTH initiator accepting remote ESP/AH proposal ikev2_proposal: 1:ESP:SPI=94e23567;ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;ESN=DISABLED Aug 26 13:10:29.226408: | converting proposal to internal trans attrs Aug 26 13:10:29.226413: | integ=sha2_512: .key_size=64 encrypt=aes: .key_size=16 .salt_size=0 keymat_len=80 Aug 26 13:10:29.226721: | install_ipsec_sa() for #2: inbound and outbound Aug 26 13:10:29.226728: | could_route called for north-eastnets/0x1 (kind=CK_PERMANENT) Aug 26 13:10:29.226731: | FOR_EACH_CONNECTION_... in route_owner Aug 26 13:10:29.226737: | conn north-eastnets/0x1 mark 0/00000000, 0/00000000 vs Aug 26 13:10:29.226740: | conn north-eastnets/0x2 mark 0/00000000, 0/00000000 Aug 26 13:10:29.226742: | conn north-eastnets/0x1 mark 0/00000000, 0/00000000 vs Aug 26 13:10:29.226745: | conn north-eastnets/0x1 mark 0/00000000, 0/00000000 Aug 26 13:10:29.226749: | route owner of "north-eastnets/0x1" unrouted: NULL; eroute owner: NULL Aug 26 13:10:29.226753: | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA2_512_256 Aug 26 13:10:29.226757: | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 Aug 26 13:10:29.226760: | st->st_esp.keymat_len=80 is encrypt_keymat_size=16 + integ_keymat_size=64 Aug 26 13:10:29.226765: | setting IPsec SA replay-window to 32 Aug 26 13:10:29.226768: | NIC esp-hw-offload not for connection 'north-eastnets/0x1' not available on interface eth1 Aug 26 13:10:29.226771: | netlink: enabling tunnel mode Aug 26 13:10:29.226773: | netlink: setting IPsec SA replay-window to 32 using old-style req Aug 26 13:10:29.226776: | netlink: esp-hw-offload not set for IPsec SA Aug 26 13:10:29.226858: | netlink response for Add SA esp.94e23567@192.1.3.33 included non-error error Aug 26 13:10:29.226863: | set up outgoing SA, ref=0/0 Aug 26 13:10:29.226867: | looking for alg with encrypt: AES_CBC keylen: 128 integ: HMAC_SHA2_512_256 Aug 26 13:10:29.226870: | encrypt AES_CBC keylen=128 transid=12, key_size=16, encryptalg=12 Aug 26 13:10:29.226873: | st->st_esp.keymat_len=80 is encrypt_keymat_size=16 + integ_keymat_size=64 Aug 26 13:10:29.226877: | setting IPsec SA replay-window to 32 Aug 26 13:10:29.226880: | NIC esp-hw-offload not for connection 'north-eastnets/0x1' not available on interface eth1 Aug 26 13:10:29.226883: | netlink: enabling tunnel mode Aug 26 13:10:29.226886: | netlink: setting IPsec SA replay-window to 32 using old-style req Aug 26 13:10:29.226889: | netlink: esp-hw-offload not set for IPsec SA Aug 26 13:10:29.226927: | netlink response for Add SA esp.f3b8aff7@192.1.2.23 included non-error error Aug 26 13:10:29.226933: | priority calculation of connection "north-eastnets/0x1" is 0xfe7e7 Aug 26 13:10:29.226940: | add inbound eroute 192.0.3.0/24:0 --0-> 192.0.2.0/24:0 => tun.10000@192.1.2.23 (raw_eroute) Aug 26 13:10:29.226945: | IPsec Sa SPD priority set to 1042407 Aug 26 13:10:29.226972: | raw_eroute result=success Aug 26 13:10:29.226976: | set up incoming SA, ref=0/0 Aug 26 13:10:29.226979: | sr for #2: unrouted Aug 26 13:10:29.226982: | route_and_eroute() for proto 0, and source port 0 dest port 0 Aug 26 13:10:29.226985: | FOR_EACH_CONNECTION_... in route_owner Aug 26 13:10:29.226988: | conn north-eastnets/0x1 mark 0/00000000, 0/00000000 vs Aug 26 13:10:29.226992: | conn north-eastnets/0x2 mark 0/00000000, 0/00000000 Aug 26 13:10:29.226995: | conn north-eastnets/0x1 mark 0/00000000, 0/00000000 vs Aug 26 13:10:29.226998: | conn north-eastnets/0x1 mark 0/00000000, 0/00000000 Aug 26 13:10:29.227002: | route owner of "north-eastnets/0x1" unrouted: NULL; eroute owner: NULL Aug 26 13:10:29.227006: | route_and_eroute with c: north-eastnets/0x1 (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #2 Aug 26 13:10:29.227009: | priority calculation of connection "north-eastnets/0x1" is 0xfe7e7 Aug 26 13:10:29.227016: | eroute_connection add eroute 192.0.2.0/24:0 --0-> 192.0.3.0/24:0 => tun.0@192.1.3.33 (raw_eroute) Aug 26 13:10:29.227019: | IPsec Sa SPD priority set to 1042407 Aug 26 13:10:29.227032: | raw_eroute result=success Aug 26 13:10:29.227036: | running updown command "ipsec _updown" for verb up Aug 26 13:10:29.227039: | command executing up-client Aug 26 13:10:29.227066: | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-eastnets/0x1' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='@north' PLUTO_PEER_CLIENT='192.0.3.0/24' PLUTO_PEER_CLIENT_NET='192.0.3.0' PLUTO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0x9 Aug 26 13:10:29.227072: | popen cmd is 1041 chars long Aug 26 13:10:29.227075: | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-eastnets/0x1': Aug 26 13:10:29.227078: | cmd( 80): PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_: Aug 26 13:10:29.227081: | cmd( 160):MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' PLU: Aug 26 13:10:29.227083: | cmd( 240):TO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_: Aug 26 13:10:29.227086: | cmd( 320):SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='@nor: Aug 26 13:10:29.227089: | cmd( 400):th' PLUTO_PEER_CLIENT='192.0.3.0/24' PLUTO_PEER_CLIENT_NET='192.0.3.0' PLUTO_PEE: Aug 26 13:10:29.227091: | cmd( 480):R_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_: Aug 26 13:10:29.227094: | cmd( 560):PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCR: Aug 26 13:10:29.227097: | cmd( 640):YPT+TUNNEL+PFS+UP+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND: Aug 26 13:10:29.227100: | cmd( 720):='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO=: Aug 26 13:10:29.227102: | cmd( 800):'0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_: Aug 26 13:10:29.227105: | cmd( 880):CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROU: Aug 26 13:10:29.227108: | cmd( 960):TING='no' VTI_SHARED='no' SPI_IN=0x94e23567 SPI_OUT=0xf3b8aff7 ipsec _updown 2>&: Aug 26 13:10:29.227110: | cmd(1040):1: Aug 26 13:10:29.235065: | route_and_eroute: firewall_notified: true Aug 26 13:10:29.235077: | running updown command "ipsec _updown" for verb prepare Aug 26 13:10:29.235080: | command executing prepare-client Aug 26 13:10:29.235103: | executing prepare-client: PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-eastnets/0x1' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='@north' PLUTO_PEER_CLIENT='192.0.3.0/24' PLUTO_PEER_CLIENT_NET='192.0.3.0' PLUTO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' Aug 26 13:10:29.235105: | popen cmd is 1046 chars long Aug 26 13:10:29.235107: | cmd( 0):PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-eastnets: Aug 26 13:10:29.235109: | cmd( 80):/0x1' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' P: Aug 26 13:10:29.235111: | cmd( 160):LUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0: Aug 26 13:10:29.235113: | cmd( 240):' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' P: Aug 26 13:10:29.235114: | cmd( 320):LUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID=: Aug 26 13:10:29.235118: | cmd( 400):'@north' PLUTO_PEER_CLIENT='192.0.3.0/24' PLUTO_PEER_CLIENT_NET='192.0.3.0' PLUT: Aug 26 13:10:29.235120: | cmd( 480):O_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' P: Aug 26 13:10:29.235121: | cmd( 560):LUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG: Aug 26 13:10:29.235123: | cmd( 640):+ENCRYPT+TUNNEL+PFS+UP+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN: Aug 26 13:10:29.235125: | cmd( 720):_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_C: Aug 26 13:10:29.235126: | cmd( 800):ISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' P: Aug 26 13:10:29.235128: | cmd( 880):LUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VT: Aug 26 13:10:29.235130: | cmd( 960):I_ROUTING='no' VTI_SHARED='no' SPI_IN=0x94e23567 SPI_OUT=0xf3b8aff7 ipsec _updow: Aug 26 13:10:29.235131: | cmd(1040):n 2>&1: Aug 26 13:10:29.242845: | running updown command "ipsec _updown" for verb route Aug 26 13:10:29.242859: | command executing route-client Aug 26 13:10:29.242881: | executing route-client: PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-eastnets/0x1' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='@north' PLUTO_PEER_CLIENT='192.0.3.0/24' PLUTO_PEER_CLIENT_NET='192.0.3.0' PLUTO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_ Aug 26 13:10:29.242884: | popen cmd is 1044 chars long Aug 26 13:10:29.242886: | cmd( 0):PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='north-eastnets/0: Aug 26 13:10:29.242888: | cmd( 80):x1' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.3.33' PLUTO_ME='192.1.2.23' PLU: Aug 26 13:10:29.242889: | cmd( 160):TO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' : Aug 26 13:10:29.242891: | cmd( 240):PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLU: Aug 26 13:10:29.242893: | cmd( 320):TO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.3.33' PLUTO_PEER_ID='@: Aug 26 13:10:29.242894: | cmd( 400):north' PLUTO_PEER_CLIENT='192.0.3.0/24' PLUTO_PEER_CLIENT_NET='192.0.3.0' PLUTO_: Aug 26 13:10:29.242896: | cmd( 480):PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: Aug 26 13:10:29.242898: | cmd( 560):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='RSASIG+E: Aug 26 13:10:29.242899: | cmd( 640):NCRYPT+TUNNEL+PFS+UP+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_K: Aug 26 13:10:29.242901: | cmd( 720):IND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CIS: Aug 26 13:10:29.242902: | cmd( 800):CO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLU: Aug 26 13:10:29.242904: | cmd( 880):TO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_: Aug 26 13:10:29.242906: | cmd( 960):ROUTING='no' VTI_SHARED='no' SPI_IN=0x94e23567 SPI_OUT=0xf3b8aff7 ipsec _updown : Aug 26 13:10:29.242907: | cmd(1040):2>&1: Aug 26 13:10:29.253278: | route_and_eroute: instance "north-eastnets/0x1", setting eroute_owner {spd=0x55e2777142d8,sr=0x55e2777142d8} to #2 (was #0) (newest_ipsec_sa=#0) Aug 26 13:10:29.253376: | #1 spent 1.84 milliseconds in install_ipsec_sa() Aug 26 13:10:29.253385: | inR2: instance north-eastnets/0x1[0], setting IKEv2 newest_ipsec_sa to #2 (was #0) (spd.eroute=#2) cloned from #1 Aug 26 13:10:29.253388: | state #2 requesting EVENT_RETRANSMIT to be deleted Aug 26 13:10:29.253393: | #2 STATE_PARENT_I2: retransmits: cleared Aug 26 13:10:29.253406: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:10:29.253412: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:29.253419: | #2 spent 2.7 milliseconds in processing: Initiator: process IKE_AUTH response in ikev2_process_state_packet() Aug 26 13:10:29.253427: | [RE]START processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in complete_v2_state_transition() at ikev2.c:3379) Aug 26 13:10:29.253431: | #2 complete_v2_state_transition() PARENT_I2->V2_IPSEC_I with status STF_OK Aug 26 13:10:29.253435: | IKEv2: transition from state STATE_PARENT_I2 to state STATE_V2_IPSEC_I Aug 26 13:10:29.253438: | child state #2: PARENT_I2(open IKE SA) => V2_IPSEC_I(established CHILD SA) Aug 26 13:10:29.253442: | Message ID: updating counters for #2 to 1 after switching state Aug 26 13:10:29.253448: | Message ID: recv #1.#2 response 1; ike: initiator.sent=1 initiator.recv=0->1 responder.sent=-1 responder.recv=-1; child: wip.initiator=1->-1 wip.responder=-1 Aug 26 13:10:29.253453: | Message ID: #1.#2 skipping update_send as nothing to send; initiator.sent=1 initiator.recv=1 responder.sent=-1 responder.recv=-1 wip.initiator=-1 wip.responder=-1 Aug 26 13:10:29.253456: | pstats #2 ikev2.child established Aug 26 13:10:29.253466: "north-eastnets/0x1" #2: negotiated connection [192.0.2.0-192.0.2.255:0-65535 0] -> [192.0.3.0-192.0.3.255:0-65535 0] Aug 26 13:10:29.253471: | NAT-T: encaps is 'auto' Aug 26 13:10:29.253476: "north-eastnets/0x1" #2: STATE_V2_IPSEC_I: IPsec SA established tunnel mode {ESP=>0x94e23567 <0xf3b8aff7 xfrm=AES_CBC_128-HMAC_SHA2_512_256 NATOA=none NATD=none DPD=passive} Aug 26 13:10:29.253479: | releasing whack for #2 (sock=fd@-1) Aug 26 13:10:29.253482: | releasing whack and unpending for parent #1 Aug 26 13:10:29.253485: | unpending state #1 connection "north-eastnets/0x1" Aug 26 13:10:29.253492: | delete from pending Child SA with 192.1.3.33 "north-eastnets/0x1" Aug 26 13:10:29.253495: | removing pending policy for no connection {0x55e27766c898} Aug 26 13:10:29.253500: | FOR_EACH_STATE_... in find_pending_phase2 Aug 26 13:10:29.253510: | creating state object #3 at 0x55e277719c38 Aug 26 13:10:29.253513: | State DB: adding IKEv2 state #3 in UNDEFINED Aug 26 13:10:29.253524: | pstats #3 ikev2.child started Aug 26 13:10:29.253528: | duplicating state object #1 "north-eastnets/0x2" as #3 for IPSEC SA Aug 26 13:10:29.253534: | #3 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1484) Aug 26 13:10:29.253546: | Message ID: init_child #1.#3; ike: initiator.sent=1 initiator.recv=1 responder.sent=-1 responder.recv=-1; child: wip.initiator=0->-1 wip.responder=0->-1 Aug 26 13:10:29.253552: | suspend processing: state #2 connection "north-eastnets/0x1" from 192.1.3.33 (in ikev2_initiate_child_sa() at ikev2_parent.c:5637) Aug 26 13:10:29.253557: | start processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_initiate_child_sa() at ikev2_parent.c:5637) Aug 26 13:10:29.253561: | child state #3: UNDEFINED(ignore) => V2_CREATE_I0(established IKE SA) Aug 26 13:10:29.253564: | create child proposal's DH changed from no-PFS to MODP2048, flushing Aug 26 13:10:29.253569: | constructing ESP/AH proposals with default DH MODP2048 for north-eastnets/0x2 (ESP/AH initiator emitting proposals) Aug 26 13:10:29.253575: | converting proposal AES_CBC_128-HMAC_SHA2_512_256-MODP3072 to ikev2 ... Aug 26 13:10:29.253582: | ... ikev2_proposal: 1:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;DH=MODP3072;ESN=DISABLED Aug 26 13:10:29.253587: "north-eastnets/0x2": constructed local ESP/AH proposals for north-eastnets/0x2 (ESP/AH initiator emitting proposals): 1:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;DH=MODP3072;ESN=DISABLED Aug 26 13:10:29.253597: | #3 schedule initiate IPsec SA RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO using IKE# 1 pfs=MODP3072 Aug 26 13:10:29.253601: | event_schedule: new EVENT_v2_INITIATE_CHILD-pe@0x7f0470002b78 Aug 26 13:10:29.253605: | inserting event EVENT_v2_INITIATE_CHILD, timeout in 0 seconds for #3 Aug 26 13:10:29.253609: | libevent_malloc: new ptr-libevent@0x55e277719b88 size 128 Aug 26 13:10:29.253614: | RESET processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in ikev2_initiate_child_sa() at ikev2_parent.c:5737) Aug 26 13:10:29.253618: | RESET processing: from 192.1.3.33:500 (in ikev2_initiate_child_sa() at ikev2_parent.c:5737) Aug 26 13:10:29.253622: | delete from pending Child SA with 192.1.3.33 "north-eastnets/0x2" Aug 26 13:10:29.253625: | removing pending policy for no connection {0x55e2777061e8} Aug 26 13:10:29.253629: | #2 will start re-keying in 28048 seconds with margin of 752 seconds (attempting re-key) Aug 26 13:10:29.253632: | event_schedule: new EVENT_SA_REKEY-pe@0x55e277716ea8 Aug 26 13:10:29.253635: | inserting event EVENT_SA_REKEY, timeout in 28048 seconds for #2 Aug 26 13:10:29.253638: | libevent_malloc: new ptr-libevent@0x55e27771c998 size 128 Aug 26 13:10:29.253642: | processing: STOP state #0 (in ikev2_process_packet() at ikev2.c:2018) Aug 26 13:10:29.253647: | #1 spent 3.2 milliseconds in ikev2_process_packet() Aug 26 13:10:29.253653: | processing: STOP state #0 (in process_md() at demux.c:382) Aug 26 13:10:29.253656: | processing: STOP connection NULL (in process_md() at demux.c:383) Aug 26 13:10:29.253661: | spent 3.21 milliseconds in comm_handle_cb() reading and processing packet Aug 26 13:10:29.253674: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:29.253678: | handling event EVENT_v2_INITIATE_CHILD for child state #3 Aug 26 13:10:29.253683: | start processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:29.253690: | adding Child Initiator KE and nonce ni work-order 3 for state #3 Aug 26 13:10:29.253693: | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x55e27771c4c8 Aug 26 13:10:29.253697: | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #3 Aug 26 13:10:29.253700: | libevent_malloc: new ptr-libevent@0x55e2777150a8 size 128 Aug 26 13:10:29.253707: | libevent_free: release ptr-libevent@0x55e277719b88 Aug 26 13:10:29.253712: | free_event_entry: release EVENT_v2_INITIATE_CHILD-pe@0x7f0470002b78 Aug 26 13:10:29.253717: | #3 spent 0.0424 milliseconds in timer_event_cb() EVENT_v2_INITIATE_CHILD Aug 26 13:10:29.253722: | stop processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:29.253726: | processing signal PLUTO_SIGCHLD Aug 26 13:10:29.253731: | waitpid returned ECHILD (no child processes left) Aug 26 13:10:29.253736: | spent 0.00554 milliseconds in signal handler PLUTO_SIGCHLD Aug 26 13:10:29.253739: | processing signal PLUTO_SIGCHLD Aug 26 13:10:29.253743: | waitpid returned ECHILD (no child processes left) Aug 26 13:10:29.253743: | crypto helper 6 resuming Aug 26 13:10:29.253756: | crypto helper 6 starting work-order 3 for state #3 Aug 26 13:10:29.253747: | spent 0.00457 milliseconds in signal handler PLUTO_SIGCHLD Aug 26 13:10:29.253761: | crypto helper 6 doing build KE and nonce (Child Initiator KE and nonce ni); request ID 3 Aug 26 13:10:29.253768: | processing signal PLUTO_SIGCHLD Aug 26 13:10:29.253774: | waitpid returned ECHILD (no child processes left) Aug 26 13:10:29.253779: | spent 0.00474 milliseconds in signal handler PLUTO_SIGCHLD Aug 26 13:10:29.255397: | crypto helper 6 finished build KE and nonce (Child Initiator KE and nonce ni); request ID 3 time elapsed 0.001635 seconds Aug 26 13:10:29.255407: | (#3) spent 1.62 milliseconds in crypto helper computing work-order 3: Child Initiator KE and nonce ni (pcr) Aug 26 13:10:29.255409: | crypto helper 6 sending results from work-order 3 for state #3 to event queue Aug 26 13:10:29.255412: | scheduling resume sending helper answer for #3 Aug 26 13:10:29.255416: | libevent_malloc: new ptr-libevent@0x7f046c001b78 size 128 Aug 26 13:10:29.255418: | libevent_realloc: release ptr-libevent@0x55e2776f5408 Aug 26 13:10:29.255420: | libevent_realloc: new ptr-libevent@0x7f046c001ac8 size 128 Aug 26 13:10:29.255440: | crypto helper 6 waiting (nothing to do) Aug 26 13:10:29.255447: | processing resume sending helper answer for #3 Aug 26 13:10:29.255456: | start processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in resume_handler() at server.c:797) Aug 26 13:10:29.255473: | crypto helper 6 replies to request ID 3 Aug 26 13:10:29.255476: | calling continuation function 0x55e2755a6b50 Aug 26 13:10:29.255480: | ikev2_child_outI_continue for #3 STATE_V2_CREATE_I0 Aug 26 13:10:29.255483: | state #3 requesting EVENT_CRYPTO_TIMEOUT to be deleted Aug 26 13:10:29.255486: | libevent_free: release ptr-libevent@0x55e2777150a8 Aug 26 13:10:29.255489: | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x55e27771c4c8 Aug 26 13:10:29.255492: | event_schedule: new EVENT_SA_REPLACE-pe@0x55e27771c4c8 Aug 26 13:10:29.255496: | inserting event EVENT_SA_REPLACE, timeout in 200 seconds for #3 Aug 26 13:10:29.255499: | libevent_malloc: new ptr-libevent@0x55e2777150a8 size 128 Aug 26 13:10:29.255504: | Message ID: #1 wakeing IKE SA (unack 0); initiator.sent=1 initiator.recv=1 responder.sent=-1 responder.recv=-1 wip.initiator=-1 wip.responder=-1 Aug 26 13:10:29.255507: | scheduling callback v2_msgid_schedule_next_initiator (#1) Aug 26 13:10:29.255510: | libevent_malloc: new ptr-libevent@0x55e277719b88 size 128 Aug 26 13:10:29.255515: | [RE]START processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in complete_v2_state_transition() at ikev2.c:3379) Aug 26 13:10:29.255518: | #3 complete_v2_state_transition() V2_CREATE_I0->V2_CREATE_I with status STF_SUSPEND Aug 26 13:10:29.255521: | suspending state #3 and saving MD Aug 26 13:10:29.255523: | #3 is busy; has a suspended MD Aug 26 13:10:29.255528: | [RE]START processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in log_stf_suspend() at ikev2.c:3269) Aug 26 13:10:29.255531: | "north-eastnets/0x2" #3 complete v2 state STATE_V2_CREATE_I0 transition with STF_SUSPEND suspended from complete_v2_state_transition:3451 Aug 26 13:10:29.255535: | resume sending helper answer for #3 suppresed complete_v2_state_transition() Aug 26 13:10:29.255539: | #3 spent 0.0651 milliseconds in resume sending helper answer Aug 26 13:10:29.255544: | stop processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in resume_handler() at server.c:833) Aug 26 13:10:29.255547: | libevent_free: release ptr-libevent@0x7f046c001b78 Aug 26 13:10:29.255551: | processing callback v2_msgid_schedule_next_initiator for #1 Aug 26 13:10:29.255555: | start processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in callback_handler() at server.c:904) Aug 26 13:10:29.255560: | Message ID: #1.#3 resuming SA using IKE SA (unack 0); initiator.sent=1 initiator.recv=1 responder.sent=-1 responder.recv=-1 wip.initiator=-1 wip.responder=-1 Aug 26 13:10:29.255565: | suspend processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in initiate_next() at ikev2_msgid.c:553) Aug 26 13:10:29.255569: | start processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in initiate_next() at ikev2_msgid.c:553) Aug 26 13:10:29.255592: | **emit ISAKMP Message: Aug 26 13:10:29.255595: | initiator cookie: Aug 26 13:10:29.255598: | 8b 87 d7 26 c3 30 6b 14 Aug 26 13:10:29.255600: | responder cookie: Aug 26 13:10:29.255602: | 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.255605: | next payload type: ISAKMP_NEXT_NONE (0x0) Aug 26 13:10:29.255608: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Aug 26 13:10:29.255611: | exchange type: ISAKMP_v2_CREATE_CHILD_SA (0x24) Aug 26 13:10:29.255614: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Aug 26 13:10:29.255617: | Message ID: 2 (0x2) Aug 26 13:10:29.255620: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Aug 26 13:10:29.255625: | ***emit IKEv2 Encryption Payload: Aug 26 13:10:29.255628: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:29.255630: | flags: none (0x0) Aug 26 13:10:29.255633: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Encryption Payload (46:ISAKMP_NEXT_v2SK) Aug 26 13:10:29.255636: | next payload chain: saving location 'IKEv2 Encryption Payload'.'next payload type' in 'reply packet' Aug 26 13:10:29.255639: | emitting 16 zero bytes of IV into IKEv2 Encryption Payload Aug 26 13:10:29.255660: | netlink_get_spi: allocated 0xe5ad0a34 for esp.0@192.1.2.23 Aug 26 13:10:29.255663: | Emitting ikev2_proposals ... Aug 26 13:10:29.255666: | ****emit IKEv2 Security Association Payload: Aug 26 13:10:29.255669: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:29.255671: | flags: none (0x0) Aug 26 13:10:29.255674: | next payload chain: setting previous 'IKEv2 Encryption Payload'.'next payload type' to current IKEv2 Security Association Payload (33:ISAKMP_NEXT_v2SA) Aug 26 13:10:29.255677: | next payload chain: saving location 'IKEv2 Security Association Payload'.'next payload type' in 'reply packet' Aug 26 13:10:29.255680: | *****emit IKEv2 Proposal Substructure Payload: Aug 26 13:10:29.255683: | last proposal: v2_PROPOSAL_LAST (0x0) Aug 26 13:10:29.255685: | prop #: 1 (0x1) Aug 26 13:10:29.255688: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Aug 26 13:10:29.255690: | spi size: 4 (0x4) Aug 26 13:10:29.255693: | # transforms: 4 (0x4) Aug 26 13:10:29.255696: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Aug 26 13:10:29.255699: | emitting 4 raw bytes of our spi into IKEv2 Proposal Substructure Payload Aug 26 13:10:29.255701: | our spi e5 ad 0a 34 Aug 26 13:10:29.255704: | ******emit IKEv2 Transform Substructure Payload: Aug 26 13:10:29.255706: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.255709: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Aug 26 13:10:29.255712: | IKEv2 transform ID: AES_CBC (0xc) Aug 26 13:10:29.255715: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:10:29.255718: | *******emit IKEv2 Attribute Substructure Payload: Aug 26 13:10:29.255720: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Aug 26 13:10:29.255723: | length/value: 128 (0x80) Aug 26 13:10:29.255726: | emitting length of IKEv2 Transform Substructure Payload: 12 Aug 26 13:10:29.255728: | ******emit IKEv2 Transform Substructure Payload: Aug 26 13:10:29.255731: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.255733: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Aug 26 13:10:29.255736: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Aug 26 13:10:29.255739: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.255742: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:10:29.255745: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:10:29.255747: | ******emit IKEv2 Transform Substructure Payload: Aug 26 13:10:29.255750: | last transform: v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.255752: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Aug 26 13:10:29.255755: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Aug 26 13:10:29.255758: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.255760: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:10:29.255763: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:10:29.255766: | ******emit IKEv2 Transform Substructure Payload: Aug 26 13:10:29.255770: | last transform: v2_TRANSFORM_LAST (0x0) Aug 26 13:10:29.255772: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Aug 26 13:10:29.255775: | IKEv2 transform ID: ESN_DISABLED (0x0) Aug 26 13:10:29.255778: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Aug 26 13:10:29.255780: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Aug 26 13:10:29.255783: | emitting length of IKEv2 Transform Substructure Payload: 8 Aug 26 13:10:29.255786: | emitting length of IKEv2 Proposal Substructure Payload: 48 Aug 26 13:10:29.255788: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Aug 26 13:10:29.255791: | emitting length of IKEv2 Security Association Payload: 52 Aug 26 13:10:29.255794: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is 0 Aug 26 13:10:29.255796: | ****emit IKEv2 Nonce Payload: Aug 26 13:10:29.255799: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:29.255801: | flags: none (0x0) Aug 26 13:10:29.255804: | next payload chain: setting previous 'IKEv2 Security Association Payload'.'next payload type' to current IKEv2 Nonce Payload (40:ISAKMP_NEXT_v2Ni) Aug 26 13:10:29.255807: | next payload chain: saving location 'IKEv2 Nonce Payload'.'next payload type' in 'reply packet' Aug 26 13:10:29.255810: | emitting 32 raw bytes of IKEv2 nonce into IKEv2 Nonce Payload Aug 26 13:10:29.255813: | IKEv2 nonce de 6c 27 d0 a6 28 94 75 1e f1 c0 3f 99 1a df ac Aug 26 13:10:29.255815: | IKEv2 nonce 47 6e c0 24 99 9d 33 d5 4d b0 1a 4c 51 99 49 b3 Aug 26 13:10:29.255818: | emitting length of IKEv2 Nonce Payload: 36 Aug 26 13:10:29.255820: | ****emit IKEv2 Key Exchange Payload: Aug 26 13:10:29.255823: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:29.255825: | flags: none (0x0) Aug 26 13:10:29.255828: | DH group: OAKLEY_GROUP_MODP3072 (0xf) Aug 26 13:10:29.255831: | next payload chain: setting previous 'IKEv2 Nonce Payload'.'next payload type' to current IKEv2 Key Exchange Payload (34:ISAKMP_NEXT_v2KE) Aug 26 13:10:29.255834: | next payload chain: saving location 'IKEv2 Key Exchange Payload'.'next payload type' in 'reply packet' Aug 26 13:10:29.255837: | emitting 384 raw bytes of ikev2 g^x into IKEv2 Key Exchange Payload Aug 26 13:10:29.255839: | ikev2 g^x 77 98 d2 54 11 68 24 3e a3 e6 7d 32 a3 ad bc 0c Aug 26 13:10:29.255842: | ikev2 g^x 20 20 92 1a ad ed ea 73 bb ba fa 07 41 0f d1 65 Aug 26 13:10:29.255844: | ikev2 g^x a2 1a cc d5 fb a9 84 00 97 de e7 32 e7 d9 37 d9 Aug 26 13:10:29.255846: | ikev2 g^x 28 14 54 2f 11 67 4a c3 ed d3 d6 ef 03 10 26 b6 Aug 26 13:10:29.255849: | ikev2 g^x 60 0a c6 2a 6b e3 6e 70 f4 73 b5 43 68 64 25 12 Aug 26 13:10:29.255851: | ikev2 g^x c0 81 48 b4 b5 e5 97 0e b0 d9 37 00 e4 cd 1e a7 Aug 26 13:10:29.255853: | ikev2 g^x 1d 29 d5 0b ee f2 c7 c3 71 45 f1 6b 0e 43 54 d6 Aug 26 13:10:29.255856: | ikev2 g^x 9a d6 00 9e 3f 49 bd 00 1a 1e bf 20 f6 b6 79 5e Aug 26 13:10:29.255858: | ikev2 g^x dc 67 31 14 73 e7 53 1f 05 eb 12 19 65 b5 62 bd Aug 26 13:10:29.255861: | ikev2 g^x 62 0a a9 5a 71 7c 6a 38 6e e8 98 01 e1 2d 90 43 Aug 26 13:10:29.255863: | ikev2 g^x a1 08 e6 f4 c9 f5 51 5c 9b 90 72 d2 54 fd bb 4a Aug 26 13:10:29.255865: | ikev2 g^x de e4 40 5f 7d 82 9a ff 88 7d 09 80 47 39 b7 08 Aug 26 13:10:29.255868: | ikev2 g^x dd f2 5b 7e a7 65 4d 02 20 56 c3 00 b0 25 6a 99 Aug 26 13:10:29.255870: | ikev2 g^x 21 01 b9 85 16 97 5d 63 c4 fc 4a 7b 79 15 65 7f Aug 26 13:10:29.255872: | ikev2 g^x 2d db 08 1c 49 e8 9d 79 bf 9f 9f bf 8d 1c 1c 2d Aug 26 13:10:29.255875: | ikev2 g^x a7 d1 4e 42 b8 d0 14 b3 1b 9a eb 64 0e dd d3 ea Aug 26 13:10:29.255877: | ikev2 g^x ff f8 fa fb 10 d1 57 92 20 b5 6f aa cf bc d6 70 Aug 26 13:10:29.255880: | ikev2 g^x bb a9 40 bf f8 55 d4 fd a6 0a c6 4e 94 70 af 96 Aug 26 13:10:29.255883: | ikev2 g^x f3 e5 83 52 40 e4 ce 8d 15 3f b2 56 16 5a bd 38 Aug 26 13:10:29.255886: | ikev2 g^x 1b 29 02 ba ae 1d c3 8c bd f5 12 2d db 36 5d c9 Aug 26 13:10:29.255888: | ikev2 g^x 2e 6c 90 79 57 d5 5b ef d1 a4 c1 06 51 81 c4 a1 Aug 26 13:10:29.255890: | ikev2 g^x 5a 3e 89 af ae eb 81 d7 44 77 27 60 b6 cb ac 95 Aug 26 13:10:29.255893: | ikev2 g^x 9b 57 5b b1 c0 d9 e7 f4 84 21 18 3c b2 02 b6 e0 Aug 26 13:10:29.255895: | ikev2 g^x df 60 d2 d3 95 7a 61 39 00 27 4a dc 88 25 2b 44 Aug 26 13:10:29.255898: | emitting length of IKEv2 Key Exchange Payload: 392 Aug 26 13:10:29.255900: | ****emit IKEv2 Traffic Selector - Initiator - Payload: Aug 26 13:10:29.255903: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:29.255905: | flags: none (0x0) Aug 26 13:10:29.255908: | number of TS: 1 (0x1) Aug 26 13:10:29.255911: | next payload chain: setting previous 'IKEv2 Key Exchange Payload'.'next payload type' to current IKEv2 Traffic Selector - Initiator - Payload (44:ISAKMP_NEXT_v2TSi) Aug 26 13:10:29.255914: | next payload chain: saving location 'IKEv2 Traffic Selector - Initiator - Payload'.'next payload type' in 'reply packet' Aug 26 13:10:29.255916: | *****emit IKEv2 Traffic Selector: Aug 26 13:10:29.255919: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Aug 26 13:10:29.255922: | IP Protocol ID: 0 (0x0) Aug 26 13:10:29.255924: | start port: 0 (0x0) Aug 26 13:10:29.255926: | end port: 65535 (0xffff) Aug 26 13:10:29.255929: | emitting 4 raw bytes of ipv4 start into IKEv2 Traffic Selector Aug 26 13:10:29.255932: | ipv4 start c0 00 16 00 Aug 26 13:10:29.255934: | emitting 4 raw bytes of ipv4 end into IKEv2 Traffic Selector Aug 26 13:10:29.255937: | ipv4 end c0 00 16 ff Aug 26 13:10:29.255939: | emitting length of IKEv2 Traffic Selector: 16 Aug 26 13:10:29.255942: | emitting length of IKEv2 Traffic Selector - Initiator - Payload: 24 Aug 26 13:10:29.255944: | ****emit IKEv2 Traffic Selector - Responder - Payload: Aug 26 13:10:29.255947: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Aug 26 13:10:29.255949: | flags: none (0x0) Aug 26 13:10:29.255952: | number of TS: 1 (0x1) Aug 26 13:10:29.255955: | next payload chain: setting previous 'IKEv2 Traffic Selector - Initiator - Payload'.'next payload type' to current IKEv2 Traffic Selector - Responder - Payload (45:ISAKMP_NEXT_v2TSr) Aug 26 13:10:29.255958: | next payload chain: saving location 'IKEv2 Traffic Selector - Responder - Payload'.'next payload type' in 'reply packet' Aug 26 13:10:29.255960: | *****emit IKEv2 Traffic Selector: Aug 26 13:10:29.255963: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Aug 26 13:10:29.255965: | IP Protocol ID: 0 (0x0) Aug 26 13:10:29.255967: | start port: 0 (0x0) Aug 26 13:10:29.255970: | end port: 65535 (0xffff) Aug 26 13:10:29.255972: | emitting 4 raw bytes of ipv4 start into IKEv2 Traffic Selector Aug 26 13:10:29.255975: | ipv4 start c0 00 03 00 Aug 26 13:10:29.255977: | emitting 4 raw bytes of ipv4 end into IKEv2 Traffic Selector Aug 26 13:10:29.255980: | ipv4 end c0 00 03 ff Aug 26 13:10:29.255982: | emitting length of IKEv2 Traffic Selector: 16 Aug 26 13:10:29.255985: | emitting length of IKEv2 Traffic Selector - Responder - Payload: 24 Aug 26 13:10:29.255987: | Initiator child policy is tunnel mode, NOT sending v2N_USE_TRANSPORT_MODE Aug 26 13:10:29.255991: | adding 16 bytes of padding (including 1 byte padding-length) Aug 26 13:10:29.255994: | emitting 1 0x00 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.255997: | emitting 1 0x01 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.255999: | emitting 1 0x02 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256002: | emitting 1 0x03 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256005: | emitting 1 0x04 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256008: | emitting 1 0x05 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256012: | emitting 1 0x06 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256015: | emitting 1 0x07 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256017: | emitting 1 0x08 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256020: | emitting 1 0x09 repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256023: | emitting 1 0x0a repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256025: | emitting 1 0x0b repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256028: | emitting 1 0x0c repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256031: | emitting 1 0x0d repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256034: | emitting 1 0x0e repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256036: | emitting 1 0x0f repeated bytes of padding and length into IKEv2 Encryption Payload Aug 26 13:10:29.256039: | emitting 16 zero bytes of length of truncated HMAC/KEY into IKEv2 Encryption Payload Aug 26 13:10:29.256042: | emitting length of IKEv2 Encryption Payload: 580 Aug 26 13:10:29.256044: | emitting length of ISAKMP Message: 608 Aug 26 13:10:29.256084: | data being hmac: 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.256087: | data being hmac: 2e 20 24 08 00 00 00 02 00 00 02 60 21 00 02 44 Aug 26 13:10:29.256090: | data being hmac: 55 f1 3f bd 0e 8f 43 e3 a0 3d 85 75 24 df 4f 7b Aug 26 13:10:29.256092: | data being hmac: 97 f7 30 f0 32 7f eb 35 7d 79 b0 e8 c6 38 1d 31 Aug 26 13:10:29.256094: | data being hmac: a4 e7 58 fc 50 ae 3c ef 9c 97 61 b4 33 8a ee 5c Aug 26 13:10:29.256097: | data being hmac: 74 71 7a 77 49 0a 51 22 03 8a 87 0e 17 6a 35 fb Aug 26 13:10:29.256099: | data being hmac: 84 e8 18 3f 7e 1e ae 76 01 59 cd 45 ff 49 0b 26 Aug 26 13:10:29.256102: | data being hmac: ac 5d 14 de c0 24 b9 02 7d 74 4f 33 4b 14 f2 0b Aug 26 13:10:29.256104: | data being hmac: 24 f6 b7 98 57 e9 c8 d4 c9 2c bb 96 98 1e 37 d5 Aug 26 13:10:29.256107: | data being hmac: 19 ed 37 ac 04 27 63 fe e5 c9 df 2c d3 7b f2 25 Aug 26 13:10:29.256109: | data being hmac: 80 8e 5c 28 8e 1c 00 62 f4 54 51 53 55 1c 8f 7b Aug 26 13:10:29.256112: | data being hmac: 59 d8 4c 8b 0b 2f 5b 18 48 3c 23 4e 99 05 59 ab Aug 26 13:10:29.256114: | data being hmac: 82 58 d1 25 f0 de df 0e ac 18 d7 4c 7a 02 e6 98 Aug 26 13:10:29.256116: | data being hmac: ae b0 2e b2 0d 86 f0 50 85 21 21 a0 fd 64 bf 42 Aug 26 13:10:29.256119: | data being hmac: c1 2a ff a0 22 bb 58 c6 86 6e 92 2f ac da 3b e4 Aug 26 13:10:29.256121: | data being hmac: 3a eb a9 9e 21 3a 42 82 96 76 b8 bd 1b 22 e6 f3 Aug 26 13:10:29.256124: | data being hmac: 45 d2 61 37 79 38 37 6a e2 8b 7e 6d 05 2c 45 ad Aug 26 13:10:29.256126: | data being hmac: ec 82 48 0a 74 e8 f8 14 30 36 2d 99 39 6c 0d 6e Aug 26 13:10:29.256129: | data being hmac: a0 0a 35 ef 66 4a 59 06 50 a2 62 3c b6 d5 3c 4c Aug 26 13:10:29.256131: | data being hmac: 7d 14 28 6c 7e 8b da 8d ab 38 50 94 11 7a e5 c9 Aug 26 13:10:29.256133: | data being hmac: b1 2a 9f 44 8d 7e ab de b8 e0 5b 6e 77 1d 2b 47 Aug 26 13:10:29.256136: | data being hmac: 43 14 b1 d9 a6 e5 e7 73 85 a4 48 27 f3 fe fa b3 Aug 26 13:10:29.256138: | data being hmac: 68 3e 47 95 e5 a0 ab bb fc 82 9a 34 75 e5 63 92 Aug 26 13:10:29.256141: | data being hmac: 04 73 77 0f 19 89 80 ac 43 e7 7e 70 a1 51 b9 47 Aug 26 13:10:29.256143: | data being hmac: f6 d9 ae 23 9a 92 d9 f4 c8 fb 9a f4 e1 93 b9 07 Aug 26 13:10:29.256145: | data being hmac: d0 ea f4 bb dd af 3e a8 c4 ad a7 7a e8 45 67 7d Aug 26 13:10:29.256148: | data being hmac: 6e bc 74 8e 75 fd 7f aa 48 54 21 fe 26 83 ef cc Aug 26 13:10:29.256150: | data being hmac: 56 d2 e7 07 6f 45 05 98 74 50 48 56 d2 a5 61 a3 Aug 26 13:10:29.256153: | data being hmac: ef 6f fe 18 c0 6c cd c8 42 3e 85 8b 34 30 9d 2b Aug 26 13:10:29.256157: | data being hmac: d2 b6 f4 52 3f 45 42 31 d7 5e 86 c1 b1 5c eb da Aug 26 13:10:29.256159: | data being hmac: 32 30 77 44 45 b3 2d d4 be ed 85 1c b5 b8 2d b0 Aug 26 13:10:29.256162: | data being hmac: d4 60 6b 3c c8 58 cc 61 45 94 27 98 80 27 22 0c Aug 26 13:10:29.256164: | data being hmac: 37 8f f7 eb 68 b8 2b 82 52 0b 96 98 58 88 96 b6 Aug 26 13:10:29.256167: | data being hmac: 05 8c 1e ab 2f ee 65 ba a5 0e ea 30 6d 21 42 d7 Aug 26 13:10:29.256169: | data being hmac: 10 78 76 a6 ab 08 50 4b 66 bf bf 37 2c 39 a6 d9 Aug 26 13:10:29.256172: | data being hmac: 22 91 67 4a 7d 67 e0 43 7d 53 07 ec 61 8b bb d7 Aug 26 13:10:29.256174: | data being hmac: 5c 4d 07 be 61 13 85 93 32 2d 9b a2 19 54 d1 92 Aug 26 13:10:29.256176: | out calculated auth: Aug 26 13:10:29.256179: | 52 95 e0 a9 ef dd 2f df 7b 20 d2 78 d8 4a e6 ef Aug 26 13:10:29.256186: | [RE]START processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in complete_v2_state_transition() at ikev2.c:3379) Aug 26 13:10:29.256189: | #3 complete_v2_state_transition() V2_CREATE_I0->V2_CREATE_I with status STF_OK Aug 26 13:10:29.256192: | IKEv2: transition from state STATE_V2_CREATE_I0 to state STATE_V2_CREATE_I Aug 26 13:10:29.256196: | child state #3: V2_CREATE_I0(established IKE SA) => V2_CREATE_I(established IKE SA) Aug 26 13:10:29.256198: | Message ID: updating counters for #3 to 4294967295 after switching state Aug 26 13:10:29.256201: | Message ID: IKE #1 skipping update_recv as MD is fake Aug 26 13:10:29.256206: | Message ID: sent #1.#3 request 2; ike: initiator.sent=1->2 initiator.recv=1 responder.sent=-1 responder.recv=-1; child: wip.initiator=-1->2 wip.responder=-1 Aug 26 13:10:29.256209: "north-eastnets/0x2" #3: STATE_V2_CREATE_I: sent IPsec Child req wait response Aug 26 13:10:29.256214: | sending V2 reply packet to 192.1.3.33:500 (from 192.1.2.23:500) Aug 26 13:10:29.256221: | sending 608 bytes for STATE_V2_CREATE_I0 through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:29.256225: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.256227: | 2e 20 24 08 00 00 00 02 00 00 02 60 21 00 02 44 Aug 26 13:10:29.256230: | 55 f1 3f bd 0e 8f 43 e3 a0 3d 85 75 24 df 4f 7b Aug 26 13:10:29.256232: | 97 f7 30 f0 32 7f eb 35 7d 79 b0 e8 c6 38 1d 31 Aug 26 13:10:29.256234: | a4 e7 58 fc 50 ae 3c ef 9c 97 61 b4 33 8a ee 5c Aug 26 13:10:29.256237: | 74 71 7a 77 49 0a 51 22 03 8a 87 0e 17 6a 35 fb Aug 26 13:10:29.256239: | 84 e8 18 3f 7e 1e ae 76 01 59 cd 45 ff 49 0b 26 Aug 26 13:10:29.256242: | ac 5d 14 de c0 24 b9 02 7d 74 4f 33 4b 14 f2 0b Aug 26 13:10:29.256244: | 24 f6 b7 98 57 e9 c8 d4 c9 2c bb 96 98 1e 37 d5 Aug 26 13:10:29.256246: | 19 ed 37 ac 04 27 63 fe e5 c9 df 2c d3 7b f2 25 Aug 26 13:10:29.256249: | 80 8e 5c 28 8e 1c 00 62 f4 54 51 53 55 1c 8f 7b Aug 26 13:10:29.256251: | 59 d8 4c 8b 0b 2f 5b 18 48 3c 23 4e 99 05 59 ab Aug 26 13:10:29.256253: | 82 58 d1 25 f0 de df 0e ac 18 d7 4c 7a 02 e6 98 Aug 26 13:10:29.256256: | ae b0 2e b2 0d 86 f0 50 85 21 21 a0 fd 64 bf 42 Aug 26 13:10:29.256258: | c1 2a ff a0 22 bb 58 c6 86 6e 92 2f ac da 3b e4 Aug 26 13:10:29.256260: | 3a eb a9 9e 21 3a 42 82 96 76 b8 bd 1b 22 e6 f3 Aug 26 13:10:29.256263: | 45 d2 61 37 79 38 37 6a e2 8b 7e 6d 05 2c 45 ad Aug 26 13:10:29.256265: | ec 82 48 0a 74 e8 f8 14 30 36 2d 99 39 6c 0d 6e Aug 26 13:10:29.256267: | a0 0a 35 ef 66 4a 59 06 50 a2 62 3c b6 d5 3c 4c Aug 26 13:10:29.256270: | 7d 14 28 6c 7e 8b da 8d ab 38 50 94 11 7a e5 c9 Aug 26 13:10:29.256272: | b1 2a 9f 44 8d 7e ab de b8 e0 5b 6e 77 1d 2b 47 Aug 26 13:10:29.256274: | 43 14 b1 d9 a6 e5 e7 73 85 a4 48 27 f3 fe fa b3 Aug 26 13:10:29.256277: | 68 3e 47 95 e5 a0 ab bb fc 82 9a 34 75 e5 63 92 Aug 26 13:10:29.256279: | 04 73 77 0f 19 89 80 ac 43 e7 7e 70 a1 51 b9 47 Aug 26 13:10:29.256281: | f6 d9 ae 23 9a 92 d9 f4 c8 fb 9a f4 e1 93 b9 07 Aug 26 13:10:29.256284: | d0 ea f4 bb dd af 3e a8 c4 ad a7 7a e8 45 67 7d Aug 26 13:10:29.256287: | 6e bc 74 8e 75 fd 7f aa 48 54 21 fe 26 83 ef cc Aug 26 13:10:29.256311: | 56 d2 e7 07 6f 45 05 98 74 50 48 56 d2 a5 61 a3 Aug 26 13:10:29.256313: | ef 6f fe 18 c0 6c cd c8 42 3e 85 8b 34 30 9d 2b Aug 26 13:10:29.256316: | d2 b6 f4 52 3f 45 42 31 d7 5e 86 c1 b1 5c eb da Aug 26 13:10:29.256331: | 32 30 77 44 45 b3 2d d4 be ed 85 1c b5 b8 2d b0 Aug 26 13:10:29.256333: | d4 60 6b 3c c8 58 cc 61 45 94 27 98 80 27 22 0c Aug 26 13:10:29.256336: | 37 8f f7 eb 68 b8 2b 82 52 0b 96 98 58 88 96 b6 Aug 26 13:10:29.256338: | 05 8c 1e ab 2f ee 65 ba a5 0e ea 30 6d 21 42 d7 Aug 26 13:10:29.256355: | 10 78 76 a6 ab 08 50 4b 66 bf bf 37 2c 39 a6 d9 Aug 26 13:10:29.256357: | 22 91 67 4a 7d 67 e0 43 7d 53 07 ec 61 8b bb d7 Aug 26 13:10:29.256360: | 5c 4d 07 be 61 13 85 93 32 2d 9b a2 19 54 d1 92 Aug 26 13:10:29.256362: | 52 95 e0 a9 ef dd 2f df 7b 20 d2 78 d8 4a e6 ef Aug 26 13:10:29.256423: | state #3 requesting EVENT_SA_REPLACE to be deleted Aug 26 13:10:29.256428: | libevent_free: release ptr-libevent@0x55e2777150a8 Aug 26 13:10:29.256445: | free_event_entry: release EVENT_SA_REPLACE-pe@0x55e27771c4c8 Aug 26 13:10:29.256448: | success_v2_state_transition scheduling EVENT_RETRANSMIT of c->r_interval=50ms Aug 26 13:10:29.256452: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e27771c4c8 Aug 26 13:10:29.256456: | inserting event EVENT_RETRANSMIT, timeout in 0.05 seconds for #3 Aug 26 13:10:29.256459: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:10:29.256464: | #3 STATE_V2_CREATE_I: retransmits: first event in 0.05 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 10314.998918 Aug 26 13:10:29.256469: | stop processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in initiate_next() at ikev2_msgid.c:557) Aug 26 13:10:29.256474: | resume processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in initiate_next() at ikev2_msgid.c:557) Aug 26 13:10:29.256479: | #1 spent 0.888 milliseconds in callback v2_msgid_schedule_next_initiator Aug 26 13:10:29.256483: | stop processing: state #1 connection "north-eastnets/0x2" from 192.1.3.33 (in callback_handler() at server.c:908) Aug 26 13:10:29.256486: | libevent_free: release ptr-libevent@0x55e277719b88 Aug 26 13:10:29.306554: | timer_event_cb: processing event@0x55e27771c4c8 Aug 26 13:10:29.306567: | handling event EVENT_RETRANSMIT for child state #3 Aug 26 13:10:29.306572: | start processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:29.306575: | IKEv2 retransmit event Aug 26 13:10:29.306579: | [RE]START processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:29.306582: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #3 attempt 2 of 0 Aug 26 13:10:29.306585: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:29.306589: | retransmits: current time 10315.049054; retransmit count 0 exceeds limit? NO; deltatime 0.05 exceeds limit? NO; monotime 0.050136 exceeds limit? NO Aug 26 13:10:29.306592: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:29.306594: | inserting event EVENT_RETRANSMIT, timeout in 0.05 seconds for #3 Aug 26 13:10:29.306597: | libevent_malloc: new ptr-libevent@0x55e277719b88 size 128 Aug 26 13:10:29.306600: "north-eastnets/0x2" #3: STATE_V2_CREATE_I: retransmission; will wait 0.05 seconds for response Aug 26 13:10:29.306607: | sending 608 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:29.306609: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.306611: | 2e 20 24 08 00 00 00 02 00 00 02 60 21 00 02 44 Aug 26 13:10:29.306612: | 55 f1 3f bd 0e 8f 43 e3 a0 3d 85 75 24 df 4f 7b Aug 26 13:10:29.306614: | 97 f7 30 f0 32 7f eb 35 7d 79 b0 e8 c6 38 1d 31 Aug 26 13:10:29.306615: | a4 e7 58 fc 50 ae 3c ef 9c 97 61 b4 33 8a ee 5c Aug 26 13:10:29.306619: | 74 71 7a 77 49 0a 51 22 03 8a 87 0e 17 6a 35 fb Aug 26 13:10:29.306621: | 84 e8 18 3f 7e 1e ae 76 01 59 cd 45 ff 49 0b 26 Aug 26 13:10:29.306622: | ac 5d 14 de c0 24 b9 02 7d 74 4f 33 4b 14 f2 0b Aug 26 13:10:29.306624: | 24 f6 b7 98 57 e9 c8 d4 c9 2c bb 96 98 1e 37 d5 Aug 26 13:10:29.306625: | 19 ed 37 ac 04 27 63 fe e5 c9 df 2c d3 7b f2 25 Aug 26 13:10:29.306627: | 80 8e 5c 28 8e 1c 00 62 f4 54 51 53 55 1c 8f 7b Aug 26 13:10:29.306628: | 59 d8 4c 8b 0b 2f 5b 18 48 3c 23 4e 99 05 59 ab Aug 26 13:10:29.306630: | 82 58 d1 25 f0 de df 0e ac 18 d7 4c 7a 02 e6 98 Aug 26 13:10:29.306631: | ae b0 2e b2 0d 86 f0 50 85 21 21 a0 fd 64 bf 42 Aug 26 13:10:29.306633: | c1 2a ff a0 22 bb 58 c6 86 6e 92 2f ac da 3b e4 Aug 26 13:10:29.306634: | 3a eb a9 9e 21 3a 42 82 96 76 b8 bd 1b 22 e6 f3 Aug 26 13:10:29.306636: | 45 d2 61 37 79 38 37 6a e2 8b 7e 6d 05 2c 45 ad Aug 26 13:10:29.306637: | ec 82 48 0a 74 e8 f8 14 30 36 2d 99 39 6c 0d 6e Aug 26 13:10:29.306639: | a0 0a 35 ef 66 4a 59 06 50 a2 62 3c b6 d5 3c 4c Aug 26 13:10:29.306640: | 7d 14 28 6c 7e 8b da 8d ab 38 50 94 11 7a e5 c9 Aug 26 13:10:29.306642: | b1 2a 9f 44 8d 7e ab de b8 e0 5b 6e 77 1d 2b 47 Aug 26 13:10:29.306643: | 43 14 b1 d9 a6 e5 e7 73 85 a4 48 27 f3 fe fa b3 Aug 26 13:10:29.306645: | 68 3e 47 95 e5 a0 ab bb fc 82 9a 34 75 e5 63 92 Aug 26 13:10:29.306646: | 04 73 77 0f 19 89 80 ac 43 e7 7e 70 a1 51 b9 47 Aug 26 13:10:29.306648: | f6 d9 ae 23 9a 92 d9 f4 c8 fb 9a f4 e1 93 b9 07 Aug 26 13:10:29.306649: | d0 ea f4 bb dd af 3e a8 c4 ad a7 7a e8 45 67 7d Aug 26 13:10:29.306651: | 6e bc 74 8e 75 fd 7f aa 48 54 21 fe 26 83 ef cc Aug 26 13:10:29.306652: | 56 d2 e7 07 6f 45 05 98 74 50 48 56 d2 a5 61 a3 Aug 26 13:10:29.306654: | ef 6f fe 18 c0 6c cd c8 42 3e 85 8b 34 30 9d 2b Aug 26 13:10:29.306655: | d2 b6 f4 52 3f 45 42 31 d7 5e 86 c1 b1 5c eb da Aug 26 13:10:29.306657: | 32 30 77 44 45 b3 2d d4 be ed 85 1c b5 b8 2d b0 Aug 26 13:10:29.306658: | d4 60 6b 3c c8 58 cc 61 45 94 27 98 80 27 22 0c Aug 26 13:10:29.306660: | 37 8f f7 eb 68 b8 2b 82 52 0b 96 98 58 88 96 b6 Aug 26 13:10:29.306661: | 05 8c 1e ab 2f ee 65 ba a5 0e ea 30 6d 21 42 d7 Aug 26 13:10:29.306663: | 10 78 76 a6 ab 08 50 4b 66 bf bf 37 2c 39 a6 d9 Aug 26 13:10:29.306664: | 22 91 67 4a 7d 67 e0 43 7d 53 07 ec 61 8b bb d7 Aug 26 13:10:29.306666: | 5c 4d 07 be 61 13 85 93 32 2d 9b a2 19 54 d1 92 Aug 26 13:10:29.306667: | 52 95 e0 a9 ef dd 2f df 7b 20 d2 78 d8 4a e6 ef Aug 26 13:10:29.306708: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:10:29.306712: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e27771c4c8 Aug 26 13:10:29.306717: | #3 spent 0.142 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:29.306720: | stop processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:29.357931: | timer_event_cb: processing event@0x7f0470002b78 Aug 26 13:10:29.357956: | handling event EVENT_RETRANSMIT for child state #3 Aug 26 13:10:29.357967: | start processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:29.357972: | IKEv2 retransmit event Aug 26 13:10:29.357979: | [RE]START processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:29.357985: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #3 attempt 2 of 0 Aug 26 13:10:29.357991: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:29.358000: | retransmits: current time 10315.100462; retransmit count 1 exceeds limit? NO; deltatime 0.1 exceeds limit? NO; monotime 0.101544 exceeds limit? NO Aug 26 13:10:29.358005: | event_schedule: new EVENT_RETRANSMIT-pe@0x55e27771c4c8 Aug 26 13:10:29.358011: | inserting event EVENT_RETRANSMIT, timeout in 0.1 seconds for #3 Aug 26 13:10:29.358015: | libevent_malloc: new ptr-libevent@0x55e277706d58 size 128 Aug 26 13:10:29.358027: "north-eastnets/0x2" #3: STATE_V2_CREATE_I: retransmission; will wait 0.1 seconds for response Aug 26 13:10:29.358036: | sending 608 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:29.358040: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.358044: | 2e 20 24 08 00 00 00 02 00 00 02 60 21 00 02 44 Aug 26 13:10:29.358047: | 55 f1 3f bd 0e 8f 43 e3 a0 3d 85 75 24 df 4f 7b Aug 26 13:10:29.358050: | 97 f7 30 f0 32 7f eb 35 7d 79 b0 e8 c6 38 1d 31 Aug 26 13:10:29.358053: | a4 e7 58 fc 50 ae 3c ef 9c 97 61 b4 33 8a ee 5c Aug 26 13:10:29.358056: | 74 71 7a 77 49 0a 51 22 03 8a 87 0e 17 6a 35 fb Aug 26 13:10:29.358059: | 84 e8 18 3f 7e 1e ae 76 01 59 cd 45 ff 49 0b 26 Aug 26 13:10:29.358063: | ac 5d 14 de c0 24 b9 02 7d 74 4f 33 4b 14 f2 0b Aug 26 13:10:29.358066: | 24 f6 b7 98 57 e9 c8 d4 c9 2c bb 96 98 1e 37 d5 Aug 26 13:10:29.358069: | 19 ed 37 ac 04 27 63 fe e5 c9 df 2c d3 7b f2 25 Aug 26 13:10:29.358072: | 80 8e 5c 28 8e 1c 00 62 f4 54 51 53 55 1c 8f 7b Aug 26 13:10:29.358075: | 59 d8 4c 8b 0b 2f 5b 18 48 3c 23 4e 99 05 59 ab Aug 26 13:10:29.358078: | 82 58 d1 25 f0 de df 0e ac 18 d7 4c 7a 02 e6 98 Aug 26 13:10:29.358081: | ae b0 2e b2 0d 86 f0 50 85 21 21 a0 fd 64 bf 42 Aug 26 13:10:29.358085: | c1 2a ff a0 22 bb 58 c6 86 6e 92 2f ac da 3b e4 Aug 26 13:10:29.358088: | 3a eb a9 9e 21 3a 42 82 96 76 b8 bd 1b 22 e6 f3 Aug 26 13:10:29.358091: | 45 d2 61 37 79 38 37 6a e2 8b 7e 6d 05 2c 45 ad Aug 26 13:10:29.358094: | ec 82 48 0a 74 e8 f8 14 30 36 2d 99 39 6c 0d 6e Aug 26 13:10:29.358097: | a0 0a 35 ef 66 4a 59 06 50 a2 62 3c b6 d5 3c 4c Aug 26 13:10:29.358100: | 7d 14 28 6c 7e 8b da 8d ab 38 50 94 11 7a e5 c9 Aug 26 13:10:29.358103: | b1 2a 9f 44 8d 7e ab de b8 e0 5b 6e 77 1d 2b 47 Aug 26 13:10:29.358107: | 43 14 b1 d9 a6 e5 e7 73 85 a4 48 27 f3 fe fa b3 Aug 26 13:10:29.358110: | 68 3e 47 95 e5 a0 ab bb fc 82 9a 34 75 e5 63 92 Aug 26 13:10:29.358113: | 04 73 77 0f 19 89 80 ac 43 e7 7e 70 a1 51 b9 47 Aug 26 13:10:29.358116: | f6 d9 ae 23 9a 92 d9 f4 c8 fb 9a f4 e1 93 b9 07 Aug 26 13:10:29.358119: | d0 ea f4 bb dd af 3e a8 c4 ad a7 7a e8 45 67 7d Aug 26 13:10:29.358122: | 6e bc 74 8e 75 fd 7f aa 48 54 21 fe 26 83 ef cc Aug 26 13:10:29.358126: | 56 d2 e7 07 6f 45 05 98 74 50 48 56 d2 a5 61 a3 Aug 26 13:10:29.358129: | ef 6f fe 18 c0 6c cd c8 42 3e 85 8b 34 30 9d 2b Aug 26 13:10:29.358132: | d2 b6 f4 52 3f 45 42 31 d7 5e 86 c1 b1 5c eb da Aug 26 13:10:29.358135: | 32 30 77 44 45 b3 2d d4 be ed 85 1c b5 b8 2d b0 Aug 26 13:10:29.358138: | d4 60 6b 3c c8 58 cc 61 45 94 27 98 80 27 22 0c Aug 26 13:10:29.358141: | 37 8f f7 eb 68 b8 2b 82 52 0b 96 98 58 88 96 b6 Aug 26 13:10:29.358144: | 05 8c 1e ab 2f ee 65 ba a5 0e ea 30 6d 21 42 d7 Aug 26 13:10:29.358148: | 10 78 76 a6 ab 08 50 4b 66 bf bf 37 2c 39 a6 d9 Aug 26 13:10:29.358151: | 22 91 67 4a 7d 67 e0 43 7d 53 07 ec 61 8b bb d7 Aug 26 13:10:29.358154: | 5c 4d 07 be 61 13 85 93 32 2d 9b a2 19 54 d1 92 Aug 26 13:10:29.358157: | 52 95 e0 a9 ef dd 2f df 7b 20 d2 78 d8 4a e6 ef Aug 26 13:10:29.358230: | libevent_free: release ptr-libevent@0x55e277719b88 Aug 26 13:10:29.358240: | free_event_entry: release EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:29.358253: | #3 spent 0.285 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:29.358264: | stop processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557) Aug 26 13:10:29.458700: | timer_event_cb: processing event@0x55e27771c4c8 Aug 26 13:10:29.458767: | handling event EVENT_RETRANSMIT for child state #3 Aug 26 13:10:29.458791: | start processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:250) Aug 26 13:10:29.458804: | IKEv2 retransmit event Aug 26 13:10:29.458821: | [RE]START processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in retransmit_v2_msg() at retry.c:144) Aug 26 13:10:29.458848: | handling event EVENT_RETRANSMIT for 192.1.3.33 "north-eastnets/0x2" #3 attempt 2 of 0 Aug 26 13:10:29.458862: | and parent for 192.1.3.33 "north-eastnets/0x2" #1 keying attempt 1 of 0; retransmit 1 Aug 26 13:10:29.458884: | retransmits: current time 10315.201338; retransmit count 2 exceeds limit? NO; deltatime 0.2 exceeds limit? NO; monotime 0.20242 exceeds limit? NO Aug 26 13:10:29.458897: | event_schedule: new EVENT_RETRANSMIT-pe@0x7f0470002b78 Aug 26 13:10:29.458909: | inserting event EVENT_RETRANSMIT, timeout in 0.2 seconds for #3 Aug 26 13:10:29.458921: | libevent_malloc: new ptr-libevent@0x55e277719b88 size 128 Aug 26 13:10:29.458935: "north-eastnets/0x2" #3: STATE_V2_CREATE_I: retransmission; will wait 0.2 seconds for response Aug 26 13:10:29.458957: | sending 608 bytes for EVENT_RETRANSMIT through eth1 from 192.1.2.23:500 to 192.1.3.33:500 (using #1) Aug 26 13:10:29.458966: | 8b 87 d7 26 c3 30 6b 14 26 f7 28 5a f4 b9 c7 d8 Aug 26 13:10:29.458974: | 2e 20 24 08 00 00 00 02 00 00 02 60 21 00 02 44 Aug 26 13:10:29.458982: | 55 f1 3f bd 0e 8f 43 e3 a0 3d 85 75 24 df 4f 7b Aug 26 13:10:29.458989: | 97 f7 30 f0 32 7f eb 35 7d 79 b0 e8 c6 38 1d 31 Aug 26 13:10:29.458997: | a4 e7 58 fc 50 ae 3c ef 9c 97 61 b4 33 8a ee 5c Aug 26 13:10:29.459005: | 74 71 7a 77 49 0a 51 22 03 8a 87 0e 17 6a 35 fb Aug 26 13:10:29.459013: | 84 e8 18 3f 7e 1e ae 76 01 59 cd 45 ff 49 0b 26 Aug 26 13:10:29.459020: | ac 5d 14 de c0 24 b9 02 7d 74 4f 33 4b 14 f2 0b Aug 26 13:10:29.459028: | 24 f6 b7 98 57 e9 c8 d4 c9 2c bb 96 98 1e 37 d5 Aug 26 13:10:29.459036: | 19 ed 37 ac 04 27 63 fe e5 c9 df 2c d3 7b f2 25 Aug 26 13:10:29.459044: | 80 8e 5c 28 8e 1c 00 62 f4 54 51 53 55 1c 8f 7b Aug 26 13:10:29.459052: | 59 d8 4c 8b 0b 2f 5b 18 48 3c 23 4e 99 05 59 ab Aug 26 13:10:29.459061: | 82 58 d1 25 f0 de df 0e ac 18 d7 4c 7a 02 e6 98 Aug 26 13:10:29.459069: | ae b0 2e b2 0d 86 f0 50 85 21 21 a0 fd 64 bf 42 Aug 26 13:10:29.459077: | c1 2a ff a0 22 bb 58 c6 86 6e 92 2f ac da 3b e4 Aug 26 13:10:29.459085: | 3a eb a9 9e 21 3a 42 82 96 76 b8 bd 1b 22 e6 f3 Aug 26 13:10:29.459094: | 45 d2 61 37 79 38 37 6a e2 8b 7e 6d 05 2c 45 ad Aug 26 13:10:29.459102: | ec 82 48 0a 74 e8 f8 14 30 36 2d 99 39 6c 0d 6e Aug 26 13:10:29.459111: | a0 0a 35 ef 66 4a 59 06 50 a2 62 3c b6 d5 3c 4c Aug 26 13:10:29.459119: | 7d 14 28 6c 7e 8b da 8d ab 38 50 94 11 7a e5 c9 Aug 26 13:10:29.459127: | b1 2a 9f 44 8d 7e ab de b8 e0 5b 6e 77 1d 2b 47 Aug 26 13:10:29.459135: | 43 14 b1 d9 a6 e5 e7 73 85 a4 48 27 f3 fe fa b3 Aug 26 13:10:29.459143: | 68 3e 47 95 e5 a0 ab bb fc 82 9a 34 75 e5 63 92 Aug 26 13:10:29.459152: | 04 73 77 0f 19 89 80 ac 43 e7 7e 70 a1 51 b9 47 Aug 26 13:10:29.459160: | f6 d9 ae 23 9a 92 d9 f4 c8 fb 9a f4 e1 93 b9 07 Aug 26 13:10:29.459169: | d0 ea f4 bb dd af 3e a8 c4 ad a7 7a e8 45 67 7d Aug 26 13:10:29.459178: | 6e bc 74 8e 75 fd 7f aa 48 54 21 fe 26 83 ef cc Aug 26 13:10:29.459186: | 56 d2 e7 07 6f 45 05 98 74 50 48 56 d2 a5 61 a3 Aug 26 13:10:29.459194: | ef 6f fe 18 c0 6c cd c8 42 3e 85 8b 34 30 9d 2b Aug 26 13:10:29.459202: | d2 b6 f4 52 3f 45 42 31 d7 5e 86 c1 b1 5c eb da Aug 26 13:10:29.459210: | 32 30 77 44 45 b3 2d d4 be ed 85 1c b5 b8 2d b0 Aug 26 13:10:29.459218: | d4 60 6b 3c c8 58 cc 61 45 94 27 98 80 27 22 0c Aug 26 13:10:29.459226: | 37 8f f7 eb 68 b8 2b 82 52 0b 96 98 58 88 96 b6 Aug 26 13:10:29.459233: | 05 8c 1e ab 2f ee 65 ba a5 0e ea 30 6d 21 42 d7 Aug 26 13:10:29.459241: | 10 78 76 a6 ab 08 50 4b 66 bf bf 37 2c 39 a6 d9 Aug 26 13:10:29.459249: | 22 91 67 4a 7d 67 e0 43 7d 53 07 ec 61 8b bb d7 Aug 26 13:10:29.459257: | 5c 4d 07 be 61 13 85 93 32 2d 9b a2 19 54 d1 92 Aug 26 13:10:29.459265: | 52 95 e0 a9 ef dd 2f df 7b 20 d2 78 d8 4a e6 ef Aug 26 13:10:29.459452: | libevent_free: release ptr-libevent@0x55e277706d58 Aug 26 13:10:29.459508: | free_event_entry: release EVENT_RETRANSMIT-pe@0x55e27771c4c8 Aug 26 13:10:29.459556: | #3 spent 0.752 milliseconds in timer_event_cb() EVENT_RETRANSMIT Aug 26 13:10:29.459587: | stop processing: state #3 connection "north-eastnets/0x2" from 192.1.3.33 (in timer_event_cb() at timer.c:557)