--- west.console.txt 2019-08-24 18:12:56.190676851 +0000 +++ OUTPUT/west.console.txt 2019-08-26 13:22:53.357744031 +0000 @@ -1,5 +1,7 @@ /testing/guestbin/swan-prep west # + +west # ip addr add 192.0.100.254/24 dev eth0:1 west # ip addr add 192.0.101.254/24 dev eth0:1 @@ -8,6 +10,8 @@ west # ip addr add 192.0.111.254/24 dev eth0:1 west # + +west # ip route add 192.0.200.0/24 via 192.1.2.23 dev eth1 west # ip route add 192.0.201.0/24 via 192.1.2.23 dev eth1 @@ -16,6 +20,8 @@ west # ip route add 192.0.211.0/24 via 192.1.2.23 dev eth1 west # + +west # # ensure that clear text does not get through west # iptables -A INPUT -i eth1 -s 192.0.2.0/24 -j LOGDROP @@ -31,9 +37,13 @@ west # ipsec whack --impair suppress-retransmits,delete-on-retransmit west # + +west # ipsec auto --add westnet-eastnet-ikev2 002 added connection description "westnet-eastnet-ikev2" west # + +west # ipsec auto --add westnet-eastnet-ikev2-00 002 added connection description "westnet-eastnet-ikev2-00" west # @@ -46,6 +56,8 @@ ipsec auto --add westnet-eastnet-ikev2-11 002 added connection description "westnet-eastnet-ikev2-11" west # + +west # echo "initdone" initdone west # @@ -62,8 +74,12 @@ ../../pluto/bin/one-ping.sh -I 192.0.1.254 192.0.2.254 up west # + +west # # remote pfs=no downgrade=no west # + +west # # pfs=no downgrade=no - connect west # ipsec auto --up westnet-eastnet-ikev2-00 @@ -74,6 +90,8 @@ ../../pluto/bin/one-ping.sh -I 192.0.100.254 192.0.200.254 up west # + +west # # pfs=no downgrade=yes - connect west # ipsec auto --up westnet-eastnet-ikev2-01 @@ -84,12 +102,16 @@ ../../pluto/bin/one-ping.sh -I 192.0.101.254 192.0.201.254 up west # + +west # # pfs=yes downgrade=no - fail west # # ipsec auto --up westnet-eastnet-ikev2-10 west # # ../../pluto/bin/one-ping.sh -I 192.0.110.254 192.0.210.254 west # + +west # # pfs=yes downgrade=yes - connect west # ipsec auto --up westnet-eastnet-ikev2-11 @@ -100,12 +122,16 @@ ../../pluto/bin/one-ping.sh -I 192.0.111.254 192.0.211.254 up west # + +west # ipsec whack --trafficstatus 006 #2: "westnet-eastnet-ikev2", type=ESP, add_time=1234567890, inBytes=84, outBytes=84, id='@east' 006 #3: "westnet-eastnet-ikev2-00", type=ESP, add_time=1234567890, inBytes=84, outBytes=84, id='@east' 006 #4: "westnet-eastnet-ikev2-01", type=ESP, add_time=1234567890, inBytes=84, outBytes=84, id='@east' 006 #5: "westnet-eastnet-ikev2-11", type=ESP, add_time=1234567890, inBytes=84, outBytes=84, id='@east' west # + +west # echo done done west #