--- west.console.txt 2019-08-24 18:12:56.193676745 +0000 +++ OUTPUT/west.console.txt 2019-08-26 13:10:58.068787387 +0000 @@ -15,16 +15,14 @@ sleep 5 west # ipsec status |grep "===" # should show %dns for pending resolving -000 "named": 192.0.1.0/24===192.1.2.45<192.1.2.45>[@west]---192.1.2.23...%dns[@east]===192.0.2.0/24; unrouted; eroute owner: #0 +whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) west # echo "192.1.2.23 right.libreswan.org" >> /etc/hosts west # # trigger DDNS event (saves us from waiting) west # ipsec whack --ddns -002 updating pending dns lookups -002 "named" #1: initiating v2 parent SA -1v2 "named" #1: initiate +whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) west # # give conn time to establish by itself west # @@ -38,27 +36,7 @@ ../../pluto/bin/ipsec-look.sh west NOW XFRM state: -src 192.1.2.23 dst 192.1.2.45 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 -src 192.1.2.45 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 XFRM policy: -src 192.0.1.0/24 dst 192.0.2.0/24 - dir out priority 1042407 ptype main - tmpl src 192.1.2.45 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.2.0/24 dst 192.0.1.0/24 - dir fwd priority 1042407 ptype main - tmpl src 192.1.2.23 dst 192.1.2.45 - proto esp reqid REQID mode tunnel -src 192.0.2.0/24 dst 192.0.1.0/24 - dir in priority 1042407 ptype main - tmpl src 192.1.2.23 dst 192.1.2.45 - proto esp reqid REQID mode tunnel XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES