#!/bin/sh kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# iptables -t nat -F kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# iptables -F kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# # NAT kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #iptables -t nat -A POSTROUTING --source 192.1.3.0/24 --destination 0.0.0.0/0 -j SNAT --to-source 192.1.2.254 kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# # make sure that we never acidentially let ESP through. kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -N LOGDROP kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -A LOGDROP -j LOG kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -A LOGDROP -j DROP kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -I FORWARD 1 --proto 50 -j LOGDROP kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -I FORWARD 2 --destination 192.0.2.0/24 -j LOGDROP kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -I FORWARD 3 --source 192.0.2.0/24 -j LOGDROP kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# # route kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -I INPUT 1 --destination 192.0.2.0/24 -j LOGDROP kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# # Display the table, so we know it is correct. kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -t nat -L -n kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# #ptables -L -n kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# echo done. done. kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# : ==== end ==== kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06]# ipsec whack --trafficstatus whack: Pluto is not running (no "/run/pluto/pluto.ctl") kroot@swantest:/home/build/libreswan/testing/pluto/netkey-vti-06\[root@nic netkey-vti-06 33]# >>>>>>>>>>cutnonzeroexit>>>>>>>>>> exit status 33 final.sh 'ipsec whack --trafficstatus' <<<<<<<<<>>>>>>>>>cutnonzeroexit>>>>>>>>>> exit status 1 final.sh 'grep -v -P "\t0$" /proc/net/xfrm_stat' <<<<<<<<<>>>>>>>>>cutnonzeroexit>>>>>>>>>> exit status 33 final.sh 'ipsec auto --status' <<<<<<<<<