--- road.console.txt 2019-08-24 18:12:56.296673115 +0000 +++ OUTPUT/road.console.txt 2019-08-26 13:19:49.710173821 +0000 @@ -57,17 +57,13 @@ ipsec whack --shuntstatus 000 Bare Shunt list: 000 -000 192.1.3.209/32:0 -0-> 7.7.7.7/32:0 => %pass 0 oe-failing road # # 7.7.7.7 is %pass, we should be able to ping it road # ping -n -c 2 -I 192.1.3.209 7.7.7.7 PING 7.7.7.7 (7.7.7.7) from 192.1.3.209 : 56(84) bytes of data. -64 bytes from 7.7.7.7: icmp_seq=1 ttl=64 time=0.XXX ms -64 bytes from 7.7.7.7: icmp_seq=2 ttl=64 time=0.XXX ms --- 7.7.7.7 ping statistics --- -2 packets transmitted, 2 received, 0% packet loss, time XXXX -rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms +2 packets transmitted, 0 received, 100% packet loss, time XXXX road # ../../pluto/bin/ipsec-look.sh road NOW @@ -84,10 +80,6 @@ proto esp spi 0xSPISPI reqid REQID mode tunnel replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 -src 192.1.3.209 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode transport - replay-window 0 - sel src 192.1.3.209/32 dst 192.1.2.23/32 proto icmp type 8 code 0 dev eth0 XFRM policy: src 192.1.2.253/32 dst 192.1.3.209/32 dir fwd priority 1564639 ptype main @@ -137,8 +129,6 @@ dir out priority 2088951 ptype main tmpl src 0.0.0.0 dst 0.0.0.0 proto esp reqid REQID mode transport -src 192.1.3.209/32 dst 7.7.7.7/32 - dir out priority 2088951 ptype main XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES @@ -213,8 +203,6 @@ dir out priority 2088951 ptype main tmpl src 0.0.0.0 dst 0.0.0.0 proto esp reqid REQID mode transport -src 192.1.3.209/32 dst 7.7.7.7/32 - dir out priority 2088951 ptype main XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES