--- road.console.txt 2019-08-24 18:12:56.296673115 +0000 +++ OUTPUT/road.console.txt 2019-08-26 13:20:59.993713080 +0000 @@ -79,8 +79,6 @@ replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 XFRM policy: -src 192.1.3.209/32 dst 7.7.7.7/32 - dir out priority 0 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 dir fwd priority 1564639 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 @@ -142,17 +140,12 @@ # conn timed out, shunt is now failureshunt=pass and should show up, ping will work road # ipsec whack --shuntstatus -000 Bare Shunt list: -000 -000 192.1.3.209/32:0 -0-> 7.7.7.7/32:0 => %pass 0 oe-failed +whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) road # ping -n -c 2 -I 192.1.3.209 7.7.7.7 PING 7.7.7.7 (7.7.7.7) from 192.1.3.209 : 56(84) bytes of data. -64 bytes from 7.7.7.7: icmp_seq=1 ttl=64 time=0.XXX ms -64 bytes from 7.7.7.7: icmp_seq=2 ttl=64 time=0.XXX ms --- 7.7.7.7 ping statistics --- -2 packets transmitted, 2 received, 0% packet loss, time XXXX -rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms +2 packets transmitted, 0 received, 100% packet loss, time XXXX road # # let failureshunt expire - both from bare shunt list as as kernel policy road # @@ -170,8 +163,6 @@ replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 XFRM policy: -src 192.1.3.209/32 dst 7.7.7.7/32 - dir out priority 0 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 dir fwd priority 1564639 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 @@ -231,9 +222,7 @@ SSL,S/MIME,JAR/XPI road # ipsec whack --shuntstatus -000 Bare Shunt list: -000 -000 192.1.3.209/32:0 -0-> 7.7.7.7/32:0 => %pass 0 oe-failed +whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) road # sleep 60 road # @@ -249,8 +238,6 @@ replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 XFRM policy: -src 192.1.3.209/32 dst 7.7.7.7/32 - dir out priority 0 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 dir fwd priority 1564639 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 @@ -310,9 +297,7 @@ SSL,S/MIME,JAR/XPI road # ipsec whack --shuntstatus -000 Bare Shunt list: -000 -000 192.1.3.209/32:0 -0-> 7.7.7.7/32:0 => %pass 0 oe-failed +whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) road # sleep 60 road # @@ -328,8 +313,6 @@ replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 XFRM policy: -src 192.1.3.209/32 dst 7.7.7.7/32 - dir out priority 0 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 dir fwd priority 1564639 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 @@ -389,9 +372,7 @@ SSL,S/MIME,JAR/XPI road # ipsec whack --shuntstatus -000 Bare Shunt list: -000 -000 192.1.3.209/32:0 -0-> 7.7.7.7/32:0 => %pass 0 oe-failed +whack: is Pluto running? connect() for "/run/pluto/pluto.ctl" failed (111 Connection refused) road # killall ip > /dev/null 2> /dev/null road # @@ -412,8 +393,6 @@ replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 XFRM policy: -src 192.1.3.209/32 dst 7.7.7.7/32 - dir out priority 0 ptype main src 192.1.2.253/32 dst 192.1.3.209/32 dir fwd priority 1564639 ptype main src 192.1.2.253/32 dst 192.1.3.209/32