/testing/guestbin/swan-prep kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# cp policies/* /etc/ipsec.d/policies/ kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# echo "192.1.2.0/24" >> /etc/ipsec.d/policies/private-or-clear kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# cp ikev2-oe.conf /etc/ipsec.d/ikev2-oe.conf kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# ipsec start Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Redirecting to: /etc/init.d/ipsec start Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Starting pluto IKE daemon for IPsec: kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# /testing/pluto/bin/wait-until-pluto-started kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# # give OE policies time to load kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# sleep 2 kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# echo "initdone" initdone kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# ipsec whack --trafficstatus 006 #2: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.254===10.0.10.1/32, type=ESP, add_time=0, inBytes=252, outBytes=252, id='ID_NULL', lease=10.0.10.1/32 kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# iptables -t nat -L -n Chain PREROUTING (policy ACCEPT) target prot opt source destination Chain INPUT (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination Chain POSTROUTING (policy ACCEPT) target prot opt source destination kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# ../../pluto/bin/ipsec-look.sh ==== cut ==== start raw xfrm state: src 192.1.2.23/32 dst 10.0.10.1/32 \ dir out priority 2088927 ptype main \ tmpl src 192.1.2.23 dst 192.1.2.254\ proto esp reqid 16425 mode tunnel\ src 10.0.10.1/32 dst 192.1.2.23/32 \ dir fwd priority 2088927 ptype main \ tmpl src 192.1.2.254 dst 192.1.2.23\ proto esp reqid 16425 mode tunnel\ src 10.0.10.1/32 dst 192.1.2.23/32 \ dir in priority 2088927 ptype main \ tmpl src 192.1.2.254 dst 192.1.2.23\ proto esp reqid 16425 mode tunnel\ src 192.1.2.23/32 dst 192.1.2.0/24 \ dir out priority 2088935 ptype main \ tmpl src 0.0.0.0 dst 0.0.0.0\ proto esp reqid 0 mode transport\ src 192.1.2.253/32 dst 192.1.2.23/32 \ dir fwd priority 1564639 ptype main \ src 192.1.2.253/32 dst 192.1.2.23/32 \ dir in priority 1564639 ptype main \ src 192.1.2.23/32 dst 192.1.2.253/32 \ dir out priority 1564639 ptype main \ src 192.1.3.253/32 dst 192.1.2.23/32 \ dir fwd priority 1564639 ptype main \ src 192.1.3.253/32 dst 192.1.2.23/32 \ dir in priority 1564639 ptype main \ src 192.1.2.23/32 dst 192.1.3.253/32 \ dir out priority 1564639 ptype main \ src 192.1.3.254/32 dst 192.1.2.23/32 \ dir fwd priority 1564639 ptype main \ src 192.1.3.254/32 dst 192.1.2.23/32 \ dir in priority 1564639 ptype main \ src 192.1.2.23/32 dst 192.1.3.254/32 \ dir out priority 1564639 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket out priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket in priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket out priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket in priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket out priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket in priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket out priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket in priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket out priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket in priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket out priority 0 ptype main \ src 0.0.0.0/0 dst 0.0.0.0/0 \ socket in priority 0 ptype main \ end raw xfrm state: ==== tuc ==== east Mon Aug 26 13:18:48 UTC 2019 XFRM state: src 192.1.2.254 dst 192.1.2.23 proto esp spi 0x693a9a70 reqid 16425 mode tunnel replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xf3a7d253d677dab8ce9bb9f6b163c41eae6146014e841957f434f319d57d1fa16e0107c3 128 encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 anti-replay context: seq 0x3, oseq 0x0, bitmap 0x00000007 src 192.1.2.23 dst 192.1.2.254 proto esp spi 0xdac59dec reqid 16425 mode tunnel replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xe7511b1cb8a7093763a26507fb24e532da14ead48a7debac6b145cdc434d1c53ce94c8dc 128 encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 anti-replay context: seq 0x0, oseq 0x3, bitmap 0x00000000 XFRM policy: src 192.1.2.23/32 dst 192.1.2.253/32 dir out priority 1564639 ptype main src 192.1.2.23/32 dst 192.1.3.253/32 dir out priority 1564639 ptype main src 192.1.2.23/32 dst 192.1.3.254/32 dir out priority 1564639 ptype main src 192.1.2.253/32 dst 192.1.2.23/32 dir fwd priority 1564639 ptype main src 192.1.2.253/32 dst 192.1.2.23/32 dir in priority 1564639 ptype main src 192.1.3.253/32 dst 192.1.2.23/32 dir fwd priority 1564639 ptype main src 192.1.3.253/32 dst 192.1.2.23/32 dir in priority 1564639 ptype main src 192.1.3.254/32 dst 192.1.2.23/32 dir fwd priority 1564639 ptype main src 192.1.3.254/32 dst 192.1.2.23/32 dir in priority 1564639 ptype main src 10.0.10.1/32 dst 192.1.2.23/32 dir fwd priority 2088927 ptype main tmpl src 192.1.2.254 dst 192.1.2.23 proto esp reqid 16425 mode tunnel src 10.0.10.1/32 dst 192.1.2.23/32 dir in priority 2088927 ptype main tmpl src 192.1.2.254 dst 192.1.2.23 proto esp reqid 16425 mode tunnel src 192.1.2.23/32 dst 10.0.10.1/32 dir out priority 2088927 ptype main tmpl src 192.1.2.23 dst 192.1.2.254 proto esp reqid 16425 mode tunnel src 192.1.2.23/32 dst 192.1.2.0/24 dir out priority 2088935 ptype main tmpl src 0.0.0.0 dst 0.0.0.0 proto esp reqid 0 mode transport XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES ROUTING TABLES default via 192.1.2.254 dev eth1 192.0.1.0/24 via 192.1.2.45 dev eth1 192.0.2.0/24 dev eth0 proto kernel scope link src 192.0.2.254 192.1.2.0/24 dev eth1 proto kernel scope link src 192.1.2.23 NSS_CERTIFICATES Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# : ==== cut ==== kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# ipsec auto --status 000 using kernel interface: netkey 000 interface lo/lo 127.0.0.1:4500 000 interface lo/lo 127.0.0.1:500 000 interface eth0/eth0 192.0.2.254:4500 000 interface eth0/eth0 192.0.2.254:500 000 interface eth1/eth1 192.1.2.23:4500 000 interface eth1/eth1 192.1.2.23:500 000 000 000 fips mode=disabled; 000 SElinux=disabled 000 seccomp=disabled 000 000 config setup options: 000 000 configdir=/etc, configfile=/etc/ipsec.conf, secrets=/etc/ipsec.secrets, ipsecdir=/etc/ipsec.d 000 nssdir=/etc/ipsec.d, dumpdir=/tmp, statsbin=unset 000 dnssec-rootkey-file=/var/lib/unbound/root.key, dnssec-trusted= 000 sbindir=/usr/local/sbin, libexecdir=/usr/local/libexec/ipsec 000 pluto_version=v3.28-685-gbfd5aef521-master-s2, pluto_vendorid=OE-Libreswan-v3.28-685, audit-log=yes 000 nhelpers=-1, uniqueids=yes, dnssec-enable=yes, perpeerlog=no, logappend=no, logip=yes, shuntlifetime=900s, xfrmlifetime=30s 000 ddos-cookies-threshold=50000, ddos-max-halfopen=25000, ddos-mode=auto 000 ikeport=500, ikebuf=0, msg_errqueue=yes, strictcrlpolicy=no, crlcheckinterval=0, listen=, nflog-all=0 000 ocsp-enable=no, ocsp-strict=no, ocsp-timeout=2, ocsp-uri= 000 ocsp-trust-name= 000 ocsp-cache-size=1000, ocsp-cache-min-age=3600, ocsp-cache-max-age=86400, ocsp-method=get 000 global-redirect=no, global-redirect-to= 000 secctx-attr-type=32001 000 debug: base+cpu-usage 000 000 nat-traversal=yes, keep-alive=20, nat-ikeport=4500 000 virtual-private (%priv): 000 000 Kernel algorithms supported: 000 000 algorithm ESP encrypt: name=3DES_CBC, keysizemin=192, keysizemax=192 000 algorithm ESP encrypt: name=AES_CBC, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=AES_CCM_12, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=AES_CCM_16, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=AES_CCM_8, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=AES_CTR, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=AES_GCM_12, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=AES_GCM_16, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=AES_GCM_8, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=CAMELLIA_CBC, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=CHACHA20_POLY1305, keysizemin=256, keysizemax=256 000 algorithm ESP encrypt: name=NULL, keysizemin=0, keysizemax=0 000 algorithm ESP encrypt: name=NULL_AUTH_AES_GMAC, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=SERPENT_CBC, keysizemin=128, keysizemax=256 000 algorithm ESP encrypt: name=TWOFISH_CBC, keysizemin=128, keysizemax=256 000 algorithm AH/ESP auth: name=AES_CMAC_96, key-length=128 000 algorithm AH/ESP auth: name=AES_XCBC_96, key-length=128 000 algorithm AH/ESP auth: name=HMAC_MD5_96, key-length=128 000 algorithm AH/ESP auth: name=HMAC_SHA1_96, key-length=160 000 algorithm AH/ESP auth: name=HMAC_SHA2_256_128, key-length=256 000 algorithm AH/ESP auth: name=HMAC_SHA2_256_TRUNCBUG, key-length=256 000 algorithm AH/ESP auth: name=HMAC_SHA2_384_192, key-length=384 000 algorithm AH/ESP auth: name=HMAC_SHA2_512_256, key-length=512 000 algorithm AH/ESP auth: name=NONE, key-length=0 000 000 IKE algorithms supported: 000 000 algorithm IKE encrypt: v1id=5, v1name=OAKLEY_3DES_CBC, v2id=3, v2name=3DES, blocksize=8, keydeflen=192 000 algorithm IKE encrypt: v1id=8, v1name=OAKLEY_CAMELLIA_CBC, v2id=23, v2name=CAMELLIA_CBC, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=-1, v1name=n/a, v2id=20, v2name=AES_GCM_C, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=-1, v1name=n/a, v2id=19, v2name=AES_GCM_B, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=-1, v1name=n/a, v2id=18, v2name=AES_GCM_A, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=13, v1name=OAKLEY_AES_CTR, v2id=13, v2name=AES_CTR, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=7, v1name=OAKLEY_AES_CBC, v2id=12, v2name=AES_CBC, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=65004, v1name=OAKLEY_SERPENT_CBC, v2id=65004, v2name=SERPENT_CBC, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=65005, v1name=OAKLEY_TWOFISH_CBC, v2id=65005, v2name=TWOFISH_CBC, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=65289, v1name=OAKLEY_TWOFISH_CBC_SSH, v2id=65289, v2name=TWOFISH_CBC_SSH, blocksize=16, keydeflen=128 000 algorithm IKE encrypt: v1id=-1, v1name=n/a, v2id=28, v2name=CHACHA20_POLY1305, blocksize=16, keydeflen=256 000 algorithm IKE PRF: name=HMAC_MD5, hashlen=16 000 algorithm IKE PRF: name=HMAC_SHA1, hashlen=20 000 algorithm IKE PRF: name=HMAC_SHA2_256, hashlen=32 000 algorithm IKE PRF: name=HMAC_SHA2_384, hashlen=48 000 algorithm IKE PRF: name=HMAC_SHA2_512, hashlen=64 000 algorithm IKE PRF: name=AES_XCBC, hashlen=16 000 algorithm IKE DH Key Exchange: name=MODP1536, bits=1536 000 algorithm IKE DH Key Exchange: name=MODP2048, bits=2048 000 algorithm IKE DH Key Exchange: name=MODP3072, bits=3072 000 algorithm IKE DH Key Exchange: name=MODP4096, bits=4096 000 algorithm IKE DH Key Exchange: name=MODP6144, bits=6144 000 algorithm IKE DH Key Exchange: name=MODP8192, bits=8192 000 algorithm IKE DH Key Exchange: name=DH19, bits=512 000 algorithm IKE DH Key Exchange: name=DH20, bits=768 000 algorithm IKE DH Key Exchange: name=DH21, bits=1056 000 algorithm IKE DH Key Exchange: name=DH31, bits=256 000 000 stats db_ops: {curr_cnt, total_cnt, maxsz} :context={0,0,0} trans={0,0,0} attrs={0,0,0} 000 000 Connection list: 000 000 "block": 192.1.2.23---192.1.2.254...%group; unrouted; eroute owner: #0 000 "block": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "block": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "block": our auth:unset, their auth:unset 000 "block": modecfg info: us:none, them:none, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:unset; 000 "block": labeled_ipsec:no; 000 "block": policy_label:unset; 000 "block": ike_life: 0s; ipsec_life: 0s; replay_window: 0; rekey_margin: 0s; rekey_fuzz: 0%; keyingtries: 0; 000 "block": retransmit-interval: 0ms; retransmit-timeout: 0s; 000 "block": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "block": policy: AUTH_NEVER+GROUP+GROUTED+REJECT+NEVER_NEGOTIATE; 000 "block": conn_prio: 32,32; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "block": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; 000 "block": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "block": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "block": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear": 192.1.2.23---192.1.2.254...%group; unrouted; eroute owner: #0 000 "clear": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "clear": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "clear": our auth:unset, their auth:unset 000 "clear": modecfg info: us:none, them:none, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:unset; 000 "clear": labeled_ipsec:no; 000 "clear": policy_label:unset; 000 "clear": ike_life: 0s; ipsec_life: 0s; replay_window: 0; rekey_margin: 0s; rekey_fuzz: 0%; keyingtries: 0; 000 "clear": retransmit-interval: 0ms; retransmit-timeout: 0s; 000 "clear": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "clear": policy: AUTH_NEVER+GROUP+GROUTED+PASS+NEVER_NEGOTIATE; 000 "clear": conn_prio: 32,32; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; 000 "clear": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear#192.1.2.253/32": 192.1.2.23---192.1.2.254...%any; prospective erouted; eroute owner: #0 000 "clear#192.1.2.253/32": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "clear#192.1.2.253/32": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "clear#192.1.2.253/32": our auth:unset, their auth:unset 000 "clear#192.1.2.253/32": modecfg info: us:none, them:none, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:unset; 000 "clear#192.1.2.253/32": labeled_ipsec:no; 000 "clear#192.1.2.253/32": policy_label:unset; 000 "clear#192.1.2.253/32": ike_life: 0s; ipsec_life: 0s; replay_window: 0; rekey_margin: 0s; rekey_fuzz: 0%; keyingtries: 0; 000 "clear#192.1.2.253/32": retransmit-interval: 0ms; retransmit-timeout: 0s; 000 "clear#192.1.2.253/32": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "clear#192.1.2.253/32": policy: AUTH_NEVER+GROUPINSTANCE+PASS+NEVER_NEGOTIATE; 000 "clear#192.1.2.253/32": conn_prio: 32,32; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear#192.1.2.253/32": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; 000 "clear#192.1.2.253/32": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear#192.1.2.253/32": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear#192.1.2.253/32": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear#192.1.3.253/32": 192.1.2.23---192.1.2.254...%any; prospective erouted; eroute owner: #0 000 "clear#192.1.3.253/32": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "clear#192.1.3.253/32": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "clear#192.1.3.253/32": our auth:unset, their auth:unset 000 "clear#192.1.3.253/32": modecfg info: us:none, them:none, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:unset; 000 "clear#192.1.3.253/32": labeled_ipsec:no; 000 "clear#192.1.3.253/32": policy_label:unset; 000 "clear#192.1.3.253/32": ike_life: 0s; ipsec_life: 0s; replay_window: 0; rekey_margin: 0s; rekey_fuzz: 0%; keyingtries: 0; 000 "clear#192.1.3.253/32": retransmit-interval: 0ms; retransmit-timeout: 0s; 000 "clear#192.1.3.253/32": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "clear#192.1.3.253/32": policy: AUTH_NEVER+GROUPINSTANCE+PASS+NEVER_NEGOTIATE; 000 "clear#192.1.3.253/32": conn_prio: 32,32; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear#192.1.3.253/32": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; 000 "clear#192.1.3.253/32": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear#192.1.3.253/32": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear#192.1.3.253/32": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear#192.1.3.254/32": 192.1.2.23---192.1.2.254...%any; prospective erouted; eroute owner: #0 000 "clear#192.1.3.254/32": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "clear#192.1.3.254/32": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "clear#192.1.3.254/32": our auth:unset, their auth:unset 000 "clear#192.1.3.254/32": modecfg info: us:none, them:none, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:unset; 000 "clear#192.1.3.254/32": labeled_ipsec:no; 000 "clear#192.1.3.254/32": policy_label:unset; 000 "clear#192.1.3.254/32": ike_life: 0s; ipsec_life: 0s; replay_window: 0; rekey_margin: 0s; rekey_fuzz: 0%; keyingtries: 0; 000 "clear#192.1.3.254/32": retransmit-interval: 0ms; retransmit-timeout: 0s; 000 "clear#192.1.3.254/32": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "clear#192.1.3.254/32": policy: AUTH_NEVER+GROUPINSTANCE+PASS+NEVER_NEGOTIATE; 000 "clear#192.1.3.254/32": conn_prio: 32,32; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear#192.1.3.254/32": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; 000 "clear#192.1.3.254/32": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear#192.1.3.254/32": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear#192.1.3.254/32": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear-or-private": 192.1.2.23[ID_NULL,+MC+CAT+S=C]---192.1.2.254...%opportunisticgroup[ID_NULL,MS+S=C]; unrouted; eroute owner: #0 000 "clear-or-private": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "clear-or-private": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "clear-or-private": our auth:null, their auth:null 000 "clear-or-private": modecfg info: us:client, them:server, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:set; 000 "clear-or-private": labeled_ipsec:no; 000 "clear-or-private": policy_label:unset; 000 "clear-or-private": ike_life: 3600s; ipsec_life: 28800s; replay_window: 32; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; 000 "clear-or-private": retransmit-interval: 500ms; retransmit-timeout: 60s; 000 "clear-or-private": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "clear-or-private": policy: AUTHNULL+ENCRYPT+TUNNEL+PFS+NEGO_PASS+OPPORTUNISTIC+GROUP+IKEV2_ALLOW+IKEV2_ALLOW_NARROWING+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO+failurePASS; 000 "clear-or-private": conn_prio: 32,0; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear-or-private": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:auto; 000 "clear-or-private": our idtype: ID_NULL; our id=ID_NULL; their idtype: ID_NULL; their id=ID_NULL 000 "clear-or-private": dpd: action:hold; delay:0; timeout:0; nat-t: encaps:auto; nat_keepalive:yes; ikev1_natt:both 000 "clear-or-private": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "private": 192.1.2.23[ID_NULL,+MC+CAT+S=C]---192.1.2.254...%opportunisticgroup[ID_NULL,MS+S=C]; unrouted; eroute owner: #0 000 "private": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "private": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "private": our auth:null, their auth:null 000 "private": modecfg info: us:client, them:server, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:set; 000 "private": labeled_ipsec:no; 000 "private": policy_label:unset; 000 "private": ike_life: 3600s; ipsec_life: 28800s; replay_window: 32; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; 000 "private": retransmit-interval: 500ms; retransmit-timeout: 60s; 000 "private": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "private": policy: AUTHNULL+ENCRYPT+TUNNEL+PFS+OPPORTUNISTIC+GROUP+GROUTED+IKEV2_ALLOW+IKEV2_ALLOW_NARROWING+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO+failureDROP; 000 "private": conn_prio: 32,0; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "private": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:auto; 000 "private": our idtype: ID_NULL; our id=ID_NULL; their idtype: ID_NULL; their id=ID_NULL 000 "private": dpd: action:hold; delay:0; timeout:0; nat-t: encaps:auto; nat_keepalive:yes; ikev1_natt:both 000 "private": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "private-or-clear": 192.1.2.23[ID_NULL,+MC+CAT+S=C]---192.1.2.254...%opportunisticgroup[ID_NULL,MS+S=C]; unrouted; eroute owner: #0 000 "private-or-clear": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "private-or-clear": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "private-or-clear": our auth:null, their auth:null 000 "private-or-clear": modecfg info: us:client, them:server, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:set; 000 "private-or-clear": labeled_ipsec:no; 000 "private-or-clear": policy_label:unset; 000 "private-or-clear": ike_life: 3600s; ipsec_life: 28800s; replay_window: 32; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; 000 "private-or-clear": retransmit-interval: 500ms; retransmit-timeout: 60s; 000 "private-or-clear": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "private-or-clear": policy: AUTHNULL+ENCRYPT+TUNNEL+PFS+NEGO_PASS+OPPORTUNISTIC+GROUP+GROUTED+IKEV2_ALLOW+IKEV2_ALLOW_NARROWING+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO+failurePASS; 000 "private-or-clear": conn_prio: 32,0; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "private-or-clear": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:auto; 000 "private-or-clear": our idtype: ID_NULL; our id=ID_NULL; their idtype: ID_NULL; their id=ID_NULL 000 "private-or-clear": dpd: action:hold; delay:0; timeout:0; nat-t: encaps:auto; nat_keepalive:yes; ikev1_natt:both 000 "private-or-clear": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "private-or-clear#192.1.2.0/24": 192.1.2.23[ID_NULL,+MC+CAT+S=C]---192.1.2.254...%opportunistic[ID_NULL,MS+S=C]===192.1.2.0/24; prospective erouted; eroute owner: #0 000 "private-or-clear#192.1.2.0/24": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "private-or-clear#192.1.2.0/24": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "private-or-clear#192.1.2.0/24": our auth:null, their auth:null 000 "private-or-clear#192.1.2.0/24": modecfg info: us:client, them:server, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:set; 000 "private-or-clear#192.1.2.0/24": labeled_ipsec:no; 000 "private-or-clear#192.1.2.0/24": policy_label:unset; 000 "private-or-clear#192.1.2.0/24": ike_life: 3600s; ipsec_life: 28800s; replay_window: 32; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; 000 "private-or-clear#192.1.2.0/24": retransmit-interval: 500ms; retransmit-timeout: 60s; 000 "private-or-clear#192.1.2.0/24": initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "private-or-clear#192.1.2.0/24": policy: AUTHNULL+ENCRYPT+TUNNEL+PFS+NEGO_PASS+OPPORTUNISTIC+GROUPINSTANCE+IKEV2_ALLOW+IKEV2_ALLOW_NARROWING+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO+failurePASS; 000 "private-or-clear#192.1.2.0/24": conn_prio: 32,0; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "private-or-clear#192.1.2.0/24": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:auto; 000 "private-or-clear#192.1.2.0/24": our idtype: ID_NULL; our id=ID_NULL; their idtype: ID_NULL; their id=ID_NULL 000 "private-or-clear#192.1.2.0/24": dpd: action:hold; delay:0; timeout:0; nat-t: encaps:auto; nat_keepalive:yes; ikev1_natt:both 000 "private-or-clear#192.1.2.0/24": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "private-or-clear#192.1.2.0/24"[1]: 192.1.2.23[ID_NULL,+MC+CAT+S=C]...192.1.2.254[ID_NULL,MS+S=C]===10.0.10.1/32; erouted; eroute owner: #2 000 "private-or-clear#192.1.2.0/24"[1]: oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "private-or-clear#192.1.2.0/24"[1]: xauth us:none, xauth them:none, my_username=[any]; their_username=[any] 000 "private-or-clear#192.1.2.0/24"[1]: our auth:null, their auth:null 000 "private-or-clear#192.1.2.0/24"[1]: modecfg info: us:client, them:server, modecfg policy:push, dns:unset, domains:unset, banner:unset, cat:set; 000 "private-or-clear#192.1.2.0/24"[1]: labeled_ipsec:no; 000 "private-or-clear#192.1.2.0/24"[1]: policy_label:unset; 000 "private-or-clear#192.1.2.0/24"[1]: ike_life: 3600s; ipsec_life: 28800s; replay_window: 32; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; 000 "private-or-clear#192.1.2.0/24"[1]: retransmit-interval: 500ms; retransmit-timeout: 60s; 000 "private-or-clear#192.1.2.0/24"[1]: initial-contact:no; cisco-unity:no; fake-strongswan:no; send-vendorid:no; send-no-esp-tfc:no; 000 "private-or-clear#192.1.2.0/24"[1]: policy: AUTHNULL+ENCRYPT+TUNNEL+PFS+NEGO_PASS+OPPORTUNISTIC+GROUPINSTANCE+IKEV2_ALLOW+IKEV2_ALLOW_NARROWING+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO+failurePASS; 000 "private-or-clear#192.1.2.0/24"[1]: conn_prio: 32,0; interface: eth1; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "private-or-clear#192.1.2.0/24"[1]: nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:auto; 000 "private-or-clear#192.1.2.0/24"[1]: our idtype: ID_NULL; our id=ID_NULL; their idtype: ID_NULL; their id=ID_NULL 000 "private-or-clear#192.1.2.0/24"[1]: dpd: action:hold; delay:0; timeout:0; nat-t: encaps:auto; nat_keepalive:yes; ikev1_natt:both 000 "private-or-clear#192.1.2.0/24"[1]: newest ISAKMP SA: #1; newest IPsec SA: #2; 000 "private-or-clear#192.1.2.0/24"[1]: IKEv2 algorithm newest: AES_GCM_16_256-HMAC_SHA2_512-MODP2048 000 "private-or-clear#192.1.2.0/24"[1]: ESP algorithm newest: AES_GCM_16_256-NONE; pfsgroup= 000 000 Total IPsec connections: loaded 10, active 1 000 000 State Information: DDoS cookies not required, Accepting new IKE connections 000 IKE SAs: total(1), half-open(0), open(0), authenticated(0), anonymous(1) 000 IPsec SAs: total(1), authenticated(0), anonymous(1) 000 000 #1: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.254===10.0.10.1/32:4500 STATE_PARENT_R2 (received v2I2, PARENT SA established); EVENT_SA_REKEY in 3325s; newest ISAKMP; idle; 000 #2: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.254===10.0.10.1/32:4500 STATE_V2_IPSEC_R (IPsec SA established); EVENT_SA_EXPIRE in 28795s; newest IPSEC; eroute owner; isakmp#1; idle; 000 #2: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.254===10.0.10.1/32 esp.dac59dec@192.1.2.254 esp.693a9a70@192.1.2.23 tun.0@192.1.2.254 tun.0@192.1.2.23 ref=0 refhim=0 Traffic: ESPin=252B ESPout=252B! ESPmax=0B 000 000 Bare Shunt list: 000 kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# : ==== tuc ==== kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# ../bin/check-for-core.sh kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# if [ -f /sbin/ausearch ]; then ausearch -r -m avc -ts recent ; fi type=AVC msg=audit(1566825527.833:204064): avc: denied { write } for pid=16463 comm="ip" path="/tmp/pluto.log" dev="dm-0" ino=578489871 scontext=unconfined_u:system_r:ifconfig_t:s0 tcontext=unconfined_u:object_r:container_file_t:s0:c718,c778 tclass=file permissive=1 type=AVC msg=audit(1566825528.477:204084): avc: denied { write } for pid=17089 comm="ip" path="/tmp/pluto.log" dev="dm-0" ino=1013371129 scontext=unconfined_u:system_r:ifconfig_t:s0 tcontext=unconfined_u:object_r:container_file_t:s0:c718,c778 tclass=file permissive=1 kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]# : ==== end ==== kroot@swantest:/home/build/libreswan/testing/pluto/newoe-25-cat-1\[root@east newoe-25-cat-1]#