--- road.console.txt 2019-08-24 18:12:56.315672445 +0000 +++ OUTPUT/road.console.txt 2019-08-26 13:18:52.154188941 +0000 @@ -128,7 +128,7 @@ 000 "block": policy: AUTH_NEVER+GROUP+GROUTED+REJECT+NEVER_NEGOTIATE; 000 "block": conn_prio: 32,32; interface: eth0; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "block": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; -000 "block": our idtype: ID_IPV4_ADDR; our id=192.1.3.209; their idtype: %none; their id=(none) +000 "block": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "block": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "block": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear": 192.1.3.209---192.1.3.254...%group; unrouted; eroute owner: #0 @@ -144,7 +144,7 @@ 000 "clear": policy: AUTH_NEVER+GROUP+GROUTED+PASS+NEVER_NEGOTIATE; 000 "clear": conn_prio: 32,32; interface: eth0; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; -000 "clear": our idtype: ID_IPV4_ADDR; our id=192.1.3.209; their idtype: %none; their id=(none) +000 "clear": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear#192.1.2.253/32": 192.1.3.209---192.1.3.254...%any; prospective erouted; eroute owner: #0 @@ -160,7 +160,7 @@ 000 "clear#192.1.2.253/32": policy: AUTH_NEVER+GROUPINSTANCE+PASS+NEVER_NEGOTIATE; 000 "clear#192.1.2.253/32": conn_prio: 32,32; interface: eth0; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear#192.1.2.253/32": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; -000 "clear#192.1.2.253/32": our idtype: ID_IPV4_ADDR; our id=192.1.3.209; their idtype: %none; their id=(none) +000 "clear#192.1.2.253/32": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear#192.1.2.253/32": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear#192.1.2.253/32": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear#192.1.3.253/32": 192.1.3.209---192.1.3.254...%any; prospective erouted; eroute owner: #0 @@ -176,7 +176,7 @@ 000 "clear#192.1.3.253/32": policy: AUTH_NEVER+GROUPINSTANCE+PASS+NEVER_NEGOTIATE; 000 "clear#192.1.3.253/32": conn_prio: 32,32; interface: eth0; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear#192.1.3.253/32": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; -000 "clear#192.1.3.253/32": our idtype: ID_IPV4_ADDR; our id=192.1.3.209; their idtype: %none; their id=(none) +000 "clear#192.1.3.253/32": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear#192.1.3.253/32": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear#192.1.3.253/32": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear#192.1.3.254/32": 192.1.3.209---192.1.3.254...%any; prospective erouted; eroute owner: #0 @@ -192,7 +192,7 @@ 000 "clear#192.1.3.254/32": policy: AUTH_NEVER+GROUPINSTANCE+PASS+NEVER_NEGOTIATE; 000 "clear#192.1.3.254/32": conn_prio: 32,32; interface: eth0; metric: 0; mtu: unset; sa_prio:auto; sa_tfc:none; 000 "clear#192.1.3.254/32": nflog-group: unset; mark: unset; vti-iface:unset; vti-routing:no; vti-shared:no; nic-offload:no; -000 "clear#192.1.3.254/32": our idtype: ID_IPV4_ADDR; our id=192.1.3.209; their idtype: %none; their id=(none) +000 "clear#192.1.3.254/32": our idtype: ID_IPV4_ADDR; our id=%any; their idtype: %none; their id=(none) 000 "clear#192.1.3.254/32": dpd: action:disabled; delay:0; timeout:0; nat-t: encaps:no; nat_keepalive:no; ikev1_natt:both 000 "clear#192.1.3.254/32": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "clear-or-private": 192.1.3.209[ID_NULL,+MC+CAT+S=C]---192.1.3.254...%opportunisticgroup[ID_NULL,MS+S=C]; unrouted; eroute owner: #0 @@ -319,7 +319,6 @@ killall ip > /dev/null 2> /dev/null road # cp /tmp/xfrm-monitor.out OUTPUT/road.xfrm-monitor.txt -cp: cannot stat '/tmp/xfrm-monitor.out': No such file or directory road # # ping should succeed through tunnel road #