/testing/guestbin/swan-prep west # # confirm that the network is alive west # ../../pluto/bin/wait-until-alive -I 192.0.1.254 192.0.2.254 destination -I 192.0.1.254 192.0.2.254 is alive west # # ensure that clear text does not get through west # iptables -A INPUT -i eth1 -s 192.0.2.0/24 -j LOGDROP west # iptables -I INPUT -m policy --dir in --pol ipsec -j ACCEPT west # # confirm clear text does not get through west # ../../pluto/bin/ping-once.sh --down -I 192.0.1.254 192.0.2.254 [ 00.00] IN=eth1 OUT= MAC=12:00:00:64:64:45:12:00:00:64:64:23:08:00 SRC=192.0.2.254 DST=192.0.1.254 LEN=XXXX TOS=0x00 PREC=0x00 TTL=64 ID=XXXXX PROTO=ICMP TYPE=0 CODE=0 ID=XXXX SEQ=1 down west # ipsec start Redirecting to: [initsystem] west # /testing/pluto/bin/wait-until-pluto-started west # ipsec whack --impair suppress-retransmits west # ipsec auto --add westnet-eastnet-ipcomp 002 added connection description "westnet-eastnet-ipcomp" west # echo "initdone" initdone west # ipsec auto --up westnet-eastnet-ipcomp 002 "westnet-eastnet-ipcomp" #1: initiating Main Mode 1v1 "westnet-eastnet-ipcomp" #1: STATE_MAIN_I1: initiate 1v1 "westnet-eastnet-ipcomp" #1: STATE_MAIN_I2: sent MI2, expecting MR2 1v1 "westnet-eastnet-ipcomp" #1: STATE_MAIN_I3: sent MI3, expecting MR3 002 "westnet-eastnet-ipcomp" #1: Peer ID is ID_FQDN: '@east' 003 "westnet-eastnet-ipcomp" #1: Authenticated using RSA 004 "westnet-eastnet-ipcomp" #1: STATE_MAIN_I4: ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP2048} 002 "westnet-eastnet-ipcomp" #2: initiating Quick Mode RSASIG+ENCRYPT+COMPRESS+TUNNEL+PFS+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO 1v1 "westnet-eastnet-ipcomp" #2: STATE_QUICK_I1: initiate 004 "westnet-eastnet-ipcomp" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 IPCOMP=>0xESPESP <0xESPESP NATOA=none NATD=none DPD=passive} west # ping -n -c 4 -I 192.0.1.254 192.0.2.254 PING 192.0.2.254 (192.0.2.254) from 192.0.1.254 : 56(84) bytes of data. 64 bytes from 192.0.2.254: icmp_seq=1 ttl=64 time=0.XXX ms 64 bytes from 192.0.2.254: icmp_seq=2 ttl=64 time=0.XXX ms 64 bytes from 192.0.2.254: icmp_seq=3 ttl=64 time=0.XXX ms 64 bytes from 192.0.2.254: icmp_seq=4 ttl=64 time=0.XXX ms --- 192.0.2.254 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time XXXX rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms west # ipsec whack --trafficstatus 006 #2: "westnet-eastnet-ipcomp", type=ESP, add_time=1234567890, inBytes=336, outBytes=336, id='@east' west # echo done done west # ../../pluto/bin/ipsec-look.sh west NOW XFRM state: src 192.1.2.23 dst 192.1.2.45 proto esp spi 0xSPISPI reqid REQID mode transport replay-window 32 auth-trunc hmac(sha1) 0xHASHKEY 96 enc cbc(aes) 0xENCKEY sel src 0.0.0.0/0 dst 0.0.0.0/0 src 192.1.2.23 dst 192.1.2.45 proto comp spi 0xSPISPI reqid REQID mode tunnel replay-window 0 flag af-unspec comp deflate src 192.1.2.23 dst 192.1.2.45 proto 4 spi 0xSPISPI reqid REQID mode tunnel replay-window 0 flag af-unspec src 192.1.2.45 dst 192.1.2.23 proto esp spi 0xSPISPI reqid REQID mode transport replay-window 32 auth-trunc hmac(sha1) 0xHASHKEY 96 enc cbc(aes) 0xENCKEY sel src 0.0.0.0/0 dst 0.0.0.0/0 src 192.1.2.45 dst 192.1.2.23 proto comp spi 0xSPISPI reqid REQID mode tunnel replay-window 0 flag af-unspec comp deflate src 192.1.2.45 dst 192.1.2.23 proto 4 spi 0xSPISPI reqid REQID mode tunnel replay-window 0 flag af-unspec XFRM policy: src 192.0.1.0/24 dst 192.0.2.0/24 dir out priority 1042407 ptype main tmpl src 192.1.2.45 dst 192.1.2.23 proto comp reqid REQID mode tunnel tmpl src 0.0.0.0 dst 0.0.0.0 proto esp reqid REQID mode transport src 192.0.2.0/24 dst 192.0.1.0/24 dir fwd priority 1042407 ptype main tmpl src 192.1.2.23 dst 192.1.2.45 proto comp reqid REQID mode tunnel level use tmpl src 0.0.0.0 dst 0.0.0.0 proto esp reqid REQID mode transport src 192.0.2.0/24 dst 192.0.1.0/24 dir in priority 1042407 ptype main tmpl src 192.1.2.23 dst 192.1.2.45 proto comp reqid REQID mode tunnel level use tmpl src 0.0.0.0 dst 0.0.0.0 proto esp reqid REQID mode transport XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES ROUTING TABLES default via 192.1.2.254 dev eth1 192.0.1.0/24 dev eth0 proto kernel scope link src 192.0.1.254 192.0.2.0/24 via 192.1.2.23 dev eth1 192.1.2.0/24 dev eth1 proto kernel scope link src 192.1.2.45 NSS_CERTIFICATES Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI west # west # ../bin/check-for-core.sh west # if [ -f /sbin/ausearch ]; then ausearch -r -m avc -ts recent ; fi