--- road.console.txt 2019-08-24 18:12:56.335671740 +0000 +++ OUTPUT/road.console.txt 2019-08-26 13:26:42.533720220 +0000 @@ -21,15 +21,31 @@ 002 "x509" #1: I am sending my cert 002 "x509" #1: I am sending a certificate request 1v1 "x509" #1: STATE_MAIN_I3: sent MI3, expecting MR3 -[ 00.00] IN=eth0 OUT= MAC=12:00:00:ab:cd:02:12:00:00:32:64:ba:08:00 SRC=192.1.2.23 DST=192.1.3.209 LEN=XXXX TOS=0x00 PREC=0x00 TTL=63 ID=XXXXX PROTO=UDP SPT=500 DPT=500 LEN=XXXX +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION 010 "x509" #1: STATE_MAIN_I3: retransmission; will wait 0.5 seconds for response -002 "x509" #1: Peer ID is ID_DER_ASN1_DN: 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org' -002 "x509" #1: certificate verified OK: E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA -003 "x509" #1: Authenticated using RSA -004 "x509" #1: STATE_MAIN_I4: ISAKMP SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP2048} -002 "x509" #2: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+IKE_FRAG_FORCE+ESN_NO -1v1 "x509" #2: STATE_QUICK_I1: initiate -004 "x509" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION +010 "x509" #1: STATE_MAIN_I3: retransmission; will wait 1 seconds for response +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION +010 "x509" #1: STATE_MAIN_I3: retransmission; will wait 2 seconds for response +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION +010 "x509" #1: STATE_MAIN_I3: retransmission; will wait 4 seconds for response +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION +010 "x509" #1: STATE_MAIN_I3: retransmission; will wait 8 seconds for response +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION +010 "x509" #1: STATE_MAIN_I3: retransmission; will wait 16 seconds for response +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION +010 "x509" #1: STATE_MAIN_I3: retransmission; will wait 32 seconds for response +003 "x509" #1: ignoring informational payload INVALID_ID_INFORMATION, msgid=00000000, length=12 +003 "x509" #1: received and ignored notification payload: INVALID_ID_INFORMATION +031 "x509" #1: STATE_MAIN_I3: 60 second timeout exceeded after 7 retransmits. Possible authentication failure: no acceptable response to our first encrypted message +000 "x509" #1: starting keying attempt 2 of an unlimited number, but releasing whack road # echo done done @@ -46,19 +62,47 @@ | sending IKE fragment id '1', number '3' | sending IKE fragment id '1', number '4' | sending IKE fragment id '1', number '5' (last) -| fragment id: 1 (0x1) -| fragment number: 1 (0x1) -| received IKE fragment id '1', number '1' -| fragment id: 1 (0x1) -| fragment number: 2 (0x2) -| received IKE fragment id '1', number '2' -| fragment id: 1 (0x1) -| fragment number: 3 (0x3) -| received IKE fragment id '1', number '3' -| fragment id: 1 (0x1) -| fragment number: 4 (0x4) -| received IKE fragment id '1', number '4'(last) -| updated IKE fragment state to respond using fragments without waiting for re-transmits +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) +| peer supports fragmentation +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) +| sending IKE fragment id '1', number '1' +| sending IKE fragment id '1', number '2' +| sending IKE fragment id '1', number '3' +| sending IKE fragment id '1', number '4' +| sending IKE fragment id '1', number '5' (last) road # road # ../bin/check-for-core.sh