--- road.console.txt	2019-08-24 18:12:56.104679882 +0000
+++ OUTPUT/road.console.txt	2019-08-26 18:32:03.704268910 +0000
@@ -44,7 +44,6 @@
  # should show established tunnel and no bare shunts
 road #
  ipsec whack --trafficstatus
-006 #2: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.23, type=ESP, add_time=1234567890, inBytes=0, outBytes=0, id='ID_NULL'
 road #
  ipsec whack --shuntstatus
 000 Bare Shunt list:
@@ -55,25 +54,13 @@
 XFRM state:
 src 192.1.2.23 dst 192.1.3.209
 	proto esp spi 0xSPISPI reqid REQID mode tunnel
-	replay-window 32 flag af-unspec
-	aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128
-src 192.1.3.209 dst 192.1.2.23
-	proto esp spi 0xSPISPI reqid REQID mode tunnel
-	replay-window 32 flag af-unspec
-	aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128
+	replay-window 0 
+	sel src 192.1.2.23/32 dst 192.1.3.209/32 
 src 192.1.3.209 dst 192.1.2.23
 	proto esp spi 0xSPISPI reqid REQID mode transport
 	replay-window 0 
 	sel src 192.1.3.209/32 dst 192.1.2.23/32 proto icmp type 8 code 0 dev eth0 
 XFRM policy:
-src 192.1.2.23/32 dst 192.1.3.209/32
-	dir fwd priority 1564639 ptype main
-	tmpl src 192.1.2.23 dst 192.1.3.209
-		proto esp reqid REQID mode tunnel
-src 192.1.2.23/32 dst 192.1.3.209/32
-	dir in priority 1564639 ptype main
-	tmpl src 192.1.2.23 dst 192.1.3.209
-		proto esp reqid REQID mode tunnel
 src 192.1.2.253/32 dst 192.1.3.209/32
 	dir fwd priority 1564639 ptype main
 src 192.1.2.253/32 dst 192.1.3.209/32
@@ -82,10 +69,6 @@
 	dir fwd priority 1564639 ptype main
 src 192.1.2.254/32 dst 192.1.3.209/32
 	dir in priority 1564639 ptype main
-src 192.1.3.209/32 dst 192.1.2.23/32
-	dir out priority 1564639 ptype main
-	tmpl src 192.1.3.209 dst 192.1.2.23
-		proto esp reqid REQID mode tunnel
 src 192.1.3.209/32 dst 192.1.2.253/32
 	dir out priority 1564639 ptype main
 src 192.1.3.209/32 dst 192.1.2.254/32
@@ -106,6 +89,8 @@
 	dir out priority 1564647 ptype main
 	tmpl src 0.0.0.0 dst 0.0.0.0
 		proto esp reqid REQID mode transport
+src 192.1.3.209/32 dst 192.1.2.23/32
+	dir out priority 1564647 ptype main
 XFRM done
 IPSEC mangle TABLES
 NEW_IPSEC_CONN mangle TABLES
@@ -132,11 +117,8 @@
 road #
  ping -n -c 2 -I 192.1.3.209 192.1.2.23
 PING 192.1.2.23 (192.1.2.23) from 192.1.3.209 : 56(84) bytes of data.
-64 bytes from 192.1.2.23: icmp_seq=1 ttl=64 time=0.XXX ms
-64 bytes from 192.1.2.23: icmp_seq=2 ttl=64 time=0.XXX ms
 --- 192.1.2.23 ping statistics ---
-2 packets transmitted, 2 received, 0% packet loss, time XXXX
-rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms
+2 packets transmitted, 0 received, 100% packet loss, time XXXX
 road #
  echo done
 done
@@ -144,18 +126,14 @@
  # A tunnel should have established with non-zero byte counters
 road #
  ipsec whack --trafficstatus
-006 #2: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.23, type=ESP, add_time=1234567890, inBytes=168, outBytes=168, id='ID_NULL'
 road #
  grep "negotiated connection" /tmp/pluto.log
-"private-or-clear#192.1.2.0/24"[1] ...192.1.2.23 #2: negotiated connection [192.1.3.209-192.1.3.209:0-65535 0] -> [192.1.2.23-192.1.2.23:0-65535 0]
 road #
  # you should see both RSA and NULL
 road #
  grep IKEv2_AUTH_ OUTPUT/*pluto.log
 OUTPUT/east.pluto.log:|    auth method: IKEv2_AUTH_RSA (0x1)
-OUTPUT/east.pluto.log:|    auth method: IKEv2_AUTH_NULL (0xd)
 OUTPUT/road.pluto.log:|    auth method: IKEv2_AUTH_RSA (0x1)
-OUTPUT/road.pluto.log:|    auth method: IKEv2_AUTH_NULL (0xd)
 road #
 road #
  ../bin/check-for-core.sh