iptables -t nat -F kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# iptables -F kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# ip addr add 192.1.3.130/24 dev eth1 kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# # Destination NAT to east's address not the port kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# iptables -t nat -A PREROUTING -d 192.1.3.130 -j DNAT --to-destination 192.1.2.23 kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# # A tunnel should have established with non-zero byte counters kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# ip addr show scope global 2: ip_vti0@NONE: mtu 1480 qdisc noop state DOWN group default qlen 1000 link/ipip 0.0.0.0 brd 0.0.0.0 26136: eth0@if26137: mtu 1500 qdisc noqueue state UP group default qlen 1000 Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. link/ether ee:eb:c0:ef:47:04 brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 192.1.2.254/24 scope global eth0 valid_lft forever preferred_lft forever 26141: eth1@if26142: mtu 1500 qdisc noqueue state UP group default qlen 1000 link/ether 12:4c:7d:a4:6f:d9 brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 192.1.3.254/24 scope global eth1 valid_lft forever preferred_lft forever inet 192.1.3.130/24 scope global secondary eth1 valid_lft forever preferred_lft forever kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# # jacob two two for east? kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# ipsec whack --trafficstatus whack: Pluto is not running (no "/run/pluto/pluto.ctl") kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server 33]# >>>>>>>>>>cutnonzeroexit>>>>>>>>>> exit status 33 final.sh 'ipsec whack --trafficstatus' <<<<<<<<<>>>>>>>>>cutnonzeroexit>>>>>>>>>> exit status 33 final.sh 'ipsec whack --trafficstatus' <<<<<<<<<>>>>>>>>>cutnonzeroexit>>>>>>>>>> exit status 1 final.sh 'grep IKEv2_AUTH_ /tmp/pluto.log' <<<<<<<<<>>>>>>>>>cutnonzeroexit>>>>>>>>>> exit status 33 final.sh 'ipsec auto --status' <<<<<<<<< mtu 1480 qdisc noop state DOWN group default qlen 1000 link/ipip 0.0.0.0 brd 0.0.0.0 26136: eth0@if26137: mtu 1500 qdisc noqueue state UP group default qlen 1000 Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. Error: Peer netns reference is invalid. link/ether ee:eb:c0:ef:47:04 brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 192.1.2.254/24 scope global eth0 valid_lft forever preferred_lft forever 26141: eth1@if26142: mtu 1500 qdisc noqueue state UP group default qlen 1000 link/ether 12:4c:7d:a4:6f:d9 brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet 192.1.3.254/24 scope global eth1 valid_lft forever preferred_lft forever inet 192.1.3.130/24 scope global secondary eth1 valid_lft forever preferred_lft forever kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# : ==== tuc ==== kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# ../bin/check-for-core.sh kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# if [ -f /sbin/ausearch ]; then ausearch -r -m avc -ts recent ; fi type=AVC msg=audit(1566844133.486:265910): avc: denied { write } for pid=7504 comm="ip" path="/tmp/pluto.log" dev="dm-0" ino=295084539 scontext=unconfined_u:system_r:ifconfig_t:s0 tcontext=unconfined_u:object_r:container_file_t:s0:c718,c778 tclass=file permissive=1 type=AVC msg=audit(1566844133.996:266013): avc: denied { write } for pid=8463 comm="ip" path="/tmp/pluto.log" dev="dm-0" ino=63889669 scontext=unconfined_u:system_r:ifconfig_t:s0 tcontext=unconfined_u:object_r:container_file_t:s0:c718,c778 tclass=file permissive=1 type=AVC msg=audit(1566844326.654:277839): avc: denied { write } for pid=19198 comm="ip" path="/tmp/pluto.log" dev="dm-0" ino=1016665168 scontext=unconfined_u:system_r:ifconfig_t:s0 tcontext=unconfined_u:object_r:container_file_t:s0:c718,c778 tclass=file permissive=1 kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]# : ==== end ==== kroot@swantest:/home/build/libreswan/testing/pluto/certoe-12-nat-server\[root@nic certoe-12-nat-server]#