--- east.console.txt 2019-08-24 18:12:56.160677908 +0000 +++ OUTPUT/east.console.txt 2019-08-26 18:26:40.987567695 +0000 @@ -13,57 +13,12 @@ initdone east # ipsec whack --trafficstatus -006 #2: "pool-eastnet-ikev2"[1] 192.1.2.254, type=ESP, add_time=1234567890, inBytes=336, outBytes=336, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org', lease=192.0.2.100/32 -006 #4: "pool-eastnet-ikev2"[2] 192.1.2.254, type=ESP, add_time=1234567890, inBytes=0, outBytes=0, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=road.testing.libreswan.org, E=user-road@testing.libreswan.org', lease=192.0.2.101/32 +whack: Pluto is not running (no "/run/pluto/pluto.ctl") east # ../../pluto/bin/ipsec-look.sh | sed "s/dport [0-9][0-9][0-9][0-9][0-9]/dport DPORT/" east NOW XFRM state: -src 192.1.2.254 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 - encap type espinudp sport SPORT dport 4500 addr 0.0.0.0 -src 192.1.2.23 dst 192.1.2.254 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 - encap type espinudp sport 4500 dport DPORT addr 0.0.0.0 -src 192.1.2.254 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 - encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 -src 192.1.2.23 dst 192.1.2.254 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 - encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 XFRM policy: -src 0.0.0.0/0 dst 192.0.2.100/32 - dir out priority 1048543 ptype main - tmpl src 192.1.2.23 dst 192.1.2.254 - proto esp reqid REQID mode tunnel -src 0.0.0.0/0 dst 192.0.2.101/32 - dir out priority 1048543 ptype main - tmpl src 192.1.2.23 dst 192.1.2.254 - proto esp reqid REQID mode tunnel -src 192.0.2.100/32 dst 0.0.0.0/0 - dir fwd priority 1048543 ptype main - tmpl src 192.1.2.254 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.2.100/32 dst 0.0.0.0/0 - dir in priority 1048543 ptype main - tmpl src 192.1.2.254 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.2.101/32 dst 0.0.0.0/0 - dir fwd priority 1048543 ptype main - tmpl src 192.1.2.254 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.2.101/32 dst 0.0.0.0/0 - dir in priority 1048543 ptype main - tmpl src 192.1.2.254 dst 192.1.2.23 - proto esp reqid REQID mode tunnel XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES @@ -71,8 +26,6 @@ default via 192.1.2.254 dev eth1 192.0.1.0/24 via 192.1.2.45 dev eth1 192.0.2.0/24 dev eth0 proto kernel scope link src 192.0.2.254 -192.0.2.100 dev eth1 scope link -192.0.2.101 dev eth1 scope link 192.1.2.0/24 dev eth1 proto kernel scope link src 192.1.2.23 NSS_CERTIFICATES Certificate Nickname Trust Attributes