--- west.console.txt 2019-08-24 18:12:56.290673326 +0000 +++ OUTPUT/west.console.txt 2019-08-26 18:36:46.005385128 +0000 @@ -14,7 +14,6 @@ # confirm clear text does not get through west # ../../pluto/bin/ping-once.sh --down -I 192.0.1.254 192.0.2.254 -[ 00.00] IN=eth1 OUT= MAC=12:00:00:64:64:45:12:00:00:64:64:23:08:00 SRC=192.0.2.254 DST=192.0.1.254 LEN=XXXX TOS=0x00 PREC=0x00 TTL=64 ID=XXXXX PROTO=ICMP TYPE=0 CODE=0 ID=XXXX SEQ=1 down west # ipsec start @@ -101,6 +100,8 @@ echo "initdone" initdone west # + +west # ipsec whack --impair suppress-retransmits west # ipsec auto --up westnet-eastnet-subnets @@ -117,13 +118,13 @@ 002 "westnet-eastnet-subnets/2x1" #4: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO 002 "westnet-eastnet-subnets/2x2" #5: initiating Quick Mode RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO 1v1 "westnet-eastnet-subnets/1x1" #2: STATE_QUICK_I1: initiate -1v1 "westnet-eastnet-subnets/2x1" #4: STATE_QUICK_I1: initiate 1v1 "westnet-eastnet-subnets/2x2" #5: STATE_QUICK_I1: initiate 1v1 "westnet-eastnet-subnets/1x2" #3: STATE_QUICK_I1: initiate +1v1 "westnet-eastnet-subnets/2x1" #4: STATE_QUICK_I1: initiate 004 "westnet-eastnet-subnets/1x1" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} -004 "westnet-eastnet-subnets/2x1" #4: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} -004 "westnet-eastnet-subnets/2x2" #5: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} 004 "westnet-eastnet-subnets/1x2" #3: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} +004 "westnet-eastnet-subnets/2x2" #5: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} +004 "westnet-eastnet-subnets/2x1" #4: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive} west # ipsec whack --trafficstatus 006 #2: "westnet-eastnet-subnets/1x1", type=ESP, add_time=1234567890, inBytes=0, outBytes=0, id='@east'