--- north.console.txt 2019-08-24 18:12:56.349671246 +0000 +++ OUTPUT/north.console.txt 2019-08-26 18:36:30.780918159 +0000 @@ -6,6 +6,7 @@ /testing/pluto/bin/wait-until-pluto-started north # ../bin/block-non-ipsec.sh +Another app is currently holding the xtables lock. Perhaps you want to use the -w option? north # ipsec auto --add north-east 002 added connection description "north-east" @@ -31,16 +32,16 @@ 002 "north-east" #2: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP+XAUTH+MODECFG_PULL+IKEV1_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO 1v1 "north-east" #2: STATE_QUICK_I1: initiate 002 "north-east" #2: up-client output: updating resolvconf +002 "north-east" #2: up-client output: rm: cannot remove '/etc/resolv.conf': Device or resource busy 004 "north-east" #2: STATE_QUICK_I2: sent QI2, IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 NATOA=none NATD=none DPD=passive username=xnorth} north # ping -q -n -c 4 -w 4 -I 192.0.2.201 192.0.2.254 PING 192.0.2.254 (192.0.2.254) from 192.0.2.201 : 56(84) bytes of data. --- 192.0.2.254 ping statistics --- -4 packets transmitted, 4 received, 0% packet loss, time XXXX -rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms +4 packets transmitted, 0 received, 100% packet loss, time XXXX north # ipsec whack --trafficstatus -006 #2: "north-east", username=xnorth, type=ESP, add_time=1234567890, inBytes=336, outBytes=336 +006 #2: "north-east", username=xnorth, type=ESP, add_time=1234567890, inBytes=0, outBytes=336 north # echo initdone initdone