--- east.console.txt 2019-09-20 17:49:12.349189580 +0000 +++ OUTPUT/east.console.txt 2019-09-21 07:17:29.626745523 +0000 @@ -14,7 +14,6 @@ east # ipsec whack --trafficstatus 006 #2: "pool-eastnet-ikev2"[1] 192.1.2.254, type=ESP, add_time=1234567890, inBytes=336, outBytes=336, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=north.testing.libreswan.org, E=user-north@testing.libreswan.org', lease=192.0.2.100/32 -006 #4: "pool-eastnet-ikev2"[2] 192.1.2.254, type=ESP, add_time=1234567890, inBytes=0, outBytes=0, id='C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=road.testing.libreswan.org, E=user-road@testing.libreswan.org', lease=192.0.2.101/32 east # ../../pluto/bin/ipsec-look.sh | sed "s/dport [0-9][0-9][0-9][0-9][0-9]/dport DPORT/" east NOW @@ -23,16 +22,6 @@ proto esp spi 0xSPISPI reqid REQID mode tunnel replay-window 32 flag af-unspec aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 - encap type espinudp sport SPORT dport 4500 addr 0.0.0.0 -src 192.1.2.23 dst 192.1.2.254 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 - encap type espinudp sport 4500 dport DPORT addr 0.0.0.0 -src 192.1.2.254 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 encap type espinudp sport 4500 dport 4500 addr 0.0.0.0 src 192.1.2.23 dst 192.1.2.254 proto esp spi 0xSPISPI reqid REQID mode tunnel @@ -44,10 +33,6 @@ dir out priority 1048543 ptype main tmpl src 192.1.2.23 dst 192.1.2.254 proto esp reqid REQID mode tunnel -src 0.0.0.0/0 dst 192.0.2.101/32 - dir out priority 1048543 ptype main - tmpl src 192.1.2.23 dst 192.1.2.254 - proto esp reqid REQID mode tunnel src 192.0.2.100/32 dst 0.0.0.0/0 dir fwd priority 1048543 ptype main tmpl src 192.1.2.254 dst 192.1.2.23 @@ -56,14 +41,6 @@ dir in priority 1048543 ptype main tmpl src 192.1.2.254 dst 192.1.2.23 proto esp reqid REQID mode tunnel -src 192.0.2.101/32 dst 0.0.0.0/0 - dir fwd priority 1048543 ptype main - tmpl src 192.1.2.254 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.2.101/32 dst 0.0.0.0/0 - dir in priority 1048543 ptype main - tmpl src 192.1.2.254 dst 192.1.2.23 - proto esp reqid REQID mode tunnel XFRM done IPSEC mangle TABLES NEW_IPSEC_CONN mangle TABLES @@ -71,8 +48,6 @@ default via 192.1.2.254 dev eth1 192.0.1.0/24 via 192.1.2.45 dev eth1 192.0.2.0/24 dev eth0 proto kernel scope link src 192.0.2.254 -192.0.2.100 dev eth1 scope link -192.0.2.101 dev eth1 scope link 192.1.2.0/24 dev eth1 proto kernel scope link src 192.1.2.23 NSS_CERTIFICATES Certificate Nickname Trust Attributes