Sep 21 07:25:08.209161: FIPS Product: YES Sep 21 07:25:08.209194: FIPS Kernel: NO Sep 21 07:25:08.209196: FIPS Mode: NO Sep 21 07:25:08.209199: NSS DB directory: sql:/etc/ipsec.d Sep 21 07:25:08.209366: Initializing NSS Sep 21 07:25:08.209370: Opening NSS database "sql:/etc/ipsec.d" read-only Sep 21 07:25:08.255070: NSS initialized Sep 21 07:25:08.255081: NSS crypto library initialized Sep 21 07:25:08.255083: FIPS HMAC integrity support [enabled] Sep 21 07:25:08.255085: FIPS mode disabled for pluto daemon Sep 21 07:25:08.340582: FIPS HMAC integrity verification self-test FAILED Sep 21 07:25:08.340688: libcap-ng support [enabled] Sep 21 07:25:08.340700: Linux audit support [enabled] Sep 21 07:25:08.340726: Linux audit activated Sep 21 07:25:08.340731: Starting Pluto (Libreswan Version v3.28-827-gc9aa82b8a6-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC SYSTEMD_WATCHDOG FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:22712 Sep 21 07:25:08.340733: core dump dir: /tmp Sep 21 07:25:08.340736: secrets file: /etc/ipsec.secrets Sep 21 07:25:08.340738: leak-detective disabled Sep 21 07:25:08.340740: NSS crypto [enabled] Sep 21 07:25:08.340742: XAUTH PAM support [enabled] Sep 21 07:25:08.340818: | libevent is using pluto's memory allocator Sep 21 07:25:08.340829: Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) Sep 21 07:25:08.340841: | libevent_malloc: new ptr-libevent@0x560eda573510 size 40 Sep 21 07:25:08.340844: | libevent_malloc: new ptr-libevent@0x560eda573540 size 40 Sep 21 07:25:08.340847: | libevent_malloc: new ptr-libevent@0x560eda574cf0 size 40 Sep 21 07:25:08.340850: | creating event base Sep 21 07:25:08.340853: | libevent_malloc: new ptr-libevent@0x560eda574cb0 size 56 Sep 21 07:25:08.340856: | libevent_malloc: new ptr-libevent@0x560eda574d20 size 664 Sep 21 07:25:08.340866: | libevent_malloc: new ptr-libevent@0x560eda574fc0 size 24 Sep 21 07:25:08.340870: | libevent_malloc: new ptr-libevent@0x560eda52e550 size 384 Sep 21 07:25:08.340880: | libevent_malloc: new ptr-libevent@0x560eda574fe0 size 16 Sep 21 07:25:08.340883: | libevent_malloc: new ptr-libevent@0x560eda575000 size 40 Sep 21 07:25:08.340886: | libevent_malloc: new ptr-libevent@0x560eda575030 size 48 Sep 21 07:25:08.340892: | libevent_realloc: new ptr-libevent@0x560eda575070 size 256 Sep 21 07:25:08.340895: | libevent_malloc: new ptr-libevent@0x560eda575180 size 16 Sep 21 07:25:08.340901: | libevent_free: release ptr-libevent@0x560eda574cb0 Sep 21 07:25:08.340905: | libevent initialized Sep 21 07:25:08.340908: | libevent_realloc: new ptr-libevent@0x560eda5751a0 size 64 Sep 21 07:25:08.340912: | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds Sep 21 07:25:08.340926: | init_nat_traversal() initialized with keep_alive=0s Sep 21 07:25:08.340928: NAT-Traversal support [enabled] Sep 21 07:25:08.340931: | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized Sep 21 07:25:08.340936: | global one-shot timer EVENT_FREE_ROOT_CERTS initialized Sep 21 07:25:08.340943: | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds Sep 21 07:25:08.340981: | global one-shot timer EVENT_REVIVE_CONNS initialized Sep 21 07:25:08.340984: | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds Sep 21 07:25:08.340987: | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Sep 21 07:25:08.341037: Encryption algorithms: Sep 21 07:25:08.341047: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c Sep 21 07:25:08.341051: AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b Sep 21 07:25:08.341055: AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a Sep 21 07:25:08.341058: 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des Sep 21 07:25:08.341061: CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} Sep 21 07:25:08.341071: CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia Sep 21 07:25:08.341075: AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c Sep 21 07:25:08.341079: AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b Sep 21 07:25:08.341083: AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a Sep 21 07:25:08.341086: AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr Sep 21 07:25:08.341090: AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes Sep 21 07:25:08.341094: SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent Sep 21 07:25:08.341097: TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish Sep 21 07:25:08.341101: TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh Sep 21 07:25:08.341105: NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac Sep 21 07:25:08.341107: NULL IKEv1: ESP IKEv2: ESP [] Sep 21 07:25:08.341111: CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Sep 21 07:25:08.341118: Hash algorithms: Sep 21 07:25:08.341121: MD5 IKEv1: IKE IKEv2: Sep 21 07:25:08.341124: SHA1 IKEv1: IKE IKEv2: FIPS sha Sep 21 07:25:08.341127: SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 Sep 21 07:25:08.341129: SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 Sep 21 07:25:08.341132: SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 Sep 21 07:25:08.341145: PRF algorithms: Sep 21 07:25:08.341148: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 Sep 21 07:25:08.341151: HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 Sep 21 07:25:08.341155: HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 Sep 21 07:25:08.341158: HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 Sep 21 07:25:08.341161: HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 Sep 21 07:25:08.341164: AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Sep 21 07:25:08.341190: Integrity algorithms: Sep 21 07:25:08.341193: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 Sep 21 07:25:08.341197: HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 Sep 21 07:25:08.341201: HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 Sep 21 07:25:08.341205: HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 Sep 21 07:25:08.341209: HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 Sep 21 07:25:08.341211: HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH Sep 21 07:25:08.341215: AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 Sep 21 07:25:08.341218: AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac Sep 21 07:25:08.341221: NONE IKEv1: ESP IKEv2: IKE ESP FIPS null Sep 21 07:25:08.341233: DH algorithms: Sep 21 07:25:08.341236: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 Sep 21 07:25:08.341239: MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 Sep 21 07:25:08.341242: MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 Sep 21 07:25:08.341247: MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 Sep 21 07:25:08.341250: MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 Sep 21 07:25:08.341253: MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 Sep 21 07:25:08.341256: MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 Sep 21 07:25:08.341259: DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 Sep 21 07:25:08.341262: DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 Sep 21 07:25:08.341265: DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 Sep 21 07:25:08.341268: DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 Sep 21 07:25:08.341270: testing CAMELLIA_CBC: Sep 21 07:25:08.341273: Camellia: 16 bytes with 128-bit key Sep 21 07:25:08.341400: Camellia: 16 bytes with 128-bit key Sep 21 07:25:08.341431: Camellia: 16 bytes with 256-bit key Sep 21 07:25:08.341460: Camellia: 16 bytes with 256-bit key Sep 21 07:25:08.341488: testing AES_GCM_16: Sep 21 07:25:08.341491: empty string Sep 21 07:25:08.341519: one block Sep 21 07:25:08.341545: two blocks Sep 21 07:25:08.341571: two blocks with associated data Sep 21 07:25:08.341597: testing AES_CTR: Sep 21 07:25:08.341600: Encrypting 16 octets using AES-CTR with 128-bit key Sep 21 07:25:08.341628: Encrypting 32 octets using AES-CTR with 128-bit key Sep 21 07:25:08.341656: Encrypting 36 octets using AES-CTR with 128-bit key Sep 21 07:25:08.341685: Encrypting 16 octets using AES-CTR with 192-bit key Sep 21 07:25:08.341712: Encrypting 32 octets using AES-CTR with 192-bit key Sep 21 07:25:08.341740: Encrypting 36 octets using AES-CTR with 192-bit key Sep 21 07:25:08.341768: Encrypting 16 octets using AES-CTR with 256-bit key Sep 21 07:25:08.341799: Encrypting 32 octets using AES-CTR with 256-bit key Sep 21 07:25:08.341830: Encrypting 36 octets using AES-CTR with 256-bit key Sep 21 07:25:08.341860: testing AES_CBC: Sep 21 07:25:08.341862: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Sep 21 07:25:08.341890: Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Sep 21 07:25:08.341920: Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Sep 21 07:25:08.341950: Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key Sep 21 07:25:08.341987: testing AES_XCBC: Sep 21 07:25:08.341990: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input Sep 21 07:25:08.342113: RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input Sep 21 07:25:08.342247: RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input Sep 21 07:25:08.342378: RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input Sep 21 07:25:08.342510: RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input Sep 21 07:25:08.342646: RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input Sep 21 07:25:08.342794: RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input Sep 21 07:25:08.343109: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) Sep 21 07:25:08.343254: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) Sep 21 07:25:08.343401: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) Sep 21 07:25:08.343652: testing HMAC_MD5: Sep 21 07:25:08.343657: RFC 2104: MD5_HMAC test 1 Sep 21 07:25:08.343840: RFC 2104: MD5_HMAC test 2 Sep 21 07:25:08.344006: RFC 2104: MD5_HMAC test 3 Sep 21 07:25:08.344195: 8 CPU cores online Sep 21 07:25:08.344199: starting up 7 crypto helpers Sep 21 07:25:08.344235: started thread for crypto helper 0 Sep 21 07:25:08.344260: started thread for crypto helper 1 Sep 21 07:25:08.344281: started thread for crypto helper 2 Sep 21 07:25:08.344299: started thread for crypto helper 3 Sep 21 07:25:08.344317: started thread for crypto helper 4 Sep 21 07:25:08.344338: started thread for crypto helper 5 Sep 21 07:25:08.344361: started thread for crypto helper 6 Sep 21 07:25:08.344365: | checking IKEv1 state table Sep 21 07:25:08.344372: | MAIN_R0: category: half-open IKE SA flags: 0: Sep 21 07:25:08.344374: | -> MAIN_R1 EVENT_SO_DISCARD Sep 21 07:25:08.344377: | MAIN_I1: category: half-open IKE SA flags: 0: Sep 21 07:25:08.344379: | -> MAIN_I2 EVENT_RETRANSMIT Sep 21 07:25:08.344381: | MAIN_R1: category: open IKE SA flags: 200: Sep 21 07:25:08.344383: | -> MAIN_R2 EVENT_RETRANSMIT Sep 21 07:25:08.344385: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:08.344387: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:08.344389: | MAIN_I2: category: open IKE SA flags: 0: Sep 21 07:25:08.344391: | -> MAIN_I3 EVENT_RETRANSMIT Sep 21 07:25:08.344392: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:08.344394: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:25:08.344396: | MAIN_R2: category: open IKE SA flags: 0: Sep 21 07:25:08.344398: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:25:08.344400: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:25:08.344402: | -> UNDEFINED EVENT_SA_REPLACE Sep 21 07:25:08.344404: | MAIN_I3: category: open IKE SA flags: 0: Sep 21 07:25:08.344406: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:25:08.344408: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:25:08.344410: | -> UNDEFINED EVENT_SA_REPLACE Sep 21 07:25:08.344413: | MAIN_R3: category: established IKE SA flags: 200: Sep 21 07:25:08.344415: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344417: | MAIN_I4: category: established IKE SA flags: 0: Sep 21 07:25:08.344419: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344421: | AGGR_R0: category: half-open IKE SA flags: 0: Sep 21 07:25:08.344423: | -> AGGR_R1 EVENT_SO_DISCARD Sep 21 07:25:08.344426: | AGGR_I1: category: half-open IKE SA flags: 0: Sep 21 07:25:08.344428: | -> AGGR_I2 EVENT_SA_REPLACE Sep 21 07:25:08.344429: | -> AGGR_I2 EVENT_SA_REPLACE Sep 21 07:25:08.344432: | AGGR_R1: category: open IKE SA flags: 200: Sep 21 07:25:08.344433: | -> AGGR_R2 EVENT_SA_REPLACE Sep 21 07:25:08.344435: | -> AGGR_R2 EVENT_SA_REPLACE Sep 21 07:25:08.344438: | AGGR_I2: category: established IKE SA flags: 200: Sep 21 07:25:08.344439: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344442: | AGGR_R2: category: established IKE SA flags: 0: Sep 21 07:25:08.344444: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344446: | QUICK_R0: category: established CHILD SA flags: 0: Sep 21 07:25:08.344448: | -> QUICK_R1 EVENT_RETRANSMIT Sep 21 07:25:08.344450: | QUICK_I1: category: established CHILD SA flags: 0: Sep 21 07:25:08.344452: | -> QUICK_I2 EVENT_SA_REPLACE Sep 21 07:25:08.344455: | QUICK_R1: category: established CHILD SA flags: 0: Sep 21 07:25:08.344457: | -> QUICK_R2 EVENT_SA_REPLACE Sep 21 07:25:08.344459: | QUICK_I2: category: established CHILD SA flags: 200: Sep 21 07:25:08.344461: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344463: | QUICK_R2: category: established CHILD SA flags: 0: Sep 21 07:25:08.344465: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344467: | INFO: category: informational flags: 0: Sep 21 07:25:08.344469: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344471: | INFO_PROTECTED: category: informational flags: 0: Sep 21 07:25:08.344473: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344476: | XAUTH_R0: category: established IKE SA flags: 0: Sep 21 07:25:08.344477: | -> XAUTH_R1 EVENT_NULL Sep 21 07:25:08.344480: | XAUTH_R1: category: established IKE SA flags: 0: Sep 21 07:25:08.344482: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:25:08.344484: | MODE_CFG_R0: category: informational flags: 0: Sep 21 07:25:08.344486: | -> MODE_CFG_R1 EVENT_SA_REPLACE Sep 21 07:25:08.344489: | MODE_CFG_R1: category: established IKE SA flags: 0: Sep 21 07:25:08.344491: | -> MODE_CFG_R2 EVENT_SA_REPLACE Sep 21 07:25:08.344493: | MODE_CFG_R2: category: established IKE SA flags: 0: Sep 21 07:25:08.344495: | -> UNDEFINED EVENT_NULL Sep 21 07:25:08.344498: | MODE_CFG_I1: category: established IKE SA flags: 0: Sep 21 07:25:08.344503: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:25:08.344505: | XAUTH_I0: category: established IKE SA flags: 0: Sep 21 07:25:08.344507: | -> XAUTH_I1 EVENT_RETRANSMIT Sep 21 07:25:08.344510: | XAUTH_I1: category: established IKE SA flags: 0: Sep 21 07:25:08.344512: | -> MAIN_I4 EVENT_RETRANSMIT Sep 21 07:25:08.344518: | checking IKEv2 state table Sep 21 07:25:08.344524: | PARENT_I0: category: ignore flags: 0: Sep 21 07:25:08.344527: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) Sep 21 07:25:08.344530: | PARENT_I1: category: half-open IKE SA flags: 0: Sep 21 07:25:08.344532: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) Sep 21 07:25:08.344535: | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) Sep 21 07:25:08.344538: | PARENT_I2: category: open IKE SA flags: 0: Sep 21 07:25:08.344540: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) Sep 21 07:25:08.344543: | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) Sep 21 07:25:08.344546: | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) Sep 21 07:25:08.344548: | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) Sep 21 07:25:08.344551: | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) Sep 21 07:25:08.344554: | PARENT_I3: category: established IKE SA flags: 0: Sep 21 07:25:08.344556: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) Sep 21 07:25:08.344558: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) Sep 21 07:25:08.344561: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) Sep 21 07:25:08.344563: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) Sep 21 07:25:08.344566: | PARENT_R0: category: half-open IKE SA flags: 0: Sep 21 07:25:08.344568: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) Sep 21 07:25:08.344571: | PARENT_R1: category: half-open IKE SA flags: 0: Sep 21 07:25:08.344574: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) Sep 21 07:25:08.344576: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) Sep 21 07:25:08.344579: | PARENT_R2: category: established IKE SA flags: 0: Sep 21 07:25:08.344581: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) Sep 21 07:25:08.344584: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) Sep 21 07:25:08.344586: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) Sep 21 07:25:08.344589: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) Sep 21 07:25:08.344591: | V2_CREATE_I0: category: established IKE SA flags: 0: Sep 21 07:25:08.344594: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) Sep 21 07:25:08.344597: | V2_CREATE_I: category: established IKE SA flags: 0: Sep 21 07:25:08.344599: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) Sep 21 07:25:08.344602: | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: Sep 21 07:25:08.344605: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) Sep 21 07:25:08.344608: | V2_REKEY_IKE_I: category: established IKE SA flags: 0: Sep 21 07:25:08.344610: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) Sep 21 07:25:08.344613: | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: Sep 21 07:25:08.344616: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) Sep 21 07:25:08.344619: | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: Sep 21 07:25:08.344621: | V2_CREATE_R: category: established IKE SA flags: 0: Sep 21 07:25:08.344624: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) Sep 21 07:25:08.344631: | V2_REKEY_IKE_R: category: established IKE SA flags: 0: Sep 21 07:25:08.344633: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) Sep 21 07:25:08.344636: | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: Sep 21 07:25:08.344639: | V2_IPSEC_I: category: established CHILD SA flags: 0: Sep 21 07:25:08.344642: | V2_IPSEC_R: category: established CHILD SA flags: 0: Sep 21 07:25:08.344644: | IKESA_DEL: category: established IKE SA flags: 0: Sep 21 07:25:08.344646: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) Sep 21 07:25:08.344649: | CHILDSA_DEL: category: informational flags: 0: Sep 21 07:25:08.344715: Using Linux XFRM/NETKEY IPsec interface code on 5.2.11+ Sep 21 07:25:08.344790: | Hard-wiring algorithms Sep 21 07:25:08.344798: | adding AES_CCM_16 to kernel algorithm db Sep 21 07:25:08.344803: | adding AES_CCM_12 to kernel algorithm db Sep 21 07:25:08.344805: | adding AES_CCM_8 to kernel algorithm db Sep 21 07:25:08.344807: | adding 3DES_CBC to kernel algorithm db Sep 21 07:25:08.344810: | adding CAMELLIA_CBC to kernel algorithm db Sep 21 07:25:08.344812: | adding AES_GCM_16 to kernel algorithm db Sep 21 07:25:08.344815: | adding AES_GCM_12 to kernel algorithm db Sep 21 07:25:08.344817: | adding AES_GCM_8 to kernel algorithm db Sep 21 07:25:08.344819: | adding AES_CTR to kernel algorithm db Sep 21 07:25:08.344821: | adding AES_CBC to kernel algorithm db Sep 21 07:25:08.344824: | adding SERPENT_CBC to kernel algorithm db Sep 21 07:25:08.344826: | adding TWOFISH_CBC to kernel algorithm db Sep 21 07:25:08.344828: | adding NULL_AUTH_AES_GMAC to kernel algorithm db Sep 21 07:25:08.344831: | adding NULL to kernel algorithm db Sep 21 07:25:08.344833: | adding CHACHA20_POLY1305 to kernel algorithm db Sep 21 07:25:08.344836: | adding HMAC_MD5_96 to kernel algorithm db Sep 21 07:25:08.344838: | adding HMAC_SHA1_96 to kernel algorithm db Sep 21 07:25:08.344840: | adding HMAC_SHA2_512_256 to kernel algorithm db Sep 21 07:25:08.344843: | adding HMAC_SHA2_384_192 to kernel algorithm db Sep 21 07:25:08.344845: | adding HMAC_SHA2_256_128 to kernel algorithm db Sep 21 07:25:08.344848: | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db Sep 21 07:25:08.344850: | adding AES_XCBC_96 to kernel algorithm db Sep 21 07:25:08.344852: | adding AES_CMAC_96 to kernel algorithm db Sep 21 07:25:08.344855: | adding NONE to kernel algorithm db Sep 21 07:25:08.344877: | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes Sep 21 07:25:08.344883: | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds Sep 21 07:25:08.344886: | setup kernel fd callback Sep 21 07:25:08.344889: | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x560eda57f960 Sep 21 07:25:08.344892: | libevent_malloc: new ptr-libevent@0x560eda5869b0 size 128 Sep 21 07:25:08.344895: | libevent_malloc: new ptr-libevent@0x560eda57f8c0 size 16 Sep 21 07:25:08.344901: | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x560eda579e10 Sep 21 07:25:08.344904: | libevent_malloc: new ptr-libevent@0x560eda586a40 size 128 Sep 21 07:25:08.344906: | libevent_malloc: new ptr-libevent@0x560eda57f8a0 size 16 Sep 21 07:25:08.345129: | global one-shot timer EVENT_CHECK_CRLS initialized Sep 21 07:25:08.345140: selinux support is enabled. Sep 21 07:25:08.345216: systemd watchdog not enabled - not sending watchdog keepalives Sep 21 07:25:08.345388: | unbound context created - setting debug level to 5 Sep 21 07:25:08.345420: | /etc/hosts lookups activated Sep 21 07:25:08.345438: | /etc/resolv.conf usage activated Sep 21 07:25:08.345501: | outgoing-port-avoid set 0-65535 Sep 21 07:25:08.345529: | outgoing-port-permit set 32768-60999 Sep 21 07:25:08.345532: | Loading dnssec root key from:/var/lib/unbound/root.key Sep 21 07:25:08.345535: | No additional dnssec trust anchors defined via dnssec-trusted= option Sep 21 07:25:08.345538: | Setting up events, loop start Sep 21 07:25:08.345542: | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x560eda579bd0 Sep 21 07:25:08.345548: | libevent_malloc: new ptr-libevent@0x560eda590fc0 size 128 Sep 21 07:25:08.345551: | libevent_malloc: new ptr-libevent@0x560eda591050 size 16 Sep 21 07:25:08.345557: | libevent_realloc: new ptr-libevent@0x560eda591070 size 256 Sep 21 07:25:08.345560: | libevent_malloc: new ptr-libevent@0x560eda591180 size 8 Sep 21 07:25:08.345563: | libevent_realloc: new ptr-libevent@0x560eda585d30 size 144 Sep 21 07:25:08.345566: | libevent_malloc: new ptr-libevent@0x560eda5911a0 size 152 Sep 21 07:25:08.345569: | libevent_malloc: new ptr-libevent@0x560eda591240 size 16 Sep 21 07:25:08.345573: | signal event handler PLUTO_SIGCHLD installed Sep 21 07:25:08.345576: | libevent_malloc: new ptr-libevent@0x560eda591260 size 8 Sep 21 07:25:08.345578: | libevent_malloc: new ptr-libevent@0x560eda591280 size 152 Sep 21 07:25:08.345581: | signal event handler PLUTO_SIGTERM installed Sep 21 07:25:08.345584: | libevent_malloc: new ptr-libevent@0x560eda591320 size 8 Sep 21 07:25:08.345586: | libevent_malloc: new ptr-libevent@0x560eda591340 size 152 Sep 21 07:25:08.345589: | signal event handler PLUTO_SIGHUP installed Sep 21 07:25:08.345592: | libevent_malloc: new ptr-libevent@0x560eda5913e0 size 8 Sep 21 07:25:08.345594: | libevent_realloc: release ptr-libevent@0x560eda585d30 Sep 21 07:25:08.345597: | libevent_realloc: new ptr-libevent@0x560eda591400 size 256 Sep 21 07:25:08.345600: | libevent_malloc: new ptr-libevent@0x560eda585d30 size 152 Sep 21 07:25:08.345603: | signal event handler PLUTO_SIGSYS installed Sep 21 07:25:08.346065: | created addconn helper (pid:22810) using fork+execve Sep 21 07:25:08.346085: | forked child 22810 Sep 21 07:25:08.346126: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:08.346148: | pluto_sd: executing action action: reloading(4), status 0 Sep 21 07:25:08.346154: listening for IKE messages Sep 21 07:25:08.346209: | starting up helper thread 5 Sep 21 07:25:08.346217: | status value returned by setting the priority of this thread (crypto helper 5) 22 Sep 21 07:25:08.346225: | crypto helper 5 waiting (nothing to do) Sep 21 07:25:08.346234: | starting up helper thread 4 Sep 21 07:25:08.346239: | status value returned by setting the priority of this thread (crypto helper 4) 22 Sep 21 07:25:08.346241: | crypto helper 4 waiting (nothing to do) Sep 21 07:25:08.346251: | starting up helper thread 2 Sep 21 07:25:08.346255: | status value returned by setting the priority of this thread (crypto helper 2) 22 Sep 21 07:25:08.346258: | crypto helper 2 waiting (nothing to do) Sep 21 07:25:08.346267: | starting up helper thread 1 Sep 21 07:25:08.346271: | status value returned by setting the priority of this thread (crypto helper 1) 22 Sep 21 07:25:08.346273: | crypto helper 1 waiting (nothing to do) Sep 21 07:25:08.346282: | starting up helper thread 0 Sep 21 07:25:08.346287: | status value returned by setting the priority of this thread (crypto helper 0) 22 Sep 21 07:25:08.346289: | crypto helper 0 waiting (nothing to do) Sep 21 07:25:08.346307: | starting up helper thread 3 Sep 21 07:25:08.346312: | status value returned by setting the priority of this thread (crypto helper 3) 22 Sep 21 07:25:08.346314: | crypto helper 3 waiting (nothing to do) Sep 21 07:25:08.349801: | starting up helper thread 6 Sep 21 07:25:08.349820: | status value returned by setting the priority of this thread (crypto helper 6) 22 Sep 21 07:25:08.349825: | crypto helper 6 waiting (nothing to do) Sep 21 07:25:08.364811: | Inspecting interface lo Sep 21 07:25:08.365269: | found lo with address 127.0.0.1 Sep 21 07:25:08.365276: | Inspecting interface eth0 Sep 21 07:25:08.365281: | found eth0 with address 192.0.3.254 Sep 21 07:25:08.365289: | Inspecting interface eth1 Sep 21 07:25:08.365294: | found eth1 with address 192.1.3.33 Sep 21 07:25:08.365356: Kernel supports NIC esp-hw-offload Sep 21 07:25:08.365373: adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.3.33:500 Sep 21 07:25:08.365443: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:25:08.365455: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:25:08.365460: adding interface eth1/eth1 192.1.3.33:4500 Sep 21 07:25:08.365491: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.3.254:500 Sep 21 07:25:08.365516: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:25:08.365522: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:25:08.365526: adding interface eth0/eth0 192.0.3.254:4500 Sep 21 07:25:08.365554: adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 Sep 21 07:25:08.365578: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:25:08.365583: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:25:08.365588: adding interface lo/lo 127.0.0.1:4500 Sep 21 07:25:08.365674: | no interfaces to sort Sep 21 07:25:08.365679: | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations Sep 21 07:25:08.365690: | add_fd_read_event_handler: new ethX-pe@0x560eda57acd0 Sep 21 07:25:08.365695: | libevent_malloc: new ptr-libevent@0x560eda5917e0 size 128 Sep 21 07:25:08.365700: | libevent_malloc: new ptr-libevent@0x560eda591870 size 16 Sep 21 07:25:08.365709: | setup callback for interface lo 127.0.0.1:4500 fd 22 Sep 21 07:25:08.365713: | add_fd_read_event_handler: new ethX-pe@0x560eda591890 Sep 21 07:25:08.365717: | libevent_malloc: new ptr-libevent@0x560eda5918d0 size 128 Sep 21 07:25:08.365720: | libevent_malloc: new ptr-libevent@0x560eda591960 size 16 Sep 21 07:25:08.365726: | setup callback for interface lo 127.0.0.1:500 fd 21 Sep 21 07:25:08.365730: | add_fd_read_event_handler: new ethX-pe@0x560eda591980 Sep 21 07:25:08.365733: | libevent_malloc: new ptr-libevent@0x560eda5919c0 size 128 Sep 21 07:25:08.365737: | libevent_malloc: new ptr-libevent@0x560eda591a50 size 16 Sep 21 07:25:08.365743: | setup callback for interface eth0 192.0.3.254:4500 fd 20 Sep 21 07:25:08.365747: | add_fd_read_event_handler: new ethX-pe@0x560eda591a70 Sep 21 07:25:08.365751: | libevent_malloc: new ptr-libevent@0x560eda591ab0 size 128 Sep 21 07:25:08.365754: | libevent_malloc: new ptr-libevent@0x560eda591b40 size 16 Sep 21 07:25:08.365761: | setup callback for interface eth0 192.0.3.254:500 fd 19 Sep 21 07:25:08.365764: | add_fd_read_event_handler: new ethX-pe@0x560eda591b60 Sep 21 07:25:08.365768: | libevent_malloc: new ptr-libevent@0x560eda591ba0 size 128 Sep 21 07:25:08.365772: | libevent_malloc: new ptr-libevent@0x560eda591c30 size 16 Sep 21 07:25:08.365778: | setup callback for interface eth1 192.1.3.33:4500 fd 18 Sep 21 07:25:08.365781: | add_fd_read_event_handler: new ethX-pe@0x560eda591c50 Sep 21 07:25:08.365792: | libevent_malloc: new ptr-libevent@0x560eda591c90 size 128 Sep 21 07:25:08.365796: | libevent_malloc: new ptr-libevent@0x560eda591d20 size 16 Sep 21 07:25:08.365802: | setup callback for interface eth1 192.1.3.33:500 fd 17 Sep 21 07:25:08.365808: | certs and keys locked by 'free_preshared_secrets' Sep 21 07:25:08.365811: | certs and keys unlocked by 'free_preshared_secrets' Sep 21 07:25:08.365837: loading secrets from "/etc/ipsec.secrets" Sep 21 07:25:08.365865: | saving Modulus Sep 21 07:25:08.365870: | saving PublicExponent Sep 21 07:25:08.365875: | ignoring PrivateExponent Sep 21 07:25:08.365880: | ignoring Prime1 Sep 21 07:25:08.365885: | ignoring Prime2 Sep 21 07:25:08.365889: | ignoring Exponent1 Sep 21 07:25:08.365894: | ignoring Exponent2 Sep 21 07:25:08.365898: | ignoring Coefficient Sep 21 07:25:08.365903: | ignoring CKAIDNSS Sep 21 07:25:08.365950: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:08.365954: | computed rsa CKAID 88 aa 7c 5d Sep 21 07:25:08.365959: loaded private key for keyid: PKK_RSA:AQPl33O2P Sep 21 07:25:08.365965: | certs and keys locked by 'process_secret' Sep 21 07:25:08.365969: | certs and keys unlocked by 'process_secret' Sep 21 07:25:08.365975: | pluto_sd: executing action action: ready(5), status 0 Sep 21 07:25:08.365985: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:08.365995: | spent 1.26 milliseconds in whack Sep 21 07:25:08.425257: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:08.425278: | pluto_sd: executing action action: reloading(4), status 0 Sep 21 07:25:08.425283: listening for IKE messages Sep 21 07:25:08.425318: | Inspecting interface lo Sep 21 07:25:08.425324: | found lo with address 127.0.0.1 Sep 21 07:25:08.425327: | Inspecting interface eth0 Sep 21 07:25:08.425331: | found eth0 with address 192.0.3.254 Sep 21 07:25:08.425333: | Inspecting interface eth1 Sep 21 07:25:08.425337: | found eth1 with address 192.1.3.33 Sep 21 07:25:08.425418: | no interfaces to sort Sep 21 07:25:08.425427: | libevent_free: release ptr-libevent@0x560eda5917e0 Sep 21 07:25:08.425430: | free_event_entry: release EVENT_NULL-pe@0x560eda57acd0 Sep 21 07:25:08.425433: | add_fd_read_event_handler: new ethX-pe@0x560eda57acd0 Sep 21 07:25:08.425436: | libevent_malloc: new ptr-libevent@0x560eda5917e0 size 128 Sep 21 07:25:08.425443: | setup callback for interface lo 127.0.0.1:4500 fd 22 Sep 21 07:25:08.425447: | libevent_free: release ptr-libevent@0x560eda5918d0 Sep 21 07:25:08.425450: | free_event_entry: release EVENT_NULL-pe@0x560eda591890 Sep 21 07:25:08.425452: | add_fd_read_event_handler: new ethX-pe@0x560eda591890 Sep 21 07:25:08.425455: | libevent_malloc: new ptr-libevent@0x560eda5918d0 size 128 Sep 21 07:25:08.425460: | setup callback for interface lo 127.0.0.1:500 fd 21 Sep 21 07:25:08.425463: | libevent_free: release ptr-libevent@0x560eda5919c0 Sep 21 07:25:08.425466: | free_event_entry: release EVENT_NULL-pe@0x560eda591980 Sep 21 07:25:08.425468: | add_fd_read_event_handler: new ethX-pe@0x560eda591980 Sep 21 07:25:08.425470: | libevent_malloc: new ptr-libevent@0x560eda5919c0 size 128 Sep 21 07:25:08.425475: | setup callback for interface eth0 192.0.3.254:4500 fd 20 Sep 21 07:25:08.425479: | libevent_free: release ptr-libevent@0x560eda591ab0 Sep 21 07:25:08.425481: | free_event_entry: release EVENT_NULL-pe@0x560eda591a70 Sep 21 07:25:08.425484: | add_fd_read_event_handler: new ethX-pe@0x560eda591a70 Sep 21 07:25:08.425486: | libevent_malloc: new ptr-libevent@0x560eda591ab0 size 128 Sep 21 07:25:08.425490: | setup callback for interface eth0 192.0.3.254:500 fd 19 Sep 21 07:25:08.425494: | libevent_free: release ptr-libevent@0x560eda591ba0 Sep 21 07:25:08.425496: | free_event_entry: release EVENT_NULL-pe@0x560eda591b60 Sep 21 07:25:08.425499: | add_fd_read_event_handler: new ethX-pe@0x560eda591b60 Sep 21 07:25:08.425501: | libevent_malloc: new ptr-libevent@0x560eda591ba0 size 128 Sep 21 07:25:08.425506: | setup callback for interface eth1 192.1.3.33:4500 fd 18 Sep 21 07:25:08.425509: | libevent_free: release ptr-libevent@0x560eda591c90 Sep 21 07:25:08.425511: | free_event_entry: release EVENT_NULL-pe@0x560eda591c50 Sep 21 07:25:08.425514: | add_fd_read_event_handler: new ethX-pe@0x560eda591c50 Sep 21 07:25:08.425516: | libevent_malloc: new ptr-libevent@0x560eda591c90 size 128 Sep 21 07:25:08.425521: | setup callback for interface eth1 192.1.3.33:500 fd 17 Sep 21 07:25:08.425524: | certs and keys locked by 'free_preshared_secrets' Sep 21 07:25:08.425526: forgetting secrets Sep 21 07:25:08.425535: | certs and keys unlocked by 'free_preshared_secrets' Sep 21 07:25:08.425549: loading secrets from "/etc/ipsec.secrets" Sep 21 07:25:08.425564: | saving Modulus Sep 21 07:25:08.425567: | saving PublicExponent Sep 21 07:25:08.425570: | ignoring PrivateExponent Sep 21 07:25:08.425574: | ignoring Prime1 Sep 21 07:25:08.425577: | ignoring Prime2 Sep 21 07:25:08.425580: | ignoring Exponent1 Sep 21 07:25:08.425583: | ignoring Exponent2 Sep 21 07:25:08.425586: | ignoring Coefficient Sep 21 07:25:08.425589: | ignoring CKAIDNSS Sep 21 07:25:08.425612: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:08.425615: | computed rsa CKAID 88 aa 7c 5d Sep 21 07:25:08.425618: loaded private key for keyid: PKK_RSA:AQPl33O2P Sep 21 07:25:08.425624: | certs and keys locked by 'process_secret' Sep 21 07:25:08.425632: | certs and keys unlocked by 'process_secret' Sep 21 07:25:08.425637: | pluto_sd: executing action action: ready(5), status 0 Sep 21 07:25:08.425644: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:08.425651: | spent 0.403 milliseconds in whack Sep 21 07:25:08.429176: | processing signal PLUTO_SIGCHLD Sep 21 07:25:08.429196: | waitpid returned pid 22810 (exited with status 0) Sep 21 07:25:08.429200: | reaped addconn helper child (status 0) Sep 21 07:25:08.429205: | waitpid returned ECHILD (no child processes left) Sep 21 07:25:08.429212: | spent 0.0181 milliseconds in signal handler PLUTO_SIGCHLD Sep 21 07:25:08.493902: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:08.493928: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:08.493932: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:25:08.493935: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:08.493937: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:25:08.493941: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:08.493948: | Added new connection northnet-eastnet-ipv4 with policy ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:25:08.493951: | No AUTH policy was set - defaulting to RSASIG Sep 21 07:25:08.494006: | ike (phase1) algorithm values: AES_GCM_16_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_GCM_16_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 Sep 21 07:25:08.494010: | from whack: got --esp= Sep 21 07:25:08.494046: | ESP/AH string values: AES_GCM_16_256-NONE, AES_GCM_16_128-NONE, AES_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128, AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 Sep 21 07:25:08.494051: | counting wild cards for @north is 0 Sep 21 07:25:08.494055: | counting wild cards for @east is 0 Sep 21 07:25:08.494065: | connect_to_host_pair: 192.1.3.33:500 192.1.2.23:500 -> hp@(nil): none Sep 21 07:25:08.494068: | new hp@0x560eda573460 Sep 21 07:25:08.494073: added connection description "northnet-eastnet-ipv4" Sep 21 07:25:08.494084: | ike_life: 50s; ipsec_life: 180s; rekey_margin: 5s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: RSASIG+ENCRYPT+TUNNEL+PFS+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:25:08.494106: | 192.0.3.0/24===192.1.3.33<192.1.3.33>[@north]...192.1.2.23<192.1.2.23>[@east]===192.0.2.0/24 Sep 21 07:25:08.494115: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:08.494122: | spent 0.221 milliseconds in whack Sep 21 07:25:08.494298: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:08.494314: add keyid @north Sep 21 07:25:08.494319: | add pubkey 01 03 e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab Sep 21 07:25:08.494321: | add pubkey 7f ec 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 Sep 21 07:25:08.494324: | add pubkey 93 9e 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 Sep 21 07:25:08.494326: | add pubkey 01 03 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 Sep 21 07:25:08.494328: | add pubkey 10 84 b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 Sep 21 07:25:08.494332: | add pubkey f4 6b 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f Sep 21 07:25:08.494334: | add pubkey 25 b4 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e Sep 21 07:25:08.494337: | add pubkey c8 16 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 Sep 21 07:25:08.494339: | add pubkey cc 92 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 Sep 21 07:25:08.494341: | add pubkey 13 0f 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 Sep 21 07:25:08.494343: | add pubkey 39 f9 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d Sep 21 07:25:08.494345: | add pubkey 9e ca 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 Sep 21 07:25:08.494353: | add pubkey ba 64 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 Sep 21 07:25:08.494355: | add pubkey 9c 85 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 Sep 21 07:25:08.494357: | add pubkey 61 eb 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 Sep 21 07:25:08.494360: | add pubkey 83 c2 d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca Sep 21 07:25:08.494362: | add pubkey f5 38 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 Sep 21 07:25:08.494364: | add pubkey c7 5e a5 99 Sep 21 07:25:08.494386: | computed rsa CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:08.494389: | computed rsa CKAID 88 aa 7c 5d Sep 21 07:25:08.494399: | keyid: *AQPl33O2P Sep 21 07:25:08.494402: | n e5 df 73 b6 3e d5 36 a8 f1 3d 0d d3 02 ab 7f ec Sep 21 07:25:08.494404: | n 4c 9e 8b 0e 0e d2 cf 0f 59 bf 6d 88 21 86 93 9e Sep 21 07:25:08.494406: | n 10 34 af 2d cf b3 7e eb e5 b2 24 b2 a5 b0 01 03 Sep 21 07:25:08.494409: | n 7d b5 96 ad 66 ee 48 c2 28 d9 9a 76 36 a9 10 84 Sep 21 07:25:08.494411: | n b5 09 8f 17 4f 65 ce d8 2f 8e 78 80 8a 87 f4 6b Sep 21 07:25:08.494413: | n 98 d9 91 94 6b 52 15 5b 9c 47 12 be d8 6f 25 b4 Sep 21 07:25:08.494415: | n 65 38 7e e4 8d c7 f0 58 d3 9f 69 14 cc 3e c8 16 Sep 21 07:25:08.494417: | n 1f af bb 5d 93 2b 33 39 0e 94 55 81 f4 b3 cc 92 Sep 21 07:25:08.494419: | n 58 6e 4a 5a 4e c3 76 ab 04 2e 11 08 06 55 13 0f Sep 21 07:25:08.494422: | n 02 6c dd d1 bc c0 b8 8d 65 f5 97 ed fc 18 39 f9 Sep 21 07:25:08.494424: | n 55 ab fa 0d c5 49 99 7f 1b cf c3 de 99 7d 9e ca Sep 21 07:25:08.494426: | n 6f 9e 14 d6 5a ff de d6 4f 57 6a 83 ab 51 ba 64 Sep 21 07:25:08.494428: | n 74 e0 22 e9 9a c5 10 71 bb d4 eb a4 99 28 9c 85 Sep 21 07:25:08.494430: | n 0e 31 ea cc ab ef 98 84 3f 59 c1 75 aa b3 61 eb Sep 21 07:25:08.494432: | n 61 8c 58 a5 92 25 84 ad c7 79 f3 87 d0 c7 83 c2 Sep 21 07:25:08.494435: | n d6 8a fe 26 9d 2a ff b1 dd 9b 89 21 7c ca f5 38 Sep 21 07:25:08.494437: | n 2d 3f 64 0c 41 9c 34 e9 b2 55 0f 82 1a b3 c7 5e Sep 21 07:25:08.494439: | n a5 99 Sep 21 07:25:08.494441: | e 03 Sep 21 07:25:08.494443: | CKAID 90 5d fc a1 08 68 74 7c 6f 20 d3 1b 2d 20 4b 8f Sep 21 07:25:08.494445: | CKAID 88 aa 7c 5d Sep 21 07:25:08.494451: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:08.494456: | spent 0.156 milliseconds in whack Sep 21 07:25:08.494503: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:08.494517: add keyid @east Sep 21 07:25:08.494521: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Sep 21 07:25:08.494524: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Sep 21 07:25:08.494526: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Sep 21 07:25:08.494529: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Sep 21 07:25:08.494531: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Sep 21 07:25:08.494534: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Sep 21 07:25:08.494536: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Sep 21 07:25:08.494538: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Sep 21 07:25:08.494541: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Sep 21 07:25:08.494543: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Sep 21 07:25:08.494546: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Sep 21 07:25:08.494548: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Sep 21 07:25:08.494550: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Sep 21 07:25:08.494553: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Sep 21 07:25:08.494555: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Sep 21 07:25:08.494557: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Sep 21 07:25:08.494567: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Sep 21 07:25:08.494569: | add pubkey 51 51 48 ef Sep 21 07:25:08.494582: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:25:08.494585: | computed rsa CKAID 8a 82 25 f1 Sep 21 07:25:08.494589: | keyid: *AQO9bJbr3 Sep 21 07:25:08.494592: | n bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b e5 16 Sep 21 07:25:08.494594: | n c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 85 7a Sep 21 07:25:08.494596: | n e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c 78 ca Sep 21 07:25:08.494599: | n 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 21 c9 Sep 21 07:25:08.494601: | n f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d d2 67 Sep 21 07:25:08.494604: | n 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 62 cd Sep 21 07:25:08.494606: | n 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce 62 b5 Sep 21 07:25:08.494608: | n af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e bb 23 Sep 21 07:25:08.494610: | n 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d ac 47 Sep 21 07:25:08.494612: | n f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce e0 98 Sep 21 07:25:08.494614: | n 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a 92 b8 Sep 21 07:25:08.494617: | n 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 4d 58 Sep 21 07:25:08.494619: | n 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 5f 56 Sep 21 07:25:08.494622: | n 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 d5 f1 Sep 21 07:25:08.494624: | n 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c 47 cc Sep 21 07:25:08.494626: | n 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 07 8f Sep 21 07:25:08.494628: | n 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 51 51 Sep 21 07:25:08.494631: | n 48 ef Sep 21 07:25:08.494633: | e 03 Sep 21 07:25:08.494635: | CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:25:08.494638: | CKAID 8a 82 25 f1 Sep 21 07:25:08.494646: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:08.494651: | spent 0.154 milliseconds in whack Sep 21 07:25:08.563095: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:08.563305: | FOR_EACH_CONNECTION_... in show_connections_status Sep 21 07:25:08.563310: | FOR_EACH_CONNECTION_... in show_connections_status Sep 21 07:25:08.563385: | FOR_EACH_STATE_... in show_states_status (sort_states) Sep 21 07:25:08.563396: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:08.563404: | spent 0.315 milliseconds in whack Sep 21 07:25:08.678925: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:25:08.678953: | dup_any(fd@16) -> fd@23 (in whack_process() at rcv_whack.c:590) Sep 21 07:25:08.678957: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:25:08.678963: | start processing: connection "northnet-eastnet-ipv4" (in initiate_a_connection() at initiate.c:186) Sep 21 07:25:08.678966: | connection 'northnet-eastnet-ipv4' +POLICY_UP Sep 21 07:25:08.678969: | dup_any(fd@23) -> fd@24 (in initiate_a_connection() at initiate.c:342) Sep 21 07:25:08.678972: | FOR_EACH_STATE_... in find_phase1_state Sep 21 07:25:08.678989: | creating state object #1 at 0x560eda593860 Sep 21 07:25:08.678992: | State DB: adding IKEv2 state #1 in UNDEFINED Sep 21 07:25:08.679000: | pstats #1 ikev2.ike started Sep 21 07:25:08.679004: | Message ID: init #1: msgid=0 lastack=4294967295 nextuse=0 lastrecv=4294967295 lastreplied=0 Sep 21 07:25:08.679007: | parent state #1: UNDEFINED(ignore) => PARENT_I0(ignore) Sep 21 07:25:08.679013: | Message ID: init_ike #1; ike: initiator.sent=0->-1 initiator.recv=0->-1 responder.sent=0->-1 responder.recv=0->-1 wip.initiator=0->-1 wip.responder=0->-1 Sep 21 07:25:08.679021: | suspend processing: connection "northnet-eastnet-ipv4" (in ikev2_parent_outI1() at ikev2_parent.c:535) Sep 21 07:25:08.679027: | start processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in ikev2_parent_outI1() at ikev2_parent.c:535) Sep 21 07:25:08.679033: | dup_any(fd@24) -> fd@25 (in ikev2_parent_outI1() at ikev2_parent.c:551) Sep 21 07:25:08.679038: | Queuing pending IPsec SA negotiating with 192.1.2.23 "northnet-eastnet-ipv4" IKE SA #1 "northnet-eastnet-ipv4" Sep 21 07:25:08.679043: "northnet-eastnet-ipv4" #1: initiating v2 parent SA Sep 21 07:25:08.679052: | constructing local IKE proposals for northnet-eastnet-ipv4 (IKE SA initiator selecting KE) Sep 21 07:25:08.679060: | converting ike_info AES_GCM_16_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:25:08.679069: | ... ikev2_proposal: 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:25:08.679072: | converting ike_info AES_GCM_16_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:25:08.679077: | ... ikev2_proposal: 2:IKE:ENCR=AES_GCM_C_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:25:08.679081: | converting ike_info AES_CBC_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:25:08.679086: | ... ikev2_proposal: 3:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:25:08.679090: | converting ike_info AES_CBC_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:25:08.679095: | ... ikev2_proposal: 4:IKE:ENCR=AES_CBC_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:25:08.679106: "northnet-eastnet-ipv4": constructed local IKE proposals for northnet-eastnet-ipv4 (IKE SA initiator selecting KE): 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 2:IKE:ENCR=AES_GCM_C_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 3:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 4:IKE:ENCR=AES_CBC_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:25:08.679112: | adding ikev2_outI1 KE work-order 1 for state #1 Sep 21 07:25:08.679116: | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x560eda595ef0 Sep 21 07:25:08.679119: | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 Sep 21 07:25:08.679123: | libevent_malloc: new ptr-libevent@0x560eda595f30 size 128 Sep 21 07:25:08.679137: | #1 spent 0.172 milliseconds in ikev2_parent_outI1() Sep 21 07:25:08.679137: | crypto helper 5 resuming Sep 21 07:25:08.679149: | crypto helper 5 starting work-order 1 for state #1 Sep 21 07:25:08.679153: | crypto helper 5 doing build KE and nonce (ikev2_outI1 KE); request ID 1 Sep 21 07:25:08.680207: | crypto helper 5 finished build KE and nonce (ikev2_outI1 KE); request ID 1 time elapsed 0.001053 seconds Sep 21 07:25:08.680218: | (#1) spent 1.06 milliseconds in crypto helper computing work-order 1: ikev2_outI1 KE (pcr) Sep 21 07:25:08.680221: | crypto helper 5 sending results from work-order 1 for state #1 to event queue Sep 21 07:25:08.680224: | scheduling resume sending helper answer for #1 Sep 21 07:25:08.680228: | libevent_malloc: new ptr-libevent@0x7fe628006900 size 128 Sep 21 07:25:08.680234: | crypto helper 5 waiting (nothing to do) Sep 21 07:25:08.679140: | processing: RESET whack log_fd (was fd@16) (in ikev2_parent_outI1() at ikev2_parent.c:610) Sep 21 07:25:08.680246: | RESET processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in ikev2_parent_outI1() at ikev2_parent.c:610) Sep 21 07:25:08.680253: | RESET processing: connection "northnet-eastnet-ipv4" (in ikev2_parent_outI1() at ikev2_parent.c:610) Sep 21 07:25:08.680256: | processing: STOP connection NULL (in initiate_a_connection() at initiate.c:349) Sep 21 07:25:08.680260: | close_any(fd@23) (in initiate_connection() at initiate.c:372) Sep 21 07:25:08.680263: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:25:08.680267: | spent 0.252 milliseconds in whack Sep 21 07:25:08.680275: | processing resume sending helper answer for #1 Sep 21 07:25:08.680280: | start processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in resume_handler() at server.c:797) Sep 21 07:25:08.680284: | crypto helper 5 replies to request ID 1 Sep 21 07:25:08.680286: | calling continuation function 0x560ed869c630 Sep 21 07:25:08.680289: | ikev2_parent_outI1_continue for #1 Sep 21 07:25:08.680319: | **emit ISAKMP Message: Sep 21 07:25:08.680322: | initiator cookie: Sep 21 07:25:08.680325: | a9 99 11 a6 c8 e2 19 a0 Sep 21 07:25:08.680327: | responder cookie: Sep 21 07:25:08.680329: | 00 00 00 00 00 00 00 00 Sep 21 07:25:08.680332: | next payload type: ISAKMP_NEXT_NONE (0x0) Sep 21 07:25:08.680335: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:25:08.680337: | exchange type: ISAKMP_v2_IKE_SA_INIT (0x22) Sep 21 07:25:08.680340: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Sep 21 07:25:08.680342: | Message ID: 0 (0x0) Sep 21 07:25:08.680345: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Sep 21 07:25:08.680362: | using existing local IKE proposals for connection northnet-eastnet-ipv4 (IKE SA initiator emitting local proposals): 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 2:IKE:ENCR=AES_GCM_C_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 3:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 4:IKE:ENCR=AES_CBC_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:25:08.680365: | Emitting ikev2_proposals ... Sep 21 07:25:08.680368: | ***emit IKEv2 Security Association Payload: Sep 21 07:25:08.680370: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.680373: | flags: none (0x0) Sep 21 07:25:08.680376: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Security Association Payload (33:ISAKMP_NEXT_v2SA) Sep 21 07:25:08.680379: | next payload chain: saving location 'IKEv2 Security Association Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.680382: | discarding INTEG=NONE Sep 21 07:25:08.680384: | ****emit IKEv2 Proposal Substructure Payload: Sep 21 07:25:08.680387: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:25:08.680389: | prop #: 1 (0x1) Sep 21 07:25:08.680392: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:25:08.680394: | spi size: 0 (0x0) Sep 21 07:25:08.680396: | # transforms: 11 (0xb) Sep 21 07:25:08.680399: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Sep 21 07:25:08.680402: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680404: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680406: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:25:08.680409: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:25:08.680412: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680414: | ******emit IKEv2 Attribute Substructure Payload: Sep 21 07:25:08.680417: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:25:08.680421: | length/value: 256 (0x100) Sep 21 07:25:08.680424: | emitting length of IKEv2 Transform Substructure Payload: 12 Sep 21 07:25:08.680427: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680429: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680431: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.680434: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:25:08.680437: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680439: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680442: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680444: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680447: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680449: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.680452: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:25:08.680454: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680457: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680460: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680462: | discarding INTEG=NONE Sep 21 07:25:08.680464: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680466: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680469: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680471: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:25:08.680474: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680476: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680479: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680481: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680484: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680486: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680488: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:25:08.680491: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680494: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680496: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680499: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680501: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680503: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680506: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:25:08.680509: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680511: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680514: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680516: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680518: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680521: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680523: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:25:08.680526: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680530: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680533: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680535: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680537: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680540: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680542: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:25:08.680545: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680548: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680550: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680553: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680555: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680557: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680559: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:25:08.680562: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680565: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680568: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680570: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680572: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680575: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680577: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:25:08.680580: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680582: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680585: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680587: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680589: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:25:08.680592: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680594: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:25:08.680597: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680600: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680602: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680605: | emitting length of IKEv2 Proposal Substructure Payload: 100 Sep 21 07:25:08.680607: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Sep 21 07:25:08.680610: | discarding INTEG=NONE Sep 21 07:25:08.680612: | ****emit IKEv2 Proposal Substructure Payload: Sep 21 07:25:08.680615: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:25:08.680617: | prop #: 2 (0x2) Sep 21 07:25:08.680619: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:25:08.680621: | spi size: 0 (0x0) Sep 21 07:25:08.680624: | # transforms: 11 (0xb) Sep 21 07:25:08.680627: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:25:08.680630: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Sep 21 07:25:08.680635: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680638: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680640: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:25:08.680642: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:25:08.680645: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680647: | ******emit IKEv2 Attribute Substructure Payload: Sep 21 07:25:08.680650: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:25:08.680652: | length/value: 128 (0x80) Sep 21 07:25:08.680655: | emitting length of IKEv2 Transform Substructure Payload: 12 Sep 21 07:25:08.680657: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680659: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680662: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.680664: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:25:08.680667: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680670: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680672: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680674: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680677: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680679: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.680681: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:25:08.680684: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680687: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680689: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680691: | discarding INTEG=NONE Sep 21 07:25:08.680694: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680696: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680698: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680701: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:25:08.680704: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680706: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680709: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680711: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680713: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680716: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680718: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:25:08.680721: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680723: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680726: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680728: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680731: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680733: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680735: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:25:08.680738: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680742: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680744: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680747: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680749: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680751: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680754: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:25:08.680757: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680760: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680762: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680764: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680767: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680769: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680771: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:25:08.680774: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680777: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680779: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680782: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680788: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680791: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680793: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:25:08.680795: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680797: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680800: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680802: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680804: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680807: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680809: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:25:08.680812: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680814: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680817: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680819: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680821: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:25:08.680824: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680826: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:25:08.680829: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680832: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680834: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680836: | emitting length of IKEv2 Proposal Substructure Payload: 100 Sep 21 07:25:08.680839: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Sep 21 07:25:08.680843: | ****emit IKEv2 Proposal Substructure Payload: Sep 21 07:25:08.680845: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:25:08.680848: | prop #: 3 (0x3) Sep 21 07:25:08.680850: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:25:08.680852: | spi size: 0 (0x0) Sep 21 07:25:08.680854: | # transforms: 13 (0xd) Sep 21 07:25:08.680857: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:25:08.680860: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Sep 21 07:25:08.680862: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680865: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680867: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:25:08.680869: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:25:08.680872: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680875: | ******emit IKEv2 Attribute Substructure Payload: Sep 21 07:25:08.680877: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:25:08.680879: | length/value: 256 (0x100) Sep 21 07:25:08.680882: | emitting length of IKEv2 Transform Substructure Payload: 12 Sep 21 07:25:08.680884: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680886: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680889: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.680891: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:25:08.680894: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680896: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680899: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680901: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680903: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680906: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.680908: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:25:08.680911: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680914: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680916: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680919: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680921: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680923: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:25:08.680926: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:25:08.680928: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680931: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680934: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680936: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680938: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680941: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:25:08.680943: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:25:08.680946: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680948: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680953: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680955: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680958: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680960: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680962: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:25:08.680965: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680968: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680970: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680973: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680975: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680977: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680980: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:25:08.680983: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680985: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.680988: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.680990: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.680992: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.680994: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.680997: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:25:08.681000: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681002: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681005: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681007: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681009: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681012: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681014: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:25:08.681017: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681019: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681022: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681024: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681026: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681029: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681031: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:25:08.681034: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681036: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681039: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681041: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681044: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681046: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681048: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:25:08.681051: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681055: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681058: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681060: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681062: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681064: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681067: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:25:08.681070: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681072: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681075: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681077: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681079: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:25:08.681082: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681084: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:25:08.681087: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681089: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681092: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681094: | emitting length of IKEv2 Proposal Substructure Payload: 116 Sep 21 07:25:08.681097: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Sep 21 07:25:08.681099: | ****emit IKEv2 Proposal Substructure Payload: Sep 21 07:25:08.681101: | last proposal: v2_PROPOSAL_LAST (0x0) Sep 21 07:25:08.681104: | prop #: 4 (0x4) Sep 21 07:25:08.681106: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:25:08.681108: | spi size: 0 (0x0) Sep 21 07:25:08.681111: | # transforms: 13 (0xd) Sep 21 07:25:08.681113: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:25:08.681116: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Sep 21 07:25:08.681119: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681121: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681123: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:25:08.681126: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:25:08.681128: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681131: | ******emit IKEv2 Attribute Substructure Payload: Sep 21 07:25:08.681133: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:25:08.681135: | length/value: 128 (0x80) Sep 21 07:25:08.681138: | emitting length of IKEv2 Transform Substructure Payload: 12 Sep 21 07:25:08.681140: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681143: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681145: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.681147: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:25:08.681150: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681153: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681155: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681158: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681161: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681163: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.681165: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:25:08.681168: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681171: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681174: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681176: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681178: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681180: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:25:08.681183: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:25:08.681186: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681188: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681191: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681193: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681195: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681197: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:25:08.681200: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:25:08.681203: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681205: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681208: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681210: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681212: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681215: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681217: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:25:08.681220: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681222: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681225: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681227: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681229: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681232: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681234: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:25:08.681237: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681240: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681242: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681245: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681247: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681249: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681252: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:25:08.681254: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681258: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681261: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681263: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681265: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681268: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681270: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:25:08.681273: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681275: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681278: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681280: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681283: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681285: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681287: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:25:08.681290: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681293: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681295: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681297: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681300: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681302: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681305: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:25:08.681308: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681310: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681313: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681315: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681317: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681320: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681322: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:25:08.681325: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681327: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681330: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681332: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:25:08.681334: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:25:08.681337: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.681339: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:25:08.681342: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.681345: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:25:08.681347: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:25:08.681349: | emitting length of IKEv2 Proposal Substructure Payload: 116 Sep 21 07:25:08.681352: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Sep 21 07:25:08.681354: | emitting length of IKEv2 Security Association Payload: 436 Sep 21 07:25:08.681358: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is 0 Sep 21 07:25:08.681361: | ***emit IKEv2 Key Exchange Payload: Sep 21 07:25:08.681363: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.681366: | flags: none (0x0) Sep 21 07:25:08.681368: | DH group: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:25:08.681371: | next payload chain: setting previous 'IKEv2 Security Association Payload'.'next payload type' to current IKEv2 Key Exchange Payload (34:ISAKMP_NEXT_v2KE) Sep 21 07:25:08.681374: | next payload chain: saving location 'IKEv2 Key Exchange Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.681377: | emitting 256 raw bytes of ikev2 g^x into IKEv2 Key Exchange Payload Sep 21 07:25:08.681380: | ikev2 g^x c4 2b d6 0f a0 37 0a 10 03 36 00 6c 97 c2 d3 4a Sep 21 07:25:08.681382: | ikev2 g^x db 63 3d 1f a9 1a 00 a6 29 c6 ab 99 59 fc 84 e0 Sep 21 07:25:08.681384: | ikev2 g^x 8e 19 c3 69 57 22 46 93 83 ac af 82 de eb 8f f8 Sep 21 07:25:08.681386: | ikev2 g^x d3 0f 0f 84 92 23 6a d5 7d 00 8c 09 ea 22 1d 69 Sep 21 07:25:08.681389: | ikev2 g^x fa a3 43 16 07 d7 28 93 f9 9b 97 2f 6c 38 b1 72 Sep 21 07:25:08.681391: | ikev2 g^x dd 58 bd 04 e5 f8 1a 86 92 2d c4 08 75 e6 76 69 Sep 21 07:25:08.681393: | ikev2 g^x 48 23 0c c5 c8 66 1f 12 e4 d9 a1 72 fe 07 9d b3 Sep 21 07:25:08.681396: | ikev2 g^x b8 b0 5d 5d e8 26 da dc d4 69 ba 52 40 bb 92 45 Sep 21 07:25:08.681398: | ikev2 g^x fb ec a4 f3 4c 3f 35 db f8 cc 39 1d aa 1e 80 8f Sep 21 07:25:08.681400: | ikev2 g^x 88 12 87 1d 9f b4 7a 5a 46 f1 14 b0 57 6a 05 f5 Sep 21 07:25:08.681402: | ikev2 g^x 6e cf 8f b3 43 f9 9b 3f 75 19 f4 24 80 69 14 13 Sep 21 07:25:08.681405: | ikev2 g^x 75 b5 26 e7 a0 30 8c 14 05 d4 05 6a f7 7f 2b 98 Sep 21 07:25:08.681407: | ikev2 g^x 6c b2 27 7f 1f e6 56 11 e7 9c a7 80 d1 f1 24 bf Sep 21 07:25:08.681409: | ikev2 g^x f6 e2 6d cf 01 82 3c 38 75 7d cf 70 9c 87 ea da Sep 21 07:25:08.681411: | ikev2 g^x e5 1a ec e8 cd 4b 49 8d 00 84 de 72 6f f6 69 44 Sep 21 07:25:08.681414: | ikev2 g^x 45 5a 52 67 81 21 6c fe ff 76 9a 4c 68 18 65 d6 Sep 21 07:25:08.681416: | emitting length of IKEv2 Key Exchange Payload: 264 Sep 21 07:25:08.681418: | ***emit IKEv2 Nonce Payload: Sep 21 07:25:08.681421: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:25:08.681423: | flags: none (0x0) Sep 21 07:25:08.681426: | next payload chain: ignoring supplied 'IKEv2 Nonce Payload'.'next payload type' value 41:ISAKMP_NEXT_v2N Sep 21 07:25:08.681429: | next payload chain: setting previous 'IKEv2 Key Exchange Payload'.'next payload type' to current IKEv2 Nonce Payload (40:ISAKMP_NEXT_v2Ni) Sep 21 07:25:08.681432: | next payload chain: saving location 'IKEv2 Nonce Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.681434: | emitting 32 raw bytes of IKEv2 nonce into IKEv2 Nonce Payload Sep 21 07:25:08.681437: | IKEv2 nonce 9d da 01 19 30 e4 27 d8 3c ca 91 37 c5 7e 94 c9 Sep 21 07:25:08.681439: | IKEv2 nonce b7 df 4e 9a 10 3f 6d 0f 1e 27 41 2a 39 77 1d ed Sep 21 07:25:08.681441: | emitting length of IKEv2 Nonce Payload: 36 Sep 21 07:25:08.681444: | Adding a v2N Payload Sep 21 07:25:08.681446: | ***emit IKEv2 Notify Payload: Sep 21 07:25:08.681449: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.681451: | flags: none (0x0) Sep 21 07:25:08.681453: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:25:08.681456: | SPI size: 0 (0x0) Sep 21 07:25:08.681458: | Notify Message Type: v2N_IKEV2_FRAGMENTATION_SUPPORTED (0x402e) Sep 21 07:25:08.681461: | next payload chain: setting previous 'IKEv2 Nonce Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Sep 21 07:25:08.681464: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.681466: | emitting length of IKEv2 Notify Payload: 8 Sep 21 07:25:08.681469: | NAT-Traversal support [enabled] add v2N payloads. Sep 21 07:25:08.681472: | natd_hash: rcookie is zero Sep 21 07:25:08.681484: | natd_hash: hasher=0x560ed87727a0(20) Sep 21 07:25:08.681486: | natd_hash: icookie= a9 99 11 a6 c8 e2 19 a0 Sep 21 07:25:08.681489: | natd_hash: rcookie= 00 00 00 00 00 00 00 00 Sep 21 07:25:08.681491: | natd_hash: ip= c0 01 03 21 Sep 21 07:25:08.681493: | natd_hash: port= 01 f4 Sep 21 07:25:08.681496: | natd_hash: hash= 97 58 46 8b e4 de fd 9e a3 21 24 56 c3 f2 0d a8 Sep 21 07:25:08.681498: | natd_hash: hash= c3 70 02 a1 Sep 21 07:25:08.681500: | Adding a v2N Payload Sep 21 07:25:08.681502: | ***emit IKEv2 Notify Payload: Sep 21 07:25:08.681505: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.681507: | flags: none (0x0) Sep 21 07:25:08.681509: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:25:08.681512: | SPI size: 0 (0x0) Sep 21 07:25:08.681514: | Notify Message Type: v2N_NAT_DETECTION_SOURCE_IP (0x4004) Sep 21 07:25:08.681517: | next payload chain: setting previous 'IKEv2 Notify Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Sep 21 07:25:08.681519: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.681522: | emitting 20 raw bytes of Notify data into IKEv2 Notify Payload Sep 21 07:25:08.681524: | Notify data 97 58 46 8b e4 de fd 9e a3 21 24 56 c3 f2 0d a8 Sep 21 07:25:08.681527: | Notify data c3 70 02 a1 Sep 21 07:25:08.681529: | emitting length of IKEv2 Notify Payload: 28 Sep 21 07:25:08.681531: | natd_hash: rcookie is zero Sep 21 07:25:08.681537: | natd_hash: hasher=0x560ed87727a0(20) Sep 21 07:25:08.681540: | natd_hash: icookie= a9 99 11 a6 c8 e2 19 a0 Sep 21 07:25:08.681542: | natd_hash: rcookie= 00 00 00 00 00 00 00 00 Sep 21 07:25:08.681544: | natd_hash: ip= c0 01 02 17 Sep 21 07:25:08.681546: | natd_hash: port= 01 f4 Sep 21 07:25:08.681548: | natd_hash: hash= 54 05 83 ef 73 c8 8c ac f9 1b dd f0 84 6a 00 a3 Sep 21 07:25:08.681551: | natd_hash: hash= 0a a7 15 3e Sep 21 07:25:08.681553: | Adding a v2N Payload Sep 21 07:25:08.681555: | ***emit IKEv2 Notify Payload: Sep 21 07:25:08.681557: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.681560: | flags: none (0x0) Sep 21 07:25:08.681562: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:25:08.681564: | SPI size: 0 (0x0) Sep 21 07:25:08.681567: | Notify Message Type: v2N_NAT_DETECTION_DESTINATION_IP (0x4005) Sep 21 07:25:08.681570: | next payload chain: setting previous 'IKEv2 Notify Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Sep 21 07:25:08.681572: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.681575: | emitting 20 raw bytes of Notify data into IKEv2 Notify Payload Sep 21 07:25:08.681577: | Notify data 54 05 83 ef 73 c8 8c ac f9 1b dd f0 84 6a 00 a3 Sep 21 07:25:08.681579: | Notify data 0a a7 15 3e Sep 21 07:25:08.681581: | emitting length of IKEv2 Notify Payload: 28 Sep 21 07:25:08.681584: | emitting length of ISAKMP Message: 828 Sep 21 07:25:08.681590: | stop processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in ikev2_parent_outI1_common() at ikev2_parent.c:817) Sep 21 07:25:08.681600: | start processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:25:08.681604: | #1 complete_v2_state_transition() PARENT_I0->PARENT_I1 with status STF_OK Sep 21 07:25:08.681606: | IKEv2: transition from state STATE_PARENT_I0 to state STATE_PARENT_I1 Sep 21 07:25:08.681609: | parent state #1: PARENT_I0(ignore) => PARENT_I1(half-open IKE SA) Sep 21 07:25:08.681612: | Message ID: updating counters for #1 to 4294967295 after switching state Sep 21 07:25:08.681615: | Message ID: IKE #1 skipping update_recv as MD is fake Sep 21 07:25:08.681620: | Message ID: sent #1 request 0; ike: initiator.sent=-1->0 initiator.recv=-1 responder.sent=-1 responder.recv=-1 wip.initiator=-1->0 wip.responder=-1 Sep 21 07:25:08.681624: "northnet-eastnet-ipv4" #1: STATE_PARENT_I1: sent v2I1, expected v2R1 Sep 21 07:25:08.681636: | sending V2 reply packet to 192.1.2.23:500 (from 192.1.3.33:500) Sep 21 07:25:08.681645: | sending 828 bytes for STATE_PARENT_I0 through eth1 from 192.1.3.33:500 to 192.1.2.23:500 (using #1) Sep 21 07:25:08.681649: | a9 99 11 a6 c8 e2 19 a0 00 00 00 00 00 00 00 00 Sep 21 07:25:08.681651: | 21 20 22 08 00 00 00 00 00 00 03 3c 22 00 01 b4 Sep 21 07:25:08.681653: | 02 00 00 64 01 01 00 0b 03 00 00 0c 01 00 00 14 Sep 21 07:25:08.681656: | 80 0e 01 00 03 00 00 08 02 00 00 07 03 00 00 08 Sep 21 07:25:08.681658: | 02 00 00 05 03 00 00 08 04 00 00 0e 03 00 00 08 Sep 21 07:25:08.681660: | 04 00 00 0f 03 00 00 08 04 00 00 10 03 00 00 08 Sep 21 07:25:08.681662: | 04 00 00 12 03 00 00 08 04 00 00 13 03 00 00 08 Sep 21 07:25:08.681664: | 04 00 00 14 03 00 00 08 04 00 00 15 00 00 00 08 Sep 21 07:25:08.681667: | 04 00 00 1f 02 00 00 64 02 01 00 0b 03 00 00 0c Sep 21 07:25:08.681669: | 01 00 00 14 80 0e 00 80 03 00 00 08 02 00 00 07 Sep 21 07:25:08.681671: | 03 00 00 08 02 00 00 05 03 00 00 08 04 00 00 0e Sep 21 07:25:08.681673: | 03 00 00 08 04 00 00 0f 03 00 00 08 04 00 00 10 Sep 21 07:25:08.681675: | 03 00 00 08 04 00 00 12 03 00 00 08 04 00 00 13 Sep 21 07:25:08.681678: | 03 00 00 08 04 00 00 14 03 00 00 08 04 00 00 15 Sep 21 07:25:08.681680: | 00 00 00 08 04 00 00 1f 02 00 00 74 03 01 00 0d Sep 21 07:25:08.681682: | 03 00 00 0c 01 00 00 0c 80 0e 01 00 03 00 00 08 Sep 21 07:25:08.681685: | 02 00 00 07 03 00 00 08 02 00 00 05 03 00 00 08 Sep 21 07:25:08.681687: | 03 00 00 0e 03 00 00 08 03 00 00 0c 03 00 00 08 Sep 21 07:25:08.681689: | 04 00 00 0e 03 00 00 08 04 00 00 0f 03 00 00 08 Sep 21 07:25:08.681691: | 04 00 00 10 03 00 00 08 04 00 00 12 03 00 00 08 Sep 21 07:25:08.681693: | 04 00 00 13 03 00 00 08 04 00 00 14 03 00 00 08 Sep 21 07:25:08.681695: | 04 00 00 15 00 00 00 08 04 00 00 1f 00 00 00 74 Sep 21 07:25:08.681698: | 04 01 00 0d 03 00 00 0c 01 00 00 0c 80 0e 00 80 Sep 21 07:25:08.681700: | 03 00 00 08 02 00 00 07 03 00 00 08 02 00 00 05 Sep 21 07:25:08.681702: | 03 00 00 08 03 00 00 0e 03 00 00 08 03 00 00 0c Sep 21 07:25:08.681704: | 03 00 00 08 04 00 00 0e 03 00 00 08 04 00 00 0f Sep 21 07:25:08.681707: | 03 00 00 08 04 00 00 10 03 00 00 08 04 00 00 12 Sep 21 07:25:08.681709: | 03 00 00 08 04 00 00 13 03 00 00 08 04 00 00 14 Sep 21 07:25:08.681711: | 03 00 00 08 04 00 00 15 00 00 00 08 04 00 00 1f Sep 21 07:25:08.681713: | 28 00 01 08 00 0e 00 00 c4 2b d6 0f a0 37 0a 10 Sep 21 07:25:08.681715: | 03 36 00 6c 97 c2 d3 4a db 63 3d 1f a9 1a 00 a6 Sep 21 07:25:08.681718: | 29 c6 ab 99 59 fc 84 e0 8e 19 c3 69 57 22 46 93 Sep 21 07:25:08.681720: | 83 ac af 82 de eb 8f f8 d3 0f 0f 84 92 23 6a d5 Sep 21 07:25:08.681722: | 7d 00 8c 09 ea 22 1d 69 fa a3 43 16 07 d7 28 93 Sep 21 07:25:08.681724: | f9 9b 97 2f 6c 38 b1 72 dd 58 bd 04 e5 f8 1a 86 Sep 21 07:25:08.681726: | 92 2d c4 08 75 e6 76 69 48 23 0c c5 c8 66 1f 12 Sep 21 07:25:08.681729: | e4 d9 a1 72 fe 07 9d b3 b8 b0 5d 5d e8 26 da dc Sep 21 07:25:08.681731: | d4 69 ba 52 40 bb 92 45 fb ec a4 f3 4c 3f 35 db Sep 21 07:25:08.681733: | f8 cc 39 1d aa 1e 80 8f 88 12 87 1d 9f b4 7a 5a Sep 21 07:25:08.681735: | 46 f1 14 b0 57 6a 05 f5 6e cf 8f b3 43 f9 9b 3f Sep 21 07:25:08.681737: | 75 19 f4 24 80 69 14 13 75 b5 26 e7 a0 30 8c 14 Sep 21 07:25:08.681740: | 05 d4 05 6a f7 7f 2b 98 6c b2 27 7f 1f e6 56 11 Sep 21 07:25:08.681742: | e7 9c a7 80 d1 f1 24 bf f6 e2 6d cf 01 82 3c 38 Sep 21 07:25:08.681744: | 75 7d cf 70 9c 87 ea da e5 1a ec e8 cd 4b 49 8d Sep 21 07:25:08.681746: | 00 84 de 72 6f f6 69 44 45 5a 52 67 81 21 6c fe Sep 21 07:25:08.681748: | ff 76 9a 4c 68 18 65 d6 29 00 00 24 9d da 01 19 Sep 21 07:25:08.681751: | 30 e4 27 d8 3c ca 91 37 c5 7e 94 c9 b7 df 4e 9a Sep 21 07:25:08.681753: | 10 3f 6d 0f 1e 27 41 2a 39 77 1d ed 29 00 00 08 Sep 21 07:25:08.681756: | 00 00 40 2e 29 00 00 1c 00 00 40 04 97 58 46 8b Sep 21 07:25:08.681759: | e4 de fd 9e a3 21 24 56 c3 f2 0d a8 c3 70 02 a1 Sep 21 07:25:08.681761: | 00 00 00 1c 00 00 40 05 54 05 83 ef 73 c8 8c ac Sep 21 07:25:08.681763: | f9 1b dd f0 84 6a 00 a3 0a a7 15 3e Sep 21 07:25:08.685102: | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted Sep 21 07:25:08.685111: | libevent_free: release ptr-libevent@0x560eda595f30 Sep 21 07:25:08.685115: | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x560eda595ef0 Sep 21 07:25:08.685118: | success_v2_state_transition scheduling EVENT_RETRANSMIT of c->r_interval=500ms Sep 21 07:25:08.685121: | event_schedule: new EVENT_RETRANSMIT-pe@0x560eda595ef0 Sep 21 07:25:08.685125: | inserting event EVENT_RETRANSMIT, timeout in 0.5 seconds for #1 Sep 21 07:25:08.685128: | libevent_malloc: new ptr-libevent@0x560eda595f30 size 128 Sep 21 07:25:08.685133: | #1 STATE_PARENT_I1: retransmits: first event in 0.5 seconds; timeout in 60 seconds; limit of 12 retransmits; current time is 49355.053385 Sep 21 07:25:08.685136: | resume sending helper answer for #1 suppresed complete_v2_state_transition() and stole MD Sep 21 07:25:08.685142: | #1 spent 1.62 milliseconds in resume sending helper answer Sep 21 07:25:08.685147: | stop processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in resume_handler() at server.c:833) Sep 21 07:25:08.685150: | libevent_free: release ptr-libevent@0x7fe628006900 Sep 21 07:25:08.685160: | spent 0.00178 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() Sep 21 07:25:08.685174: | *received 432 bytes from 192.1.2.23:500 on eth1 (192.1.3.33:500) Sep 21 07:25:08.685177: | a9 99 11 a6 c8 e2 19 a0 39 99 17 9c bc 71 23 52 Sep 21 07:25:08.685179: | 21 20 22 20 00 00 00 00 00 00 01 b0 22 00 00 28 Sep 21 07:25:08.685182: | 00 00 00 24 01 01 00 03 03 00 00 0c 01 00 00 14 Sep 21 07:25:08.685184: | 80 0e 01 00 03 00 00 08 02 00 00 07 00 00 00 08 Sep 21 07:25:08.685186: | 04 00 00 0e 28 00 01 08 00 0e 00 00 77 b5 b7 51 Sep 21 07:25:08.685188: | e8 19 f9 25 79 bf 32 bb 3d ab 54 dd 45 b5 7c 90 Sep 21 07:25:08.685191: | 85 e4 3f 0c 69 f9 3d 2b 29 5c f5 38 40 ea 48 49 Sep 21 07:25:08.685193: | 6f 5c 4f ae c3 3b f4 7e f3 eb 91 0a f3 59 5c 53 Sep 21 07:25:08.685195: | fa 6a 6e aa 88 57 6e 18 a6 78 c2 d3 79 49 37 45 Sep 21 07:25:08.685197: | 0e f4 31 00 0a 9b 2d 1c d3 db 25 fc 39 f9 24 22 Sep 21 07:25:08.685199: | 32 6c 12 cb 03 79 c5 c1 51 b6 32 ca f2 d8 c2 41 Sep 21 07:25:08.685202: | ab f4 d1 d3 58 82 28 ae cb b4 1f 1b cd 3c 86 d2 Sep 21 07:25:08.685204: | 1b 48 24 e9 dd 94 70 aa c2 41 53 16 f6 36 40 c3 Sep 21 07:25:08.685206: | ce 0f 5e d6 3a 6c 90 29 ee 44 02 9c 6c c8 63 12 Sep 21 07:25:08.685208: | ec eb 28 87 5c 1f 65 83 47 09 38 38 60 7f 37 2e Sep 21 07:25:08.685211: | 6e f1 f4 d8 d3 85 d2 41 9d 21 d8 67 06 c2 21 cb Sep 21 07:25:08.685213: | 4e a4 fc 0e 90 ed a4 dd 25 6d c7 0e d9 25 4a 3f Sep 21 07:25:08.685215: | 07 e2 99 c9 e1 fa 4c 72 6d 5d b4 4a 30 0c dd 49 Sep 21 07:25:08.685217: | 79 d5 63 7b 37 c2 24 c3 cd 1f a1 74 01 22 be d6 Sep 21 07:25:08.685219: | 2b 7d b3 15 ac 1d 3f 9b 9f c8 40 4a 0a a0 f2 3e Sep 21 07:25:08.685222: | 14 d9 11 8e e7 d3 c7 a3 df cd e8 49 29 00 00 24 Sep 21 07:25:08.685224: | c4 b0 95 37 62 73 85 99 e4 f4 7d 8a bd 80 41 c4 Sep 21 07:25:08.685226: | c8 4a 5e 36 a8 da c6 ad 71 ec 75 d3 35 55 57 8d Sep 21 07:25:08.685228: | 29 00 00 08 00 00 40 2e 29 00 00 1c 00 00 40 04 Sep 21 07:25:08.685231: | 4a a9 98 e6 25 a9 48 7f dd 2f b3 6e e3 1c d2 71 Sep 21 07:25:08.685233: | 5b 01 77 b1 00 00 00 1c 00 00 40 05 80 67 6d 5e Sep 21 07:25:08.685235: | ed 99 f9 c0 25 31 a9 d5 51 2b 44 0d 96 fe fb 5f Sep 21 07:25:08.685239: | start processing: from 192.1.2.23:500 (in process_md() at demux.c:378) Sep 21 07:25:08.685243: | **parse ISAKMP Message: Sep 21 07:25:08.685245: | initiator cookie: Sep 21 07:25:08.685247: | a9 99 11 a6 c8 e2 19 a0 Sep 21 07:25:08.685251: | responder cookie: Sep 21 07:25:08.685254: | 39 99 17 9c bc 71 23 52 Sep 21 07:25:08.685256: | next payload type: ISAKMP_NEXT_v2SA (0x21) Sep 21 07:25:08.685259: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:25:08.685262: | exchange type: ISAKMP_v2_IKE_SA_INIT (0x22) Sep 21 07:25:08.685264: | flags: ISAKMP_FLAG_v2_MSG_RESPONSE (0x20) Sep 21 07:25:08.685267: | Message ID: 0 (0x0) Sep 21 07:25:08.685269: | length: 432 (0x1b0) Sep 21 07:25:08.685272: | processing version=2.0 packet with exchange type=ISAKMP_v2_IKE_SA_INIT (34) Sep 21 07:25:08.685275: | I am the IKE SA Original Initiator receiving an IKEv2 IKE_SA_INIT response Sep 21 07:25:08.685278: | State DB: found IKEv2 state #1 in PARENT_I1 (find_v2_ike_sa_by_initiator_spi) Sep 21 07:25:08.685284: | start processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in ikev2_process_packet() at ikev2.c:2016) Sep 21 07:25:08.685288: | [RE]START processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in ike_process_packet() at ikev2.c:2062) Sep 21 07:25:08.685291: | #1 is idle Sep 21 07:25:08.685293: | #1 idle Sep 21 07:25:08.685295: | unpacking clear payload Sep 21 07:25:08.685298: | Now let's proceed with payload (ISAKMP_NEXT_v2SA) Sep 21 07:25:08.685300: | ***parse IKEv2 Security Association Payload: Sep 21 07:25:08.685303: | next payload type: ISAKMP_NEXT_v2KE (0x22) Sep 21 07:25:08.685305: | flags: none (0x0) Sep 21 07:25:08.685308: | length: 40 (0x28) Sep 21 07:25:08.685310: | processing payload: ISAKMP_NEXT_v2SA (len=36) Sep 21 07:25:08.685312: | Now let's proceed with payload (ISAKMP_NEXT_v2KE) Sep 21 07:25:08.685315: | ***parse IKEv2 Key Exchange Payload: Sep 21 07:25:08.685317: | next payload type: ISAKMP_NEXT_v2Ni (0x28) Sep 21 07:25:08.685320: | flags: none (0x0) Sep 21 07:25:08.685322: | length: 264 (0x108) Sep 21 07:25:08.685324: | DH group: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:25:08.685327: | processing payload: ISAKMP_NEXT_v2KE (len=256) Sep 21 07:25:08.685329: | Now let's proceed with payload (ISAKMP_NEXT_v2Ni) Sep 21 07:25:08.685331: | ***parse IKEv2 Nonce Payload: Sep 21 07:25:08.685333: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:25:08.685336: | flags: none (0x0) Sep 21 07:25:08.685338: | length: 36 (0x24) Sep 21 07:25:08.685340: | processing payload: ISAKMP_NEXT_v2Ni (len=32) Sep 21 07:25:08.685343: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Sep 21 07:25:08.685345: | ***parse IKEv2 Notify Payload: Sep 21 07:25:08.685347: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:25:08.685350: | flags: none (0x0) Sep 21 07:25:08.685352: | length: 8 (0x8) Sep 21 07:25:08.685354: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:25:08.685357: | SPI size: 0 (0x0) Sep 21 07:25:08.685359: | Notify Message Type: v2N_IKEV2_FRAGMENTATION_SUPPORTED (0x402e) Sep 21 07:25:08.685362: | processing payload: ISAKMP_NEXT_v2N (len=0) Sep 21 07:25:08.685364: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Sep 21 07:25:08.685366: | ***parse IKEv2 Notify Payload: Sep 21 07:25:08.685369: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:25:08.685371: | flags: none (0x0) Sep 21 07:25:08.685373: | length: 28 (0x1c) Sep 21 07:25:08.685375: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:25:08.685378: | SPI size: 0 (0x0) Sep 21 07:25:08.685380: | Notify Message Type: v2N_NAT_DETECTION_SOURCE_IP (0x4004) Sep 21 07:25:08.685382: | processing payload: ISAKMP_NEXT_v2N (len=20) Sep 21 07:25:08.685385: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Sep 21 07:25:08.685387: | ***parse IKEv2 Notify Payload: Sep 21 07:25:08.685389: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.685392: | flags: none (0x0) Sep 21 07:25:08.685394: | length: 28 (0x1c) Sep 21 07:25:08.685396: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:25:08.685398: | SPI size: 0 (0x0) Sep 21 07:25:08.685401: | Notify Message Type: v2N_NAT_DETECTION_DESTINATION_IP (0x4005) Sep 21 07:25:08.685404: | processing payload: ISAKMP_NEXT_v2N (len=20) Sep 21 07:25:08.685407: | State DB: re-hashing IKEv2 state #1 IKE SPIi and SPI[ir] Sep 21 07:25:08.685412: | #1 in state PARENT_I1: sent v2I1, expected v2R1 Sep 21 07:25:08.685416: | selected state microcode Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH Sep 21 07:25:08.685418: | Now let's proceed with state specific processing Sep 21 07:25:08.685421: | calling processor Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH Sep 21 07:25:08.685424: | ikev2 parent inR1: calculating g^{xy} in order to send I2 Sep 21 07:25:08.685440: | using existing local IKE proposals for connection northnet-eastnet-ipv4 (IKE SA initiator accepting remote proposal): 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 2:IKE:ENCR=AES_GCM_C_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 3:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 4:IKE:ENCR=AES_CBC_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:25:08.685444: | Comparing remote proposals against IKE initiator (accepting) 4 local proposals Sep 21 07:25:08.685447: | local proposal 1 type ENCR has 1 transforms Sep 21 07:25:08.685450: | local proposal 1 type PRF has 2 transforms Sep 21 07:25:08.685452: | local proposal 1 type INTEG has 1 transforms Sep 21 07:25:08.685454: | local proposal 1 type DH has 8 transforms Sep 21 07:25:08.685457: | local proposal 1 type ESN has 0 transforms Sep 21 07:25:08.685460: | local proposal 1 transforms: required: ENCR+PRF+DH; optional: INTEG Sep 21 07:25:08.685462: | local proposal 2 type ENCR has 1 transforms Sep 21 07:25:08.685465: | local proposal 2 type PRF has 2 transforms Sep 21 07:25:08.685467: | local proposal 2 type INTEG has 1 transforms Sep 21 07:25:08.685469: | local proposal 2 type DH has 8 transforms Sep 21 07:25:08.685472: | local proposal 2 type ESN has 0 transforms Sep 21 07:25:08.685475: | local proposal 2 transforms: required: ENCR+PRF+DH; optional: INTEG Sep 21 07:25:08.685477: | local proposal 3 type ENCR has 1 transforms Sep 21 07:25:08.685479: | local proposal 3 type PRF has 2 transforms Sep 21 07:25:08.685482: | local proposal 3 type INTEG has 2 transforms Sep 21 07:25:08.685484: | local proposal 3 type DH has 8 transforms Sep 21 07:25:08.685486: | local proposal 3 type ESN has 0 transforms Sep 21 07:25:08.685489: | local proposal 3 transforms: required: ENCR+PRF+INTEG+DH; optional: none Sep 21 07:25:08.685492: | local proposal 4 type ENCR has 1 transforms Sep 21 07:25:08.685494: | local proposal 4 type PRF has 2 transforms Sep 21 07:25:08.685496: | local proposal 4 type INTEG has 2 transforms Sep 21 07:25:08.685499: | local proposal 4 type DH has 8 transforms Sep 21 07:25:08.685501: | local proposal 4 type ESN has 0 transforms Sep 21 07:25:08.685504: | local proposal 4 transforms: required: ENCR+PRF+INTEG+DH; optional: none Sep 21 07:25:08.685507: | ****parse IKEv2 Proposal Substructure Payload: Sep 21 07:25:08.685509: | last proposal: v2_PROPOSAL_LAST (0x0) Sep 21 07:25:08.685511: | length: 36 (0x24) Sep 21 07:25:08.685514: | prop #: 1 (0x1) Sep 21 07:25:08.685516: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:25:08.685518: | spi size: 0 (0x0) Sep 21 07:25:08.685521: | # transforms: 3 (0x3) Sep 21 07:25:08.685524: | Comparing remote proposal 1 containing 3 transforms against local proposal [1..1] of 4 local proposals Sep 21 07:25:08.685527: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:25:08.685529: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.685531: | length: 12 (0xc) Sep 21 07:25:08.685534: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:25:08.685536: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:25:08.685540: | ******parse IKEv2 Attribute Substructure Payload: Sep 21 07:25:08.685543: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:25:08.685545: | length/value: 256 (0x100) Sep 21 07:25:08.685549: | remote proposal 1 transform 0 (ENCR=AES_GCM_C_256) matches local proposal 1 type 1 (ENCR) transform 0 Sep 21 07:25:08.685552: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:25:08.685554: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:25:08.685557: | length: 8 (0x8) Sep 21 07:25:08.685559: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:25:08.685561: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:25:08.685565: | remote proposal 1 transform 1 (PRF=HMAC_SHA2_512) matches local proposal 1 type 2 (PRF) transform 0 Sep 21 07:25:08.685567: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:25:08.685570: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:25:08.685572: | length: 8 (0x8) Sep 21 07:25:08.685574: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:25:08.685577: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:25:08.685580: | remote proposal 1 transform 2 (DH=MODP2048) matches local proposal 1 type 4 (DH) transform 0 Sep 21 07:25:08.685583: | remote proposal 1 proposed transforms: ENCR+PRF+DH; matched: ENCR+PRF+DH; unmatched: none Sep 21 07:25:08.685587: | comparing remote proposal 1 containing ENCR+PRF+DH transforms to local proposal 1; required: ENCR+PRF+DH; optional: INTEG; matched: ENCR+PRF+DH Sep 21 07:25:08.685590: | remote proposal 1 matches local proposal 1 Sep 21 07:25:08.685593: | remote accepted the proposal 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512;DH=MODP2048[first-match] Sep 21 07:25:08.685595: | converting proposal to internal trans attrs Sep 21 07:25:08.685608: | natd_hash: hasher=0x560ed87727a0(20) Sep 21 07:25:08.685611: | natd_hash: icookie= a9 99 11 a6 c8 e2 19 a0 Sep 21 07:25:08.685613: | natd_hash: rcookie= 39 99 17 9c bc 71 23 52 Sep 21 07:25:08.685615: | natd_hash: ip= c0 01 03 21 Sep 21 07:25:08.685617: | natd_hash: port= 01 f4 Sep 21 07:25:08.685620: | natd_hash: hash= 80 67 6d 5e ed 99 f9 c0 25 31 a9 d5 51 2b 44 0d Sep 21 07:25:08.685622: | natd_hash: hash= 96 fe fb 5f Sep 21 07:25:08.685627: | natd_hash: hasher=0x560ed87727a0(20) Sep 21 07:25:08.685630: | natd_hash: icookie= a9 99 11 a6 c8 e2 19 a0 Sep 21 07:25:08.685632: | natd_hash: rcookie= 39 99 17 9c bc 71 23 52 Sep 21 07:25:08.685634: | natd_hash: ip= c0 01 02 17 Sep 21 07:25:08.685636: | natd_hash: port= 01 f4 Sep 21 07:25:08.685639: | natd_hash: hash= 4a a9 98 e6 25 a9 48 7f dd 2f b3 6e e3 1c d2 71 Sep 21 07:25:08.685641: | natd_hash: hash= 5b 01 77 b1 Sep 21 07:25:08.685643: | NAT_TRAVERSAL encaps using auto-detect Sep 21 07:25:08.685645: | NAT_TRAVERSAL this end is NOT behind NAT Sep 21 07:25:08.685647: | NAT_TRAVERSAL that end is NOT behind NAT Sep 21 07:25:08.685650: | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.23 Sep 21 07:25:08.685655: | offloading IKEv2 SKEYSEED using prf=HMAC_SHA2_512 integ=NONE cipherkey=AES_GCM_16 Sep 21 07:25:08.685659: | adding ikev2_inR1outI2 KE work-order 2 for state #1 Sep 21 07:25:08.685661: | state #1 requesting EVENT_RETRANSMIT to be deleted Sep 21 07:25:08.685664: | #1 STATE_PARENT_I1: retransmits: cleared Sep 21 07:25:08.685667: | libevent_free: release ptr-libevent@0x560eda595f30 Sep 21 07:25:08.685670: | free_event_entry: release EVENT_RETRANSMIT-pe@0x560eda595ef0 Sep 21 07:25:08.685672: | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x560eda595ef0 Sep 21 07:25:08.685676: | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 Sep 21 07:25:08.685679: | libevent_malloc: new ptr-libevent@0x560eda595f30 size 128 Sep 21 07:25:08.685688: | #1 spent 0.263 milliseconds in processing: Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH in ikev2_process_state_packet() Sep 21 07:25:08.685694: | [RE]START processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:25:08.685697: | #1 complete_v2_state_transition() PARENT_I1->PARENT_I2 with status STF_SUSPEND Sep 21 07:25:08.685702: | suspending state #1 and saving MD Sep 21 07:25:08.685704: | #1 is busy; has a suspended MD Sep 21 07:25:08.685708: | [RE]START processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in log_stf_suspend() at ikev2.c:3266) Sep 21 07:25:08.685712: | "northnet-eastnet-ipv4" #1 complete v2 state STATE_PARENT_I1 transition with STF_SUSPEND suspended from complete_v2_state_transition:3448 Sep 21 07:25:08.685716: | stop processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in ikev2_process_packet() at ikev2.c:2018) Sep 21 07:25:08.685720: | #1 spent 0.556 milliseconds in ikev2_process_packet() Sep 21 07:25:08.685724: | stop processing: from 192.1.2.23:500 (in process_md() at demux.c:380) Sep 21 07:25:08.685727: | processing: STOP state #0 (in process_md() at demux.c:382) Sep 21 07:25:08.685729: | processing: STOP connection NULL (in process_md() at demux.c:383) Sep 21 07:25:08.685733: | spent 0.57 milliseconds in comm_handle_cb() reading and processing packet Sep 21 07:25:08.685742: | crypto helper 4 resuming Sep 21 07:25:08.685745: | crypto helper 4 starting work-order 2 for state #1 Sep 21 07:25:08.685749: | crypto helper 4 doing compute dh (V2) (ikev2_inR1outI2 KE); request ID 2 Sep 21 07:25:08.686768: | calculating skeyseed using prf=sha2_512 integ=none cipherkey-size=32 salt-size=4 Sep 21 07:25:08.687213: | crypto helper 4 finished compute dh (V2) (ikev2_inR1outI2 KE); request ID 2 time elapsed 0.001463 seconds Sep 21 07:25:08.687222: | (#1) spent 1.43 milliseconds in crypto helper computing work-order 2: ikev2_inR1outI2 KE (pcr) Sep 21 07:25:08.687225: | crypto helper 4 sending results from work-order 2 for state #1 to event queue Sep 21 07:25:08.687228: | scheduling resume sending helper answer for #1 Sep 21 07:25:08.687231: | libevent_malloc: new ptr-libevent@0x7fe620006b90 size 128 Sep 21 07:25:08.687238: | crypto helper 4 waiting (nothing to do) Sep 21 07:25:08.687246: | processing resume sending helper answer for #1 Sep 21 07:25:08.687252: | start processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in resume_handler() at server.c:797) Sep 21 07:25:08.687255: | crypto helper 4 replies to request ID 2 Sep 21 07:25:08.687258: | calling continuation function 0x560ed869c630 Sep 21 07:25:08.687261: | ikev2_parent_inR1outI2_continue for #1: calculating g^{xy}, sending I2 Sep 21 07:25:08.687267: | creating state object #2 at 0x560eda598790 Sep 21 07:25:08.687269: | State DB: adding IKEv2 state #2 in UNDEFINED Sep 21 07:25:08.687273: | pstats #2 ikev2.child started Sep 21 07:25:08.687276: | duplicating state object #1 "northnet-eastnet-ipv4" as #2 for IPSEC SA Sep 21 07:25:08.687280: | #2 setting local endpoint to 192.1.3.33:500 from #1.st_localport (in duplicate_state() at state.c:1481) Sep 21 07:25:08.687286: | Message ID: init_child #1.#2; ike: initiator.sent=0 initiator.recv=-1 responder.sent=-1 responder.recv=-1; child: wip.initiator=0->-1 wip.responder=0->-1 Sep 21 07:25:08.687291: | Message ID: switch-from #1 response 0; ike: initiator.sent=0 initiator.recv=-1 responder.sent=-1 responder.recv=-1 wip.initiator=0->-1 wip.responder=-1 Sep 21 07:25:08.687296: | Message ID: switch-to #1.#2 response 0; ike: initiator.sent=0 initiator.recv=-1 responder.sent=-1 responder.recv=-1; child: wip.initiator=-1->0 wip.responder=-1 Sep 21 07:25:08.687298: | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted Sep 21 07:25:08.687301: | libevent_free: release ptr-libevent@0x560eda595f30 Sep 21 07:25:08.687304: | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x560eda595ef0 Sep 21 07:25:08.687306: | event_schedule: new EVENT_SA_REPLACE-pe@0x560eda595ef0 Sep 21 07:25:08.687310: | inserting event EVENT_SA_REPLACE, timeout in 60 seconds for #1 Sep 21 07:25:08.687313: | libevent_malloc: new ptr-libevent@0x560eda595f30 size 128 Sep 21 07:25:08.687316: | parent state #1: PARENT_I1(half-open IKE SA) => PARENT_I2(open IKE SA) Sep 21 07:25:08.687321: | **emit ISAKMP Message: Sep 21 07:25:08.687328: | initiator cookie: Sep 21 07:25:08.687330: | a9 99 11 a6 c8 e2 19 a0 Sep 21 07:25:08.687332: | responder cookie: Sep 21 07:25:08.687335: | 39 99 17 9c bc 71 23 52 Sep 21 07:25:08.687337: | next payload type: ISAKMP_NEXT_NONE (0x0) Sep 21 07:25:08.687340: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:25:08.687342: | exchange type: ISAKMP_v2_IKE_AUTH (0x23) Sep 21 07:25:08.687345: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Sep 21 07:25:08.687347: | Message ID: 1 (0x1) Sep 21 07:25:08.687350: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Sep 21 07:25:08.687353: | ***emit IKEv2 Encryption Payload: Sep 21 07:25:08.687355: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.687358: | flags: none (0x0) Sep 21 07:25:08.687361: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Encryption Payload (46:ISAKMP_NEXT_v2SK) Sep 21 07:25:08.687364: | next payload chain: saving location 'IKEv2 Encryption Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.687367: | emitting 8 zero bytes of IV into IKEv2 Encryption Payload Sep 21 07:25:08.687373: | IKEv2 CERT: send a certificate? Sep 21 07:25:08.687376: | IKEv2 CERT: no certificate to send Sep 21 07:25:08.687378: | IDr payload will be sent Sep 21 07:25:08.687390: | ****emit IKEv2 Identification - Initiator - Payload: Sep 21 07:25:08.687393: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.687395: | flags: none (0x0) Sep 21 07:25:08.687398: | ID type: ID_FQDN (0x2) Sep 21 07:25:08.687401: | next payload chain: setting previous 'IKEv2 Encryption Payload'.'next payload type' to current IKEv2 Identification - Initiator - Payload (35:ISAKMP_NEXT_v2IDi) Sep 21 07:25:08.687404: | next payload chain: saving location 'IKEv2 Identification - Initiator - Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.687407: | emitting 5 raw bytes of my identity into IKEv2 Identification - Initiator - Payload Sep 21 07:25:08.687409: | my identity 6e 6f 72 74 68 Sep 21 07:25:08.687412: | emitting length of IKEv2 Identification - Initiator - Payload: 13 Sep 21 07:25:08.687420: | ****emit IKEv2 Identification - Responder - Payload: Sep 21 07:25:08.687422: | next payload type: ISAKMP_NEXT_v2AUTH (0x27) Sep 21 07:25:08.687425: | flags: none (0x0) Sep 21 07:25:08.687427: | ID type: ID_FQDN (0x2) Sep 21 07:25:08.687430: | next payload chain: ignoring supplied 'IKEv2 Identification - Responder - Payload'.'next payload type' value 39:ISAKMP_NEXT_v2AUTH Sep 21 07:25:08.687433: | next payload chain: setting previous 'IKEv2 Identification - Initiator - Payload'.'next payload type' to current IKEv2 Identification - Responder - Payload (36:ISAKMP_NEXT_v2IDr) Sep 21 07:25:08.687435: | next payload chain: saving location 'IKEv2 Identification - Responder - Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.687438: | emitting 4 raw bytes of IDr into IKEv2 Identification - Responder - Payload Sep 21 07:25:08.687440: | IDr 65 61 73 74 Sep 21 07:25:08.687443: | emitting length of IKEv2 Identification - Responder - Payload: 12 Sep 21 07:25:08.687445: | not sending INITIAL_CONTACT Sep 21 07:25:08.687448: | ****emit IKEv2 Authentication Payload: Sep 21 07:25:08.687450: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:25:08.687452: | flags: none (0x0) Sep 21 07:25:08.687455: | auth method: IKEv2_AUTH_RSA (0x1) Sep 21 07:25:08.687458: | next payload chain: setting previous 'IKEv2 Identification - Responder - Payload'.'next payload type' to current IKEv2 Authentication Payload (39:ISAKMP_NEXT_v2AUTH) Sep 21 07:25:08.687460: | next payload chain: saving location 'IKEv2 Authentication Payload'.'next payload type' in 'reply packet' Sep 21 07:25:08.687466: | started looking for secret for @north->@east of kind PKK_RSA Sep 21 07:25:08.687469: | actually looking for secret for @north->@east of kind PKK_RSA Sep 21 07:25:08.687472: | line 1: key type PKK_RSA(@north) to type PKK_RSA Sep 21 07:25:08.687476: | 1: compared key (none) to @north / @east -> 002 Sep 21 07:25:08.687481: | 2: compared key (none) to @north / @east -> 002 Sep 21 07:25:08.687483: | line 1: match=002 Sep 21 07:25:08.687486: | match 002 beats previous best_match 000 match=0x560eda586b90 (line=1) Sep 21 07:25:08.687489: | concluding with best_match=002 best=0x560eda586b90 (lineno=1) Sep 21 07:25:08.692687: "northnet-eastnet-ipv4" #1: Can't find the certificate or private key from the NSS CKA_ID Sep 21 07:25:08.692713: | #1 spent 5.12 milliseconds in ikev2_calculate_rsa_hash() calling sign_hash_RSA() Sep 21 07:25:08.692716: "northnet-eastnet-ipv4" #1: Failed to find our RSA key Sep 21 07:25:08.692725: | suspend processing: state #1 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:25:08.692730: | start processing: state #2 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:25:08.692734: | #2 complete_v2_state_transition() md.from_state=PARENT_I1 md.svm.state[from]=PARENT_I1 UNDEFINED->PARENT_I2 with status STF_FATAL Sep 21 07:25:08.693003: | release_pending_whacks: state #2 has no whack fd Sep 21 07:25:08.693013: | release_pending_whacks: IKE SA #1 fd@24 has pending CHILD SA with socket fd@25 Sep 21 07:25:08.693017: | pstats #2 ikev2.child deleted other Sep 21 07:25:08.693023: | [RE]START processing: state #2 connection "northnet-eastnet-ipv4" from 192.1.2.23:500 (in delete_state() at state.c:879) Sep 21 07:25:08.693027: "northnet-eastnet-ipv4" #2: deleting state (STATE_UNDEFINED) aged 0.005s and NOT sending notification Sep 21 07:25:08.693030: | child state #2: UNDEFINED(ignore) => delete Sep 21 07:25:08.693034: | child state #2: UNDEFINED(ignore) => CHILDSA_DEL(informational) Sep 21 07:25:08.693039: | priority calculation of connection "northnet-eastnet-ipv4" is 0xfe7e7 Sep 21 07:25:08.693047: | delete inbound eroute 192.0.2.0/24:0 --0-> 192.0.3.0/24:0 => unk255.10000@192.1.3.33 (raw_eroute) Sep 21 07:25:08.693062: | raw_eroute result=success Sep 21 07:25:08.693066: | in connection_discard for connection northnet-eastnet-ipv4 Sep 21 07:25:08.693069: | State DB: deleting IKEv2 state #2 in CHILDSA_DEL Sep 21 07:25:08.693073: | child state #2: CHILDSA_DEL(informational) => UNDEFINED(ignore) Sep 21 07:25:08.693078: | stop processing: state #2 from 192.1.2.23:500 (in delete_state() at state.c:1143) Sep 21 07:25:08.693084: | resume sending helper answer for #1 suppresed complete_v2_state_transition() Sep 21 07:25:08.693089: | #1 spent 5.58 milliseconds in resume sending helper answer Sep 21 07:25:08.693092: | processing: STOP state #0 (in resume_handler() at server.c:833) Sep 21 07:25:08.693097: | libevent_free: release ptr-libevent@0x7fe620006b90 Sep 21 07:25:28.370861: | processing global timer EVENT_SHUNT_SCAN Sep 21 07:25:28.370875: | expiring aged bare shunts from shunt table Sep 21 07:25:28.370880: | spent 0.00387 milliseconds in global timer EVENT_SHUNT_SCAN Sep 21 07:25:48.364801: | processing global timer EVENT_SHUNT_SCAN Sep 21 07:25:48.364819: | expiring aged bare shunts from shunt table Sep 21 07:25:48.364826: | spent 0.00544 milliseconds in global timer EVENT_SHUNT_SCAN