Sep 21 07:34:29.230846: FIPS Product: YES Sep 21 07:34:29.230884: FIPS Kernel: NO Sep 21 07:34:29.230887: FIPS Mode: NO Sep 21 07:34:29.230890: NSS DB directory: sql:/etc/ipsec.d Sep 21 07:34:29.231048: Initializing NSS Sep 21 07:34:29.231052: Opening NSS database "sql:/etc/ipsec.d" read-only Sep 21 07:34:29.276272: NSS initialized Sep 21 07:34:29.276285: NSS crypto library initialized Sep 21 07:34:29.276288: FIPS HMAC integrity support [enabled] Sep 21 07:34:29.276290: FIPS mode disabled for pluto daemon Sep 21 07:34:29.337391: FIPS HMAC integrity verification self-test FAILED Sep 21 07:34:29.337493: libcap-ng support [enabled] Sep 21 07:34:29.337505: Linux audit support [enabled] Sep 21 07:34:29.337528: Linux audit activated Sep 21 07:34:29.337532: Starting Pluto (Libreswan Version v3.28-827-gc9aa82b8a6-master-s2 XFRM(netkey) esp-hw-offload FORK PTHREAD_SETSCHEDPRIO NSS (IPsec profile) DNSSEC SYSTEMD_WATCHDOG FIPS_CHECK LABELED_IPSEC SECCOMP LIBCAP_NG LINUX_AUDIT XAUTH_PAM NETWORKMANAGER CURL(non-NSS)) pid:8756 Sep 21 07:34:29.337534: core dump dir: /tmp Sep 21 07:34:29.337537: secrets file: /etc/ipsec.secrets Sep 21 07:34:29.337539: leak-detective disabled Sep 21 07:34:29.337540: NSS crypto [enabled] Sep 21 07:34:29.337542: XAUTH PAM support [enabled] Sep 21 07:34:29.337613: | libevent is using pluto's memory allocator Sep 21 07:34:29.337618: Initializing libevent in pthreads mode: headers: 2.1.8-stable (2010800); library: 2.1.8-stable (2010800) Sep 21 07:34:29.337630: | libevent_malloc: new ptr-libevent@0x562c74fa8fc0 size 40 Sep 21 07:34:29.337637: | libevent_malloc: new ptr-libevent@0x562c74fa8ff0 size 40 Sep 21 07:34:29.337642: | libevent_malloc: new ptr-libevent@0x562c74faa250 size 40 Sep 21 07:34:29.337644: | creating event base Sep 21 07:34:29.337647: | libevent_malloc: new ptr-libevent@0x562c74faa210 size 56 Sep 21 07:34:29.337650: | libevent_malloc: new ptr-libevent@0x562c74faa280 size 664 Sep 21 07:34:29.337661: | libevent_malloc: new ptr-libevent@0x562c74faa520 size 24 Sep 21 07:34:29.337666: | libevent_malloc: new ptr-libevent@0x562c74f9bdc0 size 384 Sep 21 07:34:29.337675: | libevent_malloc: new ptr-libevent@0x562c74faa540 size 16 Sep 21 07:34:29.337678: | libevent_malloc: new ptr-libevent@0x562c74faa560 size 40 Sep 21 07:34:29.337680: | libevent_malloc: new ptr-libevent@0x562c74faa590 size 48 Sep 21 07:34:29.337688: | libevent_realloc: new ptr-libevent@0x562c74f2c370 size 256 Sep 21 07:34:29.337691: | libevent_malloc: new ptr-libevent@0x562c74faa5d0 size 16 Sep 21 07:34:29.337696: | libevent_free: release ptr-libevent@0x562c74faa210 Sep 21 07:34:29.337699: | libevent initialized Sep 21 07:34:29.337703: | libevent_realloc: new ptr-libevent@0x562c74faa5f0 size 64 Sep 21 07:34:29.337706: | global periodic timer EVENT_RESET_LOG_RATE_LIMIT enabled with interval of 3600 seconds Sep 21 07:34:29.337724: | init_nat_traversal() initialized with keep_alive=0s Sep 21 07:34:29.337727: NAT-Traversal support [enabled] Sep 21 07:34:29.337730: | global one-shot timer EVENT_NAT_T_KEEPALIVE initialized Sep 21 07:34:29.337735: | global one-shot timer EVENT_FREE_ROOT_CERTS initialized Sep 21 07:34:29.337742: | global periodic timer EVENT_REINIT_SECRET enabled with interval of 3600 seconds Sep 21 07:34:29.337778: | global one-shot timer EVENT_REVIVE_CONNS initialized Sep 21 07:34:29.337781: | global periodic timer EVENT_PENDING_DDNS enabled with interval of 60 seconds Sep 21 07:34:29.337787: | global periodic timer EVENT_PENDING_PHASE2 enabled with interval of 120 seconds Sep 21 07:34:29.337836: Encryption algorithms: Sep 21 07:34:29.337846: AES_CCM_16 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm, aes_ccm_c Sep 21 07:34:29.337850: AES_CCM_12 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_b Sep 21 07:34:29.337853: AES_CCM_8 IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_ccm_a Sep 21 07:34:29.337856: 3DES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS [*192] 3des Sep 21 07:34:29.337860: CAMELLIA_CTR IKEv1: ESP IKEv2: ESP {256,192,*128} Sep 21 07:34:29.337868: CAMELLIA_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} camellia Sep 21 07:34:29.337872: AES_GCM_16 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm, aes_gcm_c Sep 21 07:34:29.337876: AES_GCM_12 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_b Sep 21 07:34:29.337879: AES_GCM_8 IKEv1: ESP IKEv2: IKE ESP FIPS {256,192,*128} aes_gcm_a Sep 21 07:34:29.337882: AES_CTR IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aesctr Sep 21 07:34:29.337886: AES_CBC IKEv1: IKE ESP IKEv2: IKE ESP FIPS {256,192,*128} aes Sep 21 07:34:29.337889: SERPENT_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} serpent Sep 21 07:34:29.337892: TWOFISH_CBC IKEv1: IKE ESP IKEv2: IKE ESP {256,192,*128} twofish Sep 21 07:34:29.337896: TWOFISH_SSH IKEv1: IKE IKEv2: IKE ESP {256,192,*128} twofish_cbc_ssh Sep 21 07:34:29.337899: NULL_AUTH_AES_GMAC IKEv1: ESP IKEv2: ESP FIPS {256,192,*128} aes_gmac Sep 21 07:34:29.337902: NULL IKEv1: ESP IKEv2: ESP [] Sep 21 07:34:29.337905: CHACHA20_POLY1305 IKEv1: IKEv2: IKE ESP [*256] chacha20poly1305 Sep 21 07:34:29.337912: Hash algorithms: Sep 21 07:34:29.337915: MD5 IKEv1: IKE IKEv2: Sep 21 07:34:29.337918: SHA1 IKEv1: IKE IKEv2: FIPS sha Sep 21 07:34:29.337921: SHA2_256 IKEv1: IKE IKEv2: FIPS sha2, sha256 Sep 21 07:34:29.337923: SHA2_384 IKEv1: IKE IKEv2: FIPS sha384 Sep 21 07:34:29.337926: SHA2_512 IKEv1: IKE IKEv2: FIPS sha512 Sep 21 07:34:29.337939: PRF algorithms: Sep 21 07:34:29.337942: HMAC_MD5 IKEv1: IKE IKEv2: IKE md5 Sep 21 07:34:29.337944: HMAC_SHA1 IKEv1: IKE IKEv2: IKE FIPS sha, sha1 Sep 21 07:34:29.337948: HMAC_SHA2_256 IKEv1: IKE IKEv2: IKE FIPS sha2, sha256, sha2_256 Sep 21 07:34:29.337951: HMAC_SHA2_384 IKEv1: IKE IKEv2: IKE FIPS sha384, sha2_384 Sep 21 07:34:29.337954: HMAC_SHA2_512 IKEv1: IKE IKEv2: IKE FIPS sha512, sha2_512 Sep 21 07:34:29.337957: AES_XCBC IKEv1: IKEv2: IKE aes128_xcbc Sep 21 07:34:29.337980: Integrity algorithms: Sep 21 07:34:29.337983: HMAC_MD5_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH md5, hmac_md5 Sep 21 07:34:29.337987: HMAC_SHA1_96 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha, sha1, sha1_96, hmac_sha1 Sep 21 07:34:29.337990: HMAC_SHA2_512_256 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha512, sha2_512, sha2_512_256, hmac_sha2_512 Sep 21 07:34:29.337994: HMAC_SHA2_384_192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha384, sha2_384, sha2_384_192, hmac_sha2_384 Sep 21 07:34:29.337998: HMAC_SHA2_256_128 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS sha2, sha256, sha2_256, sha2_256_128, hmac_sha2_256 Sep 21 07:34:29.338001: HMAC_SHA2_256_TRUNCBUG IKEv1: ESP AH IKEv2: AH Sep 21 07:34:29.338004: AES_XCBC_96 IKEv1: ESP AH IKEv2: IKE ESP AH aes_xcbc, aes128_xcbc, aes128_xcbc_96 Sep 21 07:34:29.338007: AES_CMAC_96 IKEv1: ESP AH IKEv2: ESP AH FIPS aes_cmac Sep 21 07:34:29.338010: NONE IKEv1: ESP IKEv2: IKE ESP FIPS null Sep 21 07:34:29.338021: DH algorithms: Sep 21 07:34:29.338024: NONE IKEv1: IKEv2: IKE ESP AH FIPS null, dh0 Sep 21 07:34:29.338027: MODP1536 IKEv1: IKE ESP AH IKEv2: IKE ESP AH dh5 Sep 21 07:34:29.338030: MODP2048 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh14 Sep 21 07:34:29.338035: MODP3072 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh15 Sep 21 07:34:29.338038: MODP4096 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh16 Sep 21 07:34:29.338040: MODP6144 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh17 Sep 21 07:34:29.338043: MODP8192 IKEv1: IKE ESP AH IKEv2: IKE ESP AH FIPS dh18 Sep 21 07:34:29.338046: DH19 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_256, ecp256 Sep 21 07:34:29.338049: DH20 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_384, ecp384 Sep 21 07:34:29.338052: DH21 IKEv1: IKE IKEv2: IKE ESP AH FIPS ecp_521, ecp521 Sep 21 07:34:29.338054: DH31 IKEv1: IKE IKEv2: IKE ESP AH curve25519 Sep 21 07:34:29.338057: testing CAMELLIA_CBC: Sep 21 07:34:29.338059: Camellia: 16 bytes with 128-bit key Sep 21 07:34:29.338170: Camellia: 16 bytes with 128-bit key Sep 21 07:34:29.338197: Camellia: 16 bytes with 256-bit key Sep 21 07:34:29.338224: Camellia: 16 bytes with 256-bit key Sep 21 07:34:29.338250: testing AES_GCM_16: Sep 21 07:34:29.338253: empty string Sep 21 07:34:29.338278: one block Sep 21 07:34:29.338301: two blocks Sep 21 07:34:29.338324: two blocks with associated data Sep 21 07:34:29.338348: testing AES_CTR: Sep 21 07:34:29.338350: Encrypting 16 octets using AES-CTR with 128-bit key Sep 21 07:34:29.338375: Encrypting 32 octets using AES-CTR with 128-bit key Sep 21 07:34:29.338400: Encrypting 36 octets using AES-CTR with 128-bit key Sep 21 07:34:29.338425: Encrypting 16 octets using AES-CTR with 192-bit key Sep 21 07:34:29.338450: Encrypting 32 octets using AES-CTR with 192-bit key Sep 21 07:34:29.338474: Encrypting 36 octets using AES-CTR with 192-bit key Sep 21 07:34:29.338499: Encrypting 16 octets using AES-CTR with 256-bit key Sep 21 07:34:29.338523: Encrypting 32 octets using AES-CTR with 256-bit key Sep 21 07:34:29.338549: Encrypting 36 octets using AES-CTR with 256-bit key Sep 21 07:34:29.338575: testing AES_CBC: Sep 21 07:34:29.338577: Encrypting 16 bytes (1 block) using AES-CBC with 128-bit key Sep 21 07:34:29.338602: Encrypting 32 bytes (2 blocks) using AES-CBC with 128-bit key Sep 21 07:34:29.338628: Encrypting 48 bytes (3 blocks) using AES-CBC with 128-bit key Sep 21 07:34:29.338656: Encrypting 64 bytes (4 blocks) using AES-CBC with 128-bit key Sep 21 07:34:29.338691: testing AES_XCBC: Sep 21 07:34:29.338695: RFC 3566 Test Case #1: AES-XCBC-MAC-96 with 0-byte input Sep 21 07:34:29.338833: RFC 3566 Test Case #2: AES-XCBC-MAC-96 with 3-byte input Sep 21 07:34:29.338958: RFC 3566 Test Case #3: AES-XCBC-MAC-96 with 16-byte input Sep 21 07:34:29.339074: RFC 3566 Test Case #4: AES-XCBC-MAC-96 with 20-byte input Sep 21 07:34:29.339191: RFC 3566 Test Case #5: AES-XCBC-MAC-96 with 32-byte input Sep 21 07:34:29.339310: RFC 3566 Test Case #6: AES-XCBC-MAC-96 with 34-byte input Sep 21 07:34:29.339429: RFC 3566 Test Case #7: AES-XCBC-MAC-96 with 1000-byte input Sep 21 07:34:29.339698: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 16) Sep 21 07:34:29.339820: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 10) Sep 21 07:34:29.339949: RFC 4434 Test Case AES-XCBC-PRF-128 with 20-byte input (key length 18) Sep 21 07:34:29.340169: testing HMAC_MD5: Sep 21 07:34:29.340173: RFC 2104: MD5_HMAC test 1 Sep 21 07:34:29.340339: RFC 2104: MD5_HMAC test 2 Sep 21 07:34:29.340484: RFC 2104: MD5_HMAC test 3 Sep 21 07:34:29.340659: 8 CPU cores online Sep 21 07:34:29.340662: starting up 7 crypto helpers Sep 21 07:34:29.340696: started thread for crypto helper 0 Sep 21 07:34:29.340718: started thread for crypto helper 1 Sep 21 07:34:29.340737: started thread for crypto helper 2 Sep 21 07:34:29.340743: | starting up helper thread 2 Sep 21 07:34:29.340756: started thread for crypto helper 3 Sep 21 07:34:29.340757: | status value returned by setting the priority of this thread (crypto helper 2) 22 Sep 21 07:34:29.340773: | crypto helper 2 waiting (nothing to do) Sep 21 07:34:29.340777: started thread for crypto helper 4 Sep 21 07:34:29.340818: started thread for crypto helper 5 Sep 21 07:34:29.340839: started thread for crypto helper 6 Sep 21 07:34:29.340843: | checking IKEv1 state table Sep 21 07:34:29.340851: | MAIN_R0: category: half-open IKE SA flags: 0: Sep 21 07:34:29.340853: | -> MAIN_R1 EVENT_SO_DISCARD Sep 21 07:34:29.340856: | MAIN_I1: category: half-open IKE SA flags: 0: Sep 21 07:34:29.340858: | -> MAIN_I2 EVENT_RETRANSMIT Sep 21 07:34:29.340860: | MAIN_R1: category: open IKE SA flags: 200: Sep 21 07:34:29.340863: | -> MAIN_R2 EVENT_RETRANSMIT Sep 21 07:34:29.340865: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:34:29.340867: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:34:29.340869: | MAIN_I2: category: open IKE SA flags: 0: Sep 21 07:34:29.340872: | -> MAIN_I3 EVENT_RETRANSMIT Sep 21 07:34:29.340874: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:34:29.340876: | -> UNDEFINED EVENT_RETRANSMIT Sep 21 07:34:29.340878: | MAIN_R2: category: open IKE SA flags: 0: Sep 21 07:34:29.340881: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:34:29.340883: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:34:29.340885: | -> UNDEFINED EVENT_SA_REPLACE Sep 21 07:34:29.340887: | MAIN_I3: category: open IKE SA flags: 0: Sep 21 07:34:29.340889: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:34:29.340891: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:34:29.340893: | -> UNDEFINED EVENT_SA_REPLACE Sep 21 07:34:29.340896: | MAIN_R3: category: established IKE SA flags: 200: Sep 21 07:34:29.340898: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340900: | MAIN_I4: category: established IKE SA flags: 0: Sep 21 07:34:29.340903: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340905: | AGGR_R0: category: half-open IKE SA flags: 0: Sep 21 07:34:29.340907: | -> AGGR_R1 EVENT_SO_DISCARD Sep 21 07:34:29.340910: | AGGR_I1: category: half-open IKE SA flags: 0: Sep 21 07:34:29.340912: | -> AGGR_I2 EVENT_SA_REPLACE Sep 21 07:34:29.340914: | -> AGGR_I2 EVENT_SA_REPLACE Sep 21 07:34:29.340916: | AGGR_R1: category: open IKE SA flags: 200: Sep 21 07:34:29.340918: | -> AGGR_R2 EVENT_SA_REPLACE Sep 21 07:34:29.340921: | -> AGGR_R2 EVENT_SA_REPLACE Sep 21 07:34:29.340923: | AGGR_I2: category: established IKE SA flags: 200: Sep 21 07:34:29.340925: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340928: | AGGR_R2: category: established IKE SA flags: 0: Sep 21 07:34:29.340930: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340932: | QUICK_R0: category: established CHILD SA flags: 0: Sep 21 07:34:29.340935: | -> QUICK_R1 EVENT_RETRANSMIT Sep 21 07:34:29.340937: | QUICK_I1: category: established CHILD SA flags: 0: Sep 21 07:34:29.340939: | -> QUICK_I2 EVENT_SA_REPLACE Sep 21 07:34:29.340942: | QUICK_R1: category: established CHILD SA flags: 0: Sep 21 07:34:29.340944: | -> QUICK_R2 EVENT_SA_REPLACE Sep 21 07:34:29.340946: | QUICK_I2: category: established CHILD SA flags: 200: Sep 21 07:34:29.340948: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340951: | QUICK_R2: category: established CHILD SA flags: 0: Sep 21 07:34:29.340953: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340956: | INFO: category: informational flags: 0: Sep 21 07:34:29.340958: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340960: | INFO_PROTECTED: category: informational flags: 0: Sep 21 07:34:29.340962: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340965: | XAUTH_R0: category: established IKE SA flags: 0: Sep 21 07:34:29.340967: | -> XAUTH_R1 EVENT_NULL Sep 21 07:34:29.340969: | XAUTH_R1: category: established IKE SA flags: 0: Sep 21 07:34:29.340971: | -> MAIN_R3 EVENT_SA_REPLACE Sep 21 07:34:29.340974: | MODE_CFG_R0: category: informational flags: 0: Sep 21 07:34:29.340976: | -> MODE_CFG_R1 EVENT_SA_REPLACE Sep 21 07:34:29.340979: | MODE_CFG_R1: category: established IKE SA flags: 0: Sep 21 07:34:29.340981: | -> MODE_CFG_R2 EVENT_SA_REPLACE Sep 21 07:34:29.340986: | MODE_CFG_R2: category: established IKE SA flags: 0: Sep 21 07:34:29.340989: | -> UNDEFINED EVENT_NULL Sep 21 07:34:29.340991: | MODE_CFG_I1: category: established IKE SA flags: 0: Sep 21 07:34:29.340993: | -> MAIN_I4 EVENT_SA_REPLACE Sep 21 07:34:29.340996: | XAUTH_I0: category: established IKE SA flags: 0: Sep 21 07:34:29.340998: | -> XAUTH_I1 EVENT_RETRANSMIT Sep 21 07:34:29.341000: | XAUTH_I1: category: established IKE SA flags: 0: Sep 21 07:34:29.341002: | -> MAIN_I4 EVENT_RETRANSMIT Sep 21 07:34:29.341008: | checking IKEv2 state table Sep 21 07:34:29.341014: | PARENT_I0: category: ignore flags: 0: Sep 21 07:34:29.341017: | -> PARENT_I1 EVENT_RETRANSMIT send-request (initiate IKE_SA_INIT) Sep 21 07:34:29.341019: | PARENT_I1: category: half-open IKE SA flags: 0: Sep 21 07:34:29.341022: | -> PARENT_I1 EVENT_RETAIN send-request (Initiator: process SA_INIT reply notification) Sep 21 07:34:29.341025: | -> PARENT_I2 EVENT_RETRANSMIT send-request (Initiator: process IKE_SA_INIT reply, initiate IKE_AUTH) Sep 21 07:34:29.341027: | PARENT_I2: category: open IKE SA flags: 0: Sep 21 07:34:29.341030: | -> PARENT_I2 EVENT_NULL (Initiator: process INVALID_SYNTAX AUTH notification) Sep 21 07:34:29.341032: | -> PARENT_I2 EVENT_NULL (Initiator: process AUTHENTICATION_FAILED AUTH notification) Sep 21 07:34:29.341035: | -> PARENT_I2 EVENT_NULL (Initiator: process UNSUPPORTED_CRITICAL_PAYLOAD AUTH notification) Sep 21 07:34:29.341037: | -> V2_IPSEC_I EVENT_SA_REPLACE (Initiator: process IKE_AUTH response) Sep 21 07:34:29.341040: | -> PARENT_I2 EVENT_NULL (IKE SA: process IKE_AUTH response containing unknown notification) Sep 21 07:34:29.341042: | PARENT_I3: category: established IKE SA flags: 0: Sep 21 07:34:29.341045: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Request) Sep 21 07:34:29.341047: | -> PARENT_I3 EVENT_RETAIN (I3: Informational Response) Sep 21 07:34:29.341049: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Request) Sep 21 07:34:29.341052: | -> PARENT_I3 EVENT_RETAIN (I3: INFORMATIONAL Response) Sep 21 07:34:29.341054: | PARENT_R0: category: half-open IKE SA flags: 0: Sep 21 07:34:29.341056: | -> PARENT_R1 EVENT_SO_DISCARD send-request (Respond to IKE_SA_INIT) Sep 21 07:34:29.341059: | PARENT_R1: category: half-open IKE SA flags: 0: Sep 21 07:34:29.341062: | -> PARENT_R1 EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request (no SKEYSEED)) Sep 21 07:34:29.341064: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Responder: process IKE_AUTH request) Sep 21 07:34:29.341067: | PARENT_R2: category: established IKE SA flags: 0: Sep 21 07:34:29.341069: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Request) Sep 21 07:34:29.341071: | -> PARENT_R2 EVENT_RETAIN (R2: process Informational Response) Sep 21 07:34:29.341074: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Request) Sep 21 07:34:29.341076: | -> PARENT_R2 EVENT_RETAIN (R2: process INFORMATIONAL Response) Sep 21 07:34:29.341079: | V2_CREATE_I0: category: established IKE SA flags: 0: Sep 21 07:34:29.341081: | -> V2_CREATE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec SA) Sep 21 07:34:29.341084: | V2_CREATE_I: category: established IKE SA flags: 0: Sep 21 07:34:29.341086: | -> V2_IPSEC_I EVENT_SA_REPLACE (Process CREATE_CHILD_SA IPsec SA Response) Sep 21 07:34:29.341089: | V2_REKEY_IKE_I0: category: established IKE SA flags: 0: Sep 21 07:34:29.341091: | -> V2_REKEY_IKE_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IKE Rekey) Sep 21 07:34:29.341094: | V2_REKEY_IKE_I: category: established IKE SA flags: 0: Sep 21 07:34:29.341097: | -> PARENT_I3 EVENT_SA_REPLACE (Process CREATE_CHILD_SA IKE Rekey Response) Sep 21 07:34:29.341100: | V2_REKEY_CHILD_I0: category: established IKE SA flags: 0: Sep 21 07:34:29.341102: | -> V2_REKEY_CHILD_I EVENT_RETRANSMIT send-request (Initiate CREATE_CHILD_SA IPsec Rekey SA) Sep 21 07:34:29.341105: | V2_REKEY_CHILD_I: category: established IKE SA flags: 0: Sep 21 07:34:29.341109: | V2_CREATE_R: category: established IKE SA flags: 0: Sep 21 07:34:29.341112: | -> V2_IPSEC_R EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IPsec SA Request) Sep 21 07:34:29.341115: | V2_REKEY_IKE_R: category: established IKE SA flags: 0: Sep 21 07:34:29.341117: | -> PARENT_R2 EVENT_SA_REPLACE send-request (Respond to CREATE_CHILD_SA IKE Rekey) Sep 21 07:34:29.341120: | V2_REKEY_CHILD_R: category: established IKE SA flags: 0: Sep 21 07:34:29.341123: | V2_IPSEC_I: category: established CHILD SA flags: 0: Sep 21 07:34:29.341125: | V2_IPSEC_R: category: established CHILD SA flags: 0: Sep 21 07:34:29.341128: | IKESA_DEL: category: established IKE SA flags: 0: Sep 21 07:34:29.341130: | -> IKESA_DEL EVENT_RETAIN (IKE_SA_DEL: process INFORMATIONAL) Sep 21 07:34:29.341133: | CHILDSA_DEL: category: informational flags: 0: Sep 21 07:34:29.341183: Using Linux XFRM/NETKEY IPsec interface code on 5.2.11+ Sep 21 07:34:29.341244: | Hard-wiring algorithms Sep 21 07:34:29.341248: | adding AES_CCM_16 to kernel algorithm db Sep 21 07:34:29.341251: | adding AES_CCM_12 to kernel algorithm db Sep 21 07:34:29.341254: | adding AES_CCM_8 to kernel algorithm db Sep 21 07:34:29.341256: | adding 3DES_CBC to kernel algorithm db Sep 21 07:34:29.341258: | adding CAMELLIA_CBC to kernel algorithm db Sep 21 07:34:29.341261: | adding AES_GCM_16 to kernel algorithm db Sep 21 07:34:29.341263: | adding AES_GCM_12 to kernel algorithm db Sep 21 07:34:29.341265: | adding AES_GCM_8 to kernel algorithm db Sep 21 07:34:29.341267: | adding AES_CTR to kernel algorithm db Sep 21 07:34:29.341269: | adding AES_CBC to kernel algorithm db Sep 21 07:34:29.341271: | adding SERPENT_CBC to kernel algorithm db Sep 21 07:34:29.341274: | adding TWOFISH_CBC to kernel algorithm db Sep 21 07:34:29.341276: | adding NULL_AUTH_AES_GMAC to kernel algorithm db Sep 21 07:34:29.341278: | adding NULL to kernel algorithm db Sep 21 07:34:29.341281: | adding CHACHA20_POLY1305 to kernel algorithm db Sep 21 07:34:29.341283: | adding HMAC_MD5_96 to kernel algorithm db Sep 21 07:34:29.341285: | adding HMAC_SHA1_96 to kernel algorithm db Sep 21 07:34:29.341288: | adding HMAC_SHA2_512_256 to kernel algorithm db Sep 21 07:34:29.341290: | adding HMAC_SHA2_384_192 to kernel algorithm db Sep 21 07:34:29.341292: | adding HMAC_SHA2_256_128 to kernel algorithm db Sep 21 07:34:29.341294: | adding HMAC_SHA2_256_TRUNCBUG to kernel algorithm db Sep 21 07:34:29.341297: | adding AES_XCBC_96 to kernel algorithm db Sep 21 07:34:29.341299: | adding AES_CMAC_96 to kernel algorithm db Sep 21 07:34:29.341301: | adding NONE to kernel algorithm db Sep 21 07:34:29.341321: | net.ipv6.conf.all.disable_ipv6=1 ignore ipv6 holes Sep 21 07:34:29.341325: | starting up helper thread 4 Sep 21 07:34:29.341319: | starting up helper thread 3 Sep 21 07:34:29.341329: | global periodic timer EVENT_SHUNT_SCAN enabled with interval of 20 seconds Sep 21 07:34:29.341350: | status value returned by setting the priority of this thread (crypto helper 3) 22 Sep 21 07:34:29.341355: | setup kernel fd callback Sep 21 07:34:29.341337: | status value returned by setting the priority of this thread (crypto helper 4) 22 Sep 21 07:34:29.341356: | crypto helper 3 waiting (nothing to do) Sep 21 07:34:29.341360: | add_fd_read_event_handler: new KERNEL_XRM_FD-pe@0x562c74fafc90 Sep 21 07:34:29.341375: | crypto helper 4 waiting (nothing to do) Sep 21 07:34:29.341377: | libevent_malloc: new ptr-libevent@0x562c74fbbe30 size 128 Sep 21 07:34:29.341382: | libevent_malloc: new ptr-libevent@0x562c74faef70 size 16 Sep 21 07:34:29.341388: | add_fd_read_event_handler: new KERNEL_ROUTE_FD-pe@0x562c74fafc50 Sep 21 07:34:29.341391: | libevent_malloc: new ptr-libevent@0x562c74fbbec0 size 128 Sep 21 07:34:29.341394: | libevent_malloc: new ptr-libevent@0x562c74faef90 size 16 Sep 21 07:34:29.341601: | global one-shot timer EVENT_CHECK_CRLS initialized Sep 21 07:34:29.341608: selinux support is enabled. Sep 21 07:34:29.341687: systemd watchdog not enabled - not sending watchdog keepalives Sep 21 07:34:29.341869: | unbound context created - setting debug level to 5 Sep 21 07:34:29.341897: | /etc/hosts lookups activated Sep 21 07:34:29.341913: | /etc/resolv.conf usage activated Sep 21 07:34:29.341975: | outgoing-port-avoid set 0-65535 Sep 21 07:34:29.342004: | outgoing-port-permit set 32768-60999 Sep 21 07:34:29.342007: | Loading dnssec root key from:/var/lib/unbound/root.key Sep 21 07:34:29.342010: | No additional dnssec trust anchors defined via dnssec-trusted= option Sep 21 07:34:29.342013: | Setting up events, loop start Sep 21 07:34:29.342016: | add_fd_read_event_handler: new PLUTO_CTL_FD-pe@0x562c74faa210 Sep 21 07:34:29.342019: | libevent_malloc: new ptr-libevent@0x562c74fc6430 size 128 Sep 21 07:34:29.342022: | libevent_malloc: new ptr-libevent@0x562c74fc64c0 size 16 Sep 21 07:34:29.342029: | libevent_realloc: new ptr-libevent@0x562c74f2a5b0 size 256 Sep 21 07:34:29.342031: | libevent_malloc: new ptr-libevent@0x562c74fc64e0 size 8 Sep 21 07:34:29.342034: | libevent_realloc: new ptr-libevent@0x562c74fbb1b0 size 144 Sep 21 07:34:29.342037: | libevent_malloc: new ptr-libevent@0x562c74fc6500 size 152 Sep 21 07:34:29.342040: | libevent_malloc: new ptr-libevent@0x562c74fc65a0 size 16 Sep 21 07:34:29.342044: | signal event handler PLUTO_SIGCHLD installed Sep 21 07:34:29.342046: | libevent_malloc: new ptr-libevent@0x562c74fc65c0 size 8 Sep 21 07:34:29.342049: | libevent_malloc: new ptr-libevent@0x562c74fc65e0 size 152 Sep 21 07:34:29.342052: | signal event handler PLUTO_SIGTERM installed Sep 21 07:34:29.342054: | libevent_malloc: new ptr-libevent@0x562c74fc6680 size 8 Sep 21 07:34:29.342057: | libevent_malloc: new ptr-libevent@0x562c74fc66a0 size 152 Sep 21 07:34:29.342059: | signal event handler PLUTO_SIGHUP installed Sep 21 07:34:29.342062: | libevent_malloc: new ptr-libevent@0x562c74fc6740 size 8 Sep 21 07:34:29.342064: | libevent_realloc: release ptr-libevent@0x562c74fbb1b0 Sep 21 07:34:29.342067: | libevent_realloc: new ptr-libevent@0x562c74fc6760 size 256 Sep 21 07:34:29.342070: | libevent_malloc: new ptr-libevent@0x562c74fbb1b0 size 152 Sep 21 07:34:29.342072: | signal event handler PLUTO_SIGSYS installed Sep 21 07:34:29.342466: | created addconn helper (pid:8919) using fork+execve Sep 21 07:34:29.342477: | forked child 8919 Sep 21 07:34:29.342517: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.342532: | pluto_sd: executing action action: reloading(4), status 0 Sep 21 07:34:29.342538: listening for IKE messages Sep 21 07:34:29.342575: | Inspecting interface lo Sep 21 07:34:29.342581: | found lo with address 127.0.0.1 Sep 21 07:34:29.342584: | Inspecting interface eth0 Sep 21 07:34:29.342588: | found eth0 with address 192.0.2.254 Sep 21 07:34:29.342590: | Inspecting interface eth0 Sep 21 07:34:29.342594: | found eth0 with address 192.0.200.254 Sep 21 07:34:29.342596: | Inspecting interface eth1 Sep 21 07:34:29.342599: | found eth1 with address 192.1.2.23 Sep 21 07:34:29.342641: Kernel supports NIC esp-hw-offload Sep 21 07:34:29.342650: adding interface eth1/eth1 (esp-hw-offload not supported by kernel) 192.1.2.23:500 Sep 21 07:34:29.342672: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:34:29.342676: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:34:29.342680: adding interface eth1/eth1 192.1.2.23:4500 Sep 21 07:34:29.342704: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.200.254:500 Sep 21 07:34:29.342735: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:34:29.342740: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:34:29.342743: adding interface eth0/eth0 192.0.200.254:4500 Sep 21 07:34:29.342770: adding interface eth0/eth0 (esp-hw-offload not supported by kernel) 192.0.2.254:500 Sep 21 07:34:29.342796: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:34:29.342803: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:34:29.342810: adding interface eth0/eth0 192.0.2.254:4500 Sep 21 07:34:29.342835: adding interface lo/lo (esp-hw-offload not supported by kernel) 127.0.0.1:500 Sep 21 07:34:29.342856: | NAT-Traversal: Trying sockopt style NAT-T Sep 21 07:34:29.342859: | NAT-Traversal: ESPINUDP(2) setup succeeded for sockopt style NAT-T family IPv4 Sep 21 07:34:29.342863: adding interface lo/lo 127.0.0.1:4500 Sep 21 07:34:29.342913: | no interfaces to sort Sep 21 07:34:29.342918: | FOR_EACH_UNORIENTED_CONNECTION_... in check_orientations Sep 21 07:34:29.342928: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6c30 Sep 21 07:34:29.342931: | libevent_malloc: new ptr-libevent@0x562c74fc6c70 size 128 Sep 21 07:34:29.342934: | libevent_malloc: new ptr-libevent@0x562c74fc6d00 size 16 Sep 21 07:34:29.342940: | setup callback for interface lo 127.0.0.1:4500 fd 24 Sep 21 07:34:29.342943: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6d20 Sep 21 07:34:29.342946: | libevent_malloc: new ptr-libevent@0x562c74fc6d60 size 128 Sep 21 07:34:29.342948: | libevent_malloc: new ptr-libevent@0x562c74fc6df0 size 16 Sep 21 07:34:29.342954: | setup callback for interface lo 127.0.0.1:500 fd 23 Sep 21 07:34:29.342957: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6e10 Sep 21 07:34:29.342960: | libevent_malloc: new ptr-libevent@0x562c74fc6e50 size 128 Sep 21 07:34:29.342962: | libevent_malloc: new ptr-libevent@0x562c74fc6ee0 size 16 Sep 21 07:34:29.342966: | setup callback for interface eth0 192.0.2.254:4500 fd 22 Sep 21 07:34:29.342969: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6f00 Sep 21 07:34:29.342971: | libevent_malloc: new ptr-libevent@0x562c74fc6f40 size 128 Sep 21 07:34:29.342974: | libevent_malloc: new ptr-libevent@0x562c74fc6fd0 size 16 Sep 21 07:34:29.342978: | setup callback for interface eth0 192.0.2.254:500 fd 21 Sep 21 07:34:29.342981: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6ff0 Sep 21 07:34:29.342983: | libevent_malloc: new ptr-libevent@0x562c74fc7030 size 128 Sep 21 07:34:29.342985: | libevent_malloc: new ptr-libevent@0x562c74fc70c0 size 16 Sep 21 07:34:29.342990: | setup callback for interface eth0 192.0.200.254:4500 fd 20 Sep 21 07:34:29.342992: | add_fd_read_event_handler: new ethX-pe@0x562c74fc70e0 Sep 21 07:34:29.342994: | libevent_malloc: new ptr-libevent@0x562c74fc7120 size 128 Sep 21 07:34:29.342997: | libevent_malloc: new ptr-libevent@0x562c74fc71b0 size 16 Sep 21 07:34:29.343002: | setup callback for interface eth0 192.0.200.254:500 fd 19 Sep 21 07:34:29.343005: | add_fd_read_event_handler: new ethX-pe@0x562c74fc71d0 Sep 21 07:34:29.343007: | libevent_malloc: new ptr-libevent@0x562c74fc7850 size 128 Sep 21 07:34:29.343010: | libevent_malloc: new ptr-libevent@0x562c74fc7210 size 16 Sep 21 07:34:29.343014: | setup callback for interface eth1 192.1.2.23:4500 fd 18 Sep 21 07:34:29.343017: | add_fd_read_event_handler: new ethX-pe@0x562c74fc7230 Sep 21 07:34:29.343019: | libevent_malloc: new ptr-libevent@0x562c74fc78e0 size 128 Sep 21 07:34:29.343022: | libevent_malloc: new ptr-libevent@0x562c74fc7970 size 16 Sep 21 07:34:29.343026: | setup callback for interface eth1 192.1.2.23:500 fd 17 Sep 21 07:34:29.343031: | certs and keys locked by 'free_preshared_secrets' Sep 21 07:34:29.343033: | certs and keys unlocked by 'free_preshared_secrets' Sep 21 07:34:29.343051: loading secrets from "/etc/ipsec.secrets" Sep 21 07:34:29.343061: | id type added to secret(0x562c74fbc010) PKK_PSK: @west Sep 21 07:34:29.343065: | id type added to secret(0x562c74fbc010) PKK_PSK: @east Sep 21 07:34:29.343069: | Processing PSK at line 1: passed Sep 21 07:34:29.343071: | certs and keys locked by 'process_secret' Sep 21 07:34:29.343075: | certs and keys unlocked by 'process_secret' Sep 21 07:34:29.343079: | pluto_sd: executing action action: ready(5), status 0 Sep 21 07:34:29.343087: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.343097: | spent 0.576 milliseconds in whack Sep 21 07:34:29.343810: | starting up helper thread 0 Sep 21 07:34:29.343822: | status value returned by setting the priority of this thread (crypto helper 0) 22 Sep 21 07:34:29.343829: | crypto helper 0 waiting (nothing to do) Sep 21 07:34:29.345082: | starting up helper thread 6 Sep 21 07:34:29.345093: | status value returned by setting the priority of this thread (crypto helper 6) 22 Sep 21 07:34:29.345096: | crypto helper 6 waiting (nothing to do) Sep 21 07:34:29.346811: | starting up helper thread 5 Sep 21 07:34:29.346827: | status value returned by setting the priority of this thread (crypto helper 5) 22 Sep 21 07:34:29.346830: | crypto helper 5 waiting (nothing to do) Sep 21 07:34:29.346857: | starting up helper thread 1 Sep 21 07:34:29.346865: | status value returned by setting the priority of this thread (crypto helper 1) 22 Sep 21 07:34:29.346868: | crypto helper 1 waiting (nothing to do) Sep 21 07:34:29.383963: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.383990: | pluto_sd: executing action action: reloading(4), status 0 Sep 21 07:34:29.383997: listening for IKE messages Sep 21 07:34:29.384038: | Inspecting interface lo Sep 21 07:34:29.384046: | found lo with address 127.0.0.1 Sep 21 07:34:29.384050: | Inspecting interface eth0 Sep 21 07:34:29.384055: | found eth0 with address 192.0.2.254 Sep 21 07:34:29.384057: | Inspecting interface eth0 Sep 21 07:34:29.384061: | found eth0 with address 192.0.200.254 Sep 21 07:34:29.384064: | Inspecting interface eth1 Sep 21 07:34:29.384068: | found eth1 with address 192.1.2.23 Sep 21 07:34:29.384130: | no interfaces to sort Sep 21 07:34:29.384141: | libevent_free: release ptr-libevent@0x562c74fc6c70 Sep 21 07:34:29.384145: | free_event_entry: release EVENT_NULL-pe@0x562c74fc6c30 Sep 21 07:34:29.384148: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6c30 Sep 21 07:34:29.384151: | libevent_malloc: new ptr-libevent@0x562c74fc6c70 size 128 Sep 21 07:34:29.384159: | setup callback for interface lo 127.0.0.1:4500 fd 24 Sep 21 07:34:29.384163: | libevent_free: release ptr-libevent@0x562c74fc6d60 Sep 21 07:34:29.384165: | free_event_entry: release EVENT_NULL-pe@0x562c74fc6d20 Sep 21 07:34:29.384168: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6d20 Sep 21 07:34:29.384171: | libevent_malloc: new ptr-libevent@0x562c74fc6d60 size 128 Sep 21 07:34:29.384176: | setup callback for interface lo 127.0.0.1:500 fd 23 Sep 21 07:34:29.384179: | libevent_free: release ptr-libevent@0x562c74fc6e50 Sep 21 07:34:29.384182: | free_event_entry: release EVENT_NULL-pe@0x562c74fc6e10 Sep 21 07:34:29.384185: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6e10 Sep 21 07:34:29.384187: | libevent_malloc: new ptr-libevent@0x562c74fc6e50 size 128 Sep 21 07:34:29.384192: | setup callback for interface eth0 192.0.2.254:4500 fd 22 Sep 21 07:34:29.384196: | libevent_free: release ptr-libevent@0x562c74fc6f40 Sep 21 07:34:29.384199: | free_event_entry: release EVENT_NULL-pe@0x562c74fc6f00 Sep 21 07:34:29.384201: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6f00 Sep 21 07:34:29.384204: | libevent_malloc: new ptr-libevent@0x562c74fc6f40 size 128 Sep 21 07:34:29.384209: | setup callback for interface eth0 192.0.2.254:500 fd 21 Sep 21 07:34:29.384212: | libevent_free: release ptr-libevent@0x562c74fc7030 Sep 21 07:34:29.384215: | free_event_entry: release EVENT_NULL-pe@0x562c74fc6ff0 Sep 21 07:34:29.384217: | add_fd_read_event_handler: new ethX-pe@0x562c74fc6ff0 Sep 21 07:34:29.384220: | libevent_malloc: new ptr-libevent@0x562c74fc7030 size 128 Sep 21 07:34:29.384225: | setup callback for interface eth0 192.0.200.254:4500 fd 20 Sep 21 07:34:29.384228: | libevent_free: release ptr-libevent@0x562c74fc7120 Sep 21 07:34:29.384231: | free_event_entry: release EVENT_NULL-pe@0x562c74fc70e0 Sep 21 07:34:29.384234: | add_fd_read_event_handler: new ethX-pe@0x562c74fc70e0 Sep 21 07:34:29.384236: | libevent_malloc: new ptr-libevent@0x562c74fc7120 size 128 Sep 21 07:34:29.384241: | setup callback for interface eth0 192.0.200.254:500 fd 19 Sep 21 07:34:29.384245: | libevent_free: release ptr-libevent@0x562c74fc7850 Sep 21 07:34:29.384253: | free_event_entry: release EVENT_NULL-pe@0x562c74fc71d0 Sep 21 07:34:29.384256: | add_fd_read_event_handler: new ethX-pe@0x562c74fc71d0 Sep 21 07:34:29.384258: | libevent_malloc: new ptr-libevent@0x562c74fc7850 size 128 Sep 21 07:34:29.384264: | setup callback for interface eth1 192.1.2.23:4500 fd 18 Sep 21 07:34:29.384267: | libevent_free: release ptr-libevent@0x562c74fc78e0 Sep 21 07:34:29.384270: | free_event_entry: release EVENT_NULL-pe@0x562c74fc7230 Sep 21 07:34:29.384273: | add_fd_read_event_handler: new ethX-pe@0x562c74fc79f0 Sep 21 07:34:29.384275: | libevent_malloc: new ptr-libevent@0x562c74fc78e0 size 128 Sep 21 07:34:29.384280: | setup callback for interface eth1 192.1.2.23:500 fd 17 Sep 21 07:34:29.384283: | certs and keys locked by 'free_preshared_secrets' Sep 21 07:34:29.384285: forgetting secrets Sep 21 07:34:29.384294: | certs and keys unlocked by 'free_preshared_secrets' Sep 21 07:34:29.384311: loading secrets from "/etc/ipsec.secrets" Sep 21 07:34:29.384321: | id type added to secret(0x562c74fbc010) PKK_PSK: @west Sep 21 07:34:29.384324: | id type added to secret(0x562c74fbc010) PKK_PSK: @east Sep 21 07:34:29.384328: | Processing PSK at line 1: passed Sep 21 07:34:29.384331: | certs and keys locked by 'process_secret' Sep 21 07:34:29.384333: | certs and keys unlocked by 'process_secret' Sep 21 07:34:29.384338: | pluto_sd: executing action action: ready(5), status 0 Sep 21 07:34:29.384347: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.384354: | spent 0.401 milliseconds in whack Sep 21 07:34:29.384909: | processing signal PLUTO_SIGCHLD Sep 21 07:34:29.384922: | waitpid returned pid 8919 (exited with status 0) Sep 21 07:34:29.384926: | reaped addconn helper child (status 0) Sep 21 07:34:29.384931: | waitpid returned ECHILD (no child processes left) Sep 21 07:34:29.384935: | spent 0.0155 milliseconds in signal handler PLUTO_SIGCHLD Sep 21 07:34:29.452736: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.452763: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.452767: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:34:29.452770: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.452772: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:34:29.452776: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.452788: | Added new connection westnet-eastnet-ikev2a with policy PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:34:29.452844: | ike (phase1) algorithm values: AES_GCM_16_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_GCM_16_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 Sep 21 07:34:29.452847: | from whack: got --esp= Sep 21 07:34:29.452884: | ESP/AH string values: AES_GCM_16_256-NONE, AES_GCM_16_128-NONE, AES_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128, AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 Sep 21 07:34:29.452889: | counting wild cards for @west is 0 Sep 21 07:34:29.452893: | counting wild cards for @east is 0 Sep 21 07:34:29.452904: | connect_to_host_pair: 192.1.2.23:500 192.1.2.45:500 -> hp@(nil): none Sep 21 07:34:29.452908: | new hp@0x562c74f93570 Sep 21 07:34:29.452911: added connection description "westnet-eastnet-ikev2a" Sep 21 07:34:29.452922: | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:34:29.452940: | 192.0.2.0/24===192.1.2.23<192.1.2.23>[@east]...192.1.2.45<192.1.2.45>[@west]===192.0.1.0/24 Sep 21 07:34:29.452950: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.452956: | spent 0.221 milliseconds in whack Sep 21 07:34:29.453131: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.453140: add keyid @west Sep 21 07:34:29.453144: | add pubkey 01 03 a6 f5 d6 3f e3 8f 6c 01 6a fc 7b 7c 6d 57 Sep 21 07:34:29.453146: | add pubkey 8b 49 39 0d 77 f7 ac e2 85 f1 98 1e 4b 6d a5 3e Sep 21 07:34:29.453149: | add pubkey b3 96 9a d1 99 5a bc 10 f2 97 de f2 28 f9 5f 92 Sep 21 07:34:29.453151: | add pubkey 09 f0 c8 d4 12 e4 60 6e 9c 60 98 10 01 7d 26 b7 Sep 21 07:34:29.453153: | add pubkey 8f 95 62 2d 87 dd cd de f6 d3 8f 35 b0 50 d0 18 Sep 21 07:34:29.453156: | add pubkey f5 99 f8 04 f1 ff 61 5b bc 7f 1f c0 04 d8 e4 8c Sep 21 07:34:29.453158: | add pubkey ac 34 ad 7a c1 da 3c 2d 8c 30 ae d6 3c 59 b1 3a Sep 21 07:34:29.453160: | add pubkey 94 d3 d5 2a 73 91 bd 59 5f 3e 72 bf 4a 1b 9d c5 Sep 21 07:34:29.453163: | add pubkey b2 2b 4d e7 0d 24 3e 77 f9 7f 2d d6 9d 29 ef 70 Sep 21 07:34:29.453165: | add pubkey 7d 7a 6d a2 b8 61 0c 4b 09 4a 06 71 84 70 85 9a Sep 21 07:34:29.453167: | add pubkey 8f 52 a1 80 06 fd c6 fc 3e 27 fa 16 fa 32 83 a9 Sep 21 07:34:29.453169: | add pubkey ca 80 db 0f 4a bf f7 e9 55 8e bd 29 4d 23 a6 dc Sep 21 07:34:29.453172: | add pubkey 2a b3 5d 62 a9 21 1e be 83 d8 69 3c 03 0a 48 8e Sep 21 07:34:29.453174: | add pubkey d3 3a 11 f2 86 5a d1 30 65 bd c8 f4 83 87 ff 04 Sep 21 07:34:29.453176: | add pubkey 87 33 05 4f e0 d8 8c fe b3 19 4c dd 85 40 f3 4d Sep 21 07:34:29.453179: | add pubkey 6e e8 49 14 06 2c 1f 59 59 05 8f 20 b0 ca 46 3f Sep 21 07:34:29.453181: | add pubkey c9 20 7e 04 30 7d 9a 80 6c 3f 0a 89 f7 d3 af d8 Sep 21 07:34:29.453183: | add pubkey 15 04 37 f9 Sep 21 07:34:29.453222: | computed rsa CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 Sep 21 07:34:29.453225: | computed rsa CKAID 7f 0f 03 50 Sep 21 07:34:29.453232: | keyid: *AQOm9dY/4 Sep 21 07:34:29.453234: | n a6 f5 d6 3f e3 8f 6c 01 6a fc 7b 7c 6d 57 8b 49 Sep 21 07:34:29.453237: | n 39 0d 77 f7 ac e2 85 f1 98 1e 4b 6d a5 3e b3 96 Sep 21 07:34:29.453239: | n 9a d1 99 5a bc 10 f2 97 de f2 28 f9 5f 92 09 f0 Sep 21 07:34:29.453241: | n c8 d4 12 e4 60 6e 9c 60 98 10 01 7d 26 b7 8f 95 Sep 21 07:34:29.453244: | n 62 2d 87 dd cd de f6 d3 8f 35 b0 50 d0 18 f5 99 Sep 21 07:34:29.453246: | n f8 04 f1 ff 61 5b bc 7f 1f c0 04 d8 e4 8c ac 34 Sep 21 07:34:29.453248: | n ad 7a c1 da 3c 2d 8c 30 ae d6 3c 59 b1 3a 94 d3 Sep 21 07:34:29.453251: | n d5 2a 73 91 bd 59 5f 3e 72 bf 4a 1b 9d c5 b2 2b Sep 21 07:34:29.453253: | n 4d e7 0d 24 3e 77 f9 7f 2d d6 9d 29 ef 70 7d 7a Sep 21 07:34:29.453255: | n 6d a2 b8 61 0c 4b 09 4a 06 71 84 70 85 9a 8f 52 Sep 21 07:34:29.453258: | n a1 80 06 fd c6 fc 3e 27 fa 16 fa 32 83 a9 ca 80 Sep 21 07:34:29.453260: | n db 0f 4a bf f7 e9 55 8e bd 29 4d 23 a6 dc 2a b3 Sep 21 07:34:29.453262: | n 5d 62 a9 21 1e be 83 d8 69 3c 03 0a 48 8e d3 3a Sep 21 07:34:29.453264: | n 11 f2 86 5a d1 30 65 bd c8 f4 83 87 ff 04 87 33 Sep 21 07:34:29.453267: | n 05 4f e0 d8 8c fe b3 19 4c dd 85 40 f3 4d 6e e8 Sep 21 07:34:29.453269: | n 49 14 06 2c 1f 59 59 05 8f 20 b0 ca 46 3f c9 20 Sep 21 07:34:29.453271: | n 7e 04 30 7d 9a 80 6c 3f 0a 89 f7 d3 af d8 15 04 Sep 21 07:34:29.453273: | n 37 f9 Sep 21 07:34:29.453276: | e 03 Sep 21 07:34:29.453278: | CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 Sep 21 07:34:29.453280: | CKAID 7f 0f 03 50 Sep 21 07:34:29.453288: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.453292: | spent 0.166 milliseconds in whack Sep 21 07:34:29.453323: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.453332: add keyid @east Sep 21 07:34:29.453335: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Sep 21 07:34:29.453338: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Sep 21 07:34:29.453340: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Sep 21 07:34:29.453345: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Sep 21 07:34:29.453348: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Sep 21 07:34:29.453350: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Sep 21 07:34:29.453352: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Sep 21 07:34:29.453354: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Sep 21 07:34:29.453357: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Sep 21 07:34:29.453359: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Sep 21 07:34:29.453361: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Sep 21 07:34:29.453364: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Sep 21 07:34:29.453366: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Sep 21 07:34:29.453368: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Sep 21 07:34:29.453371: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Sep 21 07:34:29.453373: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Sep 21 07:34:29.453375: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Sep 21 07:34:29.453377: | add pubkey 51 51 48 ef Sep 21 07:34:29.453389: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:34:29.453391: | computed rsa CKAID 8a 82 25 f1 Sep 21 07:34:29.453396: | keyid: *AQO9bJbr3 Sep 21 07:34:29.453398: | n bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b e5 16 Sep 21 07:34:29.453401: | n c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 85 7a Sep 21 07:34:29.453403: | n e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c 78 ca Sep 21 07:34:29.453405: | n 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 21 c9 Sep 21 07:34:29.453408: | n f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d d2 67 Sep 21 07:34:29.453410: | n 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 62 cd Sep 21 07:34:29.453412: | n 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce 62 b5 Sep 21 07:34:29.453414: | n af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e bb 23 Sep 21 07:34:29.453417: | n 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d ac 47 Sep 21 07:34:29.453419: | n f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce e0 98 Sep 21 07:34:29.453421: | n 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a 92 b8 Sep 21 07:34:29.453423: | n 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 4d 58 Sep 21 07:34:29.453426: | n 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 5f 56 Sep 21 07:34:29.453428: | n 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 d5 f1 Sep 21 07:34:29.453430: | n 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c 47 cc Sep 21 07:34:29.453432: | n 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 07 8f Sep 21 07:34:29.453435: | n 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 51 51 Sep 21 07:34:29.453437: | n 48 ef Sep 21 07:34:29.453439: | e 03 Sep 21 07:34:29.453441: | CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:34:29.453444: | CKAID 8a 82 25 f1 Sep 21 07:34:29.453450: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.453455: | spent 0.135 milliseconds in whack Sep 21 07:34:29.561312: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.561332: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.561336: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:34:29.561338: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.561341: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:34:29.561344: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.561352: | Added new connection westnet-eastnet-ikev2b with policy PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:34:29.561405: | ike (phase1) algorithm values: AES_GCM_16_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_GCM_16_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 Sep 21 07:34:29.561414: | from whack: got --esp= Sep 21 07:34:29.561450: | ESP/AH string values: AES_GCM_16_256-NONE, AES_GCM_16_128-NONE, AES_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128, AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 Sep 21 07:34:29.561455: | counting wild cards for @west is 0 Sep 21 07:34:29.561458: | counting wild cards for @east is 0 Sep 21 07:34:29.561466: | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports Sep 21 07:34:29.561471: | connect_to_host_pair: 192.1.2.23:500 192.1.2.45:500 -> hp@0x562c74f93570: westnet-eastnet-ikev2a Sep 21 07:34:29.561474: added connection description "westnet-eastnet-ikev2b" Sep 21 07:34:29.561485: | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:34:29.561496: | 192.0.211.0/24===192.1.2.23<192.1.2.23>[@east]...192.1.2.45<192.1.2.45>[@west]===192.0.1.0/24 Sep 21 07:34:29.561508: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.561516: | spent 0.213 milliseconds in whack Sep 21 07:34:29.561713: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.561727: add keyid @west Sep 21 07:34:29.561733: | unreference key: 0x562c74f51650 @west cnt 1-- Sep 21 07:34:29.561738: | add pubkey 01 03 a6 f5 d6 3f e3 8f 6c 01 6a fc 7b 7c 6d 57 Sep 21 07:34:29.561741: | add pubkey 8b 49 39 0d 77 f7 ac e2 85 f1 98 1e 4b 6d a5 3e Sep 21 07:34:29.561743: | add pubkey b3 96 9a d1 99 5a bc 10 f2 97 de f2 28 f9 5f 92 Sep 21 07:34:29.561745: | add pubkey 09 f0 c8 d4 12 e4 60 6e 9c 60 98 10 01 7d 26 b7 Sep 21 07:34:29.561748: | add pubkey 8f 95 62 2d 87 dd cd de f6 d3 8f 35 b0 50 d0 18 Sep 21 07:34:29.561750: | add pubkey f5 99 f8 04 f1 ff 61 5b bc 7f 1f c0 04 d8 e4 8c Sep 21 07:34:29.561752: | add pubkey ac 34 ad 7a c1 da 3c 2d 8c 30 ae d6 3c 59 b1 3a Sep 21 07:34:29.561754: | add pubkey 94 d3 d5 2a 73 91 bd 59 5f 3e 72 bf 4a 1b 9d c5 Sep 21 07:34:29.561756: | add pubkey b2 2b 4d e7 0d 24 3e 77 f9 7f 2d d6 9d 29 ef 70 Sep 21 07:34:29.561758: | add pubkey 7d 7a 6d a2 b8 61 0c 4b 09 4a 06 71 84 70 85 9a Sep 21 07:34:29.561761: | add pubkey 8f 52 a1 80 06 fd c6 fc 3e 27 fa 16 fa 32 83 a9 Sep 21 07:34:29.561763: | add pubkey ca 80 db 0f 4a bf f7 e9 55 8e bd 29 4d 23 a6 dc Sep 21 07:34:29.561765: | add pubkey 2a b3 5d 62 a9 21 1e be 83 d8 69 3c 03 0a 48 8e Sep 21 07:34:29.561767: | add pubkey d3 3a 11 f2 86 5a d1 30 65 bd c8 f4 83 87 ff 04 Sep 21 07:34:29.561770: | add pubkey 87 33 05 4f e0 d8 8c fe b3 19 4c dd 85 40 f3 4d Sep 21 07:34:29.561772: | add pubkey 6e e8 49 14 06 2c 1f 59 59 05 8f 20 b0 ca 46 3f Sep 21 07:34:29.561774: | add pubkey c9 20 7e 04 30 7d 9a 80 6c 3f 0a 89 f7 d3 af d8 Sep 21 07:34:29.561776: | add pubkey 15 04 37 f9 Sep 21 07:34:29.561808: | computed rsa CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 Sep 21 07:34:29.561814: | computed rsa CKAID 7f 0f 03 50 Sep 21 07:34:29.561819: | keyid: *AQOm9dY/4 Sep 21 07:34:29.561821: | n a6 f5 d6 3f e3 8f 6c 01 6a fc 7b 7c 6d 57 8b 49 Sep 21 07:34:29.561823: | n 39 0d 77 f7 ac e2 85 f1 98 1e 4b 6d a5 3e b3 96 Sep 21 07:34:29.561825: | n 9a d1 99 5a bc 10 f2 97 de f2 28 f9 5f 92 09 f0 Sep 21 07:34:29.561827: | n c8 d4 12 e4 60 6e 9c 60 98 10 01 7d 26 b7 8f 95 Sep 21 07:34:29.561830: | n 62 2d 87 dd cd de f6 d3 8f 35 b0 50 d0 18 f5 99 Sep 21 07:34:29.561832: | n f8 04 f1 ff 61 5b bc 7f 1f c0 04 d8 e4 8c ac 34 Sep 21 07:34:29.561834: | n ad 7a c1 da 3c 2d 8c 30 ae d6 3c 59 b1 3a 94 d3 Sep 21 07:34:29.561836: | n d5 2a 73 91 bd 59 5f 3e 72 bf 4a 1b 9d c5 b2 2b Sep 21 07:34:29.561842: | n 4d e7 0d 24 3e 77 f9 7f 2d d6 9d 29 ef 70 7d 7a Sep 21 07:34:29.561844: | n 6d a2 b8 61 0c 4b 09 4a 06 71 84 70 85 9a 8f 52 Sep 21 07:34:29.561846: | n a1 80 06 fd c6 fc 3e 27 fa 16 fa 32 83 a9 ca 80 Sep 21 07:34:29.561848: | n db 0f 4a bf f7 e9 55 8e bd 29 4d 23 a6 dc 2a b3 Sep 21 07:34:29.561850: | n 5d 62 a9 21 1e be 83 d8 69 3c 03 0a 48 8e d3 3a Sep 21 07:34:29.561852: | n 11 f2 86 5a d1 30 65 bd c8 f4 83 87 ff 04 87 33 Sep 21 07:34:29.561854: | n 05 4f e0 d8 8c fe b3 19 4c dd 85 40 f3 4d 6e e8 Sep 21 07:34:29.561857: | n 49 14 06 2c 1f 59 59 05 8f 20 b0 ca 46 3f c9 20 Sep 21 07:34:29.561859: | n 7e 04 30 7d 9a 80 6c 3f 0a 89 f7 d3 af d8 15 04 Sep 21 07:34:29.561861: | n 37 f9 Sep 21 07:34:29.561863: | e 03 Sep 21 07:34:29.561865: | CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 Sep 21 07:34:29.561867: | CKAID 7f 0f 03 50 Sep 21 07:34:29.561874: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.561879: | spent 0.165 milliseconds in whack Sep 21 07:34:29.561927: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.561948: add keyid @east Sep 21 07:34:29.561958: | unreference key: 0x562c74f4e830 @east cnt 1-- Sep 21 07:34:29.561964: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Sep 21 07:34:29.561968: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Sep 21 07:34:29.561971: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Sep 21 07:34:29.561974: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Sep 21 07:34:29.561976: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Sep 21 07:34:29.561979: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Sep 21 07:34:29.561982: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Sep 21 07:34:29.561986: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Sep 21 07:34:29.561989: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Sep 21 07:34:29.561992: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Sep 21 07:34:29.561995: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Sep 21 07:34:29.561998: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Sep 21 07:34:29.562001: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Sep 21 07:34:29.562005: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Sep 21 07:34:29.562008: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Sep 21 07:34:29.562011: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Sep 21 07:34:29.562014: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Sep 21 07:34:29.562017: | add pubkey 51 51 48 ef Sep 21 07:34:29.562029: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:34:29.562033: | computed rsa CKAID 8a 82 25 f1 Sep 21 07:34:29.562037: | keyid: *AQO9bJbr3 Sep 21 07:34:29.562041: | n bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b e5 16 Sep 21 07:34:29.562044: | n c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 85 7a Sep 21 07:34:29.562047: | n e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c 78 ca Sep 21 07:34:29.562049: | n 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 21 c9 Sep 21 07:34:29.562050: | n f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d d2 67 Sep 21 07:34:29.562052: | n 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 62 cd Sep 21 07:34:29.562053: | n 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce 62 b5 Sep 21 07:34:29.562055: | n af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e bb 23 Sep 21 07:34:29.562056: | n 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d ac 47 Sep 21 07:34:29.562058: | n f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce e0 98 Sep 21 07:34:29.562059: | n 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a 92 b8 Sep 21 07:34:29.562062: | n 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 4d 58 Sep 21 07:34:29.562067: | n 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 5f 56 Sep 21 07:34:29.562074: | n 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 d5 f1 Sep 21 07:34:29.562076: | n 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c 47 cc Sep 21 07:34:29.562078: | n 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 07 8f Sep 21 07:34:29.562081: | n 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 51 51 Sep 21 07:34:29.562083: | n 48 ef Sep 21 07:34:29.562085: | e 03 Sep 21 07:34:29.562087: | CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:34:29.562090: | CKAID 8a 82 25 f1 Sep 21 07:34:29.562096: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.562102: | spent 0.174 milliseconds in whack Sep 21 07:34:29.653422: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.653444: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.653448: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:34:29.653451: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.653453: | FOR_EACH_CONNECTION_... in foreach_connection_by_alias Sep 21 07:34:29.653456: | FOR_EACH_CONNECTION_... in conn_by_name Sep 21 07:34:29.653461: | Added new connection westnet-eastnet-ikev2c with policy PSK+ENCRYPT+TUNNEL+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:34:29.653496: | ike (phase1) algorithm values: AES_GCM_16_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_GCM_16_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31, AES_CBC_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 Sep 21 07:34:29.653499: | from whack: got --esp= Sep 21 07:34:29.653520: | ESP/AH string values: AES_GCM_16_256-NONE, AES_GCM_16_128-NONE, AES_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128, AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 Sep 21 07:34:29.653524: | counting wild cards for @west is 0 Sep 21 07:34:29.653526: | counting wild cards for @east is 0 Sep 21 07:34:29.653532: | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports Sep 21 07:34:29.653535: | connect_to_host_pair: 192.1.2.23:500 192.1.2.45:500 -> hp@0x562c74f93570: westnet-eastnet-ikev2b Sep 21 07:34:29.653537: added connection description "westnet-eastnet-ikev2c" Sep 21 07:34:29.653545: | ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0; replay_window: 32; policy: PSK+ENCRYPT+TUNNEL+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO Sep 21 07:34:29.653556: | 192.0.212.0/24===192.1.2.23<192.1.2.23>[@east]...192.1.2.45<192.1.2.45>[@west]===192.0.1.0/24 Sep 21 07:34:29.653567: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.653574: | spent 0.159 milliseconds in whack Sep 21 07:34:29.653601: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.653610: add keyid @west Sep 21 07:34:29.653615: | unreference key: 0x562c74f51650 @west cnt 1-- Sep 21 07:34:29.653619: | add pubkey 01 03 a6 f5 d6 3f e3 8f 6c 01 6a fc 7b 7c 6d 57 Sep 21 07:34:29.653621: | add pubkey 8b 49 39 0d 77 f7 ac e2 85 f1 98 1e 4b 6d a5 3e Sep 21 07:34:29.653623: | add pubkey b3 96 9a d1 99 5a bc 10 f2 97 de f2 28 f9 5f 92 Sep 21 07:34:29.653625: | add pubkey 09 f0 c8 d4 12 e4 60 6e 9c 60 98 10 01 7d 26 b7 Sep 21 07:34:29.653627: | add pubkey 8f 95 62 2d 87 dd cd de f6 d3 8f 35 b0 50 d0 18 Sep 21 07:34:29.653628: | add pubkey f5 99 f8 04 f1 ff 61 5b bc 7f 1f c0 04 d8 e4 8c Sep 21 07:34:29.653630: | add pubkey ac 34 ad 7a c1 da 3c 2d 8c 30 ae d6 3c 59 b1 3a Sep 21 07:34:29.653632: | add pubkey 94 d3 d5 2a 73 91 bd 59 5f 3e 72 bf 4a 1b 9d c5 Sep 21 07:34:29.653634: | add pubkey b2 2b 4d e7 0d 24 3e 77 f9 7f 2d d6 9d 29 ef 70 Sep 21 07:34:29.653636: | add pubkey 7d 7a 6d a2 b8 61 0c 4b 09 4a 06 71 84 70 85 9a Sep 21 07:34:29.653644: | add pubkey 8f 52 a1 80 06 fd c6 fc 3e 27 fa 16 fa 32 83 a9 Sep 21 07:34:29.653646: | add pubkey ca 80 db 0f 4a bf f7 e9 55 8e bd 29 4d 23 a6 dc Sep 21 07:34:29.653648: | add pubkey 2a b3 5d 62 a9 21 1e be 83 d8 69 3c 03 0a 48 8e Sep 21 07:34:29.653650: | add pubkey d3 3a 11 f2 86 5a d1 30 65 bd c8 f4 83 87 ff 04 Sep 21 07:34:29.653653: | add pubkey 87 33 05 4f e0 d8 8c fe b3 19 4c dd 85 40 f3 4d Sep 21 07:34:29.653655: | add pubkey 6e e8 49 14 06 2c 1f 59 59 05 8f 20 b0 ca 46 3f Sep 21 07:34:29.653657: | add pubkey c9 20 7e 04 30 7d 9a 80 6c 3f 0a 89 f7 d3 af d8 Sep 21 07:34:29.653659: | add pubkey 15 04 37 f9 Sep 21 07:34:29.653677: | computed rsa CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 Sep 21 07:34:29.653680: | computed rsa CKAID 7f 0f 03 50 Sep 21 07:34:29.653684: | keyid: *AQOm9dY/4 Sep 21 07:34:29.653687: | n a6 f5 d6 3f e3 8f 6c 01 6a fc 7b 7c 6d 57 8b 49 Sep 21 07:34:29.653689: | n 39 0d 77 f7 ac e2 85 f1 98 1e 4b 6d a5 3e b3 96 Sep 21 07:34:29.653692: | n 9a d1 99 5a bc 10 f2 97 de f2 28 f9 5f 92 09 f0 Sep 21 07:34:29.653694: | n c8 d4 12 e4 60 6e 9c 60 98 10 01 7d 26 b7 8f 95 Sep 21 07:34:29.653696: | n 62 2d 87 dd cd de f6 d3 8f 35 b0 50 d0 18 f5 99 Sep 21 07:34:29.653699: | n f8 04 f1 ff 61 5b bc 7f 1f c0 04 d8 e4 8c ac 34 Sep 21 07:34:29.653701: | n ad 7a c1 da 3c 2d 8c 30 ae d6 3c 59 b1 3a 94 d3 Sep 21 07:34:29.653703: | n d5 2a 73 91 bd 59 5f 3e 72 bf 4a 1b 9d c5 b2 2b Sep 21 07:34:29.653705: | n 4d e7 0d 24 3e 77 f9 7f 2d d6 9d 29 ef 70 7d 7a Sep 21 07:34:29.653707: | n 6d a2 b8 61 0c 4b 09 4a 06 71 84 70 85 9a 8f 52 Sep 21 07:34:29.653709: | n a1 80 06 fd c6 fc 3e 27 fa 16 fa 32 83 a9 ca 80 Sep 21 07:34:29.653711: | n db 0f 4a bf f7 e9 55 8e bd 29 4d 23 a6 dc 2a b3 Sep 21 07:34:29.653713: | n 5d 62 a9 21 1e be 83 d8 69 3c 03 0a 48 8e d3 3a Sep 21 07:34:29.653716: | n 11 f2 86 5a d1 30 65 bd c8 f4 83 87 ff 04 87 33 Sep 21 07:34:29.653718: | n 05 4f e0 d8 8c fe b3 19 4c dd 85 40 f3 4d 6e e8 Sep 21 07:34:29.653720: | n 49 14 06 2c 1f 59 59 05 8f 20 b0 ca 46 3f c9 20 Sep 21 07:34:29.653722: | n 7e 04 30 7d 9a 80 6c 3f 0a 89 f7 d3 af d8 15 04 Sep 21 07:34:29.653724: | n 37 f9 Sep 21 07:34:29.653727: | e 03 Sep 21 07:34:29.653729: | CKAID b4 9f 1a ac 9e 45 6e 79 29 c8 81 97 3a 0c 6a d3 Sep 21 07:34:29.653731: | CKAID 7f 0f 03 50 Sep 21 07:34:29.653739: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.653744: | spent 0.146 milliseconds in whack Sep 21 07:34:29.653764: | accept(whackctlfd, (struct sockaddr *)&whackaddr, &whackaddrlen) -> fd@16 (in whack_handle() at rcv_whack.c:721) Sep 21 07:34:29.653772: add keyid @east Sep 21 07:34:29.653776: | unreference key: 0x562c74f4e830 @east cnt 1-- Sep 21 07:34:29.653780: | add pubkey 01 03 bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b Sep 21 07:34:29.653786: | add pubkey e5 16 c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 Sep 21 07:34:29.653791: | add pubkey 85 7a e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c Sep 21 07:34:29.653793: | add pubkey 78 ca 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 Sep 21 07:34:29.653796: | add pubkey 21 c9 f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d Sep 21 07:34:29.653798: | add pubkey d2 67 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 Sep 21 07:34:29.653801: | add pubkey 62 cd 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce Sep 21 07:34:29.653803: | add pubkey 62 b5 af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e Sep 21 07:34:29.653806: | add pubkey bb 23 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d Sep 21 07:34:29.653808: | add pubkey ac 47 f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce Sep 21 07:34:29.653811: | add pubkey e0 98 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a Sep 21 07:34:29.653813: | add pubkey 92 b8 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 Sep 21 07:34:29.653815: | add pubkey 4d 58 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 Sep 21 07:34:29.653830: | add pubkey 5f 56 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 Sep 21 07:34:29.653837: | add pubkey d5 f1 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c Sep 21 07:34:29.653840: | add pubkey 47 cc 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 Sep 21 07:34:29.653842: | add pubkey 07 8f 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 Sep 21 07:34:29.653844: | add pubkey 51 51 48 ef Sep 21 07:34:29.653853: | computed rsa CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:34:29.653856: | computed rsa CKAID 8a 82 25 f1 Sep 21 07:34:29.653860: | keyid: *AQO9bJbr3 Sep 21 07:34:29.653862: | n bd 6c 96 eb df 78 89 b3 ed 77 0d a1 7f 7b e5 16 Sep 21 07:34:29.653864: | n c2 c9 e4 7d 92 0a 90 9d 55 43 b4 62 13 03 85 7a Sep 21 07:34:29.653867: | n e0 26 7b 54 1f ca 09 93 cf ff 25 c9 02 4c 78 ca Sep 21 07:34:29.653869: | n 94 e5 3e ac d1 f9 a8 e5 bb 7f cc 20 84 e0 21 c9 Sep 21 07:34:29.653871: | n f0 0d c5 44 ba f3 48 64 61 58 f6 0f 63 0d d2 67 Sep 21 07:34:29.653874: | n 1e 59 8b ec f3 50 39 71 fb 39 da 11 64 b6 62 cd Sep 21 07:34:29.653876: | n 5f d3 8d 2e c1 50 ed 9c 6e 22 0c 39 a7 ce 62 b5 Sep 21 07:34:29.653878: | n af 8a 80 0f 2e 4c 05 5c 82 c7 8d 29 02 2e bb 23 Sep 21 07:34:29.653880: | n 5f db f2 9e b5 7d e2 20 70 1a 63 f3 8e 5d ac 47 Sep 21 07:34:29.653883: | n f0 5c 26 4e b1 d0 42 60 52 4a b0 77 25 ce e0 98 Sep 21 07:34:29.653885: | n 2b 43 f4 c7 59 1a 64 01 83 ea 4e e3 1a 2a 92 b8 Sep 21 07:34:29.653887: | n 55 ab 63 dd 4b 70 47 29 dc e9 b4 60 bf 43 4d 58 Sep 21 07:34:29.653889: | n 8f 64 73 95 70 ac 35 89 b2 c2 9c d4 62 c0 5f 56 Sep 21 07:34:29.653892: | n 5f ad 1b e5 dd 49 93 6a f5 23 82 ed d4 e7 d5 f1 Sep 21 07:34:29.653894: | n 55 f2 2d a2 26 a6 36 53 2f 94 fb 99 22 5c 47 cc Sep 21 07:34:29.653896: | n 6d 80 30 88 96 38 0c f5 f2 ed 37 d0 09 d5 07 8f Sep 21 07:34:29.653898: | n 69 ef a9 99 ce 4d 1a 77 9e 39 c4 38 f3 c5 51 51 Sep 21 07:34:29.653900: | n 48 ef Sep 21 07:34:29.653903: | e 03 Sep 21 07:34:29.653905: | CKAID 61 55 99 73 d3 ac ef 7d 3a 37 0e 3e 82 ad 92 c1 Sep 21 07:34:29.653907: | CKAID 8a 82 25 f1 Sep 21 07:34:29.653914: | close_any(fd@16) (in whack_process() at rcv_whack.c:700) Sep 21 07:34:29.653934: | spent 0.171 milliseconds in whack Sep 21 07:34:30.958279: | spent 0.00276 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() Sep 21 07:34:30.958305: | *received 828 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) Sep 21 07:34:30.958308: | 8d d2 34 28 c7 e8 c1 2d 00 00 00 00 00 00 00 00 Sep 21 07:34:30.958310: | 21 20 22 08 00 00 00 00 00 00 03 3c 22 00 01 b4 Sep 21 07:34:30.958311: | 02 00 00 64 01 01 00 0b 03 00 00 0c 01 00 00 14 Sep 21 07:34:30.958313: | 80 0e 01 00 03 00 00 08 02 00 00 07 03 00 00 08 Sep 21 07:34:30.958314: | 02 00 00 05 03 00 00 08 04 00 00 0e 03 00 00 08 Sep 21 07:34:30.958316: | 04 00 00 0f 03 00 00 08 04 00 00 10 03 00 00 08 Sep 21 07:34:30.958317: | 04 00 00 12 03 00 00 08 04 00 00 13 03 00 00 08 Sep 21 07:34:30.958319: | 04 00 00 14 03 00 00 08 04 00 00 15 00 00 00 08 Sep 21 07:34:30.958320: | 04 00 00 1f 02 00 00 64 02 01 00 0b 03 00 00 0c Sep 21 07:34:30.958321: | 01 00 00 14 80 0e 00 80 03 00 00 08 02 00 00 07 Sep 21 07:34:30.958323: | 03 00 00 08 02 00 00 05 03 00 00 08 04 00 00 0e Sep 21 07:34:30.958324: | 03 00 00 08 04 00 00 0f 03 00 00 08 04 00 00 10 Sep 21 07:34:30.958326: | 03 00 00 08 04 00 00 12 03 00 00 08 04 00 00 13 Sep 21 07:34:30.958327: | 03 00 00 08 04 00 00 14 03 00 00 08 04 00 00 15 Sep 21 07:34:30.958329: | 00 00 00 08 04 00 00 1f 02 00 00 74 03 01 00 0d Sep 21 07:34:30.958330: | 03 00 00 0c 01 00 00 0c 80 0e 01 00 03 00 00 08 Sep 21 07:34:30.958332: | 02 00 00 07 03 00 00 08 02 00 00 05 03 00 00 08 Sep 21 07:34:30.958333: | 03 00 00 0e 03 00 00 08 03 00 00 0c 03 00 00 08 Sep 21 07:34:30.958334: | 04 00 00 0e 03 00 00 08 04 00 00 0f 03 00 00 08 Sep 21 07:34:30.958336: | 04 00 00 10 03 00 00 08 04 00 00 12 03 00 00 08 Sep 21 07:34:30.958337: | 04 00 00 13 03 00 00 08 04 00 00 14 03 00 00 08 Sep 21 07:34:30.958341: | 04 00 00 15 00 00 00 08 04 00 00 1f 00 00 00 74 Sep 21 07:34:30.958342: | 04 01 00 0d 03 00 00 0c 01 00 00 0c 80 0e 00 80 Sep 21 07:34:30.958344: | 03 00 00 08 02 00 00 07 03 00 00 08 02 00 00 05 Sep 21 07:34:30.958345: | 03 00 00 08 03 00 00 0e 03 00 00 08 03 00 00 0c Sep 21 07:34:30.958346: | 03 00 00 08 04 00 00 0e 03 00 00 08 04 00 00 0f Sep 21 07:34:30.958348: | 03 00 00 08 04 00 00 10 03 00 00 08 04 00 00 12 Sep 21 07:34:30.958349: | 03 00 00 08 04 00 00 13 03 00 00 08 04 00 00 14 Sep 21 07:34:30.958351: | 03 00 00 08 04 00 00 15 00 00 00 08 04 00 00 1f Sep 21 07:34:30.958352: | 28 00 01 08 00 0e 00 00 7c a3 3e 7a 51 d7 e5 5c Sep 21 07:34:30.958354: | ab ca 55 29 2b 4d 1b a4 7b 10 eb 36 7d 22 1d 26 Sep 21 07:34:30.958355: | 6e 19 29 12 ac 1c 1d 55 88 4f b0 a8 a3 6b 69 49 Sep 21 07:34:30.958357: | ae 4c 80 a6 41 75 9b df 10 02 39 c5 b0 f2 d8 38 Sep 21 07:34:30.958358: | 69 d5 d1 3b 52 db 95 a3 70 67 b3 07 76 07 14 78 Sep 21 07:34:30.958360: | f9 15 a1 b1 18 07 a1 fc 9d 31 22 17 b4 1a 1b f3 Sep 21 07:34:30.958361: | ae 5f b0 1d 5b ef 65 c0 dd 8d 6e e0 5d 26 a4 c6 Sep 21 07:34:30.958362: | 1a 38 35 d1 a2 e4 44 d5 66 4e 40 b7 ca 5a 05 4d Sep 21 07:34:30.958364: | 0f 92 f9 5a ba 54 62 4e f9 67 d9 16 ae a4 48 c3 Sep 21 07:34:30.958365: | cb d3 59 cd 14 9e 9d ab b1 69 4c d8 a1 ff fe d2 Sep 21 07:34:30.958367: | e6 15 87 96 e7 4a 87 bb 0a d6 00 31 04 f1 cb f4 Sep 21 07:34:30.958368: | af f9 d2 b6 43 26 69 05 60 33 c4 f9 77 1b ad 84 Sep 21 07:34:30.958370: | 99 7c 93 43 5b b1 83 43 8a cc 68 ba 6a c0 9f 47 Sep 21 07:34:30.958371: | 2d 80 09 41 7d a7 cf 7e b4 56 f3 20 c5 41 7f 75 Sep 21 07:34:30.958373: | 55 fe ee 45 48 7e 11 5a a1 5c 4f 99 b3 61 5f 69 Sep 21 07:34:30.958374: | 69 d0 ea d2 19 fc c6 a3 cb fd 77 5b 96 dd 57 c4 Sep 21 07:34:30.958376: | d3 db 7a 46 bf d2 ed 7b 29 00 00 24 63 88 28 0e Sep 21 07:34:30.958377: | 98 be 19 6a d0 60 7e 08 dc 72 4c df 39 2e 24 e1 Sep 21 07:34:30.958378: | 46 3d 2f 62 9d 51 0b 38 62 1f 0e 0a 29 00 00 08 Sep 21 07:34:30.958380: | 00 00 40 2e 29 00 00 1c 00 00 40 04 ba 20 a9 b5 Sep 21 07:34:30.958381: | 7e 63 6b 29 df 6e fd c0 32 1b 56 79 96 0b e0 a2 Sep 21 07:34:30.958383: | 00 00 00 1c 00 00 40 05 b7 f9 b7 9f ad 63 6d 86 Sep 21 07:34:30.958384: | 94 d1 3f 33 64 04 f7 57 80 62 e7 fc Sep 21 07:34:30.958390: | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) Sep 21 07:34:30.958392: | **parse ISAKMP Message: Sep 21 07:34:30.958394: | initiator cookie: Sep 21 07:34:30.958396: | 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.958397: | responder cookie: Sep 21 07:34:30.958399: | 00 00 00 00 00 00 00 00 Sep 21 07:34:30.958400: | next payload type: ISAKMP_NEXT_v2SA (0x21) Sep 21 07:34:30.958402: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:34:30.958404: | exchange type: ISAKMP_v2_IKE_SA_INIT (0x22) Sep 21 07:34:30.958406: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Sep 21 07:34:30.958408: | Message ID: 0 (0x0) Sep 21 07:34:30.958409: | length: 828 (0x33c) Sep 21 07:34:30.958411: | processing version=2.0 packet with exchange type=ISAKMP_v2_IKE_SA_INIT (34) Sep 21 07:34:30.958417: | I am the IKE SA Original Responder receiving an IKEv2 IKE_SA_INIT request Sep 21 07:34:30.958419: | State DB: IKEv2 state not found (find_v2_ike_sa_by_initiator_spi) Sep 21 07:34:30.958421: | Now let's proceed with payload (ISAKMP_NEXT_v2SA) Sep 21 07:34:30.958424: | ***parse IKEv2 Security Association Payload: Sep 21 07:34:30.958425: | next payload type: ISAKMP_NEXT_v2KE (0x22) Sep 21 07:34:30.958427: | flags: none (0x0) Sep 21 07:34:30.958428: | length: 436 (0x1b4) Sep 21 07:34:30.958430: | processing payload: ISAKMP_NEXT_v2SA (len=432) Sep 21 07:34:30.958431: | Now let's proceed with payload (ISAKMP_NEXT_v2KE) Sep 21 07:34:30.958433: | ***parse IKEv2 Key Exchange Payload: Sep 21 07:34:30.958435: | next payload type: ISAKMP_NEXT_v2Ni (0x28) Sep 21 07:34:30.958438: | flags: none (0x0) Sep 21 07:34:30.958439: | length: 264 (0x108) Sep 21 07:34:30.958441: | DH group: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:34:30.958442: | processing payload: ISAKMP_NEXT_v2KE (len=256) Sep 21 07:34:30.958444: | Now let's proceed with payload (ISAKMP_NEXT_v2Ni) Sep 21 07:34:30.958445: | ***parse IKEv2 Nonce Payload: Sep 21 07:34:30.958447: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:34:30.958448: | flags: none (0x0) Sep 21 07:34:30.958450: | length: 36 (0x24) Sep 21 07:34:30.958451: | processing payload: ISAKMP_NEXT_v2Ni (len=32) Sep 21 07:34:30.958453: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Sep 21 07:34:30.958455: | ***parse IKEv2 Notify Payload: Sep 21 07:34:30.958456: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:34:30.958458: | flags: none (0x0) Sep 21 07:34:30.958459: | length: 8 (0x8) Sep 21 07:34:30.958461: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:34:30.958462: | SPI size: 0 (0x0) Sep 21 07:34:30.958464: | Notify Message Type: v2N_IKEV2_FRAGMENTATION_SUPPORTED (0x402e) Sep 21 07:34:30.958466: | processing payload: ISAKMP_NEXT_v2N (len=0) Sep 21 07:34:30.958467: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Sep 21 07:34:30.958469: | ***parse IKEv2 Notify Payload: Sep 21 07:34:30.958470: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:34:30.958472: | flags: none (0x0) Sep 21 07:34:30.958473: | length: 28 (0x1c) Sep 21 07:34:30.958475: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:34:30.958476: | SPI size: 0 (0x0) Sep 21 07:34:30.958478: | Notify Message Type: v2N_NAT_DETECTION_SOURCE_IP (0x4004) Sep 21 07:34:30.958480: | processing payload: ISAKMP_NEXT_v2N (len=20) Sep 21 07:34:30.958481: | Now let's proceed with payload (ISAKMP_NEXT_v2N) Sep 21 07:34:30.958483: | ***parse IKEv2 Notify Payload: Sep 21 07:34:30.958484: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.958486: | flags: none (0x0) Sep 21 07:34:30.958487: | length: 28 (0x1c) Sep 21 07:34:30.958489: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:34:30.958490: | SPI size: 0 (0x0) Sep 21 07:34:30.958492: | Notify Message Type: v2N_NAT_DETECTION_DESTINATION_IP (0x4005) Sep 21 07:34:30.958493: | processing payload: ISAKMP_NEXT_v2N (len=20) Sep 21 07:34:30.958495: | DDOS disabled and no cookie sent, continuing Sep 21 07:34:30.958498: | find_host_connection local=192.1.2.23:500 remote=192.1.2.45:500 policy=ECDSA+IKEV2_ALLOW but ignoring ports Sep 21 07:34:30.958502: | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports Sep 21 07:34:30.958504: | find_next_host_connection policy=ECDSA+IKEV2_ALLOW Sep 21 07:34:30.958506: | found policy = PSK+ENCRYPT+TUNNEL+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2c) Sep 21 07:34:30.958509: | found policy = PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2b) Sep 21 07:34:30.958511: | found policy = PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2a) Sep 21 07:34:30.958512: | find_next_host_connection returns empty Sep 21 07:34:30.958515: | find_host_connection local=192.1.2.23:500 remote= policy=ECDSA+IKEV2_ALLOW but ignoring ports Sep 21 07:34:30.958517: | find_next_host_connection policy=ECDSA+IKEV2_ALLOW Sep 21 07:34:30.958519: | find_next_host_connection returns empty Sep 21 07:34:30.958521: | initial parent SA message received on 192.1.2.23:500 but no connection has been authorized with policy ECDSA+IKEV2_ALLOW Sep 21 07:34:30.958524: | find_host_connection local=192.1.2.23:500 remote=192.1.2.45:500 policy=RSASIG+IKEV2_ALLOW but ignoring ports Sep 21 07:34:30.958527: | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports Sep 21 07:34:30.958528: | find_next_host_connection policy=RSASIG+IKEV2_ALLOW Sep 21 07:34:30.958530: | found policy = PSK+ENCRYPT+TUNNEL+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2c) Sep 21 07:34:30.958533: | found policy = PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2b) Sep 21 07:34:30.958535: | found policy = PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2a) Sep 21 07:34:30.958536: | find_next_host_connection returns empty Sep 21 07:34:30.958539: | find_host_connection local=192.1.2.23:500 remote= policy=RSASIG+IKEV2_ALLOW but ignoring ports Sep 21 07:34:30.958541: | find_next_host_connection policy=RSASIG+IKEV2_ALLOW Sep 21 07:34:30.958542: | find_next_host_connection returns empty Sep 21 07:34:30.958544: | initial parent SA message received on 192.1.2.23:500 but no connection has been authorized with policy RSASIG+IKEV2_ALLOW Sep 21 07:34:30.958547: | find_host_connection local=192.1.2.23:500 remote=192.1.2.45:500 policy=PSK+IKEV2_ALLOW but ignoring ports Sep 21 07:34:30.958550: | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports Sep 21 07:34:30.958551: | find_next_host_connection policy=PSK+IKEV2_ALLOW Sep 21 07:34:30.958553: | found policy = PSK+ENCRYPT+TUNNEL+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2c) Sep 21 07:34:30.958555: | find_next_host_connection returns westnet-eastnet-ikev2c Sep 21 07:34:30.958557: | find_next_host_connection policy=PSK+IKEV2_ALLOW Sep 21 07:34:30.958559: | found policy = PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2b) Sep 21 07:34:30.958560: | find_next_host_connection returns westnet-eastnet-ikev2b Sep 21 07:34:30.958562: | find_next_host_connection policy=PSK+IKEV2_ALLOW Sep 21 07:34:30.958563: | found policy = PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO (westnet-eastnet-ikev2a) Sep 21 07:34:30.958565: | find_next_host_connection returns westnet-eastnet-ikev2a Sep 21 07:34:30.958566: | find_next_host_connection policy=PSK+IKEV2_ALLOW Sep 21 07:34:30.958568: | find_next_host_connection returns empty Sep 21 07:34:30.958570: | found connection: westnet-eastnet-ikev2c with policy PSK+IKEV2_ALLOW Sep 21 07:34:30.958586: | creating state object #1 at 0x562c74fcc810 Sep 21 07:34:30.958588: | State DB: adding IKEv2 state #1 in UNDEFINED Sep 21 07:34:30.958594: | pstats #1 ikev2.ike started Sep 21 07:34:30.958596: | Message ID: init #1: msgid=0 lastack=4294967295 nextuse=0 lastrecv=4294967295 lastreplied=0 Sep 21 07:34:30.958599: | parent state #1: UNDEFINED(ignore) => PARENT_R0(half-open IKE SA) Sep 21 07:34:30.958602: | Message ID: init_ike #1; ike: initiator.sent=0->-1 initiator.recv=0->-1 responder.sent=0->-1 responder.recv=0->-1 wip.initiator=0->-1 wip.responder=0->-1 Sep 21 07:34:30.958608: | start processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ikev2_process_packet() at ikev2.c:2016) Sep 21 07:34:30.958610: | State DB: IKEv2 state not found (find_v2_sa_by_responder_wip) Sep 21 07:34:30.958613: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ike_process_packet() at ikev2.c:2064) Sep 21 07:34:30.958615: | #1 st.st_msgid_lastrecv -1 md.hdr.isa_msgid 00000000 Sep 21 07:34:30.958618: | Message ID: #1 not a duplicate - message is new; initiator.sent=-1 initiator.recv=-1 responder.sent=-1 responder.recv=-1 Sep 21 07:34:30.958621: | Message ID: start-responder #1 request 0; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=-1 responder.recv=-1 wip.initiator=-1 wip.responder=-1->0 Sep 21 07:34:30.958622: | #1 in state PARENT_R0: processing SA_INIT request Sep 21 07:34:30.958624: | selected state microcode Respond to IKE_SA_INIT Sep 21 07:34:30.958626: | Now let's proceed with state specific processing Sep 21 07:34:30.958627: | calling processor Respond to IKE_SA_INIT Sep 21 07:34:30.958631: | #1 updating local interface from 192.1.2.23:500 to 192.1.2.23:500 using md->iface (in update_ike_endpoints() at state.c:2668) Sep 21 07:34:30.958634: | constructing local IKE proposals for westnet-eastnet-ikev2c (IKE SA responder matching remote proposals) Sep 21 07:34:30.958641: | converting ike_info AES_GCM_16_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:34:30.958646: | ... ikev2_proposal: 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:34:30.958649: | converting ike_info AES_GCM_16_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:34:30.958652: | ... ikev2_proposal: 2:IKE:ENCR=AES_GCM_C_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:34:30.958655: | converting ike_info AES_CBC_256-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:34:30.958658: | ... ikev2_proposal: 3:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:34:30.958660: | converting ike_info AES_CBC_128-HMAC_SHA2_512+HMAC_SHA2_256-MODP2048+MODP3072+MODP4096+MODP8192+DH19+DH20+DH21+DH31 to ikev2 ... Sep 21 07:34:30.958663: | ... ikev2_proposal: 4:IKE:ENCR=AES_CBC_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:34:30.958669: "westnet-eastnet-ikev2c": constructed local IKE proposals for westnet-eastnet-ikev2c (IKE SA responder matching remote proposals): 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 2:IKE:ENCR=AES_GCM_C_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=NONE;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 3:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 4:IKE:ENCR=AES_CBC_128;PRF=HMAC_SHA2_512,HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=MODP2048,MODP3072,MODP4096,MODP8192,ECP_256,ECP_384,ECP_521,CURVE25519 Sep 21 07:34:30.958672: | Comparing remote proposals against IKE responder 4 local proposals Sep 21 07:34:30.958674: | local proposal 1 type ENCR has 1 transforms Sep 21 07:34:30.958676: | local proposal 1 type PRF has 2 transforms Sep 21 07:34:30.958677: | local proposal 1 type INTEG has 1 transforms Sep 21 07:34:30.958679: | local proposal 1 type DH has 8 transforms Sep 21 07:34:30.958680: | local proposal 1 type ESN has 0 transforms Sep 21 07:34:30.958682: | local proposal 1 transforms: required: ENCR+PRF+DH; optional: INTEG Sep 21 07:34:30.958684: | local proposal 2 type ENCR has 1 transforms Sep 21 07:34:30.958685: | local proposal 2 type PRF has 2 transforms Sep 21 07:34:30.958687: | local proposal 2 type INTEG has 1 transforms Sep 21 07:34:30.958688: | local proposal 2 type DH has 8 transforms Sep 21 07:34:30.958690: | local proposal 2 type ESN has 0 transforms Sep 21 07:34:30.958692: | local proposal 2 transforms: required: ENCR+PRF+DH; optional: INTEG Sep 21 07:34:30.958693: | local proposal 3 type ENCR has 1 transforms Sep 21 07:34:30.958695: | local proposal 3 type PRF has 2 transforms Sep 21 07:34:30.958696: | local proposal 3 type INTEG has 2 transforms Sep 21 07:34:30.958707: | local proposal 3 type DH has 8 transforms Sep 21 07:34:30.958714: | local proposal 3 type ESN has 0 transforms Sep 21 07:34:30.958718: | local proposal 3 transforms: required: ENCR+PRF+INTEG+DH; optional: none Sep 21 07:34:30.958720: | local proposal 4 type ENCR has 1 transforms Sep 21 07:34:30.958722: | local proposal 4 type PRF has 2 transforms Sep 21 07:34:30.958725: | local proposal 4 type INTEG has 2 transforms Sep 21 07:34:30.958727: | local proposal 4 type DH has 8 transforms Sep 21 07:34:30.958730: | local proposal 4 type ESN has 0 transforms Sep 21 07:34:30.958734: | local proposal 4 transforms: required: ENCR+PRF+INTEG+DH; optional: none Sep 21 07:34:30.958737: | ****parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.958742: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:30.958744: | length: 100 (0x64) Sep 21 07:34:30.958745: | prop #: 1 (0x1) Sep 21 07:34:30.958747: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:34:30.958749: | spi size: 0 (0x0) Sep 21 07:34:30.958750: | # transforms: 11 (0xb) Sep 21 07:34:30.958753: | Comparing remote proposal 1 containing 11 transforms against local proposal [1..4] of 4 local proposals Sep 21 07:34:30.958755: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958756: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958758: | length: 12 (0xc) Sep 21 07:34:30.958760: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.958761: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:30.958763: | ******parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.958765: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.958766: | length/value: 256 (0x100) Sep 21 07:34:30.958769: | remote proposal 1 transform 0 (ENCR=AES_GCM_C_256) matches local proposal 1 type 1 (ENCR) transform 0 Sep 21 07:34:30.958771: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958772: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958774: | length: 8 (0x8) Sep 21 07:34:30.958776: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.958777: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:34:30.958779: | remote proposal 1 transform 1 (PRF=HMAC_SHA2_512) matches local proposal 1 type 2 (PRF) transform 0 Sep 21 07:34:30.958781: | remote proposal 1 transform 1 (PRF=HMAC_SHA2_512) matches local proposal 2 type 2 (PRF) transform 0 Sep 21 07:34:30.958787: | remote proposal 1 transform 1 (PRF=HMAC_SHA2_512) matches local proposal 3 type 2 (PRF) transform 0 Sep 21 07:34:30.958792: | remote proposal 1 transform 1 (PRF=HMAC_SHA2_512) matches local proposal 4 type 2 (PRF) transform 0 Sep 21 07:34:30.958793: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958795: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958797: | length: 8 (0x8) Sep 21 07:34:30.958798: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.958800: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:34:30.958801: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958803: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958804: | length: 8 (0x8) Sep 21 07:34:30.958806: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958808: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:34:30.958810: | remote proposal 1 transform 3 (DH=MODP2048) matches local proposal 1 type 4 (DH) transform 0 Sep 21 07:34:30.958812: | remote proposal 1 transform 3 (DH=MODP2048) matches local proposal 2 type 4 (DH) transform 0 Sep 21 07:34:30.958814: | remote proposal 1 transform 3 (DH=MODP2048) matches local proposal 3 type 4 (DH) transform 0 Sep 21 07:34:30.958815: | remote proposal 1 transform 3 (DH=MODP2048) matches local proposal 4 type 4 (DH) transform 0 Sep 21 07:34:30.958817: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958819: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958820: | length: 8 (0x8) Sep 21 07:34:30.958822: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958823: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:34:30.958825: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958826: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958828: | length: 8 (0x8) Sep 21 07:34:30.958829: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958831: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:34:30.958833: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958834: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958836: | length: 8 (0x8) Sep 21 07:34:30.958837: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958840: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:34:30.958842: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958843: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958845: | length: 8 (0x8) Sep 21 07:34:30.958846: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958848: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:34:30.958849: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958851: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958852: | length: 8 (0x8) Sep 21 07:34:30.958854: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958856: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:34:30.958857: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958859: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958860: | length: 8 (0x8) Sep 21 07:34:30.958862: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958863: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:34:30.958865: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958866: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.958868: | length: 8 (0x8) Sep 21 07:34:30.958869: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958871: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:34:30.958873: | remote proposal 1 proposed transforms: ENCR+PRF+DH; matched: ENCR+PRF+DH; unmatched: none Sep 21 07:34:30.958876: | comparing remote proposal 1 containing ENCR+PRF+DH transforms to local proposal 1; required: ENCR+PRF+DH; optional: INTEG; matched: ENCR+PRF+DH Sep 21 07:34:30.958878: | remote proposal 1 matches local proposal 1 Sep 21 07:34:30.958880: | ****parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.958881: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:30.958883: | length: 100 (0x64) Sep 21 07:34:30.958884: | prop #: 2 (0x2) Sep 21 07:34:30.958886: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:34:30.958887: | spi size: 0 (0x0) Sep 21 07:34:30.958889: | # transforms: 11 (0xb) Sep 21 07:34:30.958891: | Comparing remote proposal 2 containing 11 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:30.958893: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958894: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958896: | length: 12 (0xc) Sep 21 07:34:30.958897: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.958899: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:30.958900: | ******parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.958902: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.958904: | length/value: 128 (0x80) Sep 21 07:34:30.958906: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958907: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958909: | length: 8 (0x8) Sep 21 07:34:30.958910: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.958912: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:34:30.958913: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958915: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958916: | length: 8 (0x8) Sep 21 07:34:30.958918: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.958919: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:34:30.958921: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958922: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958924: | length: 8 (0x8) Sep 21 07:34:30.958925: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958927: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:34:30.958929: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958930: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958932: | length: 8 (0x8) Sep 21 07:34:30.958934: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958936: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:34:30.958937: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958939: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958940: | length: 8 (0x8) Sep 21 07:34:30.958942: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958943: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:34:30.958945: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958947: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958948: | length: 8 (0x8) Sep 21 07:34:30.958950: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958951: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:34:30.958953: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958954: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958956: | length: 8 (0x8) Sep 21 07:34:30.958957: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958959: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:34:30.958960: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958962: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958963: | length: 8 (0x8) Sep 21 07:34:30.958965: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958966: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:34:30.958968: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958970: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.958971: | length: 8 (0x8) Sep 21 07:34:30.958973: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958974: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:34:30.958976: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.958977: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.958979: | length: 8 (0x8) Sep 21 07:34:30.958980: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.958982: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:34:30.958984: | remote proposal 2 proposed transforms: ENCR+PRF+DH; matched: none; unmatched: ENCR+PRF+DH Sep 21 07:34:30.958986: | remote proposal 2 does not match; unmatched remote transforms: ENCR+PRF+DH Sep 21 07:34:30.958988: | ****parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.958989: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:30.958991: | length: 116 (0x74) Sep 21 07:34:30.958992: | prop #: 3 (0x3) Sep 21 07:34:30.958994: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:34:30.958995: | spi size: 0 (0x0) Sep 21 07:34:30.958997: | # transforms: 13 (0xd) Sep 21 07:34:30.958999: | Comparing remote proposal 3 containing 13 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:30.959000: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959002: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959003: | length: 12 (0xc) Sep 21 07:34:30.959005: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.959006: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:34:30.959008: | ******parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.959009: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.959011: | length/value: 256 (0x100) Sep 21 07:34:30.959013: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959014: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959016: | length: 8 (0x8) Sep 21 07:34:30.959017: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.959019: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:34:30.959021: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959022: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959024: | length: 8 (0x8) Sep 21 07:34:30.959025: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.959027: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:34:30.959029: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959031: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959032: | length: 8 (0x8) Sep 21 07:34:30.959034: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.959036: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:34:30.959037: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959039: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959040: | length: 8 (0x8) Sep 21 07:34:30.959042: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.959043: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:34:30.959045: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959047: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959048: | length: 8 (0x8) Sep 21 07:34:30.959050: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959051: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:34:30.959053: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959054: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959056: | length: 8 (0x8) Sep 21 07:34:30.959057: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959059: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:34:30.959060: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959062: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959063: | length: 8 (0x8) Sep 21 07:34:30.959065: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959066: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:34:30.959068: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959070: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959071: | length: 8 (0x8) Sep 21 07:34:30.959073: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959074: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:34:30.959076: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959077: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959079: | length: 8 (0x8) Sep 21 07:34:30.959080: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959082: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:34:30.959083: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959085: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959086: | length: 8 (0x8) Sep 21 07:34:30.959088: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959090: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:34:30.959091: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959093: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959094: | length: 8 (0x8) Sep 21 07:34:30.959096: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959097: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:34:30.959099: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959100: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.959102: | length: 8 (0x8) Sep 21 07:34:30.959103: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959105: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:34:30.959107: | remote proposal 3 proposed transforms: ENCR+PRF+INTEG+DH; matched: none; unmatched: ENCR+PRF+INTEG+DH Sep 21 07:34:30.959109: | remote proposal 3 does not match; unmatched remote transforms: ENCR+PRF+INTEG+DH Sep 21 07:34:30.959111: | ****parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.959112: | last proposal: v2_PROPOSAL_LAST (0x0) Sep 21 07:34:30.959114: | length: 116 (0x74) Sep 21 07:34:30.959115: | prop #: 4 (0x4) Sep 21 07:34:30.959117: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:34:30.959118: | spi size: 0 (0x0) Sep 21 07:34:30.959120: | # transforms: 13 (0xd) Sep 21 07:34:30.959124: | Comparing remote proposal 4 containing 13 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:30.959126: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959127: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959129: | length: 12 (0xc) Sep 21 07:34:30.959130: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.959132: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:34:30.959133: | ******parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.959135: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.959136: | length/value: 128 (0x80) Sep 21 07:34:30.959138: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959140: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959141: | length: 8 (0x8) Sep 21 07:34:30.959143: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.959144: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:34:30.959146: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959147: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959149: | length: 8 (0x8) Sep 21 07:34:30.959150: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.959152: | IKEv2 transform ID: PRF_HMAC_SHA2_256 (0x5) Sep 21 07:34:30.959153: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959155: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959156: | length: 8 (0x8) Sep 21 07:34:30.959158: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.959159: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:34:30.959161: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959163: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959164: | length: 8 (0x8) Sep 21 07:34:30.959166: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.959167: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:34:30.959169: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959170: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959172: | length: 8 (0x8) Sep 21 07:34:30.959173: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959175: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:34:30.959177: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959178: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959180: | length: 8 (0x8) Sep 21 07:34:30.959181: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959183: | IKEv2 transform ID: OAKLEY_GROUP_MODP3072 (0xf) Sep 21 07:34:30.959184: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959186: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959187: | length: 8 (0x8) Sep 21 07:34:30.959189: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959190: | IKEv2 transform ID: OAKLEY_GROUP_MODP4096 (0x10) Sep 21 07:34:30.959192: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959193: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959195: | length: 8 (0x8) Sep 21 07:34:30.959196: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959198: | IKEv2 transform ID: OAKLEY_GROUP_MODP8192 (0x12) Sep 21 07:34:30.959200: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959201: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959202: | length: 8 (0x8) Sep 21 07:34:30.959204: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959206: | IKEv2 transform ID: OAKLEY_GROUP_ECP_256 (0x13) Sep 21 07:34:30.959207: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959209: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959210: | length: 8 (0x8) Sep 21 07:34:30.959212: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959213: | IKEv2 transform ID: OAKLEY_GROUP_ECP_384 (0x14) Sep 21 07:34:30.959215: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959217: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.959219: | length: 8 (0x8) Sep 21 07:34:30.959220: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959222: | IKEv2 transform ID: OAKLEY_GROUP_ECP_521 (0x15) Sep 21 07:34:30.959224: | *****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.959225: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.959227: | length: 8 (0x8) Sep 21 07:34:30.959228: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.959230: | IKEv2 transform ID: OAKLEY_GROUP_CURVE25519 (0x1f) Sep 21 07:34:30.959232: | remote proposal 4 proposed transforms: ENCR+PRF+INTEG+DH; matched: none; unmatched: ENCR+PRF+INTEG+DH Sep 21 07:34:30.959234: | remote proposal 4 does not match; unmatched remote transforms: ENCR+PRF+INTEG+DH Sep 21 07:34:30.959237: "westnet-eastnet-ikev2c" #1: proposal 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512;DH=MODP2048 chosen from remote proposals 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512;PRF=HMAC_SHA2_256;DH=MODP2048;DH=MODP3072;DH=MODP4096;DH=MODP8192;DH=ECP_256;DH=ECP_384;DH=ECP_521;DH=CURVE25519[first-match] 2:IKE:ENCR=AES_GCM_C_128;PRF=HMAC_SHA2_512;PRF=HMAC_SHA2_256;DH=MODP2048;DH=MODP3072;DH=MODP4096;DH=MODP8192;DH=ECP_256;DH=ECP_384;DH=ECP_521;DH=CURVE25519 3:IKE:ENCR=AES_CBC_256;PRF=HMAC_SHA2_512;PRF=HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256;INTEG=HMAC_SHA2_256_128;DH=MODP2048;DH=MODP3072;DH=MODP4096;DH=MODP8192;DH=ECP_256;DH=ECP_384;DH=ECP_521;DH=CURVE25519 4:IKE:ENCR=AES_CBC_128;PRF=HMAC_SHA2_512;PRF=HMAC_SHA2_256;INTEG=HMAC_SHA2_512_256;INTEG=HMAC_SHA2_256_128;DH=MODP2048;DH=MODP3072;DH=MODP4096;DH=MODP8192;DH=ECP_256;DH=ECP_384;DH=ECP_521;DH=CURVE25519 Sep 21 07:34:30.959240: | accepted IKE proposal ikev2_proposal: 1:IKE:ENCR=AES_GCM_C_256;PRF=HMAC_SHA2_512;DH=MODP2048 Sep 21 07:34:30.959241: | converting proposal to internal trans attrs Sep 21 07:34:30.959244: | natd_hash: rcookie is zero Sep 21 07:34:30.959251: | natd_hash: hasher=0x562c738207a0(20) Sep 21 07:34:30.959253: | natd_hash: icookie= 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.959255: | natd_hash: rcookie= 00 00 00 00 00 00 00 00 Sep 21 07:34:30.959256: | natd_hash: ip= c0 01 02 17 Sep 21 07:34:30.959258: | natd_hash: port= 01 f4 Sep 21 07:34:30.959259: | natd_hash: hash= b7 f9 b7 9f ad 63 6d 86 94 d1 3f 33 64 04 f7 57 Sep 21 07:34:30.959261: | natd_hash: hash= 80 62 e7 fc Sep 21 07:34:30.959262: | natd_hash: rcookie is zero Sep 21 07:34:30.959265: | natd_hash: hasher=0x562c738207a0(20) Sep 21 07:34:30.959267: | natd_hash: icookie= 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.959268: | natd_hash: rcookie= 00 00 00 00 00 00 00 00 Sep 21 07:34:30.959270: | natd_hash: ip= c0 01 02 2d Sep 21 07:34:30.959271: | natd_hash: port= 01 f4 Sep 21 07:34:30.959273: | natd_hash: hash= ba 20 a9 b5 7e 63 6b 29 df 6e fd c0 32 1b 56 79 Sep 21 07:34:30.959274: | natd_hash: hash= 96 0b e0 a2 Sep 21 07:34:30.959276: | NAT_TRAVERSAL encaps using auto-detect Sep 21 07:34:30.959277: | NAT_TRAVERSAL this end is NOT behind NAT Sep 21 07:34:30.959279: | NAT_TRAVERSAL that end is NOT behind NAT Sep 21 07:34:30.959281: | NAT_TRAVERSAL nat-keepalive enabled 192.1.2.45 Sep 21 07:34:30.959285: | adding ikev2_inI1outR1 KE work-order 1 for state #1 Sep 21 07:34:30.959287: | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x562c74fcf420 Sep 21 07:34:30.959290: | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 Sep 21 07:34:30.959292: | libevent_malloc: new ptr-libevent@0x562c74fcf460 size 128 Sep 21 07:34:30.959300: | #1 spent 0.659 milliseconds in processing: Respond to IKE_SA_INIT in ikev2_process_state_packet() Sep 21 07:34:30.959305: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:34:30.959308: | #1 complete_v2_state_transition() PARENT_R0->PARENT_R1 with status STF_SUSPEND Sep 21 07:34:30.959313: | suspending state #1 and saving MD Sep 21 07:34:30.959315: | #1 is busy; has a suspended MD Sep 21 07:34:30.959306: | crypto helper 2 resuming Sep 21 07:34:30.959331: | crypto helper 2 starting work-order 1 for state #1 Sep 21 07:34:30.959336: | crypto helper 2 doing build KE and nonce (ikev2_inI1outR1 KE); request ID 1 Sep 21 07:34:30.959320: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in log_stf_suspend() at ikev2.c:3266) Sep 21 07:34:30.959388: | "westnet-eastnet-ikev2c" #1 complete v2 state STATE_PARENT_R0 transition with STF_SUSPEND suspended from complete_v2_state_transition:3448 Sep 21 07:34:30.959394: | stop processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ikev2_process_packet() at ikev2.c:2018) Sep 21 07:34:30.959398: | #1 spent 1.09 milliseconds in ikev2_process_packet() Sep 21 07:34:30.959401: | stop processing: from 192.1.2.45:500 (in process_md() at demux.c:380) Sep 21 07:34:30.959403: | processing: STOP state #0 (in process_md() at demux.c:382) Sep 21 07:34:30.959405: | processing: STOP connection NULL (in process_md() at demux.c:383) Sep 21 07:34:30.959408: | spent 1.1 milliseconds in comm_handle_cb() reading and processing packet Sep 21 07:34:30.960407: | crypto helper 2 finished build KE and nonce (ikev2_inI1outR1 KE); request ID 1 time elapsed 0.001071 seconds Sep 21 07:34:30.960417: | (#1) spent 1.06 milliseconds in crypto helper computing work-order 1: ikev2_inI1outR1 KE (pcr) Sep 21 07:34:30.960421: | crypto helper 2 sending results from work-order 1 for state #1 to event queue Sep 21 07:34:30.960423: | scheduling resume sending helper answer for #1 Sep 21 07:34:30.960427: | libevent_malloc: new ptr-libevent@0x7f6f20006900 size 128 Sep 21 07:34:30.960434: | crypto helper 2 waiting (nothing to do) Sep 21 07:34:30.960463: | processing resume sending helper answer for #1 Sep 21 07:34:30.960471: | start processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in resume_handler() at server.c:797) Sep 21 07:34:30.960475: | crypto helper 2 replies to request ID 1 Sep 21 07:34:30.960477: | calling continuation function 0x562c7374a630 Sep 21 07:34:30.960478: | ikev2_parent_inI1outR1_continue for #1: calculated ke+nonce, sending R1 Sep 21 07:34:30.960505: | **emit ISAKMP Message: Sep 21 07:34:30.960507: | initiator cookie: Sep 21 07:34:30.960508: | 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.960510: | responder cookie: Sep 21 07:34:30.960511: | b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:30.960513: | next payload type: ISAKMP_NEXT_NONE (0x0) Sep 21 07:34:30.960515: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:34:30.960516: | exchange type: ISAKMP_v2_IKE_SA_INIT (0x22) Sep 21 07:34:30.960518: | flags: ISAKMP_FLAG_v2_MSG_RESPONSE (0x20) Sep 21 07:34:30.960520: | Message ID: 0 (0x0) Sep 21 07:34:30.960522: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Sep 21 07:34:30.960524: | Emitting ikev2_proposal ... Sep 21 07:34:30.960525: | ***emit IKEv2 Security Association Payload: Sep 21 07:34:30.960527: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.960528: | flags: none (0x0) Sep 21 07:34:30.960530: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Security Association Payload (33:ISAKMP_NEXT_v2SA) Sep 21 07:34:30.960532: | next payload chain: saving location 'IKEv2 Security Association Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.960534: | ****emit IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.960536: | last proposal: v2_PROPOSAL_LAST (0x0) Sep 21 07:34:30.960537: | prop #: 1 (0x1) Sep 21 07:34:30.960539: | proto ID: IKEv2_SEC_PROTO_IKE (0x1) Sep 21 07:34:30.960541: | spi size: 0 (0x0) Sep 21 07:34:30.960542: | # transforms: 3 (0x3) Sep 21 07:34:30.960544: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Sep 21 07:34:30.960546: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:34:30.960547: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.960551: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.960553: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:30.960554: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:34:30.960556: | ******emit IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.960558: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.960560: | length/value: 256 (0x100) Sep 21 07:34:30.960562: | emitting length of IKEv2 Transform Substructure Payload: 12 Sep 21 07:34:30.960563: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:34:30.960565: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.960566: | IKEv2 transform type: TRANS_TYPE_PRF (0x2) Sep 21 07:34:30.960568: | IKEv2 transform ID: PRF_HMAC_SHA2_512 (0x7) Sep 21 07:34:30.960570: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.960572: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:34:30.960573: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:34:30.960575: | *****emit IKEv2 Transform Substructure Payload: Sep 21 07:34:30.960576: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.960578: | IKEv2 transform type: TRANS_TYPE_DH (0x4) Sep 21 07:34:30.960579: | IKEv2 transform ID: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:34:30.960581: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.960583: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:34:30.960585: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:34:30.960586: | emitting length of IKEv2 Proposal Substructure Payload: 36 Sep 21 07:34:30.960588: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Sep 21 07:34:30.960590: | emitting length of IKEv2 Security Association Payload: 40 Sep 21 07:34:30.960591: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is 0 Sep 21 07:34:30.960593: | ***emit IKEv2 Key Exchange Payload: Sep 21 07:34:30.960595: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.960596: | flags: none (0x0) Sep 21 07:34:30.960598: | DH group: OAKLEY_GROUP_MODP2048 (0xe) Sep 21 07:34:30.960600: | next payload chain: setting previous 'IKEv2 Security Association Payload'.'next payload type' to current IKEv2 Key Exchange Payload (34:ISAKMP_NEXT_v2KE) Sep 21 07:34:30.960602: | next payload chain: saving location 'IKEv2 Key Exchange Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.960604: | emitting 256 raw bytes of ikev2 g^x into IKEv2 Key Exchange Payload Sep 21 07:34:30.960606: | ikev2 g^x e4 6c 04 92 1b 7d a4 02 82 a9 7d 92 af e4 b5 9b Sep 21 07:34:30.960607: | ikev2 g^x 49 0b 86 6f 4f 82 2b ab 96 d4 b2 34 7d b3 1b 81 Sep 21 07:34:30.960609: | ikev2 g^x f6 d7 d7 b7 67 4a ff db 5e f2 cd fc a2 a8 61 23 Sep 21 07:34:30.960610: | ikev2 g^x 5c c8 0f ca 61 59 2f da bb ca ec 25 15 1e 58 9e Sep 21 07:34:30.960612: | ikev2 g^x b7 c8 01 0a e8 03 71 51 5b b3 3e 4b 40 bd cb 07 Sep 21 07:34:30.960613: | ikev2 g^x 79 0b 1d 92 b0 fc c2 46 d6 da f8 1f 8c f4 8a 3e Sep 21 07:34:30.960614: | ikev2 g^x 21 58 2e 62 ec fa 7a 2b 52 1b 9a 54 20 5a c9 2e Sep 21 07:34:30.960616: | ikev2 g^x 34 15 99 dc 0a 6d 28 69 0b a4 c4 55 82 41 4c c7 Sep 21 07:34:30.960617: | ikev2 g^x 69 ed 21 7c 32 a7 d7 04 72 bb 4a 9a 14 ca f3 db Sep 21 07:34:30.960619: | ikev2 g^x 62 e6 0d ae 04 44 df 67 17 b5 c1 de c2 40 20 93 Sep 21 07:34:30.960620: | ikev2 g^x ed 60 0e ec 07 62 d9 de e7 70 9e ee c8 f5 70 07 Sep 21 07:34:30.960623: | ikev2 g^x 14 f2 76 7e 9a b6 f7 e4 53 57 c6 a2 dc 96 46 52 Sep 21 07:34:30.960624: | ikev2 g^x 6a 37 42 15 e3 29 1f e5 f9 b0 8c ac cc 83 76 25 Sep 21 07:34:30.960626: | ikev2 g^x 2a e3 0b c9 6d 10 fb ad 8e 94 35 e0 c8 b8 09 8c Sep 21 07:34:30.960627: | ikev2 g^x a8 cc fc 1b 5a 43 0c 85 8e cf e0 3a bc b8 b1 64 Sep 21 07:34:30.960629: | ikev2 g^x 7b c5 66 c5 36 6f 93 c4 df 05 6c a0 28 e0 1a d7 Sep 21 07:34:30.960630: | emitting length of IKEv2 Key Exchange Payload: 264 Sep 21 07:34:30.960632: | ***emit IKEv2 Nonce Payload: Sep 21 07:34:30.960633: | next payload type: ISAKMP_NEXT_v2N (0x29) Sep 21 07:34:30.960635: | flags: none (0x0) Sep 21 07:34:30.960637: | next payload chain: ignoring supplied 'IKEv2 Nonce Payload'.'next payload type' value 41:ISAKMP_NEXT_v2N Sep 21 07:34:30.960639: | next payload chain: setting previous 'IKEv2 Key Exchange Payload'.'next payload type' to current IKEv2 Nonce Payload (40:ISAKMP_NEXT_v2Ni) Sep 21 07:34:30.960640: | next payload chain: saving location 'IKEv2 Nonce Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.960642: | emitting 32 raw bytes of IKEv2 nonce into IKEv2 Nonce Payload Sep 21 07:34:30.960644: | IKEv2 nonce 6e 72 a9 94 dc 1e b2 de ff d4 c0 04 c5 f4 15 8c Sep 21 07:34:30.960645: | IKEv2 nonce f7 8d 24 66 a1 ec c7 c6 c7 78 a2 57 3f cf 3f 25 Sep 21 07:34:30.960647: | emitting length of IKEv2 Nonce Payload: 36 Sep 21 07:34:30.960648: | Adding a v2N Payload Sep 21 07:34:30.960650: | ***emit IKEv2 Notify Payload: Sep 21 07:34:30.960651: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.960653: | flags: none (0x0) Sep 21 07:34:30.960654: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:34:30.960656: | SPI size: 0 (0x0) Sep 21 07:34:30.960658: | Notify Message Type: v2N_IKEV2_FRAGMENTATION_SUPPORTED (0x402e) Sep 21 07:34:30.960660: | next payload chain: setting previous 'IKEv2 Nonce Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Sep 21 07:34:30.960661: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.960663: | emitting length of IKEv2 Notify Payload: 8 Sep 21 07:34:30.960665: | NAT-Traversal support [enabled] add v2N payloads. Sep 21 07:34:30.960673: | natd_hash: hasher=0x562c738207a0(20) Sep 21 07:34:30.960674: | natd_hash: icookie= 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.960676: | natd_hash: rcookie= b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:30.960677: | natd_hash: ip= c0 01 02 17 Sep 21 07:34:30.960679: | natd_hash: port= 01 f4 Sep 21 07:34:30.960681: | natd_hash: hash= 5b 8c c1 ee c5 48 7d b6 45 6f 62 b2 2f 6c d6 6f Sep 21 07:34:30.960682: | natd_hash: hash= df b2 d9 c0 Sep 21 07:34:30.960683: | Adding a v2N Payload Sep 21 07:34:30.960685: | ***emit IKEv2 Notify Payload: Sep 21 07:34:30.960687: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.960688: | flags: none (0x0) Sep 21 07:34:30.960690: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:34:30.960691: | SPI size: 0 (0x0) Sep 21 07:34:30.960693: | Notify Message Type: v2N_NAT_DETECTION_SOURCE_IP (0x4004) Sep 21 07:34:30.960694: | next payload chain: setting previous 'IKEv2 Notify Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Sep 21 07:34:30.960696: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.960698: | emitting 20 raw bytes of Notify data into IKEv2 Notify Payload Sep 21 07:34:30.960700: | Notify data 5b 8c c1 ee c5 48 7d b6 45 6f 62 b2 2f 6c d6 6f Sep 21 07:34:30.960701: | Notify data df b2 d9 c0 Sep 21 07:34:30.960703: | emitting length of IKEv2 Notify Payload: 28 Sep 21 07:34:30.960706: | natd_hash: hasher=0x562c738207a0(20) Sep 21 07:34:30.960708: | natd_hash: icookie= 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.960709: | natd_hash: rcookie= b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:30.960711: | natd_hash: ip= c0 01 02 2d Sep 21 07:34:30.960712: | natd_hash: port= 01 f4 Sep 21 07:34:30.960714: | natd_hash: hash= bb 74 8b 3a 4b 54 58 90 56 fb 18 6b fb 39 81 8c Sep 21 07:34:30.960716: | natd_hash: hash= 7e 55 d8 66 Sep 21 07:34:30.960718: | Adding a v2N Payload Sep 21 07:34:30.960719: | ***emit IKEv2 Notify Payload: Sep 21 07:34:30.960721: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.960722: | flags: none (0x0) Sep 21 07:34:30.960724: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:34:30.960725: | SPI size: 0 (0x0) Sep 21 07:34:30.960727: | Notify Message Type: v2N_NAT_DETECTION_DESTINATION_IP (0x4005) Sep 21 07:34:30.960728: | next payload chain: setting previous 'IKEv2 Notify Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Sep 21 07:34:30.960730: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.960732: | emitting 20 raw bytes of Notify data into IKEv2 Notify Payload Sep 21 07:34:30.960733: | Notify data bb 74 8b 3a 4b 54 58 90 56 fb 18 6b fb 39 81 8c Sep 21 07:34:30.960735: | Notify data 7e 55 d8 66 Sep 21 07:34:30.960736: | emitting length of IKEv2 Notify Payload: 28 Sep 21 07:34:30.960738: | emitting length of ISAKMP Message: 432 Sep 21 07:34:30.960742: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:34:30.960744: | #1 complete_v2_state_transition() PARENT_R0->PARENT_R1 with status STF_OK Sep 21 07:34:30.960746: | IKEv2: transition from state STATE_PARENT_R0 to state STATE_PARENT_R1 Sep 21 07:34:30.960748: | parent state #1: PARENT_R0(half-open IKE SA) => PARENT_R1(half-open IKE SA) Sep 21 07:34:30.960750: | Message ID: updating counters for #1 to 0 after switching state Sep 21 07:34:30.960753: | Message ID: recv #1 request 0; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=-1 responder.recv=-1->0 wip.initiator=-1 wip.responder=0->-1 Sep 21 07:34:30.960756: | Message ID: sent #1 response 0; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=-1->0 responder.recv=0 wip.initiator=-1 wip.responder=-1 Sep 21 07:34:30.960759: "westnet-eastnet-ikev2c" #1: STATE_PARENT_R1: received v2I1, sent v2R1 {auth=IKEv2 cipher=AES_GCM_16_256 integ=n/a prf=HMAC_SHA2_512 group=MODP2048} Sep 21 07:34:30.960762: | sending V2 new request packet to 192.1.2.45:500 (from 192.1.2.23:500) Sep 21 07:34:30.960768: | sending 432 bytes for STATE_PARENT_R0 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) Sep 21 07:34:30.960770: | 8d d2 34 28 c7 e8 c1 2d b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:30.960771: | 21 20 22 20 00 00 00 00 00 00 01 b0 22 00 00 28 Sep 21 07:34:30.960773: | 00 00 00 24 01 01 00 03 03 00 00 0c 01 00 00 14 Sep 21 07:34:30.960774: | 80 0e 01 00 03 00 00 08 02 00 00 07 00 00 00 08 Sep 21 07:34:30.960776: | 04 00 00 0e 28 00 01 08 00 0e 00 00 e4 6c 04 92 Sep 21 07:34:30.960777: | 1b 7d a4 02 82 a9 7d 92 af e4 b5 9b 49 0b 86 6f Sep 21 07:34:30.960778: | 4f 82 2b ab 96 d4 b2 34 7d b3 1b 81 f6 d7 d7 b7 Sep 21 07:34:30.960780: | 67 4a ff db 5e f2 cd fc a2 a8 61 23 5c c8 0f ca Sep 21 07:34:30.960781: | 61 59 2f da bb ca ec 25 15 1e 58 9e b7 c8 01 0a Sep 21 07:34:30.960789: | e8 03 71 51 5b b3 3e 4b 40 bd cb 07 79 0b 1d 92 Sep 21 07:34:30.960793: | b0 fc c2 46 d6 da f8 1f 8c f4 8a 3e 21 58 2e 62 Sep 21 07:34:30.960794: | ec fa 7a 2b 52 1b 9a 54 20 5a c9 2e 34 15 99 dc Sep 21 07:34:30.960795: | 0a 6d 28 69 0b a4 c4 55 82 41 4c c7 69 ed 21 7c Sep 21 07:34:30.960797: | 32 a7 d7 04 72 bb 4a 9a 14 ca f3 db 62 e6 0d ae Sep 21 07:34:30.960798: | 04 44 df 67 17 b5 c1 de c2 40 20 93 ed 60 0e ec Sep 21 07:34:30.960800: | 07 62 d9 de e7 70 9e ee c8 f5 70 07 14 f2 76 7e Sep 21 07:34:30.960801: | 9a b6 f7 e4 53 57 c6 a2 dc 96 46 52 6a 37 42 15 Sep 21 07:34:30.960803: | e3 29 1f e5 f9 b0 8c ac cc 83 76 25 2a e3 0b c9 Sep 21 07:34:30.960804: | 6d 10 fb ad 8e 94 35 e0 c8 b8 09 8c a8 cc fc 1b Sep 21 07:34:30.960805: | 5a 43 0c 85 8e cf e0 3a bc b8 b1 64 7b c5 66 c5 Sep 21 07:34:30.960807: | 36 6f 93 c4 df 05 6c a0 28 e0 1a d7 29 00 00 24 Sep 21 07:34:30.960809: | 6e 72 a9 94 dc 1e b2 de ff d4 c0 04 c5 f4 15 8c Sep 21 07:34:30.960811: | f7 8d 24 66 a1 ec c7 c6 c7 78 a2 57 3f cf 3f 25 Sep 21 07:34:30.960812: | 29 00 00 08 00 00 40 2e 29 00 00 1c 00 00 40 04 Sep 21 07:34:30.960814: | 5b 8c c1 ee c5 48 7d b6 45 6f 62 b2 2f 6c d6 6f Sep 21 07:34:30.960815: | df b2 d9 c0 00 00 00 1c 00 00 40 05 bb 74 8b 3a Sep 21 07:34:30.960816: | 4b 54 58 90 56 fb 18 6b fb 39 81 8c 7e 55 d8 66 Sep 21 07:34:30.960839: | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted Sep 21 07:34:30.960843: | libevent_free: release ptr-libevent@0x562c74fcf460 Sep 21 07:34:30.960845: | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x562c74fcf420 Sep 21 07:34:30.960847: | event_schedule: new EVENT_SO_DISCARD-pe@0x562c74fcf420 Sep 21 07:34:30.960849: | inserting event EVENT_SO_DISCARD, timeout in 200 seconds for #1 Sep 21 07:34:30.960851: | libevent_malloc: new ptr-libevent@0x562c74fcf460 size 128 Sep 21 07:34:30.960853: | resume sending helper answer for #1 suppresed complete_v2_state_transition() Sep 21 07:34:30.960858: | #1 spent 0.367 milliseconds in resume sending helper answer Sep 21 07:34:30.960861: | stop processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in resume_handler() at server.c:833) Sep 21 07:34:30.960863: | libevent_free: release ptr-libevent@0x7f6f20006900 Sep 21 07:34:30.963629: | spent 0.00266 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() Sep 21 07:34:30.963650: | *received 365 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) Sep 21 07:34:30.963653: | 8d d2 34 28 c7 e8 c1 2d b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:30.963654: | 2e 20 23 08 00 00 00 01 00 00 01 6d 23 00 01 51 Sep 21 07:34:30.963656: | 0a 3a 78 d7 47 65 53 55 72 f0 16 05 1b f0 33 5b Sep 21 07:34:30.963657: | 85 78 d5 f8 e2 8d 5d 76 78 dd a4 85 5a df ff f2 Sep 21 07:34:30.963659: | 21 f3 20 e7 0f f6 7e 8f 49 f2 cd 1a f5 55 02 a3 Sep 21 07:34:30.963660: | e6 51 4a 15 62 00 4c fe 01 3d ee de 94 18 75 c5 Sep 21 07:34:30.963662: | b2 d4 c1 b2 a8 23 f4 0d b6 ba aa 9a 71 a8 9a f4 Sep 21 07:34:30.963663: | ba ba fc 99 fa 9d ca 6e 54 ee ff d6 f2 7e fd f0 Sep 21 07:34:30.963665: | bf 0c b2 1b 78 60 9d be f6 5c 68 d9 1f 78 44 f5 Sep 21 07:34:30.963666: | e6 16 34 c4 ed e2 ed 0e 50 10 ce 71 a7 dd 95 b5 Sep 21 07:34:30.963667: | f1 18 1f c6 86 d3 dc 86 c2 3d 10 47 1f b9 df c8 Sep 21 07:34:30.963669: | ad ad bd c4 d0 5c dd b4 73 1a 8d 82 e0 b7 19 1a Sep 21 07:34:30.963670: | e8 c3 9d 96 43 32 7f d8 3a 41 2c 00 a4 2b a0 5e Sep 21 07:34:30.963672: | b0 8b 6a 64 b0 31 57 27 4f 35 9f b1 69 57 3c ad Sep 21 07:34:30.963673: | 4a 0c bb 7e 69 ef d0 fe 2e 6e 69 97 1f d6 0f 4a Sep 21 07:34:30.963675: | cc 77 74 98 81 da d0 6c da 21 c6 66 e4 c9 7c 4c Sep 21 07:34:30.963676: | bd c2 a1 ea db d3 3a 84 06 df 27 0a 59 79 5c 85 Sep 21 07:34:30.963678: | f2 a0 16 29 b6 47 2a 20 07 05 80 e5 94 0d 5b a3 Sep 21 07:34:30.963679: | f5 b3 92 17 52 d9 30 7c 12 72 97 19 24 c9 2e 5d Sep 21 07:34:30.963680: | 97 5c 50 4d 31 78 9d 8b bd 00 94 f8 68 71 63 34 Sep 21 07:34:30.963682: | e7 68 86 27 23 19 c9 7b 09 ad f0 83 1d 48 26 ba Sep 21 07:34:30.963683: | f6 ef d7 ca 20 71 27 dc 20 70 a0 da d6 dc ba 83 Sep 21 07:34:30.963685: | 3c 63 9c 5f 59 38 15 ca 27 bb 5a a2 bf Sep 21 07:34:30.963688: | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) Sep 21 07:34:30.963690: | **parse ISAKMP Message: Sep 21 07:34:30.963692: | initiator cookie: Sep 21 07:34:30.963693: | 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.963695: | responder cookie: Sep 21 07:34:30.963696: | b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:30.963698: | next payload type: ISAKMP_NEXT_v2SK (0x2e) Sep 21 07:34:30.963700: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:34:30.963702: | exchange type: ISAKMP_v2_IKE_AUTH (0x23) Sep 21 07:34:30.963704: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Sep 21 07:34:30.963709: | Message ID: 1 (0x1) Sep 21 07:34:30.963711: | length: 365 (0x16d) Sep 21 07:34:30.963713: | processing version=2.0 packet with exchange type=ISAKMP_v2_IKE_AUTH (35) Sep 21 07:34:30.963715: | I am the IKE SA Original Responder receiving an IKEv2 IKE_AUTH request Sep 21 07:34:30.963718: | State DB: found IKEv2 state #1 in PARENT_R1 (find_v2_ike_sa) Sep 21 07:34:30.963723: | start processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ikev2_process_packet() at ikev2.c:2016) Sep 21 07:34:30.963726: | State DB: IKEv2 state not found (find_v2_sa_by_responder_wip) Sep 21 07:34:30.963729: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ike_process_packet() at ikev2.c:2064) Sep 21 07:34:30.963731: | #1 st.st_msgid_lastrecv 0 md.hdr.isa_msgid 00000001 Sep 21 07:34:30.963733: | Message ID: #1 not a duplicate - message is new; initiator.sent=-1 initiator.recv=-1 responder.sent=0 responder.recv=0 Sep 21 07:34:30.963735: | unpacking clear payload Sep 21 07:34:30.963737: | Now let's proceed with payload (ISAKMP_NEXT_v2SK) Sep 21 07:34:30.963739: | ***parse IKEv2 Encryption Payload: Sep 21 07:34:30.963740: | next payload type: ISAKMP_NEXT_v2IDi (0x23) Sep 21 07:34:30.963742: | flags: none (0x0) Sep 21 07:34:30.963743: | length: 337 (0x151) Sep 21 07:34:30.963745: | processing payload: ISAKMP_NEXT_v2SK (len=333) Sep 21 07:34:30.963748: | Message ID: start-responder #1 request 1; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=0 responder.recv=0 wip.initiator=-1 wip.responder=-1->1 Sep 21 07:34:30.963750: | #1 in state PARENT_R1: received v2I1, sent v2R1 Sep 21 07:34:30.963752: | selected state microcode Responder: process IKE_AUTH request (no SKEYSEED) Sep 21 07:34:30.963754: | Now let's proceed with state specific processing Sep 21 07:34:30.963755: | calling processor Responder: process IKE_AUTH request (no SKEYSEED) Sep 21 07:34:30.963758: | ikev2 parent inI2outR2: calculating g^{xy} in order to decrypt I2 Sep 21 07:34:30.963760: | offloading IKEv2 SKEYSEED using prf=HMAC_SHA2_512 integ=NONE cipherkey=AES_GCM_16 Sep 21 07:34:30.963763: | adding ikev2_inI2outR2 KE work-order 2 for state #1 Sep 21 07:34:30.963765: | state #1 requesting EVENT_SO_DISCARD to be deleted Sep 21 07:34:30.963767: | libevent_free: release ptr-libevent@0x562c74fcf460 Sep 21 07:34:30.963769: | free_event_entry: release EVENT_SO_DISCARD-pe@0x562c74fcf420 Sep 21 07:34:30.963771: | event_schedule: new EVENT_CRYPTO_TIMEOUT-pe@0x562c74fcf420 Sep 21 07:34:30.963773: | inserting event EVENT_CRYPTO_TIMEOUT, timeout in 60 seconds for #1 Sep 21 07:34:30.963775: | libevent_malloc: new ptr-libevent@0x562c74fcf460 size 128 Sep 21 07:34:30.963786: | #1 spent 0.0236 milliseconds in processing: Responder: process IKE_AUTH request (no SKEYSEED) in ikev2_process_state_packet() Sep 21 07:34:30.963792: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:34:30.963795: | #1 complete_v2_state_transition() PARENT_R1->PARENT_R1 with status STF_SUSPEND Sep 21 07:34:30.963799: | suspending state #1 and saving MD Sep 21 07:34:30.963803: | #1 is busy; has a suspended MD Sep 21 07:34:30.963794: | crypto helper 3 resuming Sep 21 07:34:30.963815: | crypto helper 3 starting work-order 2 for state #1 Sep 21 07:34:30.963807: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in log_stf_suspend() at ikev2.c:3266) Sep 21 07:34:30.963819: | crypto helper 3 doing compute dh (V2) (ikev2_inI2outR2 KE); request ID 2 Sep 21 07:34:30.963824: | "westnet-eastnet-ikev2c" #1 complete v2 state STATE_PARENT_R1 transition with STF_SUSPEND suspended from complete_v2_state_transition:3448 Sep 21 07:34:30.963833: | stop processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ikev2_process_packet() at ikev2.c:2018) Sep 21 07:34:30.963837: | #1 spent 0.188 milliseconds in ikev2_process_packet() Sep 21 07:34:30.963839: | stop processing: from 192.1.2.45:500 (in process_md() at demux.c:380) Sep 21 07:34:30.963844: | processing: STOP state #0 (in process_md() at demux.c:382) Sep 21 07:34:30.963846: | processing: STOP connection NULL (in process_md() at demux.c:383) Sep 21 07:34:30.963848: | spent 0.2 milliseconds in comm_handle_cb() reading and processing packet Sep 21 07:34:30.964851: | calculating skeyseed using prf=sha2_512 integ=none cipherkey-size=32 salt-size=4 Sep 21 07:34:30.965280: | crypto helper 3 finished compute dh (V2) (ikev2_inI2outR2 KE); request ID 2 time elapsed 0.001461 seconds Sep 21 07:34:30.965287: | (#1) spent 1.46 milliseconds in crypto helper computing work-order 2: ikev2_inI2outR2 KE (pcr) Sep 21 07:34:30.965290: | crypto helper 3 sending results from work-order 2 for state #1 to event queue Sep 21 07:34:30.965293: | scheduling resume sending helper answer for #1 Sep 21 07:34:30.965296: | libevent_malloc: new ptr-libevent@0x7f6f18006b90 size 128 Sep 21 07:34:30.965303: | crypto helper 3 waiting (nothing to do) Sep 21 07:34:30.965332: | processing resume sending helper answer for #1 Sep 21 07:34:30.965340: | start processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in resume_handler() at server.c:797) Sep 21 07:34:30.965344: | crypto helper 3 replies to request ID 2 Sep 21 07:34:30.965346: | calling continuation function 0x562c7374a630 Sep 21 07:34:30.965348: | ikev2_parent_inI2outR2_continue for #1: calculating g^{xy}, sending R2 Sep 21 07:34:30.965350: | #1 in state PARENT_R1: received v2I1, sent v2R1 Sep 21 07:34:30.965359: | #1 ikev2 ISAKMP_v2_IKE_AUTH decrypt success Sep 21 07:34:30.965361: | Now let's proceed with payload (ISAKMP_NEXT_v2IDi) Sep 21 07:34:30.965364: | **parse IKEv2 Identification - Initiator - Payload: Sep 21 07:34:30.965365: | next payload type: ISAKMP_NEXT_v2IDr (0x24) Sep 21 07:34:30.965367: | flags: none (0x0) Sep 21 07:34:30.965369: | length: 12 (0xc) Sep 21 07:34:30.965371: | ID type: ID_FQDN (0x2) Sep 21 07:34:30.965373: | processing payload: ISAKMP_NEXT_v2IDi (len=4) Sep 21 07:34:30.965374: | Now let's proceed with payload (ISAKMP_NEXT_v2IDr) Sep 21 07:34:30.965376: | **parse IKEv2 Identification - Responder - Payload: Sep 21 07:34:30.965378: | next payload type: ISAKMP_NEXT_v2AUTH (0x27) Sep 21 07:34:30.965379: | flags: none (0x0) Sep 21 07:34:30.965381: | length: 12 (0xc) Sep 21 07:34:30.965383: | ID type: ID_FQDN (0x2) Sep 21 07:34:30.965384: | processing payload: ISAKMP_NEXT_v2IDr (len=4) Sep 21 07:34:30.965386: | Now let's proceed with payload (ISAKMP_NEXT_v2AUTH) Sep 21 07:34:30.965388: | **parse IKEv2 Authentication Payload: Sep 21 07:34:30.965390: | next payload type: ISAKMP_NEXT_v2SA (0x21) Sep 21 07:34:30.965391: | flags: none (0x0) Sep 21 07:34:30.965393: | length: 72 (0x48) Sep 21 07:34:30.965394: | auth method: IKEv2_AUTH_SHARED (0x2) Sep 21 07:34:30.965396: | processing payload: ISAKMP_NEXT_v2AUTH (len=64) Sep 21 07:34:30.965398: | Now let's proceed with payload (ISAKMP_NEXT_v2SA) Sep 21 07:34:30.965399: | **parse IKEv2 Security Association Payload: Sep 21 07:34:30.965401: | next payload type: ISAKMP_NEXT_v2TSi (0x2c) Sep 21 07:34:30.965403: | flags: none (0x0) Sep 21 07:34:30.965404: | length: 164 (0xa4) Sep 21 07:34:30.965406: | processing payload: ISAKMP_NEXT_v2SA (len=160) Sep 21 07:34:30.965407: | Now let's proceed with payload (ISAKMP_NEXT_v2TSi) Sep 21 07:34:30.965409: | **parse IKEv2 Traffic Selector - Initiator - Payload: Sep 21 07:34:30.965411: | next payload type: ISAKMP_NEXT_v2TSr (0x2d) Sep 21 07:34:30.965412: | flags: none (0x0) Sep 21 07:34:30.965414: | length: 24 (0x18) Sep 21 07:34:30.965415: | number of TS: 1 (0x1) Sep 21 07:34:30.965417: | processing payload: ISAKMP_NEXT_v2TSi (len=16) Sep 21 07:34:30.965419: | Now let's proceed with payload (ISAKMP_NEXT_v2TSr) Sep 21 07:34:30.965420: | **parse IKEv2 Traffic Selector - Responder - Payload: Sep 21 07:34:30.965422: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.965424: | flags: none (0x0) Sep 21 07:34:30.965425: | length: 24 (0x18) Sep 21 07:34:30.965429: | number of TS: 1 (0x1) Sep 21 07:34:30.965431: | processing payload: ISAKMP_NEXT_v2TSr (len=16) Sep 21 07:34:30.965433: | selected state microcode Responder: process IKE_AUTH request Sep 21 07:34:30.965434: | Now let's proceed with state specific processing Sep 21 07:34:30.965436: | calling processor Responder: process IKE_AUTH request Sep 21 07:34:30.965440: "westnet-eastnet-ikev2c" #1: processing decrypted IKE_AUTH request: SK{IDi,IDr,AUTH,SA,TSi,TSr} Sep 21 07:34:30.965444: | #1 updating local interface from 192.1.2.23:500 to 192.1.2.23:500 using md->iface (in update_ike_endpoints() at state.c:2668) Sep 21 07:34:30.965447: | received IDr payload - extracting our alleged ID Sep 21 07:34:30.965449: | refine_host_connection for IKEv2: starting with "westnet-eastnet-ikev2c" Sep 21 07:34:30.965452: | match_id a=@west Sep 21 07:34:30.965454: | b=@west Sep 21 07:34:30.965455: | results matched Sep 21 07:34:30.965459: | refine_host_connection: checking "westnet-eastnet-ikev2c" against "westnet-eastnet-ikev2c", best=(none) with match=1(id=1(0)/ca=1(0)/reqca=1(0)) Sep 21 07:34:30.965460: | Warning: not switching back to template of current instance Sep 21 07:34:30.965462: | Peer expects us to be @east (ID_FQDN) according to its IDr payload Sep 21 07:34:30.965464: | This connection's local id is @east (ID_FQDN) Sep 21 07:34:30.965466: | refine_host_connection: checked westnet-eastnet-ikev2c against westnet-eastnet-ikev2c, now for see if best Sep 21 07:34:30.965469: | started looking for secret for @east->@west of kind PKK_PSK Sep 21 07:34:30.965471: | actually looking for secret for @east->@west of kind PKK_PSK Sep 21 07:34:30.965473: | line 1: key type PKK_PSK(@east) to type PKK_PSK Sep 21 07:34:30.965475: | 1: compared key @east to @east / @west -> 010 Sep 21 07:34:30.965477: | 2: compared key @west to @east / @west -> 014 Sep 21 07:34:30.965479: | line 1: match=014 Sep 21 07:34:30.965481: | match 014 beats previous best_match 000 match=0x562c74fbc010 (line=1) Sep 21 07:34:30.965483: | concluding with best_match=014 best=0x562c74fbc010 (lineno=1) Sep 21 07:34:30.965485: | returning because exact peer id match Sep 21 07:34:30.965487: | offered CA: '%none' Sep 21 07:34:30.965489: "westnet-eastnet-ikev2c" #1: IKEv2 mode peer ID is ID_FQDN: '@west' Sep 21 07:34:30.965502: | verifying AUTH payload Sep 21 07:34:30.965505: | ikev2_calculate_psk_sighash() called from STATE_PARENT_R1 to verify PSK with authby=secret Sep 21 07:34:30.965507: | started looking for secret for @east->@west of kind PKK_PSK Sep 21 07:34:30.965509: | actually looking for secret for @east->@west of kind PKK_PSK Sep 21 07:34:30.965511: | line 1: key type PKK_PSK(@east) to type PKK_PSK Sep 21 07:34:30.965513: | 1: compared key @east to @east / @west -> 010 Sep 21 07:34:30.965515: | 2: compared key @west to @east / @west -> 014 Sep 21 07:34:30.965517: | line 1: match=014 Sep 21 07:34:30.965519: | match 014 beats previous best_match 000 match=0x562c74fbc010 (line=1) Sep 21 07:34:30.965520: | concluding with best_match=014 best=0x562c74fbc010 (lineno=1) Sep 21 07:34:30.965562: "westnet-eastnet-ikev2c" #1: Authenticated using authby=secret Sep 21 07:34:30.965566: | parent state #1: PARENT_R1(half-open IKE SA) => PARENT_R2(established IKE SA) Sep 21 07:34:30.965569: | #1 will start re-keying in 3330 seconds with margin of 270 seconds (attempting re-key) Sep 21 07:34:30.965571: | state #1 requesting EVENT_CRYPTO_TIMEOUT to be deleted Sep 21 07:34:30.965573: | libevent_free: release ptr-libevent@0x562c74fcf460 Sep 21 07:34:30.965575: | free_event_entry: release EVENT_CRYPTO_TIMEOUT-pe@0x562c74fcf420 Sep 21 07:34:30.965577: | event_schedule: new EVENT_SA_REKEY-pe@0x562c74fcf420 Sep 21 07:34:30.965579: | inserting event EVENT_SA_REKEY, timeout in 3330 seconds for #1 Sep 21 07:34:30.965581: | libevent_malloc: new ptr-libevent@0x562c74fcf460 size 128 Sep 21 07:34:30.965664: | pstats #1 ikev2.ike established Sep 21 07:34:30.965671: | **emit ISAKMP Message: Sep 21 07:34:30.965673: | initiator cookie: Sep 21 07:34:30.965676: | 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:30.965678: | responder cookie: Sep 21 07:34:30.965679: | b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:30.965681: | next payload type: ISAKMP_NEXT_NONE (0x0) Sep 21 07:34:30.965683: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:34:30.965685: | exchange type: ISAKMP_v2_IKE_AUTH (0x23) Sep 21 07:34:30.965687: | flags: ISAKMP_FLAG_v2_MSG_RESPONSE (0x20) Sep 21 07:34:30.965688: | Message ID: 1 (0x1) Sep 21 07:34:30.965690: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Sep 21 07:34:30.965692: | IKEv2 CERT: send a certificate? Sep 21 07:34:30.965694: | IKEv2 CERT: policy does not have RSASIG or ECDSA: PSK Sep 21 07:34:30.965696: | ***emit IKEv2 Encryption Payload: Sep 21 07:34:30.965697: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.965699: | flags: none (0x0) Sep 21 07:34:30.965701: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Encryption Payload (46:ISAKMP_NEXT_v2SK) Sep 21 07:34:30.965703: | next payload chain: saving location 'IKEv2 Encryption Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.965705: | emitting 8 zero bytes of IV into IKEv2 Encryption Payload Sep 21 07:34:30.965711: | Initiator child policy is compress=no, NOT sending v2N_IPCOMP_SUPPORTED Sep 21 07:34:30.965720: | ****emit IKEv2 Identification - Responder - Payload: Sep 21 07:34:30.965722: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.965723: | flags: none (0x0) Sep 21 07:34:30.965725: | ID type: ID_FQDN (0x2) Sep 21 07:34:30.965727: | next payload chain: setting previous 'IKEv2 Encryption Payload'.'next payload type' to current IKEv2 Identification - Responder - Payload (36:ISAKMP_NEXT_v2IDr) Sep 21 07:34:30.965729: | next payload chain: saving location 'IKEv2 Identification - Responder - Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.965731: | emitting 4 raw bytes of my identity into IKEv2 Identification - Responder - Payload Sep 21 07:34:30.965732: | my identity 65 61 73 74 Sep 21 07:34:30.965734: | emitting length of IKEv2 Identification - Responder - Payload: 12 Sep 21 07:34:30.965739: | assembled IDr payload Sep 21 07:34:30.965740: | CHILD SA proposals received Sep 21 07:34:30.965742: | going to assemble AUTH payload Sep 21 07:34:30.965744: | ****emit IKEv2 Authentication Payload: Sep 21 07:34:30.965745: | next payload type: ISAKMP_NEXT_v2SA (0x21) Sep 21 07:34:30.965747: | flags: none (0x0) Sep 21 07:34:30.965748: | auth method: IKEv2_AUTH_SHARED (0x2) Sep 21 07:34:30.965750: | next payload chain: ignoring supplied 'IKEv2 Authentication Payload'.'next payload type' value 33:ISAKMP_NEXT_v2SA Sep 21 07:34:30.965752: | next payload chain: setting previous 'IKEv2 Identification - Responder - Payload'.'next payload type' to current IKEv2 Authentication Payload (39:ISAKMP_NEXT_v2AUTH) Sep 21 07:34:30.965754: | next payload chain: saving location 'IKEv2 Authentication Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.965756: | ikev2_calculate_psk_sighash() called from STATE_PARENT_R2 to create PSK with authby=secret Sep 21 07:34:30.965758: | started looking for secret for @east->@west of kind PKK_PSK Sep 21 07:34:30.965760: | actually looking for secret for @east->@west of kind PKK_PSK Sep 21 07:34:30.965762: | line 1: key type PKK_PSK(@east) to type PKK_PSK Sep 21 07:34:30.965764: | 1: compared key @east to @east / @west -> 010 Sep 21 07:34:30.965766: | 2: compared key @west to @east / @west -> 014 Sep 21 07:34:30.965768: | line 1: match=014 Sep 21 07:34:30.965770: | match 014 beats previous best_match 000 match=0x562c74fbc010 (line=1) Sep 21 07:34:30.965772: | concluding with best_match=014 best=0x562c74fbc010 (lineno=1) Sep 21 07:34:30.965811: | emitting 64 raw bytes of PSK auth into IKEv2 Authentication Payload Sep 21 07:34:30.965816: | PSK auth 6c 30 80 cd d4 f8 b2 04 31 55 73 5f e6 11 4a f8 Sep 21 07:34:30.965818: | PSK auth 28 2a b8 08 8c e6 fc b8 2e a2 2a 3e 5b be de 7e Sep 21 07:34:30.965821: | PSK auth 5e ee eb 89 94 21 26 24 76 11 6f 7a 3a f0 f2 83 Sep 21 07:34:30.965823: | PSK auth 6a 4d 38 b0 ac 6c b0 bf 6d f9 9e 5a f5 2f 09 21 Sep 21 07:34:30.965824: | emitting length of IKEv2 Authentication Payload: 72 Sep 21 07:34:30.965828: | creating state object #2 at 0x562c74fcffc0 Sep 21 07:34:30.965829: | State DB: adding IKEv2 state #2 in UNDEFINED Sep 21 07:34:30.965832: | pstats #2 ikev2.child started Sep 21 07:34:30.965834: | duplicating state object #1 "westnet-eastnet-ikev2c" as #2 for IPSEC SA Sep 21 07:34:30.965839: | #2 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1481) Sep 21 07:34:30.965844: | Message ID: init_child #1.#2; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=0 responder.recv=0; child: wip.initiator=0->-1 wip.responder=0->-1 Sep 21 07:34:30.965848: | Message ID: switch-from #1 request 1; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=0 responder.recv=0 wip.initiator=-1 wip.responder=1->-1 Sep 21 07:34:30.965853: | Message ID: switch-to #1.#2 request 1; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=0 responder.recv=0; child: wip.initiator=-1 wip.responder=-1->1 Sep 21 07:34:30.965856: | Child SA TS Request has ike->sa == md->st; so using parent connection Sep 21 07:34:30.965859: | TSi: parsing 1 traffic selectors Sep 21 07:34:30.965862: | ***parse IKEv2 Traffic Selector: Sep 21 07:34:30.965865: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Sep 21 07:34:30.965867: | IP Protocol ID: 0 (0x0) Sep 21 07:34:30.965870: | length: 16 (0x10) Sep 21 07:34:30.965872: | start port: 0 (0x0) Sep 21 07:34:30.965874: | end port: 65535 (0xffff) Sep 21 07:34:30.965877: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS low Sep 21 07:34:30.965879: | TS low c0 00 01 00 Sep 21 07:34:30.965881: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS high Sep 21 07:34:30.965883: | TS high c0 00 01 ff Sep 21 07:34:30.965885: | TSi: parsed 1 traffic selectors Sep 21 07:34:30.965887: | TSr: parsing 1 traffic selectors Sep 21 07:34:30.965890: | ***parse IKEv2 Traffic Selector: Sep 21 07:34:30.965892: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Sep 21 07:34:30.965895: | IP Protocol ID: 0 (0x0) Sep 21 07:34:30.965897: | length: 16 (0x10) Sep 21 07:34:30.965899: | start port: 0 (0x0) Sep 21 07:34:30.965901: | end port: 65535 (0xffff) Sep 21 07:34:30.965904: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS low Sep 21 07:34:30.965906: | TS low c0 00 02 00 Sep 21 07:34:30.965908: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS high Sep 21 07:34:30.965910: | TS high c0 00 02 ff Sep 21 07:34:30.965913: | TSr: parsed 1 traffic selectors Sep 21 07:34:30.965915: | looking for best SPD in current connection Sep 21 07:34:30.965921: | evaluating our conn="westnet-eastnet-ikev2c" I=192.0.1.0/24:0:0/0 R=192.0.212.0/24:0:0/0 to their: Sep 21 07:34:30.965927: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.965933: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:30.965937: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:30.965939: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:30.965942: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:30.965945: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:30.965950: | TSr[0] .net=192.0.2.0-192.0.2.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.965955: | match address end->client=192.0.212.0/24 == TSr[0]net=192.0.2.0-192.0.2.255: NO Sep 21 07:34:30.965957: | looking for better host pair Sep 21 07:34:30.965963: | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports Sep 21 07:34:30.965968: | checking hostpair 192.0.212.0/24:0 -> 192.0.1.0/24:0 is found Sep 21 07:34:30.965970: | investigating connection "westnet-eastnet-ikev2c" as a better match Sep 21 07:34:30.965973: | match_id a=@west Sep 21 07:34:30.965978: | b=@west Sep 21 07:34:30.965980: | results matched Sep 21 07:34:30.965986: | evaluating our conn="westnet-eastnet-ikev2c" I=192.0.1.0/24:0:0/0 R=192.0.212.0/24:0:0/0 to their: Sep 21 07:34:30.965990: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.965995: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:30.965998: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:30.966000: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:30.966003: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:30.966005: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:30.966009: | TSr[0] .net=192.0.2.0-192.0.2.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.966013: | match address end->client=192.0.212.0/24 == TSr[0]net=192.0.2.0-192.0.2.255: NO Sep 21 07:34:30.966016: | investigating connection "westnet-eastnet-ikev2b" as a better match Sep 21 07:34:30.966018: | match_id a=@west Sep 21 07:34:30.966021: | b=@west Sep 21 07:34:30.966023: | results matched Sep 21 07:34:30.966029: | evaluating our conn="westnet-eastnet-ikev2b" I=192.0.1.0/24:0:0/0 R=192.0.211.0/24:0:0/0 to their: Sep 21 07:34:30.966034: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.966041: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:30.966044: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:30.966047: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:30.966050: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:30.966053: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:30.966058: | TSr[0] .net=192.0.2.0-192.0.2.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.966065: | match address end->client=192.0.211.0/24 == TSr[0]net=192.0.2.0-192.0.2.255: NO Sep 21 07:34:30.966068: | investigating connection "westnet-eastnet-ikev2a" as a better match Sep 21 07:34:30.966071: | match_id a=@west Sep 21 07:34:30.966074: | b=@west Sep 21 07:34:30.966076: | results matched Sep 21 07:34:30.966081: | evaluating our conn="westnet-eastnet-ikev2a" I=192.0.1.0/24:0:0/0 R=192.0.2.0/24:0:0/0 to their: Sep 21 07:34:30.966085: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.966091: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:30.966094: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:30.966096: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:30.966099: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:30.966102: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:30.966106: | TSr[0] .net=192.0.2.0-192.0.2.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:30.966112: | match address end->client=192.0.2.0/24 == TSr[0]net=192.0.2.0-192.0.2.255: YES fitness 32 Sep 21 07:34:30.966115: | narrow port end=0..65535 == TSr[0]=0..65535: 0 Sep 21 07:34:30.966118: | TSr[0] port match: YES fitness 65536 Sep 21 07:34:30.966122: | narrow protocol end=*0 == TSr[0]=*0: 0 Sep 21 07:34:30.966125: | match end->protocol=*0 == TSr[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:30.966128: | best fit so far: TSi[0] TSr[0] Sep 21 07:34:30.966134: | protocol fitness found better match d westnet-eastnet-ikev2a, TSi[0],TSr[0] Sep 21 07:34:30.966137: | in connection_discard for connection westnet-eastnet-ikev2c Sep 21 07:34:30.966140: | printing contents struct traffic_selector Sep 21 07:34:30.966142: | ts_type: IKEv2_TS_IPV4_ADDR_RANGE Sep 21 07:34:30.966145: | ipprotoid: 0 Sep 21 07:34:30.966148: | port range: 0-65535 Sep 21 07:34:30.966153: | ip range: 192.0.2.0-192.0.2.255 Sep 21 07:34:30.966158: | printing contents struct traffic_selector Sep 21 07:34:30.966161: | ts_type: IKEv2_TS_IPV4_ADDR_RANGE Sep 21 07:34:30.966163: | ipprotoid: 0 Sep 21 07:34:30.966166: | port range: 0-65535 Sep 21 07:34:30.966170: | ip range: 192.0.1.0-192.0.1.255 Sep 21 07:34:30.966174: | constructing ESP/AH proposals with all DH removed for westnet-eastnet-ikev2a (IKE_AUTH responder matching remote ESP/AH proposals) Sep 21 07:34:30.966180: | converting proposal AES_GCM_16_256-NONE to ikev2 ... Sep 21 07:34:30.966185: | ... ikev2_proposal: 1:ESP:ENCR=AES_GCM_C_256;INTEG=NONE;DH=NONE;ESN=DISABLED Sep 21 07:34:30.966188: | converting proposal AES_GCM_16_128-NONE to ikev2 ... Sep 21 07:34:30.966192: | ... ikev2_proposal: 2:ESP:ENCR=AES_GCM_C_128;INTEG=NONE;DH=NONE;ESN=DISABLED Sep 21 07:34:30.966195: | converting proposal AES_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128 to ikev2 ... Sep 21 07:34:30.966198: | ... ikev2_proposal: 3:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED Sep 21 07:34:30.966201: | converting proposal AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 to ikev2 ... Sep 21 07:34:30.966204: | ... ikev2_proposal: 4:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED Sep 21 07:34:30.966212: "westnet-eastnet-ikev2a": constructed local ESP/AH proposals for westnet-eastnet-ikev2a (IKE_AUTH responder matching remote ESP/AH proposals): 1:ESP:ENCR=AES_GCM_C_256;INTEG=NONE;DH=NONE;ESN=DISABLED 2:ESP:ENCR=AES_GCM_C_128;INTEG=NONE;DH=NONE;ESN=DISABLED 3:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED 4:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED Sep 21 07:34:30.966215: | Comparing remote proposals against IKE_AUTH responder matching remote ESP/AH proposals 4 local proposals Sep 21 07:34:30.966218: | local proposal 1 type ENCR has 1 transforms Sep 21 07:34:30.966220: | local proposal 1 type PRF has 0 transforms Sep 21 07:34:30.966223: | local proposal 1 type INTEG has 1 transforms Sep 21 07:34:30.966225: | local proposal 1 type DH has 1 transforms Sep 21 07:34:30.966227: | local proposal 1 type ESN has 1 transforms Sep 21 07:34:30.966230: | local proposal 1 transforms: required: ENCR+ESN; optional: INTEG+DH Sep 21 07:34:30.966233: | local proposal 2 type ENCR has 1 transforms Sep 21 07:34:30.966235: | local proposal 2 type PRF has 0 transforms Sep 21 07:34:30.966237: | local proposal 2 type INTEG has 1 transforms Sep 21 07:34:30.966239: | local proposal 2 type DH has 1 transforms Sep 21 07:34:30.966242: | local proposal 2 type ESN has 1 transforms Sep 21 07:34:30.966244: | local proposal 2 transforms: required: ENCR+ESN; optional: INTEG+DH Sep 21 07:34:30.966247: | local proposal 3 type ENCR has 1 transforms Sep 21 07:34:30.966249: | local proposal 3 type PRF has 0 transforms Sep 21 07:34:30.966251: | local proposal 3 type INTEG has 2 transforms Sep 21 07:34:30.966254: | local proposal 3 type DH has 1 transforms Sep 21 07:34:30.966256: | local proposal 3 type ESN has 1 transforms Sep 21 07:34:30.966258: | local proposal 3 transforms: required: ENCR+INTEG+ESN; optional: DH Sep 21 07:34:30.966261: | local proposal 4 type ENCR has 1 transforms Sep 21 07:34:30.966263: | local proposal 4 type PRF has 0 transforms Sep 21 07:34:30.966265: | local proposal 4 type INTEG has 2 transforms Sep 21 07:34:30.966268: | local proposal 4 type DH has 1 transforms Sep 21 07:34:30.966270: | local proposal 4 type ESN has 1 transforms Sep 21 07:34:30.966273: | local proposal 4 transforms: required: ENCR+INTEG+ESN; optional: DH Sep 21 07:34:30.966276: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.966279: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:30.966281: | length: 32 (0x20) Sep 21 07:34:30.966284: | prop #: 1 (0x1) Sep 21 07:34:30.966287: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:30.966290: | spi size: 4 (0x4) Sep 21 07:34:30.966293: | # transforms: 2 (0x2) Sep 21 07:34:30.966297: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:30.966303: | remote SPI bd 1c d6 4f Sep 21 07:34:30.966307: | Comparing remote proposal 1 containing 2 transforms against local proposal [1..4] of 4 local proposals Sep 21 07:34:30.966310: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966314: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966317: | length: 12 (0xc) Sep 21 07:34:30.966320: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.966323: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:30.966326: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.966329: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.966332: | length/value: 256 (0x100) Sep 21 07:34:30.966337: | remote proposal 1 transform 0 (ENCR=AES_GCM_C_256) matches local proposal 1 type 1 (ENCR) transform 0 Sep 21 07:34:30.966340: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966342: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.966344: | length: 8 (0x8) Sep 21 07:34:30.966347: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:30.966349: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:30.966353: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 1 type 5 (ESN) transform 0 Sep 21 07:34:30.966356: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 2 type 5 (ESN) transform 0 Sep 21 07:34:30.966359: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 3 type 5 (ESN) transform 0 Sep 21 07:34:30.966362: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 4 type 5 (ESN) transform 0 Sep 21 07:34:30.966365: | remote proposal 1 proposed transforms: ENCR+ESN; matched: ENCR+ESN; unmatched: none Sep 21 07:34:30.966371: | comparing remote proposal 1 containing ENCR+ESN transforms to local proposal 1; required: ENCR+ESN; optional: INTEG+DH; matched: ENCR+ESN Sep 21 07:34:30.966374: | remote proposal 1 matches local proposal 1 Sep 21 07:34:30.966377: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.966380: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:30.966383: | length: 32 (0x20) Sep 21 07:34:30.966386: | prop #: 2 (0x2) Sep 21 07:34:30.966389: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:30.966392: | spi size: 4 (0x4) Sep 21 07:34:30.966395: | # transforms: 2 (0x2) Sep 21 07:34:30.966398: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:30.966401: | remote SPI bd 1c d6 4f Sep 21 07:34:30.966405: | Comparing remote proposal 2 containing 2 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:30.966408: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966411: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966414: | length: 12 (0xc) Sep 21 07:34:30.966417: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.966419: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:30.966422: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.966425: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.966427: | length/value: 128 (0x80) Sep 21 07:34:30.966430: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966432: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.966435: | length: 8 (0x8) Sep 21 07:34:30.966438: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:30.966441: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:30.966445: | remote proposal 2 proposed transforms: ENCR+ESN; matched: none; unmatched: ENCR+ESN Sep 21 07:34:30.966449: | remote proposal 2 does not match; unmatched remote transforms: ENCR+ESN Sep 21 07:34:30.966452: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.966455: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:30.966458: | length: 48 (0x30) Sep 21 07:34:30.966461: | prop #: 3 (0x3) Sep 21 07:34:30.966464: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:30.966466: | spi size: 4 (0x4) Sep 21 07:34:30.966471: | # transforms: 4 (0x4) Sep 21 07:34:30.966475: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:30.966478: | remote SPI bd 1c d6 4f Sep 21 07:34:30.966481: | Comparing remote proposal 3 containing 4 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:30.966484: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966486: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966489: | length: 12 (0xc) Sep 21 07:34:30.966491: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.966494: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:34:30.966496: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.966499: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.966501: | length/value: 256 (0x100) Sep 21 07:34:30.966504: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966507: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966509: | length: 8 (0x8) Sep 21 07:34:30.966512: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.966515: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:34:30.966519: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966522: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966524: | length: 8 (0x8) Sep 21 07:34:30.966527: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.966531: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:34:30.966534: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966537: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.966540: | length: 8 (0x8) Sep 21 07:34:30.966543: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:30.966546: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:30.966550: | remote proposal 3 proposed transforms: ENCR+INTEG+ESN; matched: none; unmatched: ENCR+INTEG+ESN Sep 21 07:34:30.966553: | remote proposal 3 does not match; unmatched remote transforms: ENCR+INTEG+ESN Sep 21 07:34:30.966556: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.966559: | last proposal: v2_PROPOSAL_LAST (0x0) Sep 21 07:34:30.966561: | length: 48 (0x30) Sep 21 07:34:30.966563: | prop #: 4 (0x4) Sep 21 07:34:30.966566: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:30.966568: | spi size: 4 (0x4) Sep 21 07:34:30.966571: | # transforms: 4 (0x4) Sep 21 07:34:30.966574: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:30.966577: | remote SPI bd 1c d6 4f Sep 21 07:34:30.966580: | Comparing remote proposal 4 containing 4 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:30.966583: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966586: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966589: | length: 12 (0xc) Sep 21 07:34:30.966592: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.966595: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:34:30.966598: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.966601: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.966604: | length/value: 128 (0x80) Sep 21 07:34:30.966608: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966611: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966613: | length: 8 (0x8) Sep 21 07:34:30.966616: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.966619: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:34:30.966622: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966625: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966627: | length: 8 (0x8) Sep 21 07:34:30.966630: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:30.966632: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:34:30.966635: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966638: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.966645: | length: 8 (0x8) Sep 21 07:34:30.966648: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:30.966651: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:30.966655: | remote proposal 4 proposed transforms: ENCR+INTEG+ESN; matched: none; unmatched: ENCR+INTEG+ESN Sep 21 07:34:30.966659: | remote proposal 4 does not match; unmatched remote transforms: ENCR+INTEG+ESN Sep 21 07:34:30.966665: "westnet-eastnet-ikev2c" #1: proposal 1:ESP:SPI=bd1cd64f;ENCR=AES_GCM_C_256;ESN=DISABLED chosen from remote proposals 1:ESP:ENCR=AES_GCM_C_256;ESN=DISABLED[first-match] 2:ESP:ENCR=AES_GCM_C_128;ESN=DISABLED 3:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_512_256;INTEG=HMAC_SHA2_256_128;ESN=DISABLED 4:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;INTEG=HMAC_SHA2_256_128;ESN=DISABLED Sep 21 07:34:30.966671: | IKE_AUTH responder matching remote ESP/AH proposals ikev2_proposal: 1:ESP:SPI=bd1cd64f;ENCR=AES_GCM_C_256;ESN=DISABLED Sep 21 07:34:30.966675: | converting proposal to internal trans attrs Sep 21 07:34:30.966695: | netlink_get_spi: allocated 0x2948b9f3 for esp.0@192.1.2.23 Sep 21 07:34:30.966698: | Emitting ikev2_proposal ... Sep 21 07:34:30.966701: | ****emit IKEv2 Security Association Payload: Sep 21 07:34:30.966704: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.966706: | flags: none (0x0) Sep 21 07:34:30.966710: | next payload chain: setting previous 'IKEv2 Authentication Payload'.'next payload type' to current IKEv2 Security Association Payload (33:ISAKMP_NEXT_v2SA) Sep 21 07:34:30.966713: | next payload chain: saving location 'IKEv2 Security Association Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.966717: | *****emit IKEv2 Proposal Substructure Payload: Sep 21 07:34:30.966720: | last proposal: v2_PROPOSAL_LAST (0x0) Sep 21 07:34:30.966723: | prop #: 1 (0x1) Sep 21 07:34:30.966726: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:30.966729: | spi size: 4 (0x4) Sep 21 07:34:30.966731: | # transforms: 2 (0x2) Sep 21 07:34:30.966735: | last substructure: saving location 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' Sep 21 07:34:30.966739: | emitting 4 raw bytes of our spi into IKEv2 Proposal Substructure Payload Sep 21 07:34:30.966742: | our spi 29 48 b9 f3 Sep 21 07:34:30.966745: | ******emit IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966748: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966751: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:30.966754: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:30.966757: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:34:30.966761: | *******emit IKEv2 Attribute Substructure Payload: Sep 21 07:34:30.966763: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:30.966766: | length/value: 256 (0x100) Sep 21 07:34:30.966769: | emitting length of IKEv2 Transform Substructure Payload: 12 Sep 21 07:34:30.966771: | ******emit IKEv2 Transform Substructure Payload: Sep 21 07:34:30.966774: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:30.966776: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:30.966779: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:30.966782: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:30.966791: | last substructure: saving location 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' Sep 21 07:34:30.966794: | emitting length of IKEv2 Transform Substructure Payload: 8 Sep 21 07:34:30.966797: | emitting length of IKEv2 Proposal Substructure Payload: 32 Sep 21 07:34:30.966801: | last substructure: checking 'IKEv2 Proposal Substructure Payload'.'IKEv2 Transform Substructure Payload'.'last transform' is 0 Sep 21 07:34:30.966804: | emitting length of IKEv2 Security Association Payload: 36 Sep 21 07:34:30.966810: | last substructure: checking 'IKEv2 Security Association Payload'.'IKEv2 Proposal Substructure Payload'.'last proposal' is 0 Sep 21 07:34:30.966813: | ****emit IKEv2 Traffic Selector - Initiator - Payload: Sep 21 07:34:30.966816: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.966819: | flags: none (0x0) Sep 21 07:34:30.966822: | number of TS: 1 (0x1) Sep 21 07:34:30.966826: | next payload chain: setting previous 'IKEv2 Security Association Payload'.'next payload type' to current IKEv2 Traffic Selector - Initiator - Payload (44:ISAKMP_NEXT_v2TSi) Sep 21 07:34:30.966830: | next payload chain: saving location 'IKEv2 Traffic Selector - Initiator - Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.966833: | *****emit IKEv2 Traffic Selector: Sep 21 07:34:30.966836: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Sep 21 07:34:30.966839: | IP Protocol ID: 0 (0x0) Sep 21 07:34:30.966841: | start port: 0 (0x0) Sep 21 07:34:30.966844: | end port: 65535 (0xffff) Sep 21 07:34:30.966847: | emitting 4 raw bytes of IP start into IKEv2 Traffic Selector Sep 21 07:34:30.966850: | IP start c0 00 01 00 Sep 21 07:34:30.966852: | emitting 4 raw bytes of IP end into IKEv2 Traffic Selector Sep 21 07:34:30.966855: | IP end c0 00 01 ff Sep 21 07:34:30.966857: | emitting length of IKEv2 Traffic Selector: 16 Sep 21 07:34:30.966860: | emitting length of IKEv2 Traffic Selector - Initiator - Payload: 24 Sep 21 07:34:30.966862: | ****emit IKEv2 Traffic Selector - Responder - Payload: Sep 21 07:34:30.966865: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:30.966867: | flags: none (0x0) Sep 21 07:34:30.966869: | number of TS: 1 (0x1) Sep 21 07:34:30.966873: | next payload chain: setting previous 'IKEv2 Traffic Selector - Initiator - Payload'.'next payload type' to current IKEv2 Traffic Selector - Responder - Payload (45:ISAKMP_NEXT_v2TSr) Sep 21 07:34:30.966876: | next payload chain: saving location 'IKEv2 Traffic Selector - Responder - Payload'.'next payload type' in 'reply packet' Sep 21 07:34:30.966879: | *****emit IKEv2 Traffic Selector: Sep 21 07:34:30.966882: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Sep 21 07:34:30.966885: | IP Protocol ID: 0 (0x0) Sep 21 07:34:30.966888: | start port: 0 (0x0) Sep 21 07:34:30.966891: | end port: 65535 (0xffff) Sep 21 07:34:30.966894: | emitting 4 raw bytes of IP start into IKEv2 Traffic Selector Sep 21 07:34:30.966897: | IP start c0 00 02 00 Sep 21 07:34:30.966900: | emitting 4 raw bytes of IP end into IKEv2 Traffic Selector Sep 21 07:34:30.966902: | IP end c0 00 02 ff Sep 21 07:34:30.966905: | emitting length of IKEv2 Traffic Selector: 16 Sep 21 07:34:30.966908: | emitting length of IKEv2 Traffic Selector - Responder - Payload: 24 Sep 21 07:34:30.966912: | Initiator child policy is compress=no, NOT sending v2N_IPCOMP_SUPPORTED Sep 21 07:34:30.966916: | integ=none: .key_size=0 encrypt=aes_gcm_16: .key_size=32 .salt_size=4 keymat_len=36 Sep 21 07:34:30.967090: | FOR_EACH_CONNECTION_... in ISAKMP_SA_established Sep 21 07:34:30.967100: | #1 spent 1.65 milliseconds Sep 21 07:34:30.967104: | install_ipsec_sa() for #2: inbound and outbound Sep 21 07:34:30.967108: | could_route called for westnet-eastnet-ikev2a (kind=CK_PERMANENT) Sep 21 07:34:30.967111: | FOR_EACH_CONNECTION_... in route_owner Sep 21 07:34:30.967115: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 vs Sep 21 07:34:30.967118: | conn westnet-eastnet-ikev2c mark 0/00000000, 0/00000000 Sep 21 07:34:30.967122: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 vs Sep 21 07:34:30.967125: | conn westnet-eastnet-ikev2b mark 0/00000000, 0/00000000 Sep 21 07:34:30.967128: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 vs Sep 21 07:34:30.967131: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 Sep 21 07:34:30.967137: | route owner of "westnet-eastnet-ikev2a" unrouted: NULL; eroute owner: NULL Sep 21 07:34:30.967141: | looking for alg with encrypt: AES_GCM_16 keylen: 256 integ: NONE Sep 21 07:34:30.967147: | encrypt AES_GCM_16 keylen=256 transid=20, key_size=32, encryptalg=20 Sep 21 07:34:30.967150: | AES_GCM_16 requires 4 salt bytes Sep 21 07:34:30.967153: | st->st_esp.keymat_len=36 is encrypt_keymat_size=36 + integ_keymat_size=0 Sep 21 07:34:30.967159: | setting IPsec SA replay-window to 32 Sep 21 07:34:30.967163: | NIC esp-hw-offload not for connection 'westnet-eastnet-ikev2a' not available on interface eth1 Sep 21 07:34:30.967167: | netlink: enabling tunnel mode Sep 21 07:34:30.967170: | netlink: setting IPsec SA replay-window to 32 using old-style req Sep 21 07:34:30.967174: | netlink: esp-hw-offload not set for IPsec SA Sep 21 07:34:30.967269: | netlink response for Add SA esp.bd1cd64f@192.1.2.45 included non-error error Sep 21 07:34:30.967273: | set up outgoing SA, ref=0/0 Sep 21 07:34:30.967277: | looking for alg with encrypt: AES_GCM_16 keylen: 256 integ: NONE Sep 21 07:34:30.967281: | encrypt AES_GCM_16 keylen=256 transid=20, key_size=32, encryptalg=20 Sep 21 07:34:30.967284: | AES_GCM_16 requires 4 salt bytes Sep 21 07:34:30.967287: | st->st_esp.keymat_len=36 is encrypt_keymat_size=36 + integ_keymat_size=0 Sep 21 07:34:30.967292: | setting IPsec SA replay-window to 32 Sep 21 07:34:30.967296: | NIC esp-hw-offload not for connection 'westnet-eastnet-ikev2a' not available on interface eth1 Sep 21 07:34:30.967299: | netlink: enabling tunnel mode Sep 21 07:34:30.967302: | netlink: setting IPsec SA replay-window to 32 using old-style req Sep 21 07:34:30.967306: | netlink: esp-hw-offload not set for IPsec SA Sep 21 07:34:30.967364: | netlink response for Add SA esp.2948b9f3@192.1.2.23 included non-error error Sep 21 07:34:30.967370: | priority calculation of connection "westnet-eastnet-ikev2a" is 0xfe7e7 Sep 21 07:34:30.967380: | add inbound eroute 192.0.1.0/24:0 --0-> 192.0.2.0/24:0 => tun.10000@192.1.2.23 (raw_eroute) Sep 21 07:34:30.967384: | IPsec Sa SPD priority set to 1042407 Sep 21 07:34:30.967444: | raw_eroute result=success Sep 21 07:34:30.967448: | set up incoming SA, ref=0/0 Sep 21 07:34:30.967451: | sr for #2: unrouted Sep 21 07:34:30.967454: | route_and_eroute() for proto 0, and source port 0 dest port 0 Sep 21 07:34:30.967456: | FOR_EACH_CONNECTION_... in route_owner Sep 21 07:34:30.967459: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 vs Sep 21 07:34:30.967462: | conn westnet-eastnet-ikev2c mark 0/00000000, 0/00000000 Sep 21 07:34:30.967465: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 vs Sep 21 07:34:30.967468: | conn westnet-eastnet-ikev2b mark 0/00000000, 0/00000000 Sep 21 07:34:30.967470: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 vs Sep 21 07:34:30.967473: | conn westnet-eastnet-ikev2a mark 0/00000000, 0/00000000 Sep 21 07:34:30.967477: | route owner of "westnet-eastnet-ikev2a" unrouted: NULL; eroute owner: NULL Sep 21 07:34:30.967480: | route_and_eroute with c: westnet-eastnet-ikev2a (next: none) ero:null esr:{(nil)} ro:null rosr:{(nil)} and state: #2 Sep 21 07:34:30.967483: | priority calculation of connection "westnet-eastnet-ikev2a" is 0xfe7e7 Sep 21 07:34:30.967491: | eroute_connection add eroute 192.0.2.0/24:0 --0-> 192.0.1.0/24:0 => tun.0@192.1.2.45 (raw_eroute) Sep 21 07:34:30.967494: | IPsec Sa SPD priority set to 1042407 Sep 21 07:34:30.967524: | raw_eroute result=success Sep 21 07:34:30.967528: | running updown command "ipsec _updown" for verb up Sep 21 07:34:30.967532: | command executing up-client Sep 21 07:34:30.967561: | executing up-client: PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='westnet-eastnet-ikev2a' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='@west' PLUTO_PEER_CLIENT='192.0.1.0/24' PLUTO_PEER_CLIENT_NET='192.0.1.0' PLUTO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN Sep 21 07:34:30.967566: | popen cmd is 1045 chars long Sep 21 07:34:30.967569: | cmd( 0):PLUTO_VERB='up-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='westnet-eastnet-ike: Sep 21 07:34:30.967572: | cmd( 80):v2a' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PL: Sep 21 07:34:30.967575: | cmd( 160):UTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0': Sep 21 07:34:30.967579: | cmd( 240): PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PL: Sep 21 07:34:30.967582: | cmd( 320):UTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID=': Sep 21 07:34:30.967585: | cmd( 400):@west' PLUTO_PEER_CLIENT='192.0.1.0/24' PLUTO_PEER_CLIENT_NET='192.0.1.0' PLUTO_: Sep 21 07:34:30.967588: | cmd( 480):PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLU: Sep 21 07:34:30.967591: | cmd( 560):TO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='PSK+ENCR: Sep 21 07:34:30.967594: | cmd( 640):YPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_: Sep 21 07:34:30.967597: | cmd( 720):KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CI: Sep 21 07:34:30.967600: | cmd( 800):SCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PL: Sep 21 07:34:30.967603: | cmd( 880):UTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI: Sep 21 07:34:30.967606: | cmd( 960):_ROUTING='no' VTI_SHARED='no' SPI_IN=0xbd1cd64f SPI_OUT=0x2948b9f3 ipsec _updown: Sep 21 07:34:30.967609: | cmd(1040): 2>&1: Sep 21 07:34:30.978072: | route_and_eroute: firewall_notified: true Sep 21 07:34:30.978083: | running updown command "ipsec _updown" for verb prepare Sep 21 07:34:30.978086: | command executing prepare-client Sep 21 07:34:30.978107: | executing prepare-client: PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='westnet-eastnet-ikev2a' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='@west' PLUTO_PEER_CLIENT='192.0.1.0/24' PLUTO_PEER_CLIENT_NET='192.0.1.0' PLUTO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED=' Sep 21 07:34:30.978109: | popen cmd is 1050 chars long Sep 21 07:34:30.978112: | cmd( 0):PLUTO_VERB='prepare-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='westnet-eastne: Sep 21 07:34:30.978113: | cmd( 80):t-ikev2a' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.2: Sep 21 07:34:30.978115: | cmd( 160):3' PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0: Sep 21 07:34:30.978117: | cmd( 240):.2.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL=': Sep 21 07:34:30.978118: | cmd( 320):0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER: Sep 21 07:34:30.978120: | cmd( 400):_ID='@west' PLUTO_PEER_CLIENT='192.0.1.0/24' PLUTO_PEER_CLIENT_NET='192.0.1.0' P: Sep 21 07:34:30.978121: | cmd( 480):LUTO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0: Sep 21 07:34:30.978127: | cmd( 560):' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='PSK: Sep 21 07:34:30.978129: | cmd( 640):+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_: Sep 21 07:34:30.978130: | cmd( 720):CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PE: Sep 21 07:34:30.978132: | cmd( 800):ER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER=: Sep 21 07:34:30.978133: | cmd( 880):'' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE=': Sep 21 07:34:30.978135: | cmd( 960):' VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xbd1cd64f SPI_OUT=0x2948b9f3 ipsec _u: Sep 21 07:34:30.978137: | cmd(1040):pdown 2>&1: Sep 21 07:34:30.988595: | running updown command "ipsec _updown" for verb route Sep 21 07:34:30.988607: | command executing route-client Sep 21 07:34:30.988627: | executing route-client: PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='westnet-eastnet-ikev2a' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23' PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0' PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_ID='@west' PLUTO_PEER_CLIENT='192.0.1.0/24' PLUTO_PEER_CLIENT_NET='192.0.1.0' PLUTO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='PSK+ENCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CONN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='' PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' VTI_ROUTING='no' VTI_SHARED='no' Sep 21 07:34:30.988630: | popen cmd is 1048 chars long Sep 21 07:34:30.988632: | cmd( 0):PLUTO_VERB='route-client' PLUTO_VERSION='2.0' PLUTO_CONNECTION='westnet-eastnet-: Sep 21 07:34:30.988634: | cmd( 80):ikev2a' PLUTO_INTERFACE='eth1' PLUTO_NEXT_HOP='192.1.2.45' PLUTO_ME='192.1.2.23': Sep 21 07:34:30.988635: | cmd( 160): PLUTO_MY_ID='@east' PLUTO_MY_CLIENT='192.0.2.0/24' PLUTO_MY_CLIENT_NET='192.0.2: Sep 21 07:34:30.988637: | cmd( 240):.0' PLUTO_MY_CLIENT_MASK='255.255.255.0' PLUTO_MY_PORT='0' PLUTO_MY_PROTOCOL='0': Sep 21 07:34:30.988639: | cmd( 320): PLUTO_SA_REQID='16388' PLUTO_SA_TYPE='ESP' PLUTO_PEER='192.1.2.45' PLUTO_PEER_I: Sep 21 07:34:30.988640: | cmd( 400):D='@west' PLUTO_PEER_CLIENT='192.0.1.0/24' PLUTO_PEER_CLIENT_NET='192.0.1.0' PLU: Sep 21 07:34:30.988642: | cmd( 480):TO_PEER_CLIENT_MASK='255.255.255.0' PLUTO_PEER_PORT='0' PLUTO_PEER_PROTOCOL='0' : Sep 21 07:34:30.988644: | cmd( 560):PLUTO_PEER_CA='' PLUTO_STACK='netkey' PLUTO_ADDTIME='0' PLUTO_CONN_POLICY='PSK+E: Sep 21 07:34:30.988645: | cmd( 640):NCRYPT+TUNNEL+DONT_REKEY+IKEV2_ALLOW+SAREF_TRACK+IKE_FRAG_ALLOW+ESN_NO' PLUTO_CO: Sep 21 07:34:30.988647: | cmd( 720):NN_KIND='CK_PERMANENT' PLUTO_CONN_ADDRFAMILY='ipv4' XAUTH_FAILED=0 PLUTO_IS_PEER: Sep 21 07:34:30.988648: | cmd( 800):_CISCO='0' PLUTO_PEER_DNS_INFO='' PLUTO_PEER_DOMAIN_INFO='' PLUTO_PEER_BANNER='': Sep 21 07:34:30.988650: | cmd( 880): PLUTO_CFG_SERVER='0' PLUTO_CFG_CLIENT='0' PLUTO_NM_CONFIGURED='0' VTI_IFACE='' : Sep 21 07:34:30.988652: | cmd( 960):VTI_ROUTING='no' VTI_SHARED='no' SPI_IN=0xbd1cd64f SPI_OUT=0x2948b9f3 ipsec _upd: Sep 21 07:34:30.988653: | cmd(1040):own 2>&1: Sep 21 07:34:31.000021: | route_and_eroute: instance "westnet-eastnet-ikev2a", setting eroute_owner {spd=0x562c74fc7b80,sr=0x562c74fc7b80} to #2 (was #0) (newest_ipsec_sa=#0) Sep 21 07:34:31.000244: | #1 spent 0.919 milliseconds in install_ipsec_sa() Sep 21 07:34:31.000253: | ISAKMP_v2_IKE_AUTH: instance westnet-eastnet-ikev2a[0], setting IKEv2 newest_ipsec_sa to #2 (was #0) (spd.eroute=#2) cloned from #1 Sep 21 07:34:31.000256: | adding 1 bytes of padding (including 1 byte padding-length) Sep 21 07:34:31.000264: | emitting 1 0x00 repeated bytes of padding and length into IKEv2 Encryption Payload Sep 21 07:34:31.000267: | emitting 16 zero bytes of length of truncated HMAC/KEY into IKEv2 Encryption Payload Sep 21 07:34:31.000271: | emitting length of IKEv2 Encryption Payload: 197 Sep 21 07:34:31.000273: | emitting length of ISAKMP Message: 225 Sep 21 07:34:31.000294: | ikev2_parent_inI2outR2_continue_tail returned STF_OK Sep 21 07:34:31.000301: | #1 spent 2.63 milliseconds in processing: Responder: process IKE_AUTH request in ikev2_process_state_packet() Sep 21 07:34:31.000308: | suspend processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:34:31.000313: | start processing: state #2 connection "westnet-eastnet-ikev2a" from 192.1.2.45:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:34:31.000318: | #2 complete_v2_state_transition() md.from_state=PARENT_R1 md.svm.state[from]=PARENT_R1 UNDEFINED->V2_IPSEC_R with status STF_OK Sep 21 07:34:31.000322: | IKEv2: transition from state STATE_PARENT_R1 to state STATE_V2_IPSEC_R Sep 21 07:34:31.000325: | child state #2: UNDEFINED(ignore) => V2_IPSEC_R(established CHILD SA) Sep 21 07:34:31.000329: | Message ID: updating counters for #2 to 1 after switching state Sep 21 07:34:31.000334: | Message ID: recv #1.#2 request 1; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=0 responder.recv=0->1; child: wip.initiator=-1 wip.responder=1->-1 Sep 21 07:34:31.000339: | Message ID: sent #1.#2 response 1; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=0->1 responder.recv=1; child: wip.initiator=-1 wip.responder=-1 Sep 21 07:34:31.000342: | pstats #2 ikev2.child established Sep 21 07:34:31.000351: "westnet-eastnet-ikev2a" #2: negotiated connection [192.0.2.0-192.0.2.255:0-65535 0] -> [192.0.1.0-192.0.1.255:0-65535 0] Sep 21 07:34:31.000355: | NAT-T: encaps is 'auto' Sep 21 07:34:31.000360: "westnet-eastnet-ikev2a" #2: STATE_V2_IPSEC_R: IPsec SA established tunnel mode {ESP=>0xbd1cd64f <0x2948b9f3 xfrm=AES_GCM_16_256-NONE NATOA=none NATD=none DPD=passive} Sep 21 07:34:31.000365: | sending V2 new request packet to 192.1.2.45:500 (from 192.1.2.23:500) Sep 21 07:34:31.000371: | sending 225 bytes for STATE_PARENT_R1 through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) Sep 21 07:34:31.000374: | 8d d2 34 28 c7 e8 c1 2d b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:31.000377: | 2e 20 23 20 00 00 00 01 00 00 00 e1 24 00 00 c5 Sep 21 07:34:31.000379: | 89 e3 ef 60 91 64 d2 bd 2d 2b 9e ee 8b f8 72 e9 Sep 21 07:34:31.000382: | d5 cc 4c a6 e5 01 59 0c 85 54 e0 0f e0 91 90 a9 Sep 21 07:34:31.000384: | a7 cc 78 71 6a 98 5e f3 d0 78 8a 0e 07 e1 e4 61 Sep 21 07:34:31.000387: | e8 6b dc a5 2b 2e 3a a4 64 5d 01 84 b2 82 23 a0 Sep 21 07:34:31.000389: | 46 49 a2 5b 74 3b 37 06 d9 f9 ce 5a d1 e5 25 85 Sep 21 07:34:31.000391: | a9 24 f8 9c 35 2f a9 f2 bf ee ff b8 04 94 b6 e6 Sep 21 07:34:31.000394: | f9 8f d2 60 a7 07 29 68 c4 22 d4 5a e4 00 1e 87 Sep 21 07:34:31.000396: | cb 71 23 56 d5 30 6a 06 c8 4a 10 1a cc aa 5c 0d Sep 21 07:34:31.000399: | 25 22 63 76 c0 61 58 7d 47 9a ce 17 94 62 fa 1d Sep 21 07:34:31.000401: | bc f9 20 e6 36 93 1d d9 17 c8 1d c8 a1 36 68 02 Sep 21 07:34:31.000403: | b3 05 f5 38 57 1d 75 9f 91 07 05 ff 81 fd 62 c0 Sep 21 07:34:31.000406: | 25 a5 be c7 5a b4 71 c8 15 e3 05 fa d1 40 01 64 Sep 21 07:34:31.000408: | 8d Sep 21 07:34:31.000449: | releasing whack for #2 (sock=fd@-1) Sep 21 07:34:31.000453: | releasing whack and unpending for parent #1 Sep 21 07:34:31.000456: | unpending state #1 connection "westnet-eastnet-ikev2a" Sep 21 07:34:31.000460: | #2 will expire in 28800 seconds (policy doesn't allow re-key) Sep 21 07:34:31.000463: | event_schedule: new EVENT_SA_EXPIRE-pe@0x7f6f20002b20 Sep 21 07:34:31.000467: | inserting event EVENT_SA_EXPIRE, timeout in 28800 seconds for #2 Sep 21 07:34:31.000470: | libevent_malloc: new ptr-libevent@0x562c74fd38d0 size 128 Sep 21 07:34:31.000478: | resume sending helper answer for #1 suppresed complete_v2_state_transition() Sep 21 07:34:31.000483: | #1 spent 2.89 milliseconds in resume sending helper answer Sep 21 07:34:31.000488: | stop processing: state #2 connection "westnet-eastnet-ikev2a" from 192.1.2.45:500 (in resume_handler() at server.c:833) Sep 21 07:34:31.000492: | libevent_free: release ptr-libevent@0x7f6f18006b90 Sep 21 07:34:31.000502: | processing signal PLUTO_SIGCHLD Sep 21 07:34:31.000507: | waitpid returned ECHILD (no child processes left) Sep 21 07:34:31.000511: | spent 0.00525 milliseconds in signal handler PLUTO_SIGCHLD Sep 21 07:34:31.000514: | processing signal PLUTO_SIGCHLD Sep 21 07:34:31.000518: | waitpid returned ECHILD (no child processes left) Sep 21 07:34:31.000521: | spent 0.00346 milliseconds in signal handler PLUTO_SIGCHLD Sep 21 07:34:31.000524: | processing signal PLUTO_SIGCHLD Sep 21 07:34:31.000527: | waitpid returned ECHILD (no child processes left) Sep 21 07:34:31.000530: | spent 0.00341 milliseconds in signal handler PLUTO_SIGCHLD Sep 21 07:34:32.285234: | spent 0.00301 milliseconds in comm_handle_cb() calling check_incoming_msg_errqueue() Sep 21 07:34:32.285254: | *received 305 bytes from 192.1.2.45:500 on eth1 (192.1.2.23:500) Sep 21 07:34:32.285257: | 8d d2 34 28 c7 e8 c1 2d b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:32.285260: | 2e 20 24 08 00 00 00 02 00 00 01 31 21 00 01 15 Sep 21 07:34:32.285262: | 31 5b b0 61 ed a7 8c f4 3d f2 ce 09 a4 75 2a 6c Sep 21 07:34:32.285264: | d2 95 e6 9f e9 9a 63 26 cf 5b b4 34 9b fa 77 85 Sep 21 07:34:32.285267: | 59 01 b0 cf e3 90 c4 5d e7 f1 c3 50 5c 8b 80 a8 Sep 21 07:34:32.285269: | 1b d5 b1 8a 59 ff ae f7 6a 63 4a ed 73 4d 6b a3 Sep 21 07:34:32.285271: | 77 d7 17 9f 1b 09 46 28 12 bc 99 65 77 42 4c 52 Sep 21 07:34:32.285274: | 51 e3 92 c9 8b 92 87 1d 5d 7c bc 8d ee 2d d5 3e Sep 21 07:34:32.285276: | 36 d2 c9 42 59 8b b9 c7 d0 5c d1 ab 7e c1 52 01 Sep 21 07:34:32.285278: | 81 e8 e1 13 3c e0 5f 40 3c b2 3f be cf 20 7a 14 Sep 21 07:34:32.285280: | 39 29 24 49 5f 80 9d cb 02 8d 1b 60 f5 95 8a ba Sep 21 07:34:32.285282: | 45 72 54 02 64 29 3f dc b6 68 f2 6d 80 55 5b 13 Sep 21 07:34:32.285284: | 6e b7 a9 21 d4 27 f3 b6 5f 7b 38 27 ae 5d 89 40 Sep 21 07:34:32.285286: | 44 42 94 fd ee 0c fe 13 f6 2f 9a a2 5f 24 48 32 Sep 21 07:34:32.285288: | 81 5b ce db f2 df e3 67 b5 34 ba e8 60 b9 59 f5 Sep 21 07:34:32.285290: | 56 6f d9 c8 0c f5 7b 72 75 01 da ee 21 c5 60 b1 Sep 21 07:34:32.285293: | 88 30 e4 2c 10 ff c9 1d be 55 5f 39 eb 05 2d 99 Sep 21 07:34:32.285295: | b8 55 fd cc 01 fa a8 ea aa 13 3e 09 45 93 b0 94 Sep 21 07:34:32.285297: | 9e e9 40 f7 d4 dc 6c 4a 2b f8 e1 3a cd 4c 5a ab Sep 21 07:34:32.285299: | 54 Sep 21 07:34:32.285303: | start processing: from 192.1.2.45:500 (in process_md() at demux.c:378) Sep 21 07:34:32.285306: | **parse ISAKMP Message: Sep 21 07:34:32.285308: | initiator cookie: Sep 21 07:34:32.285310: | 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:32.285313: | responder cookie: Sep 21 07:34:32.285314: | b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:32.285317: | next payload type: ISAKMP_NEXT_v2SK (0x2e) Sep 21 07:34:32.285319: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:34:32.285322: | exchange type: ISAKMP_v2_CREATE_CHILD_SA (0x24) Sep 21 07:34:32.285324: | flags: ISAKMP_FLAG_v2_IKE_INIT (0x8) Sep 21 07:34:32.285327: | Message ID: 2 (0x2) Sep 21 07:34:32.285329: | length: 305 (0x131) Sep 21 07:34:32.285331: | processing version=2.0 packet with exchange type=ISAKMP_v2_CREATE_CHILD_SA (36) Sep 21 07:34:32.285335: | I am the IKE SA Original Responder receiving an IKEv2 CREATE_CHILD_SA request Sep 21 07:34:32.285339: | State DB: found IKEv2 state #1 in PARENT_R2 (find_v2_ike_sa) Sep 21 07:34:32.285345: | start processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ikev2_process_packet() at ikev2.c:2016) Sep 21 07:34:32.285348: | State DB: IKEv2 state not found (find_v2_sa_by_responder_wip) Sep 21 07:34:32.285357: | [RE]START processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ike_process_packet() at ikev2.c:2064) Sep 21 07:34:32.285361: | #1 st.st_msgid_lastrecv 1 md.hdr.isa_msgid 00000002 Sep 21 07:34:32.285365: | Message ID: #1 not a duplicate - message is new; initiator.sent=-1 initiator.recv=-1 responder.sent=1 responder.recv=1 Sep 21 07:34:32.285367: | unpacking clear payload Sep 21 07:34:32.285369: | Now let's proceed with payload (ISAKMP_NEXT_v2SK) Sep 21 07:34:32.285372: | ***parse IKEv2 Encryption Payload: Sep 21 07:34:32.285374: | next payload type: ISAKMP_NEXT_v2SA (0x21) Sep 21 07:34:32.285376: | flags: none (0x0) Sep 21 07:34:32.285379: | length: 277 (0x115) Sep 21 07:34:32.285381: | processing payload: ISAKMP_NEXT_v2SK (len=273) Sep 21 07:34:32.285386: | Message ID: start-responder #1 request 2; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=1 responder.recv=1 wip.initiator=-1 wip.responder=-1->2 Sep 21 07:34:32.285389: | #1 in state PARENT_R2: received v2I2, PARENT SA established Sep 21 07:34:32.285405: | #1 ikev2 ISAKMP_v2_CREATE_CHILD_SA decrypt success Sep 21 07:34:32.285408: | Now let's proceed with payload (ISAKMP_NEXT_v2SA) Sep 21 07:34:32.285411: | **parse IKEv2 Security Association Payload: Sep 21 07:34:32.285414: | next payload type: ISAKMP_NEXT_v2Ni (0x28) Sep 21 07:34:32.285416: | flags: none (0x0) Sep 21 07:34:32.285418: | length: 164 (0xa4) Sep 21 07:34:32.285421: | processing payload: ISAKMP_NEXT_v2SA (len=160) Sep 21 07:34:32.285423: | Now let's proceed with payload (ISAKMP_NEXT_v2Ni) Sep 21 07:34:32.285425: | **parse IKEv2 Nonce Payload: Sep 21 07:34:32.285428: | next payload type: ISAKMP_NEXT_v2TSi (0x2c) Sep 21 07:34:32.285430: | flags: none (0x0) Sep 21 07:34:32.285432: | length: 36 (0x24) Sep 21 07:34:32.285434: | processing payload: ISAKMP_NEXT_v2Ni (len=32) Sep 21 07:34:32.285436: | Now let's proceed with payload (ISAKMP_NEXT_v2TSi) Sep 21 07:34:32.285439: | **parse IKEv2 Traffic Selector - Initiator - Payload: Sep 21 07:34:32.285441: | next payload type: ISAKMP_NEXT_v2TSr (0x2d) Sep 21 07:34:32.285443: | flags: none (0x0) Sep 21 07:34:32.285445: | length: 24 (0x18) Sep 21 07:34:32.285447: | number of TS: 1 (0x1) Sep 21 07:34:32.285450: | processing payload: ISAKMP_NEXT_v2TSi (len=16) Sep 21 07:34:32.285452: | Now let's proceed with payload (ISAKMP_NEXT_v2TSr) Sep 21 07:34:32.285454: | **parse IKEv2 Traffic Selector - Responder - Payload: Sep 21 07:34:32.285457: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:32.285459: | flags: none (0x0) Sep 21 07:34:32.285461: | length: 24 (0x18) Sep 21 07:34:32.285463: | number of TS: 1 (0x1) Sep 21 07:34:32.285466: | processing payload: ISAKMP_NEXT_v2TSr (len=16) Sep 21 07:34:32.285475: | state #1 forced to match CREATE_CHILD_SA from V2_CREATE_R->V2_IPSEC_R by ignoring from state Sep 21 07:34:32.285477: | selected state microcode Respond to CREATE_CHILD_SA IPsec SA Request Sep 21 07:34:32.285481: | #1 updating local interface from 192.1.2.23:500 to 192.1.2.23:500 using md->iface (in update_ike_endpoints() at state.c:2668) Sep 21 07:34:32.285484: | creating state object #3 at 0x562c74fce870 Sep 21 07:34:32.285486: | State DB: adding IKEv2 state #3 in UNDEFINED Sep 21 07:34:32.285491: | pstats #3 ikev2.child started Sep 21 07:34:32.285493: | duplicating state object #1 "westnet-eastnet-ikev2c" as #3 for IPSEC SA Sep 21 07:34:32.285496: | #3 setting local endpoint to 192.1.2.23:500 from #1.st_localport (in duplicate_state() at state.c:1481) Sep 21 07:34:32.285501: | Message ID: init_child #1.#3; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=1 responder.recv=1; child: wip.initiator=0->-1 wip.responder=0->-1 Sep 21 07:34:32.285503: | child state #3: UNDEFINED(ignore) => V2_CREATE_R(established IKE SA) Sep 21 07:34:32.285507: | "westnet-eastnet-ikev2c" #1 received Child SA Request CREATE_CHILD_SA from 192.1.2.45:500 Child "westnet-eastnet-ikev2c" #3 in STATE_V2_CREATE_R will process it further Sep 21 07:34:32.285509: | Message ID: switch-from #1 request 2; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=1 responder.recv=1 wip.initiator=-1 wip.responder=2->-1 Sep 21 07:34:32.285514: | Message ID: switch-to #1.#3 request 2; ike: initiator.sent=-1 initiator.recv=-1 responder.sent=1 responder.recv=1; child: wip.initiator=-1 wip.responder=-1->2 Sep 21 07:34:32.285516: | forcing ST #1 to CHILD #1.#3 in FSM processor Sep 21 07:34:32.285517: | Now let's proceed with state specific processing Sep 21 07:34:32.285519: | calling processor Respond to CREATE_CHILD_SA IPsec SA Request Sep 21 07:34:32.285523: | create child proposal's DH changed from no-PFS to NONE, flushing Sep 21 07:34:32.285525: | constructing ESP/AH proposals with default DH NONE for westnet-eastnet-ikev2c (CREATE_CHILD_SA responder matching remote ESP/AH proposals) Sep 21 07:34:32.285528: | converting proposal AES_GCM_16_256-NONE to ikev2 ... Sep 21 07:34:32.285532: | ... ikev2_proposal: 1:ESP:ENCR=AES_GCM_C_256;INTEG=NONE;DH=NONE;ESN=DISABLED Sep 21 07:34:32.285534: | converting proposal AES_GCM_16_128-NONE to ikev2 ... Sep 21 07:34:32.285537: | ... ikev2_proposal: 2:ESP:ENCR=AES_GCM_C_128;INTEG=NONE;DH=NONE;ESN=DISABLED Sep 21 07:34:32.285539: | converting proposal AES_CBC_256-HMAC_SHA2_512_256+HMAC_SHA2_256_128 to ikev2 ... Sep 21 07:34:32.285541: | ... ikev2_proposal: 3:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED Sep 21 07:34:32.285543: | converting proposal AES_CBC_128-HMAC_SHA2_512_256+HMAC_SHA2_256_128 to ikev2 ... Sep 21 07:34:32.285546: | ... ikev2_proposal: 4:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED Sep 21 07:34:32.285550: "westnet-eastnet-ikev2c": constructed local ESP/AH proposals for westnet-eastnet-ikev2c (CREATE_CHILD_SA responder matching remote ESP/AH proposals): 1:ESP:ENCR=AES_GCM_C_256;INTEG=NONE;DH=NONE;ESN=DISABLED 2:ESP:ENCR=AES_GCM_C_128;INTEG=NONE;DH=NONE;ESN=DISABLED 3:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED 4:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256,HMAC_SHA2_256_128;DH=NONE;ESN=DISABLED Sep 21 07:34:32.285552: | Comparing remote proposals against CREATE_CHILD_SA responder matching remote ESP/AH proposals 4 local proposals Sep 21 07:34:32.285555: | local proposal 1 type ENCR has 1 transforms Sep 21 07:34:32.285557: | local proposal 1 type PRF has 0 transforms Sep 21 07:34:32.285558: | local proposal 1 type INTEG has 1 transforms Sep 21 07:34:32.285560: | local proposal 1 type DH has 1 transforms Sep 21 07:34:32.285561: | local proposal 1 type ESN has 1 transforms Sep 21 07:34:32.285563: | local proposal 1 transforms: required: ENCR+ESN; optional: INTEG+DH Sep 21 07:34:32.285565: | local proposal 2 type ENCR has 1 transforms Sep 21 07:34:32.285566: | local proposal 2 type PRF has 0 transforms Sep 21 07:34:32.285568: | local proposal 2 type INTEG has 1 transforms Sep 21 07:34:32.285569: | local proposal 2 type DH has 1 transforms Sep 21 07:34:32.285571: | local proposal 2 type ESN has 1 transforms Sep 21 07:34:32.285573: | local proposal 2 transforms: required: ENCR+ESN; optional: INTEG+DH Sep 21 07:34:32.285574: | local proposal 3 type ENCR has 1 transforms Sep 21 07:34:32.285576: | local proposal 3 type PRF has 0 transforms Sep 21 07:34:32.285577: | local proposal 3 type INTEG has 2 transforms Sep 21 07:34:32.285579: | local proposal 3 type DH has 1 transforms Sep 21 07:34:32.285580: | local proposal 3 type ESN has 1 transforms Sep 21 07:34:32.285582: | local proposal 3 transforms: required: ENCR+INTEG+ESN; optional: DH Sep 21 07:34:32.285584: | local proposal 4 type ENCR has 1 transforms Sep 21 07:34:32.285585: | local proposal 4 type PRF has 0 transforms Sep 21 07:34:32.285587: | local proposal 4 type INTEG has 2 transforms Sep 21 07:34:32.285588: | local proposal 4 type DH has 1 transforms Sep 21 07:34:32.285590: | local proposal 4 type ESN has 1 transforms Sep 21 07:34:32.285591: | local proposal 4 transforms: required: ENCR+INTEG+ESN; optional: DH Sep 21 07:34:32.285593: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:32.285596: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:32.285598: | length: 32 (0x20) Sep 21 07:34:32.285599: | prop #: 1 (0x1) Sep 21 07:34:32.285601: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:32.285603: | spi size: 4 (0x4) Sep 21 07:34:32.285604: | # transforms: 2 (0x2) Sep 21 07:34:32.285607: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:32.285609: | remote SPI 66 7f 96 44 Sep 21 07:34:32.285612: | Comparing remote proposal 1 containing 2 transforms against local proposal [1..4] of 4 local proposals Sep 21 07:34:32.285615: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285617: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285620: | length: 12 (0xc) Sep 21 07:34:32.285622: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:32.285624: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:32.285627: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:32.285629: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:32.285631: | length/value: 256 (0x100) Sep 21 07:34:32.285635: | remote proposal 1 transform 0 (ENCR=AES_GCM_C_256) matches local proposal 1 type 1 (ENCR) transform 0 Sep 21 07:34:32.285638: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285641: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:32.285643: | length: 8 (0x8) Sep 21 07:34:32.285645: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:32.285648: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:32.285651: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 1 type 5 (ESN) transform 0 Sep 21 07:34:32.285653: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 2 type 5 (ESN) transform 0 Sep 21 07:34:32.285656: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 3 type 5 (ESN) transform 0 Sep 21 07:34:32.285659: | remote proposal 1 transform 1 (ESN=DISABLED) matches local proposal 4 type 5 (ESN) transform 0 Sep 21 07:34:32.285663: | remote proposal 1 proposed transforms: ENCR+ESN; matched: ENCR+ESN; unmatched: none Sep 21 07:34:32.285667: | comparing remote proposal 1 containing ENCR+ESN transforms to local proposal 1; required: ENCR+ESN; optional: INTEG+DH; matched: ENCR+ESN Sep 21 07:34:32.285669: | remote proposal 1 matches local proposal 1 Sep 21 07:34:32.285672: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:32.285675: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:32.285677: | length: 32 (0x20) Sep 21 07:34:32.285679: | prop #: 2 (0x2) Sep 21 07:34:32.285681: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:32.285683: | spi size: 4 (0x4) Sep 21 07:34:32.285686: | # transforms: 2 (0x2) Sep 21 07:34:32.285689: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:32.285691: | remote SPI 66 7f 96 44 Sep 21 07:34:32.285694: | Comparing remote proposal 2 containing 2 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:32.285697: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285699: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285702: | length: 12 (0xc) Sep 21 07:34:32.285704: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:32.285706: | IKEv2 transform ID: AES_GCM_C (0x14) Sep 21 07:34:32.285709: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:32.285712: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:32.285714: | length/value: 128 (0x80) Sep 21 07:34:32.285717: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285720: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:32.285722: | length: 8 (0x8) Sep 21 07:34:32.285724: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:32.285727: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:32.285730: | remote proposal 2 proposed transforms: ENCR+ESN; matched: none; unmatched: ENCR+ESN Sep 21 07:34:32.285733: | remote proposal 2 does not match; unmatched remote transforms: ENCR+ESN Sep 21 07:34:32.285738: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:32.285740: | last proposal: v2_PROPOSAL_NON_LAST (0x2) Sep 21 07:34:32.285741: | length: 48 (0x30) Sep 21 07:34:32.285743: | prop #: 3 (0x3) Sep 21 07:34:32.285744: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:32.285746: | spi size: 4 (0x4) Sep 21 07:34:32.285747: | # transforms: 4 (0x4) Sep 21 07:34:32.285749: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:32.285751: | remote SPI 66 7f 96 44 Sep 21 07:34:32.285752: | Comparing remote proposal 3 containing 4 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:32.285754: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285756: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285757: | length: 12 (0xc) Sep 21 07:34:32.285759: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:32.285760: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:34:32.285762: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:32.285763: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:32.285765: | length/value: 256 (0x100) Sep 21 07:34:32.285767: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285768: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285770: | length: 8 (0x8) Sep 21 07:34:32.285771: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:32.285773: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:34:32.285775: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285776: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285778: | length: 8 (0x8) Sep 21 07:34:32.285779: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:32.285781: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:34:32.285787: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285792: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:32.285794: | length: 8 (0x8) Sep 21 07:34:32.285796: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:32.285797: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:32.285799: | remote proposal 3 proposed transforms: ENCR+INTEG+ESN; matched: none; unmatched: ENCR+INTEG+ESN Sep 21 07:34:32.285801: | remote proposal 3 does not match; unmatched remote transforms: ENCR+INTEG+ESN Sep 21 07:34:32.285803: | ***parse IKEv2 Proposal Substructure Payload: Sep 21 07:34:32.285804: | last proposal: v2_PROPOSAL_LAST (0x0) Sep 21 07:34:32.285806: | length: 48 (0x30) Sep 21 07:34:32.285807: | prop #: 4 (0x4) Sep 21 07:34:32.285809: | proto ID: IKEv2_SEC_PROTO_ESP (0x3) Sep 21 07:34:32.285810: | spi size: 4 (0x4) Sep 21 07:34:32.285812: | # transforms: 4 (0x4) Sep 21 07:34:32.285813: | parsing 4 raw bytes of IKEv2 Proposal Substructure Payload into remote SPI Sep 21 07:34:32.285815: | remote SPI 66 7f 96 44 Sep 21 07:34:32.285817: | Comparing remote proposal 4 containing 4 transforms against local proposal [1..0] of 4 local proposals Sep 21 07:34:32.285818: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285820: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285821: | length: 12 (0xc) Sep 21 07:34:32.285823: | IKEv2 transform type: TRANS_TYPE_ENCR (0x1) Sep 21 07:34:32.285824: | IKEv2 transform ID: AES_CBC (0xc) Sep 21 07:34:32.285826: | *****parse IKEv2 Attribute Substructure Payload: Sep 21 07:34:32.285827: | af+type: AF+IKEv2_KEY_LENGTH (0x800e) Sep 21 07:34:32.285829: | length/value: 128 (0x80) Sep 21 07:34:32.285831: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285832: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285834: | length: 8 (0x8) Sep 21 07:34:32.285835: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:32.285837: | IKEv2 transform ID: AUTH_HMAC_SHA2_512_256 (0xe) Sep 21 07:34:32.285839: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285841: | last transform: v2_TRANSFORM_NON_LAST (0x3) Sep 21 07:34:32.285843: | length: 8 (0x8) Sep 21 07:34:32.285844: | IKEv2 transform type: TRANS_TYPE_INTEG (0x3) Sep 21 07:34:32.285846: | IKEv2 transform ID: AUTH_HMAC_SHA2_256_128 (0xc) Sep 21 07:34:32.285848: | ****parse IKEv2 Transform Substructure Payload: Sep 21 07:34:32.285849: | last transform: v2_TRANSFORM_LAST (0x0) Sep 21 07:34:32.285851: | length: 8 (0x8) Sep 21 07:34:32.285852: | IKEv2 transform type: TRANS_TYPE_ESN (0x5) Sep 21 07:34:32.285854: | IKEv2 transform ID: ESN_DISABLED (0x0) Sep 21 07:34:32.285856: | remote proposal 4 proposed transforms: ENCR+INTEG+ESN; matched: none; unmatched: ENCR+INTEG+ESN Sep 21 07:34:32.285857: | remote proposal 4 does not match; unmatched remote transforms: ENCR+INTEG+ESN Sep 21 07:34:32.285861: "westnet-eastnet-ikev2c" #1: proposal 1:ESP:SPI=667f9644;ENCR=AES_GCM_C_256;ESN=DISABLED chosen from remote proposals 1:ESP:ENCR=AES_GCM_C_256;ESN=DISABLED[first-match] 2:ESP:ENCR=AES_GCM_C_128;ESN=DISABLED 3:ESP:ENCR=AES_CBC_256;INTEG=HMAC_SHA2_512_256;INTEG=HMAC_SHA2_256_128;ESN=DISABLED 4:ESP:ENCR=AES_CBC_128;INTEG=HMAC_SHA2_512_256;INTEG=HMAC_SHA2_256_128;ESN=DISABLED Sep 21 07:34:32.285864: | CREATE_CHILD_SA responder matching remote ESP/AH proposals ikev2_proposal: 1:ESP:SPI=667f9644;ENCR=AES_GCM_C_256;ESN=DISABLED Sep 21 07:34:32.285866: | converting proposal to internal trans attrs Sep 21 07:34:32.285869: | Child SA TS Request has child->sa == md->st; so using child connection Sep 21 07:34:32.285872: | TSi: parsing 1 traffic selectors Sep 21 07:34:32.285874: | ***parse IKEv2 Traffic Selector: Sep 21 07:34:32.285877: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Sep 21 07:34:32.285879: | IP Protocol ID: 0 (0x0) Sep 21 07:34:32.285882: | length: 16 (0x10) Sep 21 07:34:32.285884: | start port: 0 (0x0) Sep 21 07:34:32.285887: | end port: 65535 (0xffff) Sep 21 07:34:32.285889: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS low Sep 21 07:34:32.285891: | TS low c0 00 01 00 Sep 21 07:34:32.285894: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS high Sep 21 07:34:32.285896: | TS high c0 00 01 ff Sep 21 07:34:32.285899: | TSi: parsed 1 traffic selectors Sep 21 07:34:32.285901: | TSr: parsing 1 traffic selectors Sep 21 07:34:32.285904: | ***parse IKEv2 Traffic Selector: Sep 21 07:34:32.285906: | TS type: IKEv2_TS_IPV4_ADDR_RANGE (0x7) Sep 21 07:34:32.285909: | IP Protocol ID: 0 (0x0) Sep 21 07:34:32.285911: | length: 16 (0x10) Sep 21 07:34:32.285914: | start port: 0 (0x0) Sep 21 07:34:32.285916: | end port: 65535 (0xffff) Sep 21 07:34:32.285919: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS low Sep 21 07:34:32.285921: | TS low c0 00 c8 00 Sep 21 07:34:32.285924: | parsing 4 raw bytes of IKEv2 Traffic Selector into TS high Sep 21 07:34:32.285926: | TS high c0 00 c8 ff Sep 21 07:34:32.285928: | TSr: parsed 1 traffic selectors Sep 21 07:34:32.285930: | looking for best SPD in current connection Sep 21 07:34:32.285937: | evaluating our conn="westnet-eastnet-ikev2c" I=192.0.1.0/24:0:0/0 R=192.0.212.0/24:0:0/0 to their: Sep 21 07:34:32.285942: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.285950: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:32.285952: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:32.285955: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:32.285958: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:32.285960: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:32.285965: | TSr[0] .net=192.0.200.0-192.0.200.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.285971: | match address end->client=192.0.212.0/24 == TSr[0]net=192.0.200.0-192.0.200.255: NO Sep 21 07:34:32.285973: | looking for better host pair Sep 21 07:34:32.285978: | find_host_pair: comparing 192.1.2.23:500 to 192.1.2.45:500 but ignoring ports Sep 21 07:34:32.285985: | checking hostpair 192.0.212.0/24:0 -> 192.0.1.0/24:0 is found Sep 21 07:34:32.285988: | investigating connection "westnet-eastnet-ikev2c" as a better match Sep 21 07:34:32.285991: | match_id a=@west Sep 21 07:34:32.285994: | b=@west Sep 21 07:34:32.285996: | results matched Sep 21 07:34:32.286001: | evaluating our conn="westnet-eastnet-ikev2c" I=192.0.1.0/24:0:0/0 R=192.0.212.0/24:0:0/0 to their: Sep 21 07:34:32.286006: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.286012: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:32.286015: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:32.286017: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:32.286020: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:32.286023: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:32.286027: | TSr[0] .net=192.0.200.0-192.0.200.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.286033: | match address end->client=192.0.212.0/24 == TSr[0]net=192.0.200.0-192.0.200.255: NO Sep 21 07:34:32.286036: | investigating connection "westnet-eastnet-ikev2b" as a better match Sep 21 07:34:32.286038: | match_id a=@west Sep 21 07:34:32.286040: | b=@west Sep 21 07:34:32.286043: | results matched Sep 21 07:34:32.286047: | evaluating our conn="westnet-eastnet-ikev2b" I=192.0.1.0/24:0:0/0 R=192.0.211.0/24:0:0/0 to their: Sep 21 07:34:32.286051: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.286056: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:32.286058: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:32.286060: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:32.286062: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:32.286065: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:32.286069: | TSr[0] .net=192.0.200.0-192.0.200.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.286074: | match address end->client=192.0.211.0/24 == TSr[0]net=192.0.200.0-192.0.200.255: NO Sep 21 07:34:32.286077: | investigating connection "westnet-eastnet-ikev2a" as a better match Sep 21 07:34:32.286079: | match_id a=@west Sep 21 07:34:32.286082: | b=@west Sep 21 07:34:32.286084: | results matched Sep 21 07:34:32.286089: | evaluating our conn="westnet-eastnet-ikev2a" I=192.0.1.0/24:0:0/0 R=192.0.2.0/24:0:0/0 to their: Sep 21 07:34:32.286093: | TSi[0] .net=192.0.1.0-192.0.1.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.286098: | match address end->client=192.0.1.0/24 == TSi[0]net=192.0.1.0-192.0.1.255: YES fitness 32 Sep 21 07:34:32.286101: | narrow port end=0..65535 == TSi[0]=0..65535: 0 Sep 21 07:34:32.286103: | TSi[0] port match: YES fitness 65536 Sep 21 07:34:32.286106: | narrow protocol end=*0 == TSi[0]=*0: 0 Sep 21 07:34:32.286109: | match end->protocol=*0 == TSi[0].ipprotoid=*0: YES fitness 255 Sep 21 07:34:32.286113: | TSr[0] .net=192.0.200.0-192.0.200.255 .iporotoid=0 .{start,end}port=0..65535 Sep 21 07:34:32.286119: | match address end->client=192.0.2.0/24 == TSr[0]net=192.0.200.0-192.0.200.255: NO Sep 21 07:34:32.286122: | did not find a better connection using host pair Sep 21 07:34:32.286125: | no best spd route; but the current CK_PERMANENT connection "westnet-eastnet-ikev2c" is not a CK_INSTANCE Sep 21 07:34:32.286128: | giving up Sep 21 07:34:32.286133: | #3 spent 0.607 milliseconds in processing: Respond to CREATE_CHILD_SA IPsec SA Request in ikev2_process_state_packet() Sep 21 07:34:32.286137: | suspend processing: state #1 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:34:32.286142: | start processing: state #3 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in complete_v2_state_transition() at ikev2.c:3376) Sep 21 07:34:32.286144: | #3 complete_v2_state_transition() V2_CREATE_R->V2_IPSEC_R with status STF_FAIL+v2N_TS_UNACCEPTABLE Sep 21 07:34:32.286206: | sending a notification reply Sep 21 07:34:32.286215: "westnet-eastnet-ikev2c" #3: responding to CREATE_CHILD_SA message (ID 2) from 192.1.2.45:500 with encrypted notification TS_UNACCEPTABLE Sep 21 07:34:32.286219: | Opening output PBS encrypted notification Sep 21 07:34:32.286222: | **emit ISAKMP Message: Sep 21 07:34:32.286225: | initiator cookie: Sep 21 07:34:32.286227: | 8d d2 34 28 c7 e8 c1 2d Sep 21 07:34:32.286230: | responder cookie: Sep 21 07:34:32.286232: | b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:32.286236: | next payload type: ISAKMP_NEXT_NONE (0x0) Sep 21 07:34:32.286239: | ISAKMP version: IKEv2 version 2.0 (rfc4306/rfc5996) (0x20) Sep 21 07:34:32.286242: | exchange type: ISAKMP_v2_CREATE_CHILD_SA (0x24) Sep 21 07:34:32.286245: | flags: ISAKMP_FLAG_v2_MSG_RESPONSE (0x20) Sep 21 07:34:32.286248: | Message ID: 2 (0x2) Sep 21 07:34:32.286252: | next payload chain: saving message location 'ISAKMP Message'.'next payload type' Sep 21 07:34:32.286255: | ***emit IKEv2 Encryption Payload: Sep 21 07:34:32.286258: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:32.286261: | flags: none (0x0) Sep 21 07:34:32.286265: | next payload chain: setting previous 'ISAKMP Message'.'next payload type' to current IKEv2 Encryption Payload (46:ISAKMP_NEXT_v2SK) Sep 21 07:34:32.286269: | next payload chain: saving location 'IKEv2 Encryption Payload'.'next payload type' in 'encrypted notification' Sep 21 07:34:32.286272: | emitting 8 zero bytes of IV into IKEv2 Encryption Payload Sep 21 07:34:32.286279: | Adding a v2N Payload Sep 21 07:34:32.286282: | ****emit IKEv2 Notify Payload: Sep 21 07:34:32.286285: | next payload type: ISAKMP_NEXT_v2NONE (0x0) Sep 21 07:34:32.286288: | flags: none (0x0) Sep 21 07:34:32.286290: | Protocol ID: PROTO_v2_RESERVED (0x0) Sep 21 07:34:32.286293: | SPI size: 0 (0x0) Sep 21 07:34:32.286296: | Notify Message Type: v2N_TS_UNACCEPTABLE (0x26) Sep 21 07:34:32.286301: | next payload chain: setting previous 'IKEv2 Encryption Payload'.'next payload type' to current IKEv2 Notify Payload (41:ISAKMP_NEXT_v2N) Sep 21 07:34:32.286307: | next payload chain: saving location 'IKEv2 Notify Payload'.'next payload type' in 'encrypted notification' Sep 21 07:34:32.286310: | emitting length of IKEv2 Notify Payload: 8 Sep 21 07:34:32.286314: | adding 1 bytes of padding (including 1 byte padding-length) Sep 21 07:34:32.286317: | emitting 1 0x00 repeated bytes of padding and length into IKEv2 Encryption Payload Sep 21 07:34:32.286320: | emitting 16 zero bytes of length of truncated HMAC/KEY into IKEv2 Encryption Payload Sep 21 07:34:32.286323: | emitting length of IKEv2 Encryption Payload: 37 Sep 21 07:34:32.286326: | emitting length of ISAKMP Message: 65 Sep 21 07:34:32.286341: | sending 65 bytes for v2 notify through eth1 from 192.1.2.23:500 to 192.1.2.45:500 (using #1) Sep 21 07:34:32.286344: | 8d d2 34 28 c7 e8 c1 2d b9 d2 a5 24 9f c6 1e 32 Sep 21 07:34:32.286346: | 2e 20 24 20 00 00 00 02 00 00 00 41 29 00 00 25 Sep 21 07:34:32.286349: | 59 4a bf e3 bb 9e 45 41 2c 3c 4e df 42 d7 51 6c Sep 21 07:34:32.286351: | 2a 8b 34 8b ee f6 15 21 9f a1 a0 2d 18 59 67 d3 Sep 21 07:34:32.286353: | fe Sep 21 07:34:32.286384: | forcing #3 to a discard event Sep 21 07:34:32.286389: | event_schedule: new EVENT_SO_DISCARD-pe@0x562c74fd1ff0 Sep 21 07:34:32.286393: | inserting event EVENT_SO_DISCARD, timeout in 200 seconds for #3 Sep 21 07:34:32.286396: | libevent_malloc: new ptr-libevent@0x7f6f18006b90 size 128 Sep 21 07:34:32.286400: | state transition function for STATE_V2_CREATE_R failed: v2N_TS_UNACCEPTABLE Sep 21 07:34:32.286405: | stop processing: state #3 connection "westnet-eastnet-ikev2c" from 192.1.2.45:500 (in ikev2_process_packet() at ikev2.c:2018) Sep 21 07:34:32.286412: | #1 spent 1.14 milliseconds in ikev2_process_packet() Sep 21 07:34:32.286417: | stop processing: from 192.1.2.45:500 (in process_md() at demux.c:380) Sep 21 07:34:32.286420: | processing: STOP state #0 (in process_md() at demux.c:382) Sep 21 07:34:32.286423: | processing: STOP connection NULL (in process_md() at demux.c:383) Sep 21 07:34:32.286428: | spent 1.15 milliseconds in comm_handle_cb() reading and processing packet