--- road.console.txt 2019-09-20 17:49:12.491184451 +0000 +++ OUTPUT/road.console.txt 2019-09-21 07:30:20.047379891 +0000 @@ -27,9 +27,14 @@ 006 #2: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.23, type=ESP, road # ipsec stop -Redirecting to: [initsystem] +PATH/bin/nsenter --mount=/run/mountns/road-newoe-08-restart --net=/run/netns/road-newoe-08-restart --uts=/run/utsns/road-newoe-08-restart /bin/bash +002 shutting down road # ip xfrm state +src 192.1.3.209 dst 192.1.2.23 + proto esp spi 0xSPISPI reqid REQID mode transport + replay-window 0 + sel src 192.1.3.209/32 dst 192.1.2.23/32 proto icmp type 8 code 0 dev eth0 road # ipsec start Redirecting to: [initsystem] @@ -45,7 +50,6 @@ ping -n -c 4 -I 192.1.3.209 192.1.2.23 > /dev/null road # ipsec whack --trafficstatus | sed "s/add_time.*$//" -006 #2: "private-or-clear#192.1.2.0/24"[1] ...192.1.2.23, type=ESP, road # killall ip > /dev/null 2> /dev/null road # @@ -57,14 +61,6 @@ ../../pluto/bin/ipsec-look.sh road NOW XFRM state: -src 192.1.2.23 dst 192.1.3.209 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 -src 192.1.3.209 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 32 flag af-unspec - aead rfc4106(gcm(aes)) 0xENCAUTHKEY 128 src 192.1.3.209 dst 192.1.2.23 proto esp spi 0xSPISPI reqid REQID mode transport replay-window 0 @@ -94,18 +90,6 @@ dir fwd priority 1564639 ptype main src 192.1.3.254/32 dst 192.1.3.209/32 dir in priority 1564639 ptype main -src 192.1.2.23/32 dst 192.1.3.209/32 - dir fwd priority 2088927 ptype main - tmpl src 192.1.2.23 dst 192.1.3.209 - proto esp reqid REQID mode tunnel -src 192.1.2.23/32 dst 192.1.3.209/32 - dir in priority 2088927 ptype main - tmpl src 192.1.2.23 dst 192.1.3.209 - proto esp reqid REQID mode tunnel -src 192.1.3.209/32 dst 192.1.2.23/32 - dir out priority 2088927 ptype main - tmpl src 192.1.3.209 dst 192.1.2.23 - proto esp reqid REQID mode tunnel src 192.1.3.209/32 dst 192.1.2.0/24 dir out priority 2088935 ptype main tmpl src 0.0.0.0 dst 0.0.0.0