--- north.console.txt 2020-10-28 10:59:11.456390964 +0000 +++ OUTPUT/north.console.txt 2020-10-31 15:24:58.986018601 +0000 @@ -58,7 +58,7 @@ 000 "north-eastnets/0x1": aliases: north-eastnets 000 "north-eastnets/0x1": IKE algorithms: AES_CBC_256-HMAC_SHA2_256-MODP2048 000 "north-eastnets/0x1": ESP algorithms: AES_CBC_128-HMAC_SHA2_512_256-MODP3072 -000 "north-eastnets/0x1": ESP algorithm newest: AES_CBC_128-HMAC_SHA2_512_256; pfsgroup=MODP3072 +000 "north-eastnets/0x1": ESP algorithm newest: AES_CBC_128-HMAC_SHA2_512_256; pfsgroup= 000 "north-eastnets/0x2": 192.0.3.0/24===192.1.3.33<192.1.3.33>[@north]...192.1.2.23<192.1.2.23>[@east]===192.0.22.0/24; erouted; eroute owner: #3 000 "north-eastnets/0x2": oriented; my_ip=unset; their_ip=unset; my_updown=ipsec _updown; 000 "north-eastnets/0x2": xauth us:none, xauth them:none, my_username=[any]; their_username=[any] @@ -79,9 +79,9 @@ 000 "north-eastnets/0x2": IKE algorithms: AES_CBC_256-HMAC_SHA2_256-MODP2048 000 "north-eastnets/0x2": IKEv2 algorithm newest: AES_CBC_256-HMAC_SHA2_256-MODP2048 000 "north-eastnets/0x2": ESP algorithms: AES_CBC_128-HMAC_SHA2_512_256-MODP3072 -000 "north-eastnets/0x2": ESP algorithm newest: AES_CBC_128-HMAC_SHA2_512_256; pfsgroup=MODP3072 +000 "north-eastnets/0x2": ESP algorithm newest: AES_CBC_128-HMAC_SHA2_512_256; pfsgroup= 000 #2: "north-eastnets/0x1":500 STATE_V2_ESTABLISHED_CHILD_SA (IPsec SA established); EVENT_SA_REKEY in XXs; newest IPSEC; eroute owner; isakmp#1; idle; -000 #2: "north-eastnets/0x1" esp.ESPSPIi@192.1.2.23 esp.ESPSPIi@192.1.3.33 tun.0@192.1.2.23 tun.0@192.1.3.33 Traffic: ESPin=336B ESPout=336B! ESPmax=0B +000 #2: "north-eastnets/0x1" esp.ESPSPIi@192.1.2.23 esp.ESPSPIi@192.1.3.33 tun.0@192.1.2.23 tun.0@192.1.3.33 Traffic: ESPin=0B ESPout=0B! ESPmax=0B 000 #1: "north-eastnets/0x2":500 STATE_V2_ESTABLISHED_IKE_SA (established IKE SA); EVENT_SA_REKEY in XXs; newest ISAKMP; idle; 000 #3: "north-eastnets/0x2":500 STATE_V2_ESTABLISHED_CHILD_SA (IPsec SA established); EVENT_SA_REKEY in XXs; newest IPSEC; eroute owner; isakmp#1; idle; 000 #3: "north-eastnets/0x2" esp.ESPSPIi@192.1.2.23 esp.ESPSPIi@192.1.3.33 tun.0@192.1.2.23 tun.0@192.1.3.33 Traffic: ESPin=0B ESPout=0B! ESPmax=0B @@ -95,8 +95,9 @@ rtt min/avg/max/mdev = 0.XXX/0.XXX/0.XXX/0.XXX ms north # ipsec whack --trafficstatus -006 #2: "north-eastnets/0x1", type=ESP, add_time=1234567890, inBytes=840, outBytes=840, id='@east' +006 #2: "north-eastnets/0x1", type=ESP, add_time=1234567890, inBytes=504, outBytes=504, id='@east' 006 #3: "north-eastnets/0x2", type=ESP, add_time=1234567890, inBytes=336, outBytes=336, id='@east' +006 #5: "north-eastnets/0x2", type=ESP, add_time=1234567890, inBytes=0, outBytes=0, id='@east' north # echo done done