Title | Test IKEv2.EN.I.1.1.3.4: Close Connection when receiving INITIAL_CONTACT |
CommandLine | ./1-EN-I/IKEv2-EN-I-1-1-3-4-A.seq -log 12.html -ti Test IKEv2.EN.I.1.1.3.4: Close Connection when receiving INITIAL_CONTACT |
TestVersion | REL_1_0_3 |
ToolVersion | REL_2_1_6 |
Start | 2010/03/09 03:43:04 |
Tn | /usr/local/koi//etc//tn.def |
Nu | /usr/local/koi//etc//nut.def |
03:43:04 | Start | ||||||||||||||||||||||||||||||
TEST SETUP | |||||||||||||||||||||||||||||||
initializing IKEv2 module ... | |||||||||||||||||||||||||||||||
configuring Common Topology for End-Node: End-Node to End-Node ... | |||||||||||||||||||||||||||||||
parsing ./config.pl ... | |||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||
setting up TN ... | |||||||||||||||||||||||||||||||
03:43:04 |
ikev2Local("/sbin/sysctl -w net.inet6.ip6.forwarding=1")net.inet6.ip6.forwarding: 0 -> 1 |
||||||||||||||||||||||||||||||
03:43:04 |
ikev2Local("/sbin/ifconfig -a")em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=19b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,TSO4> ether 00:23:ae:9d:94:70 inet6 fe80::223:aeff:fe9d:9470%em0 prefixlen 64 scopeid 0x1 inet 10.66.70.72 netmask 0xffffff00 broadcast 10.66.70.255 media: Ethernet autoselect (1000baseT <full-duplex>) status: active rl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:e0:4c:0d:51:49 inet 192.168.0.20 netmask 0xffffff00 broadcast 192.168.0.255 inet6 fe80::2e0:4cff:fe0d:5149%rl0 prefixlen 64 scopeid 0x2 media: Ethernet autoselect (100baseTX <full-duplex>) status: active rl1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:1d:0f:0f:be:4e inet6 fe80::21d:fff:fe0f:be4e%rl1 prefixlen 64 scopeid 0x3 media: Ethernet autoselect (none) status: no carrier plip0: flags=8810<POINTOPOINT,SIMPLEX,MULTICAST> metric 0 mtu 1500 lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=3<RXCSUM,TXCSUM> inet 127.0.0.1 netmask 0xff000000 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x5 |
||||||||||||||||||||||||||||||
03:43:04 |
ikev2Local("/sbin/ifconfig rl0 inet6 fe80::f%rl0/64") |
||||||||||||||||||||||||||||||
03:43:04 |
ikev2Local("/sbin/ifconfig rl0 inet6 2001:0db8:0001:0001::f/64") |
||||||||||||||||||||||||||||||
03:43:04 |
ikev2Local("/sbin/ifconfig lo1 create") |
||||||||||||||||||||||||||||||
03:43:04 |
ikev2Local("/sbin/ifconfig lo1 up") |
||||||||||||||||||||||||||||||
03:43:04 |
ikev2Local("/sbin/ifconfig lo1 inet6 2001:0db8:000f:0001::1/64") |
||||||||||||||||||||||||||||||
03:43:07 |
ikev2Local("/sbin/ifconfig -a")em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=19b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,TSO4> ether 00:23:ae:9d:94:70 inet6 fe80::223:aeff:fe9d:9470%em0 prefixlen 64 scopeid 0x1 inet 10.66.70.72 netmask 0xffffff00 broadcast 10.66.70.255 media: Ethernet autoselect (1000baseT <full-duplex>) status: active rl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:e0:4c:0d:51:49 inet 192.168.0.20 netmask 0xffffff00 broadcast 192.168.0.255 inet6 fe80::2e0:4cff:fe0d:5149%rl0 prefixlen 64 scopeid 0x2 inet6 fe80::f%rl0 prefixlen 64 scopeid 0x2 inet6 2001:db8:1:1::f prefixlen 64 media: Ethernet autoselect (100baseTX <full-duplex>) status: active rl1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:1d:0f:0f:be:4e inet6 fe80::21d:fff:fe0f:be4e%rl1 prefixlen 64 scopeid 0x3 media: Ethernet autoselect (none) status: no carrier plip0: flags=8810<POINTOPOINT,SIMPLEX,MULTICAST> metric 0 mtu 1500 lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=3<RXCSUM,TXCSUM> inet 127.0.0.1 netmask 0xff000000 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x5 lo1: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=3<RXCSUM,TXCSUM> inet6 2001:db8:f:1::1 prefixlen 64 |
||||||||||||||||||||||||||||||
03:43:07 |
ikev2Local("/sbin/setkey -D")No SAD entries. |
||||||||||||||||||||||||||||||
03:43:07 |
ikev2Local("/sbin/setkey -F") |
||||||||||||||||||||||||||||||
03:43:10 |
ikev2Local("/sbin/setkey -D")No SAD entries. |
||||||||||||||||||||||||||||||
03:43:10 |
ikev2Local("/sbin/setkey -DP")No SPD entries. |
||||||||||||||||||||||||||||||
03:43:10 |
ikev2Local("/sbin/setkey -FP") |
||||||||||||||||||||||||||||||
03:43:13 |
ikev2Local("/sbin/setkey -DP")No SPD entries. |
||||||||||||||||||||||||||||||
setting up NUT ... | |||||||||||||||||||||||||||||||
03:43:13 |
kRemote(ifconfig.rmt) ``/usr/local/koi/bin/remotes/manual//ifconfig.rmt ifconfig.address=2001:0db8:0001:0001::1234/64 ifconfig.address_family=inet6 ifconfig.interface=eth0'' kRemote()... /usr/local/koi/bin/remotes/manual//ifconfig.rmt ifconfig.address=2001:0db8:0001:0001::1234/64 ifconfig.address_family=inet6 ifconfig.interface=eth0 ifconfig> ifconfig> ifconfig.address: 2001:0db8:0001:0001::1234/64 ifconfig> ifconfig.address_family: inet6 ifconfig> ifconfig.interface: eth0 ifconfig> ifconfig> Press Enter key for continue. ifconfig> | ||||||||||||||||||||||||||||||
03:43:43 |
kRemote(route.rmt) ``/usr/local/koi/bin/remotes/manual//route.rmt route.0.address_family=inet6 route.0.gateway=fe80::f%eth0 route.0.interface=eth0 route.0.network=2001:0db8:000f:0001::/64 route.num=1'' kRemote()... /usr/local/koi/bin/remotes/manual//route.rmt route.0.address_family=inet6 route.0.gateway=fe80::f%eth0 route.0.interface=eth0 route.0.network=2001:0db8:000f:0001::/64 route.num=1 route> route> route.0.address_family: inet6 route> route.0.gateway: fe80::f%eth0 route> route.0.interface: eth0 route> route.0.network: 2001:0db8:000f:0001::/64 route> route.num: 1 route> route> Press Enter key for continue. route> | ||||||||||||||||||||||||||||||
03:43:44 |
kRemote(ikev2.rmt) ``/usr/local/koi/bin/remotes/manual//ikev2.rmt operation=stop'' kRemote()... /usr/local/koi/bin/remotes/manual//ikev2.rmt operation=stop ikev2> ikev2> operation: stop ikev2> ikev2> Press Enter key for continue. ikev2> | ||||||||||||||||||||||||||||||
03:43:52 |
kRemote(ikev2.rmt) ``/usr/local/koi/bin/remotes/manual//ikev2.rmt ikev2.addresspool.0.eaddr= ikev2.addresspool.0.saddr= ikev2.addresspool.num=1 ikev2.interface.ike.0.address=2001:0db8:0001:0001::1234 ikev2.interface.ike.0.port=500 ikev2.interface.ike.num=1 ikev2.ipsec.0.ext_sequence=off ikev2.ipsec.0.ipsec_index=common_ipsec_index ikev2.ipsec.0.ipsec_sa_lifetime_time=128 ikev2.ipsec.0.sa_index.0=common_sa_index ikev2.ipsec.0.sa_index.num=1 ikev2.ipsec.num=1 ikev2.policy.0.ipsec_index.0=common_ipsec_index ikev2.policy.0.ipsec_index.num=1 ikev2.policy.0.ipsec_mode=transport ikev2.policy.0.policy_index=common_policy_index ikev2.policy.0.remote_index=common_remote_index ikev2.policy.num=1 ikev2.remote.0.ikev2.initial_contact.initial_contact=off ikev2.remote.0.ikev2.kmp_auth_method.0=psk ikev2.remote.0.ikev2.kmp_auth_method.num=1 ikev2.remote.0.ikev2.kmp_dh_group.0=modp1024 ikev2.remote.0.ikev2.kmp_dh_group.num=1 ikev2.remote.0.ikev2.kmp_enc_alg.0=3des_cbc ikev2.remote.0.ikev2.kmp_enc_alg.num=1 ikev2.remote.0.ikev2.kmp_hash_alg.0=hmac_sha1 ikev2.remote.0.ikev2.kmp_hash_alg.num=1 ikev2.remote.0.ikev2.kmp_prf_alg.0=hmac_sha1 ikev2.remote.0.ikev2.kmp_prf_alg.num=1 ikev2.remote.0.ikev2.kmp_sa_lifetime_time=64 ikev2.remote.0.ikev2.my_id.fqdn.num=0 ikev2.remote.0.ikev2.my_id.ipaddr.0=2001:0db8:0001:0001::1234 ikev2.remote.0.ikev2.my_id.ipaddr.num=1 ikev2.remote.0.ikev2.my_id.keyid.num=0 ikev2.remote.0.ikev2.my_id.rfc822addr.num=0 ikev2.remote.0.ikev2.need_pfs=off ikev2.remote.0.ikev2.peers_id.fqdn.num=0 ikev2.remote.0.ikev2.peers_id.ipaddr.0=2001:0db8:000f:0001::1 ikev2.remote.0.ikev2.peers_id.ipaddr.num=1 ikev2.remote.0.ikev2.peers_id.keyid.num=0 ikev2.remote.0.ikev2.peers_id.rfc822addr.num=0 ikev2.remote.0.ikev2.peers_ipaddr.address=2001:0db8:000f:0001::1 ikev2.remote.0.ikev2.peers_ipaddr.port=500 ikev2.remote.0.ikev2.pre_shared_key.local=IKETEST12345678! ikev2.remote.0.ikev2.pre_shared_key.remote=IKETEST12345678! ikev2.remote.0.ikev2.send_cert_req.send_cert_req=on ikev2.remote.0.remote_index=common_remote_index ikev2.remote.num=1 ikev2.sa.0.esp_auth_alg.0=hmac_sha1 ikev2.sa.0.esp_auth_alg.num=1 ikev2.sa.0.esp_enc_alg.0=3des_cbc ikev2.sa.0.esp_enc_alg.num=1 ikev2.sa.0.sa_index=common_sa_index ikev2.sa.0.sa_protocol=esp ikev2.sa.num=1 ikev2.selector.0.direction=outbound ikev2.selector.0.dst.address=2001:0db8:000f:0001::1 ikev2.selector.0.dst.address_family=inet6 ikev2.selector.0.policy_index=common_policy_index ikev2.selector.0.selector_index=common_selector_index_outbound ikev2.selector.0.src.address=2001:0db8:0001:0001::1234 ikev2.selector.0.src.address_family=inet6 ikev2.selector.0.upper_layer_protocol.protocol=any ikev2.selector.1.direction=inbound ikev2.selector.1.dst.address=2001:0db8:0001:0001::1234 ikev2.selector.1.dst.address_family=inet6 ikev2.selector.1.policy_index=common_policy_index ikev2.selector.1.selector_index=common_selector_index_inbound ikev2.selector.1.src.address=2001:0db8:000f:0001::1 ikev2.selector.1.src.address_family=inet6 ikev2.selector.1.upper_layer_protocol.protocol=any ikev2.selector.num=2'' kRemote()... /usr/local/koi/bin/remotes/manual//ikev2.rmt ikev2.addresspool.0.eaddr= ikev2.addresspool.0.saddr= ikev2.addresspool.num=1 ikev2.interface.ike.0.address=2001:0db8:0001:0001::1234 ikev2.interface.ike.0.port=500 ikev2.interface.ike.num=1 ikev2.ipsec.0.ext_sequence=off ikev2.ipsec.0.ipsec_index=common_ipsec_index ikev2.ipsec.0.ipsec_sa_lifetime_time=128 ikev2.ipsec.0.sa_index.0=common_sa_index ikev2.ipsec.0.sa_index.num=1 ikev2.ipsec.num=1 ikev2.policy.0.ipsec_index.0=common_ipsec_index ikev2.policy.0.ipsec_index.num=1 ikev2.policy.0.ipsec_mode=transport ikev2.policy.0.policy_index=common_policy_index ikev2.policy.0.remote_index=common_remote_index ikev2.policy.num=1 ikev2.remote.0.ikev2.initial_contact.initial_contact=off ikev2.remote.0.ikev2.kmp_auth_method.0=psk ikev2.remote.0.ikev2.kmp_auth_method.num=1 ikev2.remote.0.ikev2.kmp_dh_group.0=modp1024 ikev2.remote.0.ikev2.kmp_dh_group.num=1 ikev2.remote.0.ikev2.kmp_enc_alg.0=3des_cbc ikev2.remote.0.ikev2.kmp_enc_alg.num=1 ikev2.remote.0.ikev2.kmp_hash_alg.0=hmac_sha1 ikev2.remote.0.ikev2.kmp_hash_alg.num=1 ikev2.remote.0.ikev2.kmp_prf_alg.0=hmac_sha1 ikev2.remote.0.ikev2.kmp_prf_alg.num=1 ikev2.remote.0.ikev2.kmp_sa_lifetime_time=64 ikev2.remote.0.ikev2.my_id.fqdn.num=0 ikev2.remote.0.ikev2.my_id.ipaddr.0=2001:0db8:0001:0001::1234 ikev2.remote.0.ikev2.my_id.ipaddr.num=1 ikev2.remote.0.ikev2.my_id.keyid.num=0 ikev2.remote.0.ikev2.my_id.rfc822addr.num=0 ikev2.remote.0.ikev2.need_pfs=off ikev2.remote.0.ikev2.peers_id.fqdn.num=0 ikev2.remote.0.ikev2.peers_id.ipaddr.0=2001:0db8:000f:0001::1 ikev2.remote.0.ikev2.peers_id.ipaddr.num=1 ikev2.remote.0.ikev2.peers_id.keyid.num=0 ikev2.remote.0.ikev2.peers_id.rfc822addr.num=0 ikev2.remote.0.ikev2.peers_ipaddr.address=2001:0db8:000f:0001::1 ikev2.remote.0.ikev2.peers_ipaddr.port=500 ikev2.remote.0.ikev2.pre_shared_key.local=IKETEST12345678! ikev2.remote.0.ikev2.pre_shared_key.remote=IKETEST12345678! ikev2.remote.0.ikev2.send_cert_req.send_cert_req=on ikev2.remote.0.remote_index=common_remote_index ikev2.remote.num=1 ikev2.sa.0.esp_auth_alg.0=hmac_sha1 ikev2.sa.0.esp_auth_alg.num=1 ikev2.sa.0.esp_enc_alg.0=3des_cbc ikev2.sa.0.esp_enc_alg.num=1 ikev2.sa.0.sa_index=common_sa_index ikev2.sa.0.sa_protocol=esp ikev2.sa.num=1 ikev2.selector.0.direction=outbound ikev2.selector.0.dst.address=2001:0db8:000f:0001::1 ikev2.selector.0.dst.address_family=inet6 ikev2.selector.0.policy_index=common_policy_index ikev2.selector.0.selector_index=common_selector_index_outbound ikev2.selector.0.src.address=2001:0db8:0001:0001::1234 ikev2.selector.0.src.address_family=inet6 ikev2.selector.0.upper_layer_protocol.protocol=any ikev2.selector.1.direction=inbound ikev2.selector.1.dst.address=2001:0db8:0001:0001::1234 ikev2.selector.1.dst.address_family=inet6 ikev2.selector.1.policy_index=common_policy_index ikev2.selector.1.selector_index=common_selector_index_inbound ikev2.selector.1.src.address=2001:0db8:000f:0001::1 ikev2.selector.1.src.address_family=inet6 ikev2.selector.1.upper_layer_protocol.protocol=any ikev2.selector.num=2 ikev2> ikev2> ikev2.addresspool.0.eaddr: 1 ikev2> ikev2.addresspool.0.saddr: 1 ikev2> ikev2.addresspool.num: 1 ikev2> ikev2.interface.ike.0.address: 2001:0db8:0001:0001::1234 ikev2> ikev2.interface.ike.0.port: 500 ikev2> ikev2.interface.ike.num: 1 ikev2> ikev2.ipsec.0.ext_sequence: off ikev2> ikev2.ipsec.0.ipsec_index: common_ipsec_index ikev2> ikev2.ipsec.0.ipsec_sa_lifetime_time: 128 ikev2> ikev2.ipsec.0.sa_index.0: common_sa_index ikev2> ikev2.ipsec.0.sa_index.num: 1 ikev2> ikev2.ipsec.num: 1 ikev2> ikev2.policy.0.ipsec_index.0: common_ipsec_index ikev2> ikev2.policy.0.ipsec_index.num: 1 ikev2> ikev2.policy.0.ipsec_mode: transport ikev2> ikev2.policy.0.policy_index: common_policy_index ikev2> ikev2.policy.0.remote_index: common_remote_index ikev2> ikev2.policy.num: 1 ikev2> ikev2.remote.0.ikev2.initial_contact.initial_contact: off ikev2> ikev2.remote.0.ikev2.kmp_auth_method.0: psk ikev2> ikev2.remote.0.ikev2.kmp_auth_method.num: 1 ikev2> ikev2.remote.0.ikev2.kmp_dh_group.0: modp1024 ikev2> ikev2.remote.0.ikev2.kmp_dh_group.num: 1 ikev2> ikev2.remote.0.ikev2.kmp_enc_alg.0: 3des_cbc ikev2> ikev2.remote.0.ikev2.kmp_enc_alg.num: 1 ikev2> ikev2.remote.0.ikev2.kmp_hash_alg.0: hmac_sha1 ikev2> ikev2.remote.0.ikev2.kmp_hash_alg.num: 1 ikev2> ikev2.remote.0.ikev2.kmp_prf_alg.0: hmac_sha1 ikev2> ikev2.remote.0.ikev2.kmp_prf_alg.num: 1 ikev2> ikev2.remote.0.ikev2.kmp_sa_lifetime_time: 64 ikev2> ikev2.remote.0.ikev2.my_id.fqdn.num: 0 ikev2> ikev2.remote.0.ikev2.my_id.ipaddr.0: 2001:0db8:0001:0001::1234 ikev2> ikev2.remote.0.ikev2.my_id.ipaddr.num: 1 ikev2> ikev2.remote.0.ikev2.my_id.keyid.num: 0 ikev2> ikev2.remote.0.ikev2.my_id.rfc822addr.num: 0 ikev2> ikev2.remote.0.ikev2.need_pfs: off ikev2> ikev2.remote.0.ikev2.peers_id.fqdn.num: 0 ikev2> ikev2.remote.0.ikev2.peers_id.ipaddr.0: 2001:0db8:000f:0001::1 ikev2> ikev2.remote.0.ikev2.peers_id.ipaddr.num: 1 ikev2> ikev2.remote.0.ikev2.peers_id.keyid.num: 0 ikev2> ikev2.remote.0.ikev2.peers_id.rfc822addr.num: 0 ikev2> ikev2.remote.0.ikev2.peers_ipaddr.address: 2001:0db8:000f:0001::1 ikev2> ikev2.remote.0.ikev2.peers_ipaddr.port: 500 ikev2> ikev2.remote.0.ikev2.pre_shared_key.local: IKETEST12345678! ikev2> ikev2.remote.0.ikev2.pre_shared_key.remote: IKETEST12345678! ikev2> ikev2.remote.0.ikev2.send_cert_req.send_cert_req: on ikev2> ikev2.remote.0.remote_index: common_remote_index ikev2> ikev2.remote.num: 1 ikev2> ikev2.sa.0.esp_auth_alg.0: hmac_sha1 ikev2> ikev2.sa.0.esp_auth_alg.num: 1 ikev2> ikev2.sa.0.esp_enc_alg.0: 3des_cbc ikev2> ikev2.sa.0.esp_enc_alg.num: 1 ikev2> ikev2.sa.0.sa_index: common_sa_index ikev2> ikev2.sa.0.sa_protocol: esp ikev2> ikev2.sa.num: 1 ikev2> ikev2.selector.0.direction: outbound ikev2> ikev2.selector.0.dst.address: 2001:0db8:000f:0001::1 ikev2> ikev2.selector.0.dst.address_family: inet6 ikev2> ikev2.selector.0.policy_index: common_policy_index ikev2> ikev2.selector.0.selector_index: common_selector_index_outbound ikev2> ikev2.selector.0.src.address: 2001:0db8:0001:0001::1234 ikev2> ikev2.selector.0.src.address_family: inet6 ikev2> ikev2.selector.0.upper_layer_protocol.protocol: any ikev2> ikev2.selector.1.direction: inbound ikev2> ikev2.selector.1.dst.address: 2001:0db8:0001:0001::1234 ikev2> ikev2.selector.1.dst.address_family: inet6 ikev2> ikev2.selector.1.policy_index: common_policy_index ikev2> ikev2.selector.1.selector_index: common_selector_index_inbound ikev2> ikev2.selector.1.src.address: 2001:0db8:000f:0001::1 ikev2> ikev2.selector.1.src.address_family: inet6 ikev2> ikev2.selector.1.upper_layer_protocol.protocol: any ikev2> ikev2.selector.num: 2 ikev2> ikev2> Press Enter key for continue. ikev2> | ||||||||||||||||||||||||||||||
TEST PROCEDURE | |||||||||||||||||||||||||||||||
(I) (R) NUT TN1 | | |-------------->| IKE_SA_INIT request (HDR, SAi1, KEi, Ni) | | V V | |||||||||||||||||||||||||||||||
03:44:02 |
Clear Buffer done |
||||||||||||||||||||||||||||||
03:44:02 |
kRemoteAsync(ikev2.rmt) ``/usr/local/koi/bin/remotes/manual//ikev2.rmt selector.direction=outbound selector.dst.address=2001:0db8:000f:0001::1 selector.dst.address_family=inet6 selector.policy_index=common_policy_index selector.selector_index=common_selector_index_outbound selector.src.address=2001:0db8:0001:0001::1234 selector.src.address_family=inet6 selector.upper_layer_protocol.protocol=any target=2001:0db8:000f:0001::1 operation=initiate'' kRemoteAsync()... /usr/local/koi/bin/remotes/manual//ikev2.rmt selector.direction=outbound selector.dst.address=2001:0db8:000f:0001::1 selector.dst.address_family=inet6 selector.policy_index=common_policy_index selector.selector_index=common_selector_index_outbound selector.src.address=2001:0db8:0001:0001::1234 selector.src.address_family=inet6 selector.upper_layer_protocol.protocol=any target=2001:0db8:000f:0001::1 operation=initiate Link to remote control log |
||||||||||||||||||||||||||||||
03:44:02 |
Listen SrcAddr:2001:0db8:000f:0001::1 SrcPort:500 done listening at SocketID:3 |
||||||||||||||||||||||||||||||
03:44:02 |
Receive SrcAddr:2001:db8:1:1::1234 SrcPort:500 DstAddr:2001:db8:f:1::1 DstPort:500 done received from SocketID:4 receive 1st packet |
||||||||||||||||||||||||||||||
compare the received packet with packets('common_remote_index') | |||||||||||||||||||||||||||||||
03:44:09 | Checking Payload Order ... | ||||||||||||||||||||||||||||||
OK: Payload Order ('HDR', 'SA', 'KE', 'Ni, Nr', 'V') | |||||||||||||||||||||||||||||||
03:44:09 | Preparing Expected Packet ... | ||||||||||||||||||||||||||||||
OK: Added Payloads:Added#0 vendorID = 24533135371380597343774798968 inserted = 4 added = 1 self = V critical = 0 length = 16 nexttype = 0 reserved = 0 offset = 228OK: Modified Payloads: Modified#0 critical = 0 length = ARRAY(0x8a8abc4) length_comparator = range nexttype = V self = Ni, Nr nonce = NaN reserved = 0 modified = nexttype(0 -> V) | |||||||||||||||||||||||||||||||
03:44:09 | Checking Fields ... | ||||||||||||||||||||||||||||||
IKE Header OK initSPI: (received: f954ad51b46c796e, expected: 0000000000000000, comp: ne) OK respSPI: (received: 0000000000000000, expected: 0000000000000000, comp: eq) OK nexttype: (received: SA, expected: SA, comp: eq) OK major: (received: 2, expected: 2, comp: eq) OK minor: (received: 0, expected: 0, comp: eq) OK exchType: (received: IKE_SA_INIT, expected: IKE_SA_INIT, comp: eq) OK reserved1: (received: 0, expected: 0, comp: eq) OK initiator: (received: 1, expected: 1, comp: eq) OK higher: (received: 0, expected: 0, comp: eq) OK response: (received: 0, expected: 0, comp: eq) OK reserved2: (received: 0, expected: 0, comp: eq) OK messID: (received: 0, expected: 0, comp: eq) OK length: (received: 244, expected: any, comp: eq) | |||||||||||||||||||||||||||||||
SA Proposal Comparison OK ENCR: (received:ENCR_3DES, expected:ENCR_3DES) OK PRF: (received:PRF_HMAC_SHA1, expected:PRF_HMAC_SHA1) OK INTEG: (received:INTEG_HMAC_SHA1_96, expected:INTEG_HMAC_SHA1_96) OK D-H: (received:D-H_1024 MODP Group, expected:D-H_1024 MODP Group) OK ESN: (received:, expected:) | |||||||||||||||||||||||||||||||
Security Association Payload OK nexttype: (received:KE, expected:KE, comp: ne) OK reserved: (received:0, expected:0, comp: eq) OK critical: (received:0, expected:0, comp: eq) OK length: (received:44, expected:44, comp: eq) | |||||||||||||||||||||||||||||||
Proposal Substructure OK nexttype: (received:0, expected:0, comp: eq) OK reserved: (received:0, expected:0, comp: eq) OK number: (received:1, expected:1, comp: eq) OK proposalLen: (received:40, expected:40, comp: eq) OK transformCount: (received:4, expected:4, comp: eq) OK id: (received:IKE, expected:IKE, comp: eq) OK spiSize: (received:0, expected:0, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:ENCR, expected:ENCR, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:3DES, expected:3DES, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:INTEG, expected:INTEG, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:HMAC_SHA1_96, expected:HMAC_SHA1_96, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:PRF, expected:PRF, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:HMAC_SHA1, expected:HMAC_SHA1, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:0, expected:0, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:D-H, expected:D-H, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:1024 MODP Group, expected:1024 MODP Group, comp: eq) | |||||||||||||||||||||||||||||||
Key Exchange Payload OK nexttype: (received: Ni, Nr, expected: Ni, Nr, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 136, expected: 136, comp: eq) OK group: (received: 2, expected: 2, comp: eq) OK reserved1: (received: 0, expected: 0, comp: eq) OK publicKey: (received: 0xb94f3b208233e00bf4ace27a8786ef2ed321beab221717e1c6e3b17d55322aff67ecd15e1167333baa7b7eaec2b4a63ddc3a744442359b2ae6d44ba16efd8d2df24d7d4bcd03b9c3eb858f9f4028c6dfc73a6bbd39fa7aa043b0bc7d7bed6112c4619690f1196ca0575362433d1467212419375e7740f1e063c5f092b0f39a7e, expected: any, comp: eq) | |||||||||||||||||||||||||||||||
Nonce Payload OK nexttype: (received: V, expected: V, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 20, expected: [20-260], comp: range) OK nonce: (received: 0x94e4aceb2bf8dfe930a8d9a8920f0be5, expected: any, comp: eq) | |||||||||||||||||||||||||||||||
Vendor Payload OK nexttype: (received: 0, expected: 0, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 16, expected: 16, comp: eq) OK vendorID: (received: 24533135371380597343774798968, expected: 24533135371380597343774798968, comp: eq) | |||||||||||||||||||||||||||||||
Match with packet('common_remote_index') | |||||||||||||||||||||||||||||||
(I) (R) NUT TN1 | | |<--------------| IKE_SA_INIT response (HDR, SAr1, KEr, Nr) | | V V | |||||||||||||||||||||||||||||||
03:44:09 |
Clear Buffer done |
||||||||||||||||||||||||||||||
03:44:09 |
Send done sent to SocketID:4 send 2nd packet |
||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||
(I) (R) NUT TN1 | | |-------------->| IKE_AUTH request (HDR, SK {IDi, AUTH, N(USE_TRANSPORT_MODE), SAi2, TSi, TSr}) | | V V | |||||||||||||||||||||||||||||||
03:44:09 |
Receive SrcAddr:2001:db8:1:1::1234 SrcPort:500 DstAddr:2001:db8:f:1::1 DstPort:500 done received from SocketID:4 receive 3rd packet |
||||||||||||||||||||||||||||||
Authentication Success. expected(05da27434e3a21568234301ba37317572557d155) received(05da27434e3a21568234301ba37317572557d155) | |||||||||||||||||||||||||||||||
compare the received packet with packets('common_remote_index') | |||||||||||||||||||||||||||||||
03:44:09 | Checking Payload Order ... | ||||||||||||||||||||||||||||||
OK: Payload Order ('HDR', 'E', 'IDi', 'AUTH', 'SA', 'TSi', 'TSr', 'N') | |||||||||||||||||||||||||||||||
03:44:09 | Preparing Expected Packet ... | ||||||||||||||||||||||||||||||
OK: Added Payloads:Added#0 paylen = 4 inserted = 6 added = 1 self = N spi = data = critical = 0 length = 8 nexttype = 0 spiSize = 0 id = 0 type = USE_TRANSPORT_MODE reserved = 0 offset = 304OK: Modified Payloads: Modified#0 count = 1 self = TSr modified = nexttype(0 -> N) selectors = ARRAY(0x8ac5190) critical = 0 reserved1 = 0 length = 48 nexttype = N reserved = 0 | |||||||||||||||||||||||||||||||
03:44:09 | Checking Fields ... | ||||||||||||||||||||||||||||||
IKE Header OK initSPI: (received: f954ad51b46c796e, expected: f954ad51b46c796e, comp: eq) OK respSPI: (received: 8ea71d65af3263f5, expected: 8ea71d65af3263f5, comp: eq) OK nexttype: (received: E, expected: E, comp: eq) OK major: (received: 2, expected: 2, comp: eq) OK minor: (received: 0, expected: 0, comp: eq) OK exchType: (received: IKE_AUTH, expected: IKE_AUTH, comp: eq) OK reserved1: (received: 0, expected: 0, comp: eq) OK initiator: (received: 1, expected: 1, comp: eq) OK higher: (received: 0, expected: 0, comp: eq) OK response: (received: 0, expected: 0, comp: eq) OK reserved2: (received: 0, expected: 0, comp: eq) OK messID: (received: 1, expected: 1, comp: eq) OK length: (received: 372, expected: any, comp: eq) | |||||||||||||||||||||||||||||||
Encrypted Payload OK innerType: (received: IDi, expected: IDi, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 32, expected: any, comp: eq) OK iv: (received: E51DDE71 82CB51F1, expected: any, comp: eq) OK checksum: (received: 9ABB260A 03E0BABC 83AC94E3, expected: any, comp: eq) | |||||||||||||||||||||||||||||||
Identification Payload - Initiator OK nexttype: (received: AUTH, expected: AUTH, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 24, expected: 24, comp: eq) OK type: (received: IPV6_ADDR, expected: IPV6_ADDR, comp: eq) OK reserved1: (received: 0, expected: 0, comp: eq) OK value: (received: 20010DB8 00010001 00000000 00001234, expected: 20010DB8 00010001 00000000 00001234, comp: eq) | |||||||||||||||||||||||||||||||
Authentication Payload OK nexttype: (received: SA, expected: SA, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 28, expected: any, comp: eq) OK method: (received: SK_MIC, expected: SK_MIC, comp: eq) OK reserved1: (received: 0, expected: 0, comp: eq) OK data: (received: 05da27434e3a21568234301ba37317572557d155, expected: any, comp: eq) | |||||||||||||||||||||||||||||||
SA Proposal Comparison OK ENCR: (received:ENCR_3DES, expected:ENCR_3DES) OK PRF: (received:, expected:) OK INTEG: (received:INTEG_HMAC_SHA1_96, expected:INTEG_HMAC_SHA1_96) OK D-H: (received:, expected:) OK ESN: (received:ESN_No ESN, expected:ESN_No ESN) | |||||||||||||||||||||||||||||||
Security Association Payload OK nexttype: (received:TSi, expected:TSi, comp: ne) OK reserved: (received:0, expected:0, comp: eq) OK critical: (received:0, expected:0, comp: eq) OK length: (received:156, expected:156, comp: eq) | |||||||||||||||||||||||||||||||
Proposal Substructure OK nexttype: (received:2, expected:2, comp: eq) OK reserved: (received:0, expected:0, comp: eq) OK number: (received:1, expected:1, comp: eq) OK id: (received:ESP, expected:ESP, comp: eq) OK proposalLen: (received:40, expected:40, comp: eq) OK transformCount: (received:3, expected:3, comp: eq) OK spiSize: (received:4, expected:4, comp: eq) OK spi: (received:d02f0b66, expected:any, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:12, expected:12, comp: eq) OK type: (received:ENCR, expected:ENCR, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:AES_CBC, expected:AES_CBC, comp: eq) | |||||||||||||||||||||||||||||||
Transform Attribute OK type: (received:Key Length, expected:Key Length, comp: eq) OK value: (received:128, expected:128, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:INTEG, expected:INTEG, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:HMAC_SHA1_96, expected:HMAC_SHA1_96, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:0, expected:0, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:ESN, expected:ESN, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:No ESN, expected:No ESN, comp: eq) | |||||||||||||||||||||||||||||||
Proposal Substructure OK nexttype: (received:2, expected:2, comp: eq) OK reserved: (received:0, expected:0, comp: eq) OK number: (received:2, expected:0, comp: ne) OK id: (received:ESP, expected:ESP, comp: eq) OK proposalLen: (received:40, expected:40, comp: eq) OK transformCount: (received:3, expected:3, comp: eq) OK spiSize: (received:4, expected:4, comp: eq) OK spi: (received:d02f0b66, expected:any, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:12, expected:12, comp: eq) OK type: (received:ENCR, expected:ENCR, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:AES_CBC, expected:AES_CBC, comp: eq) | |||||||||||||||||||||||||||||||
Transform Attribute OK type: (received:Key Length, expected:Key Length, comp: eq) OK value: (received:128, expected:128, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:INTEG, expected:INTEG, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:HMAC_MD5_96, expected:HMAC_MD5_96, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:0, expected:0, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:ESN, expected:ESN, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:No ESN, expected:No ESN, comp: eq) | |||||||||||||||||||||||||||||||
Proposal Substructure OK nexttype: (received:2, expected:2, comp: eq) OK reserved: (received:0, expected:0, comp: eq) OK number: (received:3, expected:0, comp: ne) OK id: (received:ESP, expected:ESP, comp: eq) OK proposalLen: (received:36, expected:36, comp: eq) OK transformCount: (received:3, expected:3, comp: eq) OK spiSize: (received:4, expected:4, comp: eq) OK spi: (received:d02f0b66, expected:any, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:ENCR, expected:ENCR, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:3DES, expected:3DES, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:INTEG, expected:INTEG, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:HMAC_SHA1_96, expected:HMAC_SHA1_96, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:0, expected:0, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:ESN, expected:ESN, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:No ESN, expected:No ESN, comp: eq) | |||||||||||||||||||||||||||||||
Proposal Substructure OK nexttype: (received:0, expected:0, comp: eq) OK reserved: (received:0, expected:0, comp: eq) OK number: (received:4, expected:0, comp: ne) OK id: (received:ESP, expected:ESP, comp: eq) OK proposalLen: (received:36, expected:36, comp: eq) OK transformCount: (received:3, expected:3, comp: eq) OK spiSize: (received:4, expected:4, comp: eq) OK spi: (received:d02f0b66, expected:any, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:ENCR, expected:ENCR, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:3DES, expected:3DES, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:3, expected:3, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:INTEG, expected:INTEG, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:HMAC_MD5_96, expected:HMAC_MD5_96, comp: eq) | |||||||||||||||||||||||||||||||
Transform Substructure OK nexttype: (received:0, expected:0, comp: eq) OK reserved1: (received:0, expected:0, comp: eq) OK transformLen: (received:8, expected:8, comp: eq) OK type: (received:ESN, expected:ESN, comp: eq) OK reserved2: (received:0, expected:0, comp: eq) OK id: (received:No ESN, expected:No ESN, comp: eq) | |||||||||||||||||||||||||||||||
Traffic Selector Payload - Initiator OK nexttype: (received: TSr, expected: TSr, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 48, expected: 48, comp: eq) OK count: (received: 1, expected: 1, comp: eq) OK reserved1: (received: 0, expected: 0, comp: eq) | |||||||||||||||||||||||||||||||
Traffic Selector (expected #0) OK type: (received: IPV6_ADDR_RANGE, expected: IPV6_ADDR_RANGE, comp: eq) OK protocol: (received: 0, expected: 0, comp: eq) OK selectorLen: (received: 40, expected: 40, comp: eq) OK sport: (received: 0, expected: 0, comp: eq) OK eport: (received: 65535, expected: 65535, comp: eq) OK saddr: (received: 20010DB8 00010001 00000000 00001234, expected: 20010DB8 00010001 00000000 00001234, comp: eq) OK eaddr: (received: 20010DB8 00010001 00000000 00001234, expected: 20010DB8 00010001 00000000 00001234, comp: eq) | |||||||||||||||||||||||||||||||
Traffic Selector Payload - Responder OK nexttype: (received: N, expected: N, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 48, expected: 48, comp: eq) OK count: (received: 1, expected: 1, comp: eq) OK reserved1: (received: 0, expected: 0, comp: eq) | |||||||||||||||||||||||||||||||
Traffic Selector (expected #0) OK type: (received: IPV6_ADDR_RANGE, expected: IPV6_ADDR_RANGE, comp: eq) OK protocol: (received: 0, expected: 0, comp: eq) OK selectorLen: (received: 40, expected: 40, comp: eq) OK sport: (received: 0, expected: 0, comp: eq) OK eport: (received: 65535, expected: 65535, comp: eq) OK saddr: (received: 20010DB8 000F0001 00000000 00000001, expected: 20010DB8 000F0001 00000000 00000001, comp: eq) OK eaddr: (received: 20010DB8 000F0001 00000000 00000001, expected: 20010DB8 000F0001 00000000 00000001, comp: eq) | |||||||||||||||||||||||||||||||
Notify Payload OK nexttype: (received: 0, expected: 0, comp: eq) OK critical: (received: 0, expected: 0, comp: eq) OK reserved: (received: 0, expected: 0, comp: eq) OK length: (received: 8, expected: 8, comp: eq) OK id: (received: 0, expected: 0, comp: eq) OK spiSize: (received: 0, expected: 0, comp: eq) OK type: (received: USE_TRANSPORT_MODE, expected: USE_TRANSPORT_MODE, comp: eq) OK spi: (received: , expected: , comp: eq) OK data: (received: , expected: , comp: eq) | |||||||||||||||||||||||||||||||
Match with packet('common_remote_index') | |||||||||||||||||||||||||||||||
(I) (R) NUT TN1 | | |<--------------| IKE_AUTH response (HDR, SK {IDr, AUTH, N(USE_TRANSPORT_MODE), SAr2, TSi, TSr}) | | V V | |||||||||||||||||||||||||||||||
03:44:09 |
Clear Buffer done |
||||||||||||||||||||||||||||||
03:44:09 |
Send done sent to SocketID:4 send 4th packet |
||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||
03:44:09 |
ikev2Local("/usr/local/sbin/setkey -c << EOF
add 2001:0db8:000f:0001::1 2001:0db8:0001:0001::1234 esp 0xd02f0b66
-E 3des-cbc 0x2a946c537ca6b3ca29e9eaeb4d004d6961b58af4bed622c8
-A hmac-sha1 0x4dd776f23590e8664bef81156861d260f73bb0d2;
add 2001:0db8:0001:0001::1234 2001:0db8:000f:0001::1 esp 0xe97cb023
-E 3des-cbc 0x39a2fb59baf9255927c2e04949f3df17aeb17618fe646d58
-A hmac-sha1 0xaf13dd1a32b32da73e0ce273a55e518beb7ede29;
spdadd 2001:0db8:0001:0001::1234[any] 2001:0db8:000f:0001::1[any] icmp6
-P in ipsec esp/transport//require;
spdadd 2001:0db8:000f:0001::1[any] 2001:0db8:0001:0001::1234[any] icmp6
-P out ipsec esp/transport//require;
EOF
")add 2001:0db8:000f:0001::1 2001:0db8:0001:0001::1234 esp 0xd02f0b66 -E 3des-cbc 0x2a946c537ca6b3ca29e9eaeb4d004d6961b58af4bed622c8 -A hmac-sha1 0x4dd776f23590e8664bef81156861d260f73bb0d2; add 2001:0db8:0001:0001::1234 2001:0db8:000f:0001::1 esp 0xe97cb023 -E 3des-cbc 0x39a2fb59baf9255927c2e04949f3df17aeb17618fe646d58 -A hmac-sha1 0xaf13dd1a32b32da73e0ce273a55e518beb7ede29; spdadd 2001:0db8:0001:0001::1234[any] 2001:0db8:000f:0001::1[any] icmp6 -P in ipsec esp/transport//require; spdadd 2001:0db8:000f:0001::1[any] 2001:0db8:0001:0001::1234[any] icmp6 -P out ipsec esp/transport//require; |
||||||||||||||||||||||||||||||
03:44:09 |
ikev2Local("/usr/local/sbin/setkey -DP")2001:db8:1:1::1234 2001:db8:f:1::1 icmp6 in ipsec esp/transport//require spid=7 seq=1 pid=5482 refcnt=1 2001:db8:f:1::1 2001:db8:1:1::1234 icmp6 out ipsec esp/transport//require spid=8 seq=0 pid=5482 refcnt=1 |
||||||||||||||||||||||||||||||
03:44:09 |
ikev2Local("/usr/local/sbin/setkey -D")2001:db8:1:1::1234 2001:db8:f:1::1 esp mode=any spi=3917262883(0xe97cb023) reqid=0(0x00000000) E: 3des-cbc 39a2fb59 baf92559 27c2e049 49f3df17 aeb17618 fe646d58 A: hmac-sha1 af13dd1a 32b32da7 3e0ce273 a55e518b eb7ede29 seq=0x00000000 replay=0 flags=0x00000040 state=mature created: Mar 9 03:44:09 2010 current: Mar 9 03:44:09 2010 diff: 0(s) hard: 0(s) soft: 0(s) last: hard: 0(s) soft: 0(s) current: 0(bytes) hard: 0(bytes) soft: 0(bytes) allocated: 0 hard: 0 soft: 0 sadb_seq=1 pid=5483 refcnt=1 2001:db8:f:1::1 2001:db8:1:1::1234 esp mode=any spi=3492744038(0xd02f0b66) reqid=0(0x00000000) E: 3des-cbc 2a946c53 7ca6b3ca 29e9eaeb 4d004d69 61b58af4 bed622c8 A: hmac-sha1 4dd776f2 3590e866 4bef8115 6861d260 f73bb0d2 seq=0x00000000 replay=0 flags=0x00000040 state=mature created: Mar 9 03:44:09 2010 current: Mar 9 03:44:09 2010 diff: 0(s) hard: 0(s) soft: 0(s) last: hard: 0(s) soft: 0(s) current: 0(bytes) hard: 0(bytes) soft: 0(bytes) allocated: 0 hard: 0 soft: 0 sadb_seq=0 pid=5483 refcnt=1 |
||||||||||||||||||||||||||||||
03:44:09 |
Connect SrcAddr:2001:0db8:000f:0001::1 SrcPort:0 DstAddr:2001:0db8:0001:0001::1234 DstPort:0 done connected to SocketID:5 |
||||||||||||||||||||||||||||||
03:44:09 |
Receive Can't receive any packets at SrcAddr:2001:db8:f:1::1 SrcPort:0 | ||||||||||||||||||||||||||||||
(I) (R) NUT TN1 | | |<--------------| IPsec {Echo Request} | | V V | |||||||||||||||||||||||||||||||
03:44:11 |
Send done sent to SocketID:5 send 5th packet |
||||||||||||||||||||||||||||||
(I) (R) NUT TN1 | | |-------------->| IPsec {Echo Reply} | | V V | |||||||||||||||||||||||||||||||
03:44:11 |
Receive SrcAddr:2001:db8:1:1::1234 SrcPort:0 DstAddr:2001:db8:f:1::1 DstPort:0 done received from SocketID:5 receive 6th packet |
||||||||||||||||||||||||||||||
(I) (R) NUT TN1 | | |-------------->| IKE_SA_INIT request (HDR, SAi1, KEi, Ni) | | V V | |||||||||||||||||||||||||||||||
03:44:11 |
Receive Can't receive any packets at SrcAddr:2001:db8:f:1::1 SrcPort:500 | ||||||||||||||||||||||||||||||
kCommon.pm: 1948: kCommon::kMakeRecvAck(): result: 33025(0x8101) -- fails. kCommon.pm: 1270: kCommon::PKTSendCMD(): kMakeData: failure | |||||||||||||||||||||||||||||||
Can't observe IKE_SA_INIT request. | |||||||||||||||||||||||||||||||
TEST CLEANUP | |||||||||||||||||||||||||||||||
03:44:24 |
kRemoteAsyncWait()
Link to remote control start point ikev2> ikev2> operation: initiate ikev2> selector.direction: outbound ikev2> selector.dst.address: 2001:0db8:000f:0001::1 ikev2> selector.dst.address_family: inet6 ikev2> selector.policy_index: common_policy_index ikev2> selector.selector_index: common_selector_index_outbound ikev2> selector.src.address: 2001:0db8:0001:0001::1234 ikev2> selector.src.address_family: inet6 ikev2> selector.upper_layer_protocol.protocol: any ikev2> target: 2001:0db8:000f:0001::1 ikev2> ikev2> Press Enter key for continue. ikev2> | ||||||||||||||||||||||||||||||
cleaning up NUT ... | |||||||||||||||||||||||||||||||
03:44:30 |
kRemote(ikev2.rmt) ``/usr/local/koi/bin/remotes/manual//ikev2.rmt operation=stop'' kRemote()... /usr/local/koi/bin/remotes/manual//ikev2.rmt operation=stop ikev2> ikev2> operation: stop ikev2> ikev2> Press Enter key for continue. ikev2> | ||||||||||||||||||||||||||||||
03:44:40 |
kRemote(route.rmt) ``/usr/local/koi/bin/remotes/manual//route.rmt operation=delete route.0.address_family=inet6 route.0.gateway=fe80::f%eth0 route.0.interface=eth0 route.0.network=2001:0db8:000f:0001::/64 route.num=1'' kRemote()... /usr/local/koi/bin/remotes/manual//route.rmt operation=delete route.0.address_family=inet6 route.0.gateway=fe80::f%eth0 route.0.interface=eth0 route.0.network=2001:0db8:000f:0001::/64 route.num=1 route> route> operation: delete route> route.0.address_family: inet6 route> route.0.gateway: fe80::f%eth0 route> route.0.interface: eth0 route> route.0.network: 2001:0db8:000f:0001::/64 route> route.num: 1 route> route> Press Enter key for continue. route> | ||||||||||||||||||||||||||||||
03:44:42 |
kRemote(ifconfig.rmt) ``/usr/local/koi/bin/remotes/manual//ifconfig.rmt operation=delete ifconfig.address=2001:0db8:0001:0001::1234/64 ifconfig.address_family=inet6 ifconfig.interface=eth0'' kRemote()... /usr/local/koi/bin/remotes/manual//ifconfig.rmt operation=delete ifconfig.address=2001:0db8:0001:0001::1234/64 ifconfig.address_family=inet6 ifconfig.interface=eth0 ifconfig> ifconfig> ifconfig.address: 2001:0db8:0001:0001::1234/64 ifconfig> ifconfig.address_family: inet6 ifconfig> ifconfig.interface: eth0 ifconfig> operation: delete ifconfig> ifconfig> Press Enter key for continue. ifconfig> | ||||||||||||||||||||||||||||||
cleaning up TN ... | |||||||||||||||||||||||||||||||
03:44:42 |
ikev2Local("/sbin/setkey -D")2001:db8:1:1::1234 2001:db8:f:1::1 esp mode=any spi=3917262883(0xe97cb023) reqid=0(0x00000000) E: 3des-cbc 39a2fb59 baf92559 27c2e049 49f3df17 aeb17618 fe646d58 A: hmac-sha1 af13dd1a 32b32da7 3e0ce273 a55e518b eb7ede29 seq=0x00000001 replay=0 flags=0x00000040 state=mature created: Mar 9 03:44:09 2010 current: Mar 9 03:44:42 2010 diff: 33(s) hard: 0(s) soft: 0(s) last: Mar 9 03:44:11 2010 hard: 0(s) soft: 0(s) current: 80(bytes) hard: 0(bytes) soft: 0(bytes) allocated: 1 hard: 0 soft: 0 sadb_seq=1 pid=5487 refcnt=1 2001:db8:f:1::1 2001:db8:1:1::1234 esp mode=any spi=3492744038(0xd02f0b66) reqid=0(0x00000000) E: 3des-cbc 2a946c53 7ca6b3ca 29e9eaeb 4d004d69 61b58af4 bed622c8 A: hmac-sha1 4dd776f2 3590e866 4bef8115 6861d260 f73bb0d2 seq=0x00000001 replay=0 flags=0x00000040 state=mature created: Mar 9 03:44:09 2010 current: Mar 9 03:44:42 2010 diff: 33(s) hard: 0(s) soft: 0(s) last: Mar 9 03:44:11 2010 hard: 0(s) soft: 0(s) current: 116(bytes) hard: 0(bytes) soft: 0(bytes) allocated: 1 hard: 0 soft: 0 sadb_seq=0 pid=5487 refcnt=2 |
||||||||||||||||||||||||||||||
03:44:42 |
ikev2Local("/sbin/setkey -F") |
||||||||||||||||||||||||||||||
03:44:45 |
ikev2Local("/sbin/setkey -D") |
||||||||||||||||||||||||||||||
03:44:45 |
ikev2Local("/sbin/setkey -DP")2001:db8:1:1::1234 2001:db8:f:1::1 icmp6 in ipsec esp/transport//require spid=7 seq=1 pid=5490 refcnt=1 2001:db8:f:1::1 2001:db8:1:1::1234 icmp6 out ipsec esp/transport//require spid=8 seq=0 pid=5490 refcnt=1 |
||||||||||||||||||||||||||||||
03:44:45 |
ikev2Local("/sbin/setkey -FP") |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/setkey -DP")No SPD entries. |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/sysctl -w net.inet6.ip6.forwarding=0")net.inet6.ip6.forwarding: 1 -> 0 |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/ifconfig -a")em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=19b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,TSO4> ether 00:23:ae:9d:94:70 inet6 fe80::223:aeff:fe9d:9470%em0 prefixlen 64 scopeid 0x1 inet 10.66.70.72 netmask 0xffffff00 broadcast 10.66.70.255 media: Ethernet autoselect (1000baseT <full-duplex>) status: active rl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:e0:4c:0d:51:49 inet 192.168.0.20 netmask 0xffffff00 broadcast 192.168.0.255 inet6 fe80::2e0:4cff:fe0d:5149%rl0 prefixlen 64 scopeid 0x2 inet6 fe80::f%rl0 prefixlen 64 scopeid 0x2 inet6 2001:db8:1:1::f prefixlen 64 media: Ethernet autoselect (100baseTX <full-duplex>) status: active rl1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:1d:0f:0f:be:4e inet6 fe80::21d:fff:fe0f:be4e%rl1 prefixlen 64 scopeid 0x3 media: Ethernet autoselect (none) status: no carrier plip0: flags=8810<POINTOPOINT,SIMPLEX,MULTICAST> metric 0 mtu 1500 lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=3<RXCSUM,TXCSUM> inet 127.0.0.1 netmask 0xff000000 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x5 lo1: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=3<RXCSUM,TXCSUM> inet6 2001:db8:f:1::1 prefixlen 64 |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/ifconfig lo1 inet6 2001:0db8:000f:0001::1/64 delete") |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/ifconfig lo1 down") |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/ifconfig lo1 destroy") |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/ifconfig rl0 inet6 2001:0db8:0001:0001::f/64 delete") |
||||||||||||||||||||||||||||||
03:44:48 |
ikev2Local("/sbin/ifconfig rl0 inet6 fe80::f%rl0/64 delete") |
||||||||||||||||||||||||||||||
03:44:51 |
ikev2Local("/sbin/ifconfig -a")em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=19b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,TSO4> ether 00:23:ae:9d:94:70 inet6 fe80::223:aeff:fe9d:9470%em0 prefixlen 64 scopeid 0x1 inet 10.66.70.72 netmask 0xffffff00 broadcast 10.66.70.255 media: Ethernet autoselect (1000baseT <full-duplex>) status: active rl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:e0:4c:0d:51:49 inet 192.168.0.20 netmask 0xffffff00 broadcast 192.168.0.255 inet6 fe80::2e0:4cff:fe0d:5149%rl0 prefixlen 64 scopeid 0x2 media: Ethernet autoselect (100baseTX <full-duplex>) status: active rl1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:1d:0f:0f:be:4e inet6 fe80::21d:fff:fe0f:be4e%rl1 prefixlen 64 scopeid 0x3 media: Ethernet autoselect (none) status: no carrier plip0: flags=8810<POINTOPOINT,SIMPLEX,MULTICAST> metric 0 mtu 1500 lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=3<RXCSUM,TXCSUM> inet 127.0.0.1 netmask 0xff000000 inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x5 |
||||||||||||||||||||||||||||||
FAIL |
IP Packet | IP Header | | Version = 6 | | Source Address = 2001:db8:1:1::1234 | | Destination Address = 2001:db8:f:1::1 | UDP Header | | Source Port = 500 | | Destination Port = 500 | Internet Security Association and Key Management Protocol Payload | | IKE Header | | | IKE_SA Initiator's SPI = f954ad51b46c796e | | | IKE_SA Responder's SPI = 0000000000000000 | | | Next Payload = 33 (SA) | | | Major Version = 2 | | | Minor Version = 0 | | | Exchange Type = 34 (IKE_SA_INIT) | | | Flags = 8 (0b00001000) | | | | Reserved (XX000000) = 0 | | | | Response (00R00000) = 0 | | | | Version (000V0000) = 0 | | | | Initiator (0000I000) = 1 | | | | Reserved (00000XXX) = 0 | | | Message ID = 0 (0x0) | | | Length = 244 (0xf4) | | | SA Payload | | | | Next Payload = 34 (KE) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 44 (0x2c) | | | | Proposal #1 | | | | | Next Payload = 0 (last) | | | | | RESERVED = 0 | | | | | Proposal Length = 40 | | | | | Proposal # = 1 | | | | | Proposal ID = IKE | | | | | SPI Size = 0 | | | | | # of Transforms = 4 | | | | | Transfrom | | | | | | Next Payload = 3 (Transform) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 1 (ENCR) | | | | | | RESERVED = 0 | | | | | | Transform ID = 3 (3DES) | | | | | Transfrom | | | | | | Next Payload = 3 (Transform) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 3 (INTEG) | | | | | | RESERVED = 0 | | | | | | Transform ID = 2 (HMAC_SHA1_96) | | | | | Transfrom | | | | | | Next Payload = 3 (Transform) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 2 (PRF) | | | | | | RESERVED = 0 | | | | | | Transform ID = 2 (HMAC_SHA1) | | | | | Transfrom | | | | | | Next Payload = 0 (last) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 4 (D-H) | | | | | | RESERVED = 0 | | | | | | Transform ID = 2 (1024 MODP Group) | | | KE Payload | | | | Next Payload = 40 (Ni, Nr) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 136 (0x88) | | | | DH Group # = 2 | | | | RESERVED = 0 | | | | Key Exchange Data = 0xb94f3b208233e00bf4ace27a8786ef2ed321beab221717e1c6e3b17d55322aff67ecd15e1167333baa7b7eaec2b4a63ddc3a744442359b2ae6d44ba16efd8d2df24d7d4bcd03b9c3eb858f9f4028c6dfc73a6bbd39fa7aa043b0bc7d7bed6112c4619690f1196ca0575362433d1467212419375e7740f1e063c5f092b0f39a7e | | | Ni, Nr Payload | | | | Next Payload = 43 (V) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 20 (0x14) | | | | Nonce Data = 94e4aceb2bf8dfe930a8d9a8920f0be5 | | | UNDEFINED Payload (type(V)) | | | | Next Payload = 0 (0) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 16 (0x10)
IP Packet | IP Header | | Version = 6 | | Source Address = 2001:db8:f:1::1 | | Destination Address = 2001:db8:1:1::1234 | UDP Header | | Source Port = 500 | | Destination Port = 500 | Internet Security Association and Key Management Protocol Payload | | IKE Header | | | IKE_SA Initiator's SPI = f954ad51b46c796e | | | IKE_SA Responder's SPI = 8ea71d65af3263f5 | | | Next Payload = 33 (SA) | | | Major Version = 2 | | | Minor Version = 0 | | | Exchange Type = 34 (IKE_SA_INIT) | | | Flags = 32 (0b00100000) | | | | Reserved (XX000000) = 0 | | | | Response (00R00000) = 1 | | | | Version (000V0000) = 0 | | | | Initiator (0000I000) = 0 | | | | Reserved (00000XXX) = 0 | | | Message ID = 0 (0x0) | | | Length = 451 (0x1c3) | | | SA Payload | | | | Next Payload = 34 (KE) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 44 (0x2c) | | | | Proposal #1 | | | | | Next Payload = 0 (last) | | | | | RESERVED = 0 | | | | | Proposal Length = 40 | | | | | Proposal # = 1 | | | | | Proposal ID = IKE | | | | | SPI Size = 0 | | | | | # of Transforms = 4 | | | | | Transfrom | | | | | | Next Payload = 3 (Transform) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 1 (ENCR) | | | | | | RESERVED = 0 | | | | | | Transform ID = 3 (3DES) | | | | | Transfrom | | | | | | Next Payload = 3 (Transform) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 2 (PRF) | | | | | | RESERVED = 0 | | | | | | Transform ID = 2 (HMAC_SHA1) | | | | | Transfrom | | | | | | Next Payload = 3 (Transform) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 3 (INTEG) | | | | | | RESERVED = 0 | | | | | | Transform ID = 2 (HMAC_SHA1_96) | | | | | Transfrom | | | | | | Next Payload = 0 (last) | | | | | | RESERVED = 0 | | | | | | Transform Length = 8 | | | | | | Transform Type = 4 (D-H) | | | | | | RESERVED = 0 | | | | | | Transform ID = 2 (1024 MODP Group) | | | KE Payload | | | | Next Payload = 40 (Ni, Nr) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 136 (0x88) | | | | DH Group # = 2 | | | | RESERVED = 0 | | | | Key Exchange Data = 0x1d39d1897a351c1818e660df48af043cc066fe341fa50e32ce9e99d667abff63eef7187f51360fe5921a4206cf113b9282678148810881274813854ccd39d79f28956eede640b54fd370a200a2cea1654f84601d6229619de692e36ca495205cea05329318fc219e69c197047202affbe799169bf669670b0dfb4a0c8958e866 | | | Ni, Nr Payload | | | | Next Payload = 0 (0) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 243 (0xf3) | | | | Nonce Data = f6ebb0529afeeaa411ced7864fbb28a46cadfec10bb9f3d77f363f6dbf4e19b66cd0ef243f131ad4051ce99b881a79b33fa98b194a5d38015aa8e5b9bb08a4babb2bdbd69b736af98817be1747cc81cf8e3db87dfc86aedef23626d5269b8ab0c5e5b22447473b5b1c522df32dca621e6976a63a1abfa732c7c9ffea54f2c6749cd7960f5d48cfff1d7fff7653440eacbf21f12c655b6eedf3efb134841859921035983a49c73d2d274ef5ab33883b5a5af41286a3d1235e7336d9861ed60c63b96dd14d26fa9f6ac5492b225e619cae749099e21e5537c45b2d4dc6a55a5a48dd8aaebd2642134fb702597a9a295c
IP Packet | IP Header | | Version = 6 | | Source Address = 2001:db8:1:1::1234 | | Destination Address = 2001:db8:f:1::1 | UDP Header | | Source Port = 500 | | Destination Port = 500 | Internet Security Association and Key Management Protocol Payload | | IKE Header | | | IKE_SA Initiator's SPI = f954ad51b46c796e | | | IKE_SA Responder's SPI = 8ea71d65af3263f5 | | | Next Payload = 46 (E) | | | Major Version = 2 | | | Minor Version = 0 | | | Exchange Type = 35 (IKE_AUTH) | | | Flags = 8 (0b00001000) | | | | Reserved (XX000000) = 0 | | | | Response (00R00000) = 0 | | | | Version (000V0000) = 0 | | | | Initiator (0000I000) = 1 | | | | Reserved (00000XXX) = 0 | | | Message ID = 1 (0x1) | | | Length = 372 (0x174) | | | E Payload | | | | Next Payload = 35 (IDi) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 344 (0x158) | | | | Initialization Vector = e51dde7182cb51f1 | | | | Encrypted IKE Payloads | | | | | IDi Payload | | | | | | Next Payload = 39 (AUTH) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 24 (0x18) | | | | | | ID Type = 5 (IPV6_ADDR) | | | | | | RESERVED = 0 | | | | | | Identification Data = 20010db8000100010000000000001234 (2001:db8:1:1::1234) | | | | | AUTH Payload | | | | | | Next Payload = 33 (SA) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 28 (0x1c) | | | | | | Auth Method = 2 (SK_MIC) | | | | | | RESERVED = 0 | | | | | | Authentication Data = 3035646132373433346533613231353638323334 | | | | | SA Payload | | | | | | Next Payload = 44 (TSi) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 156 (0x9c) | | | | | | Proposal #1 | | | | | | | Next Payload = 2 (Proposal) | | | | | | | RESERVED = 0 | | | | | | | Proposal Length = 40 | | | | | | | Proposal # = 1 | | | | | | | Proposal ID = ESP | | | | | | | SPI Size = 4 | | | | | | | # of Transforms = 3 | | | | | | | SPI = d02f0b66 | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 12 | | | | | | | | Transform Type = 1 (ENCR) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 12 (AES_CBC) | | | | | | | | | Attribute | | | | | | | | | | Attribute Type = Key Length | | | | | | | | | | Attribute Value = 128 | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 3 (INTEG) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 2 (HMAC_SHA1_96) | | | | | | | Transfrom | | | | | | | | Next Payload = 0 (last) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 5 (ESN) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 0 (No ESN) | | | | | | Proposal #2 | | | | | | | Next Payload = 2 (Proposal) | | | | | | | RESERVED = 0 | | | | | | | Proposal Length = 40 | | | | | | | Proposal # = 2 | | | | | | | Proposal ID = ESP | | | | | | | SPI Size = 4 | | | | | | | # of Transforms = 3 | | | | | | | SPI = d02f0b66 | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 12 | | | | | | | | Transform Type = 1 (ENCR) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 12 (AES_CBC) | | | | | | | | | Attribute | | | | | | | | | | Attribute Type = Key Length | | | | | | | | | | Attribute Value = 128 | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 3 (INTEG) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 1 (HMAC_MD5_96) | | | | | | | Transfrom | | | | | | | | Next Payload = 0 (last) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 5 (ESN) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 0 (No ESN) | | | | | | Proposal #3 | | | | | | | Next Payload = 2 (Proposal) | | | | | | | RESERVED = 0 | | | | | | | Proposal Length = 36 | | | | | | | Proposal # = 3 | | | | | | | Proposal ID = ESP | | | | | | | SPI Size = 4 | | | | | | | # of Transforms = 3 | | | | | | | SPI = d02f0b66 | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 1 (ENCR) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 3 (3DES) | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 3 (INTEG) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 2 (HMAC_SHA1_96) | | | | | | | Transfrom | | | | | | | | Next Payload = 0 (last) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 5 (ESN) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 0 (No ESN) | | | | | | Proposal #4 | | | | | | | Next Payload = 0 (last) | | | | | | | RESERVED = 0 | | | | | | | Proposal Length = 36 | | | | | | | Proposal # = 4 | | | | | | | Proposal ID = ESP | | | | | | | SPI Size = 4 | | | | | | | # of Transforms = 3 | | | | | | | SPI = d02f0b66 | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 1 (ENCR) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 3 (3DES) | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 3 (INTEG) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 1 (HMAC_MD5_96) | | | | | | | Transfrom | | | | | | | | Next Payload = 0 (last) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 5 (ESN) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 0 (No ESN) | | | | | TSi Payload | | | | | | Next Payload = 45 (TSr) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 48 (0x30) | | | | | | Number of TSs = 1 | | | | | | RESERVED = 0 | | | | | | Traffic Selector | | | | | | | TS Type = 8 (IPV6_ADDR_RANGE) | | | | | | | IP Protocol ID = 0 (any) | | | | | | | Selector Length = 40 | | | | | | | Start Port = 0 | | | | | | | End Port = 65535 | | | | | | | Starting Address = 20010db8000100010000000000001234 | | | | | | | Ending Address = 20010db8000100010000000000001234 | | | | | TSr Payload | | | | | | Next Payload = 41 (N) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 48 (0x30) | | | | | | Number of TSs = 1 | | | | | | RESERVED = 0 | | | | | | Traffic Selector | | | | | | | TS Type = 8 (IPV6_ADDR_RANGE) | | | | | | | IP Protocol ID = 0 (any) | | | | | | | Selector Length = 40 | | | | | | | Start Port = 0 | | | | | | | End Port = 65535 | | | | | | | Starting Address = 20010db8000f00010000000000000001 | | | | | | | Ending Address = 20010db8000f00010000000000000001 | | | | | N Payload | | | | | | Next Payload = 0 (0) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 8 (0x8) | | | | | | Protocol ID = 0 (no relation) | | | | | | SPI Size = 0 | | | | | | Notify Message Type = 16391 (USE_TRANSPORT_MODE) | | | | Integrity Checksum Data = 9abb260a03e0babc83ac94e3
IP Packet | IP Header | | Version = 6 | | Source Address = 2001:db8:f:1::1 | | Destination Address = 2001:db8:1:1::1234 | UDP Header | | Source Port = 500 | | Destination Port = 500 | Internet Security Association and Key Management Protocol Payload | | IKE Header | | | IKE_SA Initiator's SPI = f954ad51b46c796e | | | IKE_SA Responder's SPI = 8ea71d65af3263f5 | | | Next Payload = 46 (E) | | | Major Version = 2 | | | Minor Version = 0 | | | Exchange Type = 35 (IKE_AUTH) | | | Flags = 32 (0b00100000) | | | | Reserved (XX000000) = 0 | | | | Response (00R00000) = 1 | | | | Version (000V0000) = 0 | | | | Initiator (0000I000) = 0 | | | | Reserved (00000XXX) = 0 | | | Message ID = 1 (0x1) | | | Length = 252 (0xfc) | | | E Payload | | | | Next Payload = 36 (IDr) | | | | Critical = 0 | | | | Reserved = 0 | | | | Payload Length = 224 (0xe0) | | | | Initialization Vector = 03638b478b88222f | | | | Encrypted IKE Payloads | | | | | IDr Payload | | | | | | Next Payload = 39 (AUTH) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 24 (0x18) | | | | | | ID Type = 5 (IPV6_ADDR) | | | | | | RESERVED = 0 | | | | | | Identification Data = 20010db8000f00010000000000000001 (2001:db8:f:1::1) | | | | | AUTH Payload | | | | | | Next Payload = 41 (N) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 28 (0x1c) | | | | | | Auth Method = 2 (SK_MIC) | | | | | | RESERVED = 0 | | | | | | Authentication Data = 3135373365346465643631656430666131626333 | | | | | N Payload | | | | | | Next Payload = 33 (SA) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 8 (0x8) | | | | | | Protocol ID = 0 (no relation) | | | | | | SPI Size = 0 | | | | | | Notify Message Type = 16391 (USE_TRANSPORT_MODE) | | | | | SA Payload | | | | | | Next Payload = 44 (TSi) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 40 (0x28) | | | | | | Proposal #1 | | | | | | | Next Payload = 0 (last) | | | | | | | RESERVED = 0 | | | | | | | Proposal Length = 36 | | | | | | | Proposal # = 1 | | | | | | | Proposal ID = ESP | | | | | | | SPI Size = 4 | | | | | | | # of Transforms = 3 | | | | | | | SPI = e97cb023 | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 1 (ENCR) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 3 (3DES) | | | | | | | Transfrom | | | | | | | | Next Payload = 3 (Transform) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 3 (INTEG) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 2 (HMAC_SHA1_96) | | | | | | | Transfrom | | | | | | | | Next Payload = 0 (last) | | | | | | | | RESERVED = 0 | | | | | | | | Transform Length = 8 | | | | | | | | Transform Type = 5 (ESN) | | | | | | | | RESERVED = 0 | | | | | | | | Transform ID = 0 (No ESN) | | | | | TSi Payload | | | | | | Next Payload = 45 (TSr) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 48 (0x30) | | | | | | Number of TSs = 1 | | | | | | RESERVED = 0 | | | | | | Traffic Selector | | | | | | | TS Type = 8 (IPV6_ADDR_RANGE) | | | | | | | IP Protocol ID = 0 (any) | | | | | | | Selector Length = 40 | | | | | | | Start Port = 0 | | | | | | | End Port = 65535 | | | | | | | Starting Address = 20010db8000100010000000000001234 | | | | | | | Ending Address = 20010db8000100010000000000001234 | | | | | TSr Payload | | | | | | Next Payload = 0 (0) | | | | | | Critical = 0 | | | | | | Reserved = 0 | | | | | | Payload Length = 48 (0x30) | | | | | | Number of TSs = 1 | | | | | | RESERVED = 0 | | | | | | Traffic Selector | | | | | | | TS Type = 8 (IPV6_ADDR_RANGE) | | | | | | | IP Protocol ID = 0 (any) | | | | | | | Selector Length = 40 | | | | | | | Start Port = 0 | | | | | | | End Port = 65535 | | | | | | | Starting Address = 20010db8000f00010000000000000001 | | | | | | | Ending Address = 20010db8000f00010000000000000001 | | | | Integrity Checksum Data = d78c631c895b1c122c718fe8
IP Packet | IP Header | | Version = 6 | | Source Address = 2001:db8:f:1::1 | | Destination Address = 2001:db8:1:1::1234 | ICMP Header | | Type = 128 (Echo Request) | | Code = 0 | | Checksum = 0x0000
IP Packet | IP Header | | Version = 6 | | Source Address = 2001:db8:1:1::1234 | | Destination Address = 2001:db8:f:1::1 | ICMP Header | | Type = 129 (Echo Reply) | | Code = 0 | | Checksum = 0x10e4 | | Identifier = 0x0000 | | Sequence Number = 0x0000