--- MASTER/testing/pluto/github-1210-ikev1-quick-mismatch/road.console.txt +++ OUTPUT/testing/pluto/github-1210-ikev1-quick-mismatch/road.console.txt @@ -17,10 +17,11 @@ 1v1 "road" #1: sent Main Mode I2 1v1 "road" #1: sent Main Mode I3 002 "road" #1: Peer ID is ID_FQDN: '@east' -004 "road" #1: IKE SA established {auth=PRESHARED_KEY cipher=3DES_CBC_192 integ=HMAC_SHA1 group=MODP2048} +004 "road" #1: ISAKMP SA established {auth=PRESHARED_KEY cipher=3DES_CBC_192 integ=HMAC_SHA1 group=MODP2048} 002 "road" #2: initiating Quick Mode IKEv1+PSK+ENCRYPT+TUNNEL+PFS+UP+IKE_FRAG_ALLOW+ESN_NO+ESN_YES 1v1 "road" #2: sent Quick Mode request -004 "road" #2: IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 DPD=passive} +031 "road" #2: STATE_QUICK_I1: 60 second timeout exceeded after 7 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal +002 "road" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification road # echo done done @@ -28,37 +29,7 @@ ../../guestbin/ipsec-look.sh road NOW XFRM state: -src 192.1.2.23 dst 192.1.3.209 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 0 flag af-unspec - auth-trunc hmac(sha1) 0xHASHKEY 96 - enc cbc(aes) 0xENCKEY - anti-replay esn context: - seq-hi 0x0, seq 0xXX, oseq-hi 0x0, oseq 0xXX - replay_window 128, bitmap-length 4 - 00000000 00000000 00000000 XXXXXXXX -src 192.1.3.209 dst 192.1.2.23 - proto esp spi 0xSPISPI reqid REQID mode tunnel - replay-window 0 flag af-unspec - auth-trunc hmac(sha1) 0xHASHKEY 96 - enc cbc(aes) 0xENCKEY - anti-replay esn context: - seq-hi 0x0, seq 0xXX, oseq-hi 0x0, oseq 0xXX - replay_window 128, bitmap-length 4 - 00000000 00000000 00000000 XXXXXXXX XFRM policy: -src 192.0.1.0/24 dst 192.0.2.0/24 - dir out priority PRIORITY ptype main - tmpl src 192.1.3.209 dst 192.1.2.23 - proto esp reqid REQID mode tunnel -src 192.0.2.0/24 dst 192.0.1.0/24 - dir fwd priority PRIORITY ptype main - tmpl src 192.1.2.23 dst 192.1.3.209 - proto esp reqid REQID mode tunnel -src 192.0.2.0/24 dst 192.0.1.0/24 - dir in priority PRIORITY ptype main - tmpl src 192.1.2.23 dst 192.1.3.209 - proto esp reqid REQID mode tunnel XFRM done IPSEC mangle TABLES iptables filter TABLE