/testing/guestbin/swan-prep --x509 Preparing X.509 files west # certutil -D -n east -d sql:/etc/ipsec.d west # ipsec start Redirecting to: [initsystem] west # ../../guestbin/wait-until-pluto-started west # ipsec auto --add san 002 "san": added IKEv1 connection west # echo "initdone" initdone west # ipsec whack --impair suppress-retransmits west # # this should succeed west # ipsec auto --up san 002 "san" #1: initiating IKEv1 Main Mode connection 1v1 "san" #1: sent Main Mode request 1v1 "san" #1: sent Main Mode I2 002 "san" #1: I am sending my cert 002 "san" #1: I am sending a certificate request 1v1 "san" #1: sent Main Mode I3 003 "san" #1: authenticated using RSA with SHA1 and peer certificate '192.1.2.23' issued by CA 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=Libreswan test CA for mainca, E=testing@libreswan.org' 004 "san" #1: IKE SA established {auth=RSA_SIG cipher=AES_CBC_256 integ=HMAC_SHA2_256 group=MODP2048} 002 "san" #2: initiating Quick Mode IKEv1+RSASIG+ENCRYPT+TUNNEL+PFS+UP+IKE_FRAG_ALLOW+ESN_NO+ESN_YES 1v1 "san" #2: sent Quick Mode request 004 "san" #2: IPsec SA established tunnel mode {ESP=>0xESPESP <0xESPESP xfrm=AES_CBC_128-HMAC_SHA1_96 DPD=passive} west # echo "done" done west # # confirm the right ID types were sent/received west # grep "ID type" /tmp/pluto.log | sort | uniq | ID type: ID_IPV4_ADDR (0x1) west #