mirror of
https://github.com/strongswan/strongswan.git
synced 2025-10-05 00:00:45 -04:00
The main difference is that ping now reports icmp_seq instead of icmp_req, so we match for icmp_.eq, which works with both releases. tcpdump now also reports port 4500 as ipsec-nat-t.
27 lines
1.8 KiB
Plaintext
27 lines
1.8 KiB
Plaintext
moon:: ipsec status 2> /dev/null::rw\[1]: ESTABLISHED.*moon.strongswan.org.*carol@strongswan.org::YES
|
|
moon:: ipsec status 2> /dev/null::rw\[2]: ESTABLISHED.*moon.strongswan.org.*dave@strongswan.org::YES
|
|
carol::ipsec status 2> /dev/null::home.*ESTABLISHED.*carol@strongswan.org.*moon.strongswan.org::YES
|
|
dave:: ipsec status 2> /dev/null::home.*ESTABLISHED.*dave@strongswan.org.*moon.strongswan.org::YES
|
|
moon:: ipsec status 2> /dev/null::rw[{]1}.*INSTALLED, TUNNEL::YES
|
|
moon:: ipsec status 2> /dev/null::rw[{]2}.*INSTALLED, TUNNEL::YES
|
|
carol::ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
|
|
dave:: ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
|
|
carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_.eq=1::YES
|
|
dave:: ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_.eq=1::YES
|
|
moon:: ipsec statusall 2> /dev/null::rw\[1].*IKE proposal: AES_GCM_16_256::YES
|
|
moon:: ipsec statusall 2> /dev/null::rw\[2].*IKE proposal: AES_GCM_16_128::YES
|
|
carol::ipsec statusall 2> /dev/null::IKE proposal: AES_GCM_16_256::YES
|
|
dave:: ipsec statusall 2> /dev/null::IKE proposal: AES_GCM_16_128::YES
|
|
moon:: ipsec statusall 2> /dev/null::rw[{]1}.*AES_GCM_16_256,::YES
|
|
moon:: ipsec statusall 2> /dev/null::rw[{]2}.*AES_GCM_16_128,::YES
|
|
carol::ipsec statusall 2> /dev/null::AES_GCM_16_256,::YES
|
|
dave:: ipsec statusall 2> /dev/null::AES_GCM_16_128,::YES
|
|
moon:: ip xfrm state::aead rfc4106(gcm(aes))::YES
|
|
carol::ip xfrm state::aead rfc4106(gcm(aes))::YES
|
|
dave:: ip xfrm state::aead rfc4106(gcm(aes))::YES
|
|
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP.*length 184::YES
|
|
moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP.*length 184::YES
|
|
moon::tcpdump::IP dave.strongswan.org > moon.strongswan.org: ESP.*length 184::YES
|
|
moon::tcpdump::IP moon.strongswan.org > dave.strongswan.org: ESP.*length 184::YES
|
|
|