opensuse-11.1-run1.txt

opensuse-11.1 + strongswan-4.2.8 - Marius Tomaschewski, 11.08.2009 19:14

Download (14.8 kB)

 
1

    
2
host one:  kernel 2.6.27.25-0.1-default x86_64, strongswan-4.2.8 + sec fixes
3
host two:  kernel 2.6.27.25-0.1-xen i686, strongswan-4.2.8 + sec fixes
4

    
5
============================================================================
6

    
7
*** test01_ike1_rsa_tunnel_ipv4_start.ok
8

    
9
*** test02_ike1_rsa_tunnel_ipv4_route.ok.txt
10
    
11
    First ping "hangs" for ~ 30sec, then the responses arrives.
12

    
13

    
14
*** test03_ike1_rsa_transp_ipv4_start.ok
15

    
16
*** test04_ike1_rsa_transp_ipv4_route.ok.txt
17
    
18
    ping "hangs" 30 sec, then the response packets start to arrive:
19
    
20
    one:~ # rcipsec start
21
    Starting strongSwan 4.2.8 IPsec [starter]...                         done
22
    one:~ # date ; ping -c 1 172.16.2.142 ; date
23
    Di 11. Aug 14:21:29 CEST 2009
24
    PING 172.16.2.142 (172.16.2.142) 56(84) bytes of data.
25
    64 bytes from 172.16.2.142: icmp_seq=1 ttl=64 time=1.06 ms
26
    
27
    --- 172.16.2.142 ping statistics ---
28
    1 packets transmitted, 1 received, 0% packet loss, time 0ms
29
    rtt min/avg/max/mdev = 1.060/1.060/1.060/0.000 ms
30
    Di 11. Aug 14:21:59 CEST 2009
31
    
32

    
33
*** test05_ike1_rsa_tunnel_ipv6_start.ok
34

    
35
*** test06_ike1_rsa_tunnel_ipv6_route.err.txt
36
    
37
    Aug 11 14:25:16 one pluto[10402]: added connection description "test"
38
    Aug 11 14:25:19 one pluto[10402]: ERROR: netlink XFRM_MSG_DELPOLICY response
39
    	for flow int.0@0.0.0.0 included errno 2: No such file or directory
40
    Aug 11 14:25:49 one pluto[10402]: ERROR: netlink XFRM_MSG_DELPOLICY response
41
    	for flow int.0@0.0.0.0 included errno 2: No such file or directory
42
    
43
    one:~ # date ; ping6 -c 1 2001:6f8:10c4:2::142 ; date
44
    Di 11. Aug 14:25:19 CEST 2009
45
    ^C
46
    Di 11. Aug 14:26:42 CEST 2009
47
    
48

    
49
*** test07_ike1_rsa_transp_ipv6_start.ok
50

    
51
*** test08_ike1_rsa_transp_ipv6_route.err.txt
52
    
53
    one:~ # rcipsec start
54
    Starting strongSwan 4.2.8 IPsec [starter]...                         done
55
    one:~ # date ; ping6 -c 1 2001:6f8:10c4:2::142 ; date
56
    Di 11. Aug 14:34:44 CEST 2009
57
    ^C
58
    Di 11. Aug 14:35:19 CEST 2009
59
    
60
    pluto[10778]: added connection description "test"
61
    pluto[10778]: ERROR: netlink XFRM_MSG_DELPOLICY response for flow int.0@0.0.0.0 
62
    pluto[10778]: ERROR: netlink XFRM_MSG_DELPOLICY response for flow int.0@0.0.0.0 
63
    
64

    
65
*** test11_ike2_rsa_tunnel_ipv4_start.ok
66

    
67
*** test12_ike2_rsa_tunnel_ipv4_route.ok
68

    
69
*** test13_ike2_rsa_transp_ipv4_start.ok
70

    
71
*** test14_ike2_rsa_transp_ipv4_route.ok
72

    
73
*** test15_ike2_rsa_tunnel_ipv6_start.ok
74

    
75
*** test16_ike2_rsa_tunnel_ipv6_route.ok
76

    
77
*** test17_ike2_rsa_transp_ipv6_start.ok
78

    
79
*** test18_ike2_rsa_transp_ipv6_route.ok
80

    
81
*** test21_ike1_psk_tunnel_ipv4_start.ok
82

    
83
*** test22_ike1_psk_tunnel_ipv4_route.ok.txt
84
    
85
    OK...
86
    
87
    one~ # rcipsec start
88
    Starting strongSwan 4.2.8 IPsec [starter]...                         done
89
    one:~ # date ; ping -c 2 172.16.2.142 ; date
90
    Di 11. Aug 14:46:55 CEST 2009
91
    PING 172.16.2.142 (172.16.2.142) 56(84) bytes of data.
92
    64 bytes from 172.16.2.142: icmp_seq=1 ttl=64 time=1.06 ms
93
    64 bytes from 172.16.2.142: icmp_seq=2 ttl=64 time=1.73 ms
94
    
95
    --- 172.16.2.142 ping statistics ---
96
    2 packets transmitted, 2 received, 0% packet loss, time 1003ms
97
    rtt min/avg/max/mdev = 1.066/1.399/1.732/0.333 ms
98
    Di 11. Aug 14:47:26 CEST 2009
99
    
100

    
101
*** test23_ike1_psk_transp_ipv4_start.ok
102

    
103
*** test24_ike1_psk_transp_ipv4_route.ok.txt
104
    
105
    OK...
106
    
107
    one:~ # rcipsec start
108
    Starting strongSwan 4.2.8 IPsec [starter]...                         done
109
    one:~ # date ; ping -c 2 172.16.2.142 ; date
110
    Di 11. Aug 14:49:49 CEST 2009
111
    PING 172.16.2.142 (172.16.2.142) 56(84) bytes of data.
112
    64 bytes from 172.16.2.142: icmp_seq=1 ttl=64 time=1.17 ms
113
    64 bytes from 172.16.2.142: icmp_seq=2 ttl=64 time=2.07 ms
114
    
115
    --- 172.16.2.142 ping statistics ---
116
    2 packets transmitted, 2 received, 0% packet loss, time 1003ms
117
    rtt min/avg/max/mdev = 1.178/1.626/2.074/0.448 ms
118
    Di 11. Aug 14:50:20 CEST 2009
119
    
120

    
121
*** test25_ike1_psk_tunnel_ipv6_start.ok
122

    
123
*** test26_ike1_psk_tunnel_ipv6_route.err.txt
124
    
125
    one:~ # rcipsec start
126
    Starting strongSwan 4.2.8 IPsec [starter]...                         done
127
    one:~ # date ; ping6 -c 2 2001:6f8:10c4:2::142 ; date
128
    Di 11. Aug 14:55:39 CEST 2009
129
    ^C
130
    Di 11. Aug 14:56:25 CEST 2009
131
    
132
    pluto[13309]: added connection description "test"
133
    pluto[13309]: ERROR: netlink XFRM_MSG_DELPOLICY response for flow int.0@0.0.0.0 
134
    pluto[13309]: ERROR: netlink XFRM_MSG_DELPOLICY response for flow int.0@0.0.0.0 
135
    
136

    
137
*** test27_ike1_psk_transp_ipv6_start.ok
138

    
139
*** test28_ike1_psk_transp_ipv6_route.err.txt
140
    
141
    one:~ # rcipsec start
142
    Starting strongSwan 4.2.8 IPsec [starter]...                         done
143
    one:~ # date ; ping6 -c 2 2001:6f8:10c4:2::142 ; date
144
    Di 11. Aug 14:57:56 CEST 2009
145
    ^C
146
    Di 11. Aug 14:59:34 CEST 2009
147
    
148
    pluto[13655]: ERROR: netlink XFRM_MSG_DELPOLICY response for flow int.0@0.0.0.0 
149
    pluto[13655]: ERROR: netlink XFRM_MSG_DELPOLICY response for flow int.0@0.0.0.0 
150
    [...]
151
    
152

    
153
*** test31_ike2_psk_tunnel_ipv4_start.ok
154

    
155
*** test32_ike2_psk_tunnel_ipv4_route.ok
156

    
157
*** test33_ike2_psk_transp_ipv4_start.ok
158

    
159
*** test34_ike2_psk_transp_ipv4_route.ok
160

    
161
*** test35_ike2_psk_tunnel_ipv6_start.ok
162

    
163
*** test36_ike2_psk_tunnel_ipv6_route.ok
164

    
165
*** test37_ike2_psk_transp_ipv6_start.ok
166

    
167
*** test38_ike2_psk_transp_ipv6_route.err.txt
168
    one # grep -Ev "^$|^.*#" /etc/ipsec.secrets /etc/ipsec.conf 
169
    /etc/ipsec.secrets:: PSK "A12@9f+A?<f*IH9cn;yJ`1 [oN/'*v4"
170
    /etc/ipsec.conf:config setup
171
    /etc/ipsec.conf:        strictcrlpolicy=no
172
    /etc/ipsec.conf:        plutostart=no
173
    /etc/ipsec.conf:conn test
174
    /etc/ipsec.conf:        keyexchange=ikev2
175
    /etc/ipsec.conf:        type=transport
176
    /etc/ipsec.conf:        auto=route
177
    /etc/ipsec.conf:        authby=psk
178
    /etc/ipsec.conf:        left=2001:6f8:10c4:2::121
179
    /etc/ipsec.conf:        leftid=2001:6f8:10c4:2::121
180
    /etc/ipsec.conf:        right=2001:6f8:10c4:2::142
181
    /etc/ipsec.conf:        rightid=2001:6f8:10c4:2::142
182
    
183
    one ipsec_starter[15060]: Starting strongSwan 4.2.8 IPsec [starter]...
184
    one charon: 01[DMN] starting charon (strongSwan Version 4.2.8)
185
    one charon: 01[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
186
    one charon: 01[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
187
    one charon: 01[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
188
    one charon: 01[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
189
    one charon: 01[CFG] loading crls from '/etc/ipsec.d/crls'
190
    one charon: 01[CFG] loading secrets from '/etc/ipsec.secrets'
191
    one charon: 01[CFG]   loaded IKE secret for %any
192
    one charon: 01[KNL] listening on interfaces:
193
    one charon: 01[KNL]   eth0
194
    one charon: 01[KNL]     172.16.2.121
195
    one charon: 01[KNL]     2001:6f8:10c4:2::121
196
    one charon: 01[KNL]     fe80::216:3eff:fe6c:a5ab
197
    one charon: 01[JOB] spawning 16 worker threads
198
    one ipsec_starter[15068]: charon (15069) started after 20 ms
199
    one charon: 03[CFG] received stroke: add connection 'test'
200
    one charon: 03[CFG] added configuration 'test': 2001:6f8:10c4:2::121[2001:6f8:10c4:2::121]...2001:6f8:10c4:2::142[2001:6f8:10c4:2::142]
201
    one charon: 03[CFG] received stroke: route 'test'
202
    one charon: 11[AUD] routing CHILD_SA
203
    one charon: 11[AUD] routing CHILD_SA
204
    one charon: 11[AUD] CHILD_SA routed
205
    one charon: 11[AUD] CHILD_SA routed
206
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
207
    one charon: 13[AUD] initiating IKE_SA test[1] to 2001:6f8:10c4:2::142
208
    one charon: 13[AUD] initiating IKE_SA test[1] to 2001:6f8:10c4:2::142
209
    one charon: 13[ENC] generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
210
    one charon: 13[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
211
    one charon: 14[IKE] retransmit 1 of request with message ID 0
212
    one charon: 14[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
213
    one charon: 15[IKE] retransmit 2 of request with message ID 0
214
    one charon: 15[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
215
    one charon: 16[IKE] retransmit 3 of request with message ID 0
216
    one charon: 16[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
217
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
218
    one charon: 09[IKE] retransmit 4 of request with message ID 0
219
    one charon: 09[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
220
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
221
    one charon: 08[IKE] retransmit 5 of request with message ID 0
222
    one charon: 08[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
223
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
224
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
225
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
226
    one charon: 14[IKE] giving up after 5 retransmits
227
    one charon: 14[AUD] peer not responding, trying again (2/3) in background
228
    one charon: 14[AUD] peer not responding, trying again (2/3) in background
229
    one charon: 14[AUD] initiating IKE_SA test[1] to 2001:6f8:10c4:2::142
230
    one charon: 14[AUD] initiating IKE_SA test[1] to 2001:6f8:10c4:2::142
231
    one charon: 14[ENC] generating IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
232
    one charon: 14[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
233
    one charon: 15[IKE] retransmit 1 of request with message ID 0
234
    one charon: 15[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
235
    one charon: 16[IKE] retransmit 2 of request with message ID 0
236
    one charon: 16[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
237
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
238
    one charon: 09[IKE] retransmit 3 of request with message ID 0
239
    one charon: 09[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
240
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
241
    one charon: 08[IKE] retransmit 4 of request with message ID 0
242
    one charon: 08[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
243
    one charon: 11[IKE] retransmit 5 of request with message ID 0
244
    one charon: 11[NET] sending packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
245
    one charon: 04[KNL] creating acquire job for CHILD_SA with reqid {1}
246
    
247
    two # grep -Ev "^$|^.*#" /etc/ipsec.secrets /etc/ipsec.conf 
248
    /etc/ipsec.secrets:: PSK "A12@9f+A?<f*IH9cn;yJ`1 [oN/'*v4"
249
    /etc/ipsec.conf:config setup
250
    /etc/ipsec.conf:        strictcrlpolicy=no
251
    /etc/ipsec.conf:        plutostart=no
252
    /etc/ipsec.conf:conn test
253
    /etc/ipsec.conf:        keyexchange=ikev2
254
    /etc/ipsec.conf:        type=transport
255
    /etc/ipsec.conf:        auto=route
256
    /etc/ipsec.conf:        authby=psk
257
    /etc/ipsec.conf:        left=2001:6f8:10c4:2::121
258
    /etc/ipsec.conf:        leftid=2001:6f8:10c4:2::121
259
    /etc/ipsec.conf:        right=2001:6f8:10c4:2::142
260
    /etc/ipsec.conf:        rightid=2001:6f8:10c4:2::142
261
    
262
    two ipsec_starter[31844]: Starting strongSwan 4.2.8 IPsec [starter]...
263
    two charon: 01[DMN] starting charon (strongSwan Version 4.2.8)
264
    two charon: 01[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
265
    two charon: 01[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
266
    two charon: 01[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
267
    two charon: 01[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
268
    two charon: 01[CFG] loading crls from '/etc/ipsec.d/crls'
269
    two charon: 01[CFG] loading secrets from '/etc/ipsec.secrets'
270
    two charon: 01[CFG]   loaded IKE secret for %any
271
    two charon: 01[KNL] listening on interfaces:
272
    two charon: 01[KNL]   eth0
273
    two charon: 01[KNL]     172.16.2.142
274
    two charon: 01[KNL]     2001:6f8:10c4:2::142
275
    two charon: 01[KNL]     fe80::a00:27ff:fed6:312e
276
    two charon: 01[JOB] spawning 16 worker threads
277
    two ipsec_starter[31852]: charon (31853) started after 20 ms
278
    two charon: 03[CFG] received stroke: add connection 'test'
279
    two charon: 03[CFG] added configuration 'test': 2001:6f8:10c4:2::142[2001:6f8:10c4:2::142]...2001:6f8:10c4:2::121[2001:6f8:10c4:2::121]
280
    two charon: 03[CFG] received stroke: route 'test'
281
    two charon: 10[AUD] routing CHILD_SA
282
    two charon: 10[AUD] routing CHILD_SA
283
    two charon: 10[AUD] CHILD_SA routed
284
    two charon: 10[AUD] CHILD_SA routed
285
    two charon: 13[NET] received packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
286
    two charon: 13[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
287
    two charon: 13[AUD] 2001:6f8:10c4:2::121 is initiating an IKE_SA
288
    two charon: 13[AUD] 2001:6f8:10c4:2::121 is initiating an IKE_SA
289
    two charon: 13[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
290
    two charon: 13[NET] sending packet: from 2001:6f8:10c4:2::142[500] to 2001:6f8:10c4:2::121[500]
291
    two charon: 14[NET] received packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
292
    two charon: 14[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
293
    two charon: 14[IKE] received retransmit of request with ID 0, retransmitting response
294
    two charon: 14[NET] sending packet: from 2001:6f8:10c4:2::142[500] to 2001:6f8:10c4:2::121[500]
295
    two charon: 15[NET] received packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
296
    two charon: 15[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
297
    two charon: 15[IKE] received retransmit of request with ID 0, retransmitting response
298
    two charon: 15[NET] sending packet: from 2001:6f8:10c4:2::142[500] to 2001:6f8:10c4:2::121[500]
299
    two charon: 16[NET] received packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
300
    two charon: 16[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
301
    two charon: 16[IKE] received retransmit of request with ID 0, retransmitting response
302
    two charon: 16[NET] sending packet: from 2001:6f8:10c4:2::142[500] to 2001:6f8:10c4:2::121[500]
303
    two charon: 17[JOB] deleting half open IKE_SA after timeout
304
    two sshd[31870]: Accepted publickey for root from 172.16.2.1 port 45710 ssh2
305
    two charon: 09[NET] received packet: from 2001:6f8:10c4:2::121[500] to 2001:6f8:10c4:2::142[500]
306
    two charon: 09[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
307
    two charon: 09[AUD] 2001:6f8:10c4:2::121 is initiating an IKE_SA
308
    two charon: 09[AUD] 2001:6f8:10c4:2::121 is initiating an IKE_SA
309
    two charon: 09[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ]
310
    two charon: 09[NET] sending packet: from 2001:6f8:10c4:2::142[500] to 2001:6f8:10c4:2::121[500]
311
    two charon: 08[JOB] deleting half open IKE_SA after timeout
312
    
313