Two transport connections to gateway sun are set up, one from client carol and the other from client dave. The gateway sun uses the Trusted Key Manager (TKM) and is the responder for both connections. The authentication is based on X.509 certificates. In order to test the connections, both carol and dave ping gateway sun.
24 lines
1.8 KiB
Plaintext
24 lines
1.8 KiB
Plaintext
sun::ipsec stroke status 2> /dev/null::conn1.*ESTABLISHED.*sun.strongswan.org.*carol.strongswan.org::YES
|
|
sun::ipsec stroke status 2> /dev/null::conn2.*ESTABLISHED.*sun.strongswan.org.*dave.strongswan.org::YES
|
|
carol::ipsec status 2> /dev/null::host-host.*ESTABLISHED.*carol.strongswan.org.*sun.strongswan.org::YES
|
|
dave::ipsec status 2> /dev/null::host-host.*ESTABLISHED.*dave.strongswan.org.*sun.strongswan.org::YES
|
|
sun::ipsec stroke status 2> /dev/null::conn1.*INSTALLED, TRANSPORT::YES
|
|
sun::ipsec stroke status 2> /dev/null::conn2.*INSTALLED, TRANSPORT::YES
|
|
carol::ipsec status 2> /dev/null::host-host.*INSTALLED, TRANSPORT::YES
|
|
dave::ipsec status 2> /dev/null::host-host.*INSTALLED, TRANSPORT::YES
|
|
carol::ping -c 1 PH_IP_SUN::64 bytes from PH_IP_SUN: icmp_req=1::YES
|
|
dave::ping -c 1 PH_IP_SUN::64 bytes from PH_IP_SUN: icmp_req=1::YES
|
|
carol::tcpdump::IP carol.strongswan.org > sun.strongswan.org: ESP::YES
|
|
carol::tcpdump::IP sun.strongswan.org > carol.strongswan.org: ESP::YES
|
|
dave::tcpdump::IP dave.strongswan.org > sun.strongswan.org: ESP::YES
|
|
dave::tcpdump::IP sun.strongswan.org > dave.strongswan.org: ESP::YES
|
|
sun::cat /tmp/tkm.log::RSA private key '/etc/tkm/sunKey.der' loaded::YES
|
|
sun::cat /tmp/tkm.log::Adding policy \[ 1, 192.168.0.2 <-> 192.168.0.100 \]::YES
|
|
sun::cat /tmp/tkm.log::Adding policy \[ 2, 192.168.0.2 <-> 192.168.0.200 \]::YES
|
|
sun::cat /tmp/tkm.log::Checked CA certificate of CC context 1::YES
|
|
sun::cat /tmp/tkm.log::Checked CA certificate of CC context 2::YES
|
|
sun::cat /tmp/tkm.log::Authentication of ISA context 1 successful::YES
|
|
sun::cat /tmp/tkm.log::Authentication of ISA context 2 successful::YES
|
|
sun::cat /tmp/tkm.log::Adding SA \[ 1, 192.168.0.2 <-> 192.168.0.100, SPI_in.*, SPI_out.*, soft 30, hard 60 \]::YES
|
|
sun::cat /tmp/tkm.log::Adding SA \[ 2, 192.168.0.2 <-> 192.168.0.200, SPI_in.*, SPI_out.*, soft 30, hard 60 \]::YES
|