000 interface eth1/eth1 fec2::1:500 000 interface lo/lo ::1:500 000 interface eth0/eth0 fec0::2:500 000 interface lo/lo 127.0.0.1:4500 000 interface lo/lo 127.0.0.1:500 000 interface eth0/eth0 192.168.0.2:4500 000 interface eth0/eth0 192.168.0.2:500 000 interface eth1/eth1 10.2.0.1:4500 000 interface eth1/eth1 10.2.0.1:500 000 %myid = (none) 000 debug control 000 000 "host-host": 192.168.0.2[@sun.strongswan.org]...192.168.0.1[@moon.strongswan.org]; unrouted; eroute owner: #0 000 "host-host": CAs: 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA'...'%any' 000 "host-host": ike_life: 3600s; ipsec_life: 1200s; rekey_margin: 180s; rekey_fuzz: 100%; keyingtries: 1 000 "host-host": policy: RSASIG+ENCRYPT+TUNNEL+PFS; prio: 32,32; interface: eth0; 000 "host-host": newest ISAKMP SA: #1; newest IPsec SA: #0; 000 "host-host": IKE algorithms wanted: 5_000-2-5, 5_000-2-2, 5_000-1-5, 5_000-1-2, 000 "host-host": IKE algorithms found: 5_192-2_160-5, 5_192-2_160-2, 5_192-1_128-5, 5_192-1_128-2, 000 "host-host": IKE algorithm newest: 3DES_CBC_192-SHA-MODP1536 000 "host-host": ESP algorithms wanted: 3_000-2, 3_000-1, 000 "host-host": ESP algorithms loaded: 3_192-2_160, 3_192-1_128, 000 "nat-t": 10.2.0.0/16===192.168.0.2[@sun.strongswan.org]...%any==={10.1.0.0/16}; unrouted; eroute owner: #0 000 "nat-t": CAs: 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA'...'%any' 000 "nat-t": ike_life: 3600s; ipsec_life: 1200s; rekey_margin: 180s; rekey_fuzz: 100%; keyingtries: 1 000 "nat-t": policy: RSASIG+ENCRYPT+TUNNEL+PFS; prio: 16,16; interface: eth0; 000 "nat-t": newest ISAKMP SA: #0; newest IPsec SA: #0; 000 "nat-t": IKE algorithms wanted: 5_000-2-5, 5_000-2-2, 5_000-1-5, 5_000-1-2, 000 "nat-t": IKE algorithms found: 5_192-2_160-5, 5_192-2_160-2, 5_192-1_128-5, 5_192-1_128-2, 000 "nat-t": ESP algorithms wanted: 3_000-2, 3_000-1, 000 "nat-t": ESP algorithms loaded: 3_192-2_160, 3_192-1_128, 000 "net-net": 10.2.0.0/16===192.168.0.2[@sun.strongswan.org]...192.168.0.1[@moon.strongswan.org]===10.1.0.0/16; erouted; eroute owner: #2 000 "net-net": CAs: 'C=CH, O=Linux strongSwan, CN=strongSwan Root CA'...'%any' 000 "net-net": ike_life: 3600s; ipsec_life: 1200s; rekey_margin: 180s; rekey_fuzz: 100%; keyingtries: 1 000 "net-net": policy: RSASIG+ENCRYPT+TUNNEL+PFS; prio: 16,16; interface: eth0; 000 "net-net": newest ISAKMP SA: #0; newest IPsec SA: #2; 000 "net-net": IKE algorithms wanted: 5_000-2-5, 5_000-2-2, 5_000-1-5, 5_000-1-2, 000 "net-net": IKE algorithms found: 5_192-2_160-5, 5_192-2_160-2, 5_192-1_128-5, 5_192-1_128-2, 000 "net-net": ESP algorithms wanted: 3_000-2, 3_000-1, 000 "net-net": ESP algorithms loaded: 3_192-2_160, 3_192-1_128, 000 "net-net": ESP algorithm newest: 3DES_0-HMAC_SHA1; pfsgroup= 000 000 #1: "host-host" STATE_MAIN_R3 (sent MR3, ISAKMP SA established); EVENT_SA_REPLACE in 3497s; newest ISAKMP 000 #2: "net-net" STATE_QUICK_R2 (IPsec SA established); EVENT_SA_REPLACE in 1099s; newest IPSEC; eroute owner 000 #2: "net-net" esp.258123c2@192.168.0.1 (672 bytes, 2s ago) esp.ef70015e@192.168.0.2 (672 bytes, 2s ago); tunnel 000