May 1 02:01:45 moon charon: 00[DMN] Starting IKEv2 charon daemon (strongSwan 4.6.3) May 1 02:01:46 moon charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts' May 1 02:01:46 moon charon: 00[CFG] loaded ca certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" from '/etc/ipsec.d/cacerts/strongswanCert.pem' May 1 02:01:46 moon charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts' May 1 02:01:46 moon charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts' May 1 02:01:46 moon charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts' May 1 02:01:46 moon charon: 00[CFG] loading crls from '/etc/ipsec.d/crls' May 1 02:01:46 moon charon: 00[CFG] loading secrets from '/etc/ipsec.secrets' May 1 02:01:46 moon charon: 00[CFG] loaded RSA private key from '/etc/ipsec.d/private/moonKey.pem' May 1 02:01:46 moon charon: 00[KNL] listening on interfaces: May 1 02:01:46 moon charon: 00[KNL] eth0 May 1 02:01:46 moon charon: 00[KNL] 192.168.0.1 May 1 02:01:46 moon charon: 00[KNL] fec0::1 May 1 02:01:46 moon charon: 00[KNL] fe80::fcfd:c0ff:fea8:1 May 1 02:01:46 moon charon: 00[KNL] eth1 May 1 02:01:46 moon charon: 00[KNL] 10.1.0.1 May 1 02:01:46 moon charon: 00[KNL] fec1::1 May 1 02:01:46 moon charon: 00[KNL] fe80::fcfd:aff:fe01:1 May 1 02:01:46 moon charon: 00[DMN] loaded plugins: curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation addrblock hmac xcbc stroke kernel-netlink socket-default updown May 1 02:01:46 moon charon: 00[JOB] spawning 16 worker threads May 1 02:01:46 moon charon: 16[CFG] received stroke: add ca 'strongswan' May 1 02:01:46 moon charon: 16[CFG] added ca 'strongswan' May 1 02:01:46 moon charon: 12[CFG] received stroke: add connection 'rw' May 1 02:01:46 moon charon: 12[CFG] loaded certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=moon.strongswan.org" from 'moonCert.pem' May 1 02:01:46 moon charon: 12[CFG] added configuration 'rw' May 1 02:01:48 moon charon: 05[NET] received packet: from fec0::10[500] to fec0::1[500] May 1 02:01:48 moon charon: 05[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ] May 1 02:01:48 moon charon: 05[IKE] fec0::10 is initiating an IKE_SA May 1 02:01:48 moon charon: 05[IKE] sending cert request for "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:48 moon charon: 05[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(HTTP_CERT_LOOK) CERTREQ N(MULT_AUTH) ] May 1 02:01:48 moon charon: 05[NET] sending packet: from fec0::1[500] to fec0::10[500] May 1 02:01:48 moon charon: 07[NET] received packet: from fec0::10[4500] to fec0::1[4500] May 1 02:01:48 moon charon: 07[ENC] parsed IKE_AUTH request 1 [ IDi CERT N(INIT_CONTACT) N(HTTP_CERT_LOOK) CERTREQ IDr AUTH SA TSi TSr N(MOBIKE_SUP) N(ADD_4_ADDR) N(MULT_AUTH) N(EAP_ONLY) ] May 1 02:01:48 moon charon: 07[IKE] received cert request for "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:48 moon charon: 07[IKE] received hash-and-url for end entity cert "http://ip6-winnetou.strongswan.org/certs/rfc3779/0b5362afd8838bafb66c854732b490d5d8318261" May 1 02:01:49 moon charon: 07[CFG] looking for peer configs matching fec0::1[moon.strongswan.org]...fec0::10[carol@strongswan.org] May 1 02:01:49 moon charon: 07[CFG] selected peer config 'rw' May 1 02:01:49 moon charon: 07[CFG] fetching certificate from 'http://ip6-winnetou.strongswan.org/certs/rfc3779/0b5362afd8838bafb66c854732b490d5d8318261' ... May 1 02:01:49 moon charon: 07[CFG] fetched certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=carol@strongswan.org" May 1 02:01:49 moon charon: 07[CFG] using certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=carol@strongswan.org" May 1 02:01:49 moon charon: 07[CFG] using trusted ca certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:49 moon charon: 07[CFG] checking certificate status of "C=CH, O=Linux strongSwan, OU=RFC3779, CN=carol@strongswan.org" May 1 02:01:49 moon charon: 07[CFG] fetching crl from 'http://ip6-winnetou.strongswan.org/strongswan_rfc3779.crl' ... May 1 02:01:49 moon charon: 07[CFG] using trusted certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:49 moon charon: 07[CFG] crl correctly signed by "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:49 moon charon: 07[CFG] crl is valid: until May 15 20:17:23 2012 May 1 02:01:49 moon charon: 07[CFG] certificate status is good May 1 02:01:49 moon charon: 07[CFG] reached self-signed root ca with a path length of 0 May 1 02:01:49 moon charon: 07[IKE] authentication of 'carol@strongswan.org' with RSA signature successful May 1 02:01:49 moon charon: 07[IKE] peer supports MOBIKE May 1 02:01:49 moon charon: 07[IKE] authentication of 'moon.strongswan.org' (myself) with RSA signature successful May 1 02:01:49 moon charon: 07[IKE] IKE_SA rw[1] established between fec0::1[moon.strongswan.org]...fec0::10[carol@strongswan.org] May 1 02:01:49 moon charon: 07[IKE] scheduling reauthentication in 3400s May 1 02:01:49 moon charon: 07[IKE] maximum IKE_SA lifetime 3580s May 1 02:01:49 moon charon: 07[IKE] sending hash-and-url "http://ip6-winnetou.strongswan.org/certs/rfc3779/533394399c61128c957881790d70511537798da1" May 1 02:01:49 moon charon: 07[IKE] sending end entity cert "C=CH, O=Linux strongSwan, OU=RFC3779, CN=moon.strongswan.org" May 1 02:01:49 moon charon: 07[IKE] checking certificate-based traffic selector constraints [RFC 3779] May 1 02:01:49 moon charon: 07[IKE] TS fec0::10/128 is contained in address block constraint fec0::10/128 May 1 02:01:49 moon charon: 07[IKE] CHILD_SA rw{1} established with SPIs c2ffa2c7_i c145f084_o and TS fec1::/16 === fec0::10/128 May 1 02:01:50 moon charon: 07[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_6_ADDR) ] May 1 02:01:50 moon charon: 07[NET] sending packet: from fec0::1[4500] to fec0::10[4500] May 1 02:01:50 moon charon: 16[IKE] old path is not available anymore, try to find another May 1 02:01:50 moon charon: 16[IKE] looking for a route to fec0::10 ... May 1 02:01:50 moon charon: 16[IKE] looking for a route to 192.168.0.100 ... May 1 02:01:50 moon charon: 16[IKE] sending address list update using MOBIKE, implicitly requesting an address change May 1 02:01:50 moon charon: 16[ENC] generating INFORMATIONAL request 0 [ ] May 1 02:01:50 moon charon: 16[IKE] checking path 192.168.0.1[4500] - 192.168.0.100[4500] May 1 02:01:50 moon charon: 16[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] May 1 02:01:50 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:01:50 moon charon: 09[NET] received packet: from fec0::20[500] to fec0::1[500] May 1 02:01:50 moon charon: 09[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ] May 1 02:01:50 moon charon: 09[IKE] fec0::20 is initiating an IKE_SA May 1 02:01:50 moon charon: 09[IKE] sending cert request for "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:50 moon charon: 09[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) N(HTTP_CERT_LOOK) CERTREQ N(MULT_AUTH) ] May 1 02:01:50 moon charon: 09[NET] sending packet: from fec0::1[500] to fec0::20[500] May 1 02:01:50 moon charon: 02[IKE] old path is not available anymore, try to find another May 1 02:01:50 moon charon: 02[IKE] looking for a route to fec0::10 ... May 1 02:01:50 moon charon: 02[IKE] looking for a route to 192.168.0.100 ... May 1 02:01:50 moon charon: 02[IKE] sending address list update using MOBIKE, implicitly requesting an address change May 1 02:01:50 moon charon: 05[NET] received packet: from fec0::20[4500] to fec0::1[4500] May 1 02:01:50 moon charon: 05[ENC] parsed IKE_AUTH request 1 [ IDi CERT N(INIT_CONTACT) N(HTTP_CERT_LOOK) CERTREQ IDr AUTH SA TSi TSr N(MOBIKE_SUP) N(ADD_4_ADDR) N(MULT_AUTH) N(EAP_ONLY) ] May 1 02:01:50 moon charon: 05[IKE] received cert request for "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:50 moon charon: 05[IKE] received hash-and-url for end entity cert "http://ip6-winnetou.strongswan.org/certs/rfc3779/6b5aec8fe9dcb8d0f707490abc84ab0890a7d2da" May 1 02:01:50 moon charon: 05[CFG] looking for peer configs matching fec0::1[moon.strongswan.org]...fec0::20[dave@strongswan.org] May 1 02:01:50 moon charon: 05[CFG] selected peer config 'rw' May 1 02:01:50 moon charon: 05[CFG] fetching certificate from 'http://ip6-winnetou.strongswan.org/certs/rfc3779/6b5aec8fe9dcb8d0f707490abc84ab0890a7d2da' ... May 1 02:01:50 moon charon: 05[CFG] fetched certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=dave@strongswan.org" May 1 02:01:50 moon charon: 05[CFG] using certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=dave@strongswan.org" May 1 02:01:50 moon charon: 05[CFG] using trusted ca certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:50 moon charon: 05[CFG] checking certificate status of "C=CH, O=Linux strongSwan, OU=RFC3779, CN=dave@strongswan.org" May 1 02:01:50 moon charon: 05[CFG] using trusted certificate "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:50 moon charon: 05[CFG] crl correctly signed by "C=CH, O=Linux strongSwan, OU=RFC3779, CN=strongSwan RFC3779 CA" May 1 02:01:50 moon charon: 05[CFG] crl is valid: until May 15 20:17:23 2012 May 1 02:01:50 moon charon: 05[CFG] using cached crl May 1 02:01:50 moon charon: 05[CFG] certificate status is good May 1 02:01:50 moon charon: 05[CFG] reached self-signed root ca with a path length of 0 May 1 02:01:50 moon charon: 05[IKE] authentication of 'dave@strongswan.org' with RSA signature successful May 1 02:01:51 moon charon: 05[IKE] peer supports MOBIKE May 1 02:01:51 moon charon: 05[IKE] authentication of 'moon.strongswan.org' (myself) with RSA signature successful May 1 02:01:51 moon charon: 05[IKE] IKE_SA rw[2] established between fec0::1[moon.strongswan.org]...fec0::20[dave@strongswan.org] May 1 02:01:51 moon charon: 05[IKE] scheduling reauthentication in 3312s May 1 02:01:51 moon charon: 05[IKE] maximum IKE_SA lifetime 3492s May 1 02:01:51 moon charon: 05[IKE] sending hash-and-url "http://ip6-winnetou.strongswan.org/certs/rfc3779/533394399c61128c957881790d70511537798da1" May 1 02:01:51 moon charon: 05[IKE] sending end entity cert "C=CH, O=Linux strongSwan, OU=RFC3779, CN=moon.strongswan.org" May 1 02:01:51 moon charon: 05[IKE] checking certificate-based traffic selector constraints [RFC 3779] May 1 02:01:51 moon charon: 05[IKE] TS fec0::20/128 is contained in address block constraint fec0::20/128 May 1 02:01:51 moon charon: 05[IKE] CHILD_SA rw{2} established with SPIs c69edca7_i cda3155d_o and TS fec1::/16 === fec0::20/128 May 1 02:01:51 moon charon: 05[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_4_ADDR) N(ADD_6_ADDR) ] May 1 02:01:51 moon charon: 05[NET] sending packet: from fec0::1[4500] to fec0::20[4500] May 1 02:01:52 moon charon: 04[IKE] path probing attempt 1 May 1 02:01:52 moon charon: 04[IKE] checking path 192.168.0.1[4500] - 192.168.0.100[4500] May 1 02:01:52 moon charon: 04[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] May 1 02:01:52 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:01:55 moon charon: 03[IKE] path probing attempt 2 May 1 02:01:55 moon charon: 03[IKE] checking path 192.168.0.1[4500] - 192.168.0.100[4500] May 1 02:01:55 moon charon: 03[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] May 1 02:01:55 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:01:57 moon charon: 09[IKE] old path is not available anymore, try to find another May 1 02:01:57 moon charon: 09[IKE] looking for a route to fec0::20 ... May 1 02:01:57 moon charon: 09[IKE] looking for a route to 192.168.0.200 ... May 1 02:01:57 moon charon: 09[IKE] sending address list update using MOBIKE, implicitly requesting an address change May 1 02:01:57 moon charon: 09[ENC] generating INFORMATIONAL request 0 [ ] May 1 02:01:57 moon charon: 09[IKE] checking path 192.168.0.1[4500] - 192.168.0.200[4500] May 1 02:01:57 moon charon: 09[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.200[4500] May 1 02:01:57 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:01:57 moon charon: 09[IKE] old path is not available anymore, try to find another May 1 02:01:57 moon charon: 09[IKE] looking for a route to fec0::10 ... May 1 02:01:57 moon charon: 09[IKE] looking for a route to 192.168.0.100 ... May 1 02:01:57 moon charon: 09[IKE] sending address list update using MOBIKE, implicitly requesting an address change May 1 02:01:57 moon charon: 12[IKE] path probing attempt 3 May 1 02:01:57 moon charon: 12[IKE] checking path 192.168.0.1[4500] - 192.168.0.100[4500] May 1 02:01:57 moon charon: 12[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] May 1 02:01:57 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:01:59 moon charon: 08[IKE] path probing attempt 1 May 1 02:01:59 moon charon: 08[IKE] checking path 192.168.0.1[4500] - 192.168.0.200[4500] May 1 02:01:59 moon charon: 08[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.200[4500] May 1 02:01:59 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:02:00 moon charon: 07[IKE] path probing attempt 4 May 1 02:02:00 moon charon: 07[IKE] checking path 192.168.0.1[4500] - 192.168.0.100[4500] May 1 02:02:00 moon charon: 07[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] May 1 02:02:00 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:02:02 moon charon: 16[IKE] path probing attempt 2 May 1 02:02:02 moon charon: 16[IKE] checking path 192.168.0.1[4500] - 192.168.0.200[4500] May 1 02:02:02 moon charon: 16[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.200[4500] May 1 02:02:02 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:02:02 moon charon: 09[IKE] path probing attempt 5 May 1 02:02:02 moon charon: 09[IKE] checking path 192.168.0.1[4500] - 192.168.0.100[4500] May 1 02:02:02 moon charon: 09[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] May 1 02:02:02 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:02:04 moon charon: 12[IKE] path probing attempt 3 May 1 02:02:04 moon charon: 12[IKE] checking path 192.168.0.1[4500] - 192.168.0.200[4500] May 1 02:02:04 moon charon: 12[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.200[4500] May 1 02:02:04 moon charon: 11[NET] error writing to socket: Operation not permitted May 1 02:02:05 moon charon: 00[DMN] signal of type SIGINT received. Shutting down May 1 02:02:07 moon charon: 00[KNL] received netlink error: No route to host (113)