Jul 20 15:39:22 sun charon: 01[DMN] starting charon (strongSwan Version 4.2.17) Jul 20 15:39:22 sun charon: 01[CFG] loading ca certificates from '/etc/ipsec.d/cacerts' Jul 20 15:39:22 sun charon: 01[LIB] loaded certificate file '/etc/ipsec.d/cacerts/strongswanCert.pem' Jul 20 15:39:22 sun charon: 01[CFG] loading aa certificates from '/etc/ipsec.d/aacerts' Jul 20 15:39:22 sun charon: 01[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts' Jul 20 15:39:22 sun charon: 01[CFG] loading attribute certificates from '/etc/ipsec.d/acerts' Jul 20 15:39:22 sun charon: 01[CFG] loading crls from '/etc/ipsec.d/crls' Jul 20 15:39:22 sun charon: 01[CFG] loading secrets from '/etc/ipsec.secrets' Jul 20 15:39:22 sun charon: 01[CFG] loaded private key file '/etc/ipsec.d/private/sunKey.pem' Jul 20 15:39:22 sun charon: 01[DMN] loaded plugins: curl aes des sha1 sha2 md5 gmp random x509 pubkey hmac xcbc stroke kernel-netlink Jul 20 15:39:22 sun charon: 01[KNL] listening on interfaces: Jul 20 15:39:22 sun charon: 01[KNL] eth0 Jul 20 15:39:22 sun charon: 01[KNL] 192.168.0.2 Jul 20 15:39:22 sun charon: 01[KNL] fec0::2 Jul 20 15:39:22 sun charon: 01[KNL] fe80::fcfd:c0ff:fea8:2 Jul 20 15:39:22 sun charon: 01[KNL] eth1 Jul 20 15:39:22 sun charon: 01[KNL] 10.2.0.1 Jul 20 15:39:22 sun charon: 01[KNL] fec2::1 Jul 20 15:39:22 sun charon: 01[KNL] fe80::fcfd:aff:fe02:1 Jul 20 15:39:22 sun charon: 01[DMN] integrity test of libstrongswan code Jul 20 15:39:22 sun charon: 01[LIB] TEXT: 0x40024e08 + 52128 = 0x400319a8 Jul 20 15:39:22 sun charon: 01[LIB] RODATA: 0x40031a20 + 9716 = 0x40034014 Jul 20 15:39:22 sun charon: 01[LIB] SHA-1 HMAC key: strongSwan Version 4.2.17 Jul 20 15:39:22 sun charon: 01[LIB] SHA-1 HMAC sig: a8:79:ce:93:03:c1:35:1f:be:cd:2f:9b:ac:57:0d:9a Jul 20 15:39:22 sun charon: 01[DMN] integrity test passed Jul 20 15:39:22 sun charon: 01[JOB] spawning 16 worker threads Jul 20 15:39:22 sun charon: 03[CFG] received stroke: add connection 'remote' Jul 20 15:39:22 sun charon: 03[CFG] left nor right host is our side, assuming left=local Jul 20 15:39:22 sun charon: 03[LIB] loaded certificate file '/etc/ipsec.d/certs/sunCert.pem' Jul 20 15:39:22 sun charon: 03[CFG] peerid %any not confirmed by certificate, defaulting to subject DN Jul 20 15:39:22 sun charon: 03[CFG] added configuration 'remote': %any[C=CH, O=Linux strongSwan, CN=sun.strongswan.org]...%any[%any] Jul 20 15:39:28 sun charon: 10[NET] received packet: from 192.168.0.1[500] to 192.168.0.2[500] Jul 20 15:39:28 sun charon: 10[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ] Jul 20 15:39:28 sun charon: 10[IKE] 192.168.0.1 is initiating an IKE_SA Jul 20 15:39:28 sun charon: 10[IKE] sending cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:28 sun charon: 10[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ ] Jul 20 15:39:28 sun charon: 10[NET] sending packet: from 192.168.0.2[500] to 192.168.0.1[500] Jul 20 15:39:29 sun charon: 11[NET] received packet: from 192.168.0.1[500] to 192.168.0.2[500] Jul 20 15:39:29 sun charon: 11[ENC] parsed IKE_AUTH request 1 [ IDi CERT CERTREQ IDr AUTH N(IPCOMP_SUPP) N(USE_TRANSP) SA TSi TSr ] Jul 20 15:39:29 sun charon: 11[IKE] received cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:29 sun charon: 11[IKE] received end entity cert "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" Jul 20 15:39:29 sun charon: 11[CFG] using certificate "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" Jul 20 15:39:29 sun charon: 11[CFG] using trusted ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:29 sun charon: 11[CFG] checking certificate status of "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" Jul 20 15:39:29 sun charon: 11[CFG] fetching crl from 'http://crl.strongswan.org/strongswan.crl' ... Jul 20 15:39:29 sun charon: 11[CFG] using trusted certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:29 sun charon: 11[CFG] crl correctly signed by "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:29 sun charon: 11[CFG] crl is valid: until Aug 19 13:47:17 2009 Jul 20 15:39:29 sun charon: 11[CFG] certificate status is good Jul 20 15:39:29 sun charon: 11[IKE] authentication of 'C=CH, O=Linux strongSwan, CN=moon.strongswan.org' with RSA signature successful Jul 20 15:39:29 sun charon: 11[CFG] found matching peer config "remote": C=CH, O=Linux strongSwan, CN=sun.strongswan.org...%any with prio 21.2 Jul 20 15:39:29 sun charon: 11[IKE] authentication of 'C=CH, O=Linux strongSwan, CN=sun.strongswan.org' (myself) with RSA signature successful Jul 20 15:39:29 sun charon: 11[IKE] scheduling reauthentication in 3413s Jul 20 15:39:29 sun charon: 11[IKE] maximum IKE_SA lifetime 3593s Jul 20 15:39:29 sun charon: 11[IKE] IKE_SA remote[1] established between 192.168.0.2[C=CH, O=Linux strongSwan, CN=sun.strongswan.org]...192.168.0.1[C=CH, O=Linux strongSwan, CN=moon.strongswan.org] Jul 20 15:39:29 sun charon: 11[IKE] sending end entity cert "C=CH, O=Linux strongSwan, CN=sun.strongswan.org" Jul 20 15:39:29 sun charon: 11[IKE] CHILD_SA remote{1} established with SPIs c7fa94d1_i cf6f216c_o and TS 192.168.0.2/32 === 192.168.0.1/32 Jul 20 15:39:29 sun charon: 11[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH N(IPCOMP_SUPP) N(USE_TRANSP) SA TSi TSr N(AUTH_LFT) ] Jul 20 15:39:29 sun charon: 11[NET] sending packet: from 192.168.0.2[500] to 192.168.0.1[500] Jul 20 15:39:32 sun charon: 12[NET] received packet: from 10.2.0.10[500] to 10.2.0.1[500] Jul 20 15:39:32 sun charon: 12[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ] Jul 20 15:39:32 sun charon: 12[IKE] 10.2.0.10 is initiating an IKE_SA Jul 20 15:39:32 sun charon: 12[IKE] sending cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:32 sun charon: 12[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ ] Jul 20 15:39:32 sun charon: 12[NET] sending packet: from 10.2.0.1[500] to 10.2.0.10[500] Jul 20 15:39:32 sun charon: 13[NET] received packet: from 10.2.0.10[500] to 10.2.0.1[500] Jul 20 15:39:32 sun charon: 13[ENC] parsed IKE_AUTH request 1 [ IDi CERT CERTREQ IDr AUTH N(IPCOMP_SUPP) N(USE_TRANSP) SA TSi TSr ] Jul 20 15:39:32 sun charon: 13[IKE] received cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:32 sun charon: 13[IKE] received end entity cert "C=CH, O=Linux strongSwan, OU=Research, CN=bob@strongswan.org" Jul 20 15:39:32 sun charon: 13[CFG] using certificate "C=CH, O=Linux strongSwan, OU=Research, CN=bob@strongswan.org" Jul 20 15:39:32 sun charon: 13[CFG] using trusted ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:32 sun charon: 13[CFG] checking certificate status of "C=CH, O=Linux strongSwan, OU=Research, CN=bob@strongswan.org" Jul 20 15:39:32 sun charon: 13[CFG] using trusted certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:32 sun charon: 13[CFG] crl correctly signed by "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Jul 20 15:39:32 sun charon: 13[CFG] crl is valid: until Aug 19 13:47:17 2009 Jul 20 15:39:32 sun charon: 13[CFG] using cached crl Jul 20 15:39:32 sun charon: 13[CFG] certificate status is good Jul 20 15:39:32 sun charon: 13[IKE] authentication of 'C=CH, O=Linux strongSwan, OU=Research, CN=bob@strongswan.org' with RSA signature successful Jul 20 15:39:32 sun charon: 13[CFG] found matching peer config "remote": C=CH, O=Linux strongSwan, CN=sun.strongswan.org...%any with prio 21.2 Jul 20 15:39:32 sun charon: 13[IKE] authentication of 'C=CH, O=Linux strongSwan, CN=sun.strongswan.org' (myself) with RSA signature successful Jul 20 15:39:32 sun charon: 13[IKE] scheduling reauthentication in 3370s Jul 20 15:39:32 sun charon: 13[IKE] maximum IKE_SA lifetime 3550s Jul 20 15:39:32 sun charon: 13[IKE] IKE_SA remote[2] established between 10.2.0.1[C=CH, O=Linux strongSwan, CN=sun.strongswan.org]...10.2.0.10[C=CH, O=Linux strongSwan, OU=Research, CN=bob@strongswan.org] Jul 20 15:39:32 sun charon: 13[IKE] sending end entity cert "C=CH, O=Linux strongSwan, CN=sun.strongswan.org" Jul 20 15:39:32 sun charon: 13[IKE] CHILD_SA remote{2} established with SPIs cd185177_i c14093d5_o and TS 10.2.0.1/32 === 10.2.0.10/32 Jul 20 15:39:32 sun charon: 13[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH N(IPCOMP_SUPP) N(USE_TRANSP) SA TSi TSr N(AUTH_LFT) ] Jul 20 15:39:32 sun charon: 13[NET] sending packet: from 10.2.0.1[500] to 10.2.0.10[500] Jul 20 15:39:40 sun charon: 17[IKE] sending DPD request Jul 20 15:39:40 sun charon: 17[ENC] generating INFORMATIONAL request 0 [ ] Jul 20 15:39:40 sun charon: 17[NET] sending packet: from 192.168.0.2[500] to 192.168.0.1[500] Jul 20 15:39:40 sun charon: 09[NET] received packet: from 192.168.0.1[500] to 192.168.0.2[500] Jul 20 15:39:40 sun charon: 09[ENC] parsed INFORMATIONAL response 0 [ ] Jul 20 15:39:43 sun charon: 10[IKE] sending DPD request Jul 20 15:39:43 sun charon: 10[ENC] generating INFORMATIONAL request 0 [ ] Jul 20 15:39:43 sun charon: 10[NET] sending packet: from 10.2.0.1[500] to 10.2.0.10[500] Jul 20 15:39:43 sun charon: 11[NET] received packet: from 10.2.0.10[500] to 10.2.0.1[500] Jul 20 15:39:43 sun charon: 11[ENC] parsed INFORMATIONAL response 0 [ ] Jul 20 15:39:50 sun charon: 09[NET] received packet: from 192.168.0.1[500] to 192.168.0.2[500] Jul 20 15:39:50 sun charon: 09[ENC] parsed INFORMATIONAL request 2 [ ] Jul 20 15:39:50 sun charon: 09[ENC] generating INFORMATIONAL response 2 [ ] Jul 20 15:39:50 sun charon: 09[NET] sending packet: from 192.168.0.2[500] to 192.168.0.1[500] Jul 20 15:39:53 sun charon: 10[IKE] sending DPD request Jul 20 15:39:53 sun charon: 10[ENC] generating INFORMATIONAL request 1 [ ] Jul 20 15:39:53 sun charon: 10[NET] sending packet: from 10.2.0.1[500] to 10.2.0.10[500] Jul 20 15:39:53 sun charon: 11[NET] received packet: from 10.2.0.10[500] to 10.2.0.1[500] Jul 20 15:39:53 sun charon: 11[ENC] parsed INFORMATIONAL response 1 [ ] Jul 20 15:39:55 sun charon: 12[NET] received packet: from 192.168.0.1[500] to 192.168.0.2[500] Jul 20 15:39:55 sun charon: 12[ENC] parsed INFORMATIONAL request 3 [ D ] Jul 20 15:39:55 sun charon: 12[IKE] received DELETE for IKE_SA remote[1] Jul 20 15:39:55 sun charon: 12[IKE] deleting IKE_SA remote[1] between 192.168.0.2[C=CH, O=Linux strongSwan, CN=sun.strongswan.org]...192.168.0.1[C=CH, O=Linux strongSwan, CN=moon.strongswan.org] Jul 20 15:39:55 sun charon: 12[IKE] IKE_SA deleted Jul 20 15:39:55 sun charon: 12[ENC] generating INFORMATIONAL response 3 [ ] Jul 20 15:39:55 sun charon: 12[NET] sending packet: from 192.168.0.2[500] to 192.168.0.1[500] Jul 20 15:39:57 sun charon: 01[DMN] signal of type SIGINT received. Shutting down Jul 20 15:39:57 sun charon: 01[IKE] deleting IKE_SA remote[2] between 10.2.0.1[C=CH, O=Linux strongSwan, CN=sun.strongswan.org]...10.2.0.10[C=CH, O=Linux strongSwan, OU=Research, CN=bob@strongswan.org] Jul 20 15:39:57 sun charon: 01[IKE] sending DELETE for IKE_SA remote[2] Jul 20 15:39:57 sun charon: 01[ENC] generating INFORMATIONAL request 2 [ D ] Jul 20 15:39:57 sun charon: 01[NET] sending packet: from 10.2.0.1[500] to 10.2.0.10[500]