| Title | Processing invalid proposal(Encryption Algorithm) * |
| CommandLine | ./ENODE/I_A_RFC2408_5_4_2_3_SA.seq -pkt ./ENODE/I_A_RFC2408_5_4_2_3_SA.def test_type=BASIC -log 44.html -ti Processing invalid proposal(Encryption Algorithm) * |
| TestVersion | undefined |
| ToolVersion | REL_3_0_8 |
| Start | 2006/03/17 22:58:43 |
| Tn | /usr/local/v6eval//etc//tn.def |
| Nu | /usr/local/v6eval//etc//nut.def |
| Pkt | ./ENODE/I_A_RFC2408_5_4_2_3_SA.def |
| System | freebsd-i386 |
| TargetName | freebsd5.4 |
| HostName | racoon |
| Type | host |
| 22:58:43 | Start |
|
*** Target IKE initialization phase *** Target: Reset IKE SA entries: saddump |
|
| 22:58:43 |
vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 saddump ''
Connected dell# dell# /usr/local/sbin/setkey -c <<EOD dump; flush; EOD ? dump; ? flush; ? EOD No SAD entries. dell# dell# sendMessagesSync: never got /usr/local/sbin/setkey -c <<EODdump;flush;EOD echo $status 0 dell# kill -TERM `head -1 /var/run/racoon.pid` head: /var/run/racoon.pid: No such file or directory dell# echo $status dell# echo $status 1 dell# /bin/rm -f /var/run/racoon.pid dell# dell# echo $status 0~ [EOT] |
| Target: Clear SPD entries: spddump | |
| 22:58:51 |
vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 spddump ''
Connected dell# dell# /usr/local/sbin/setkey -c <<EOD spddump; spdflush;? spddump; EOD ? spdflush; EOD ? EOD No SPD entries. dell# dell# sendMessagesSync: never got /usr/local/sbin/setkey -c <<EODspddump;spdflush;EOD echo $status 0~ [EOT] |
| Target: Set SPD entries: src=3ffe:501:ffff:100:290:99ff:fe7e:3e52 dst=3ffe:501:ffff:101::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Transport | |
| 22:58:59 |
vRemote(ipsecSetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecSetSPD.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 src=3ffe:501:ffff:100:290:99ff:fe7e:3e52 dst=3ffe:501:ffff:101::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Transport ''
Connected
dell#
dell# /usr/local/sbin/setkey -c <<EOD
spdadd 3ffe:501:ffff:100:290:99ff:fe7e:3e52 3ffe:501:ffff:101::11
any
-P out ipsec
esp/transport/3ffe:501:ffff:100:290:99ff:fe7e:3e52-3ffe:501:ffff:101::11/require
;
spddump;
EOD
? spdadd 3ffe:501:ffff:100:290:99ff:fe7e:3e52 3ffe:501:ffff:101::11
any
-P out ipsec
esp/transport/3ffe:501:ffff:100:290:99ff:fe7e:3e52-3ffe:501:ffff:101::11/require
;
spddump;
EOD
? any
? -P out ipsec
? esp/transport/3ffe:501:ffff:100:290:99ff:fe7e:3e52-3ffe:501:ffff:101::1 1/require
? ;
? spddump;
? EOD
3ffe:501:ffff:100:290:99ff:fe7e:3e52[any] 3ffe:501:ffff:101::11[any] any
out ipsec
esp/transport/3ffe:501:ffff:100:290:99ff:fe7e:3e52-3ffe:501:ffff:101::11/require
created: Mar 17 14:06:18 2006 lastused: Mar 17 14:06:18 2006
lifetime: 0(s) validtime: 0(s)
spid=16979 seq=0 pid=983
refcnt=1
dell#
dell# sendMessagesSync: never got /usr/local/sbin/setkey -c <<EODspdadd 3ffe:501:ffff:100:290:99ff:fe7e:3e52 3ffe:501:ffff:101::11 any -P out ipsec esp/transport/3ffe:501:ffff:100:290:99ff:fe7e:3e52-3ffe:501:ffff:101::11/require;spddump;EOD
echo $status
0~
[EOT]
|
| Target: Set IKE SA entries: dst=3ffe:501:ffff:101::11 dst_port=500 exchange_mode=aggressive doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:100:290:99ff:fe7e:3e52 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:101::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100:290:99ff:fe7e:3e52 ph2_dst_id=3ffe:501:ffff:101::11 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA | |
| 22:59:07 |
vRemote(ikeSetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeSetSA.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 dst=3ffe:501:ffff:101::11 dst_port=500 exchange_mode=aggressive doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:100:290:99ff:fe7e:3e52 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:101::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100:290:99ff:fe7e:3e52 ph2_dst_id=3ffe:501:ffff:101::11 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA ''
Connected dell# dell# ~[set] echocheck dell# dell# ~[put] freebsd-i386.psk.txt /tmp/psk.txt Ddell# dell# dell# /bin/chmod 600 /tmp/psk.txt dell# echo $status 0 dell# ~[set] echocheck dell# dell# ~[put] freebsd-i386.ike.conf /tmp/ike.conf Ddell# dell# dell# test -f /var/run/racoon.pid &&kill -TERM `head -1 /var/run/racoon.pid` dell# dell# echo $status 1 dell# /usr/local/sbin/racoon -f /tmp/ike.conf dell# echo $status dell# echo $status 0~ [EOT] |
| 22:59:20 | vRemote(ikeEnable.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeEnable.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 '' |
|
*** Target initialization phase *** |
|
| 22:59:20 | Start Capturing Packets (Link0) |
| 22:59:20 | vRecv(Link0,rs_from_nut rs_from_nut_wsll) timeout:15 cntLimit:0 seektime:0 vRecv() return status=1 |
|
*** Target testing phase *** |
|
| 22:59:35 | Clear Captured Packets (Link0) |
|
*** Phase-1 1st message recv *** HOST1(NUT) send ICMP to HOST2(TN) |
|
| 22:59:35 |
vRemoteAsync(ping6.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ping6.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 count=2 interval=1 if=rl0 addr=3ffe:501:ffff:101::11''
Link to remote control log |
| 22:59:35 | vRecv(Link0,isakmp_phase1_recv ns_uni rs_from_nut rs_from_nut_wsll ns_uni_tll_sll ns_uni_sll ns_multi_llt ns_multi) timeout:10 cntLimit:0 seektime:0 Recv 1st message from HOST1(NUT) |
|
OK payload_check *** Phase-1 2nd message send *** |
|
| 22:59:39 | Clear Captured Packets (Link0) |
| 22:59:39 |
vSend(Link0,isakmp_phase1_send_2nd_agg) Send 2nd message from HOST2(TN) |
|
*** Phase-1 3rd message recv *** |
|
| 22:59:39 | vRecv(Link0,isakmp_phase1_recv_3rd isakmp_phase1_recv_3rd_agg_enc ns_uni rs_from_nut rs_from_nut_wsll ns_uni_tll_sll ns_uni_sll ns_multi_llt ns_multi) timeout:5 cntLimit:0 seektime:0 vRecv() return status=1 |
|
NG:Receive no packets OK:Phase-1 3rd message is not returned. Check the proposal to confirm it is valid(Encryption Algorithm) is correct *** Target test finish *** |
|
| 22:59:44 | Stop Capturing Packets (Link0) |
| 22:59:44 |
vRemoteAsyncWait()
Link to remote control start point sleep 3 [sec] for escaping critical point of asynchronous remoteconf. Connected dell# dell# /sbin/ping6 -n -c 2 -i 1 -h 64 -s 2 -p 00 -I rl0 3ffe:501:ffff:101::11 PATTERN: 0x00 PING6(50=40+8+2 bytes) 3ffe:501:ffff:100:290:99ff:fe7e:3e52 --> 3ffe:501:ffff:101::11 --- 3ffe:501:ffff:101::11 ping6 statistics --- 2 packets transmitted, 0 packets received, 100.0% packet loss dell# echo $status dell# echo $status 1~ [EOT] |
| Target: Reset IKE SA entries: saddump | |
| 22:59:53 |
vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 saddump ''
Connected dell# dell# /usr/local/sbin/setkey -c <<EOD dump; flush; EOD ? dump; ? flush; ? EOD No SAD entries. dell# dell# sendMessagesSync: never got /usr/local/sbin/setkey -c <<EODdump;flush;EOD echo $status 0 dell# kill -TERM `head -1 /var/run/racoon.pid` dell# echo $status dell# echo $status 0 dell# /bin/rm -f /var/run/racoon.pid dell# dell# echo $status 0~ [EOT] |
| Target: Clear SPD entries: spddump | |
| 23:00:00 |
vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d ucom0 -o 1 spddump ''
Connected
dell#
dell# /usr/local/sbin/setkey -c <<EOD
spddump;
spdflush;? spddump;
EOD
? spdflush;
EOD
? EOD
3ffe:501:ffff:100:290:99ff:fe7e:3e52[any] 3ffe:501:ffff:101::11[any] any
out ipsec
esp/transport/3ffe:501:ffff:100:290:99ff:fe7e:3e52-3ffe:501:ffff:101::11/require
created: Mar 17 14:06:18 2006 lastused: Mar 17 14:06:57 2006
lifetime: 0(s) validtime: 0(s)
spid=16979 seq=0 pid=994
refcnt=1
dell#
dell# sendMessagesSync: never got /usr/local/sbin/setkey -c <<EODspddump;spdflush;EOD
echo $status
0~
[EOT]
|
|
OK |
|
| 23:00:08 | End |
Frame_Ether (length:338) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:00:00:00:11 | | SourceAddress = 00:90:99:7e:3e:52 | | Type = 34525 | Packet_IPv6 (length:324) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 284 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:100:290:99ff:fe7e:3e52 | | | DestinationAddress = 3ffe:501:ffff:101::11 | | Upp_UDP (length:284) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 284 | | | | Checksum = 29795 calc(29795) | | | Udp_ISAKMP (length:276) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 2b79cd108ab827d5 | | | | | ResponderCookie = 0000000000000000 | | | | | NextPayload = 1 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 4 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 276 | | | | Pld_ISAKMP_SA_IPsec_IDonly (length:52) | | | | | NextPayload = 4 | | | | | Reserved1 = 0 | | | | | PayloadLength = 52 | | | | | DOI = 1 | | | | | Situation = 1 | | | | | Pld_ISAKMP_P_ISAKMP (length:40) | | | | | | NextPayload = 0 | | | | | | Reserved1 = 0 | | | | | | PayloadLength = 40 | | | | | | ProposalNumber = 1 | | | | | | ProtocolID = 1 | | | | | | SPIsize = 0 | | | | | | NumOfTransforms = 1 | | | | | | SPI = | | | | | | Pld_ISAKMP_T (length:32) | | | | | | | NextPayload = 0 | | | | | | | Reserved1 = 0 | | | | | | | PayloadLength = 32 | | | | | | | TransformNumber = 1 | | | | | | | TransformID = 1 | | | | | | | Reserved2 = 0 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 11 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 12 | | | | | | | | Value = 28800 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 1 | | | | | | | | Value = 5 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 3 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 2 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 4 | | | | | | | | Value = 2 | | | | Pld_ISAKMP_KE (length:132) | | | | | NextPayload = 10 | | | | | Reserved1 = 0 | | | | | PayloadLength = 132 | | | | | KeyExchangeData = | | | | | eef80673 45239b95 8cea8ee2 6b47d212 470e6d2c 665af220 ee270c15 db61403e | | | | | ea88f1a4 e72be9c0 b8247160 e438e988 17f20ea1 31b76d4a 72aae738 e0a527b1 | | | | | 8b5f6e08 6b68bcbb 7fc3580f 091432e8 d582b09f 5276ca3e 828acb72 9ad9a81d | | | | | daa2f3c1 de1c40f1 61305f33 e11e2105 d57db21b f3bf3761 f079e925 19474c4f | | | | Pld_ISAKMP_NONCE (length:20) | | | | | NextPayload = 5 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | NonceData = a3d3890b 061c3ef4 6a1f0cd7 6f85d6b1 | | | | Pld_ISAKMP_ID_IPV6_ADDR (length:24) | | | | | NextPayload = 13 | | | | | Reserved1 = 0 | | | | | PayloadLength = 24 | | | | | IDtype = 5 | | | | | ProtocolID = 17 | | | | | Port = 500 | | | | | ID = 3ffe:501:ffff:100:290:99ff:fe7e:3e52 | | | | Pld_ISAKMP_VID (length:20) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | VID = afcad713 68a1f1c9 6b8696fc 77570100 ===isakmp_phase1_recv=================================
Frame_Ether (length:346) | Hdr_Ether (length:14) | | DestinationAddress = 00:90:99:7e:3e:52 | | SourceAddress = 00:00:00:00:00:11 | | Type = 34525 | Packet_IPv6 (length:332) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 292 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:101::11 | | | DestinationAddress = 3ffe:501:ffff:100:290:99ff:fe7e:3e52 | | Upp_UDP (length:292) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 292 | | | | Checksum = 1837 calc(1837) | | | Udp_ISAKMP (length:284) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 2b79cd108ab827d5 | | | | | ResponderCookie = 8cb1f3ba871ba907 | | | | | NextPayload = 1 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 4 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 284 | | | | Pld_ISAKMP_SA_IPsec_IDonly (length:56) | | | | | NextPayload = 4 | | | | | Reserved1 = 0 | | | | | PayloadLength = 56 | | | | | DOI = 1 | | | | | Situation = 1 | | | | | Pld_ISAKMP_P_ISAKMP (length:44) | | | | | | NextPayload = 0 | | | | | | Reserved1 = 0 | | | | | | PayloadLength = 44 | | | | | | ProposalNumber = 1 | | | | | | ProtocolID = 1 | | | | | | SPIsize = 0 | | | | | | NumOfTransforms = 1 | | | | | | SPI = | | | | | | Pld_ISAKMP_T (length:36) | | | | | | | NextPayload = 0 | | | | | | | Reserved1 = 0 | | | | | | | PayloadLength = 36 | | | | | | | TransformNumber = 1 | | | | | | | TransformID = 1 | | | | | | | Reserved2 = 0 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 1 | | | | | | | | Value = 65000 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 2 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 3 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 4 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 11 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TLV (length:8) | | | | | | | | AF = 0 | | | | | | | | Type = 12 | | | | | | | | Length = 4 | | | | | | | | Value = 00007080 | | | | Pld_ISAKMP_KE (length:132) | | | | | NextPayload = 10 | | | | | Reserved1 = 0 | | | | | PayloadLength = 132 | | | | | KeyExchangeData = | | | | | a2114a36 fa961c0c f295d23e 94647615 6a9786ef ae40c10d 497b3a58 196bf78a | | | | | e99e7de3 57a60dc7 189b9793 d4903845 d6352c9e 270a73bb 79094925 6f2712d3 | | | | | c5e98f1b cc243d86 f85554c1 dc38f72b f6940e7a f7cf084b 8bdb953c fa4140c3 | | | | | e353f0a1 cead5538 8d728fd3 c382dbad fac3bc70 08f9aa59 75a62e2b fd043e2a | | | | Pld_ISAKMP_NONCE (length:20) | | | | | NextPayload = 5 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | NonceData = 00000000 00000000 00000000 00000000 | | | | Pld_ISAKMP_ID_IPV6_ADDR (length:24) | | | | | NextPayload = 8 | | | | | Reserved1 = 0 | | | | | PayloadLength = 24 | | | | | IDtype = 5 | | | | | ProtocolID = 17 | | | | | Port = 500 | | | | | ID = 3ffe:501:ffff:101::11 | | | | Pld_ISAKMP_HASH (length:24) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 24 | | | | | HashData = | | | | | ebc9bdfa d2ca4449 5f51ba74 b07bea60 ad2a9cc5