Test Information

TitleAccept both old and new SA for incoming traffic **
CommandLine./SGW/SG_I_RFC2408_5_3_2_2.seq -pkt ./SGW/SG_I_RFC2408_5_3_2_2.def test_phase=2 test_type=BASIC -log 109.html -ti Accept both old and new SA for incoming traffic **
TestVersionundefined
ToolVersionREL_3_0_8
Start2006/03/16 14:41:16
Tn/usr/local/v6eval//etc//tn.def
Nu/usr/local/v6eval//etc//nut.def
Pkt./SGW/SG_I_RFC2408_5_3_2_2.def
Systemfreebsd-i386
TargetNameFreeBSD 5.4-RELEASE
HostNametarget1.tahi.org
Typerouter

Test Sequence Execution Log

14:41:16Start

*** Target IKE initialization phase ***
Target: Reset IKE SA entries: saddump
14:41:17 vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
dump;
flush;
? dump;
? flush;
EOD

? EOD
The result of line 1: No SAD entries.

target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD
echo $status
0
target1# kill -TERM `head -1 /var/run/racoon.pid`
head: /var/run/racoon.pid: No such file or directory

target1# 
target1# echo $status
1
target1# /bin/rm -f /var/run/racoon.pid

target1# 
target1# echo $status
0
~
[EOT]

Target: Clear SPD entries: spddump
14:41:24 vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spddump;
spdfl? spddump;
ush;
EOD

? spdflush;
EOD

? EOD
The result of line 1: No SPD entries.
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD
echo $status
0
~
[EOT]

Target: Set SPD entries: src=3ffe:501:ffff:100::/64 dst=3ffe:501:ffff:104::/64 tsrc=3ffe:501:ffff:102::1 tdst=3ffe:501:ffff:103::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Tunnel
14:41:30 vRemote(ipsecSetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecSetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 src=3ffe:501:ffff:100::/64 dst=3ffe:501:ffff:104::/64 tsrc=3ffe:501:ffff:102::1 tdst=3ffe:501:ffff:103::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Tunnel ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:104::/64
       any
       -P out ipsec
       esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
;
spddump;
EOD

? spdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:104::/64
       any
       -P out ipsec
       esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
;
spddump;
EOD

?        any
?        -P out ipsec
?        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
? ;
? spddump;
? EOD
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:104::/64[any] any
        out ipsec
        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
        created: Mar 16 14:48:40 2006  lastused: Mar 16 14:48:40 2006
        lifetime: 0(s) validtime: 0(s)
        spid=17551 seq=0 pid=1599
        refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:104::/64       any       -P out ipsec       esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require;spddump;EOD
echo $status
0
~
[EOT]

Target: Set SPD entries: dst=3ffe:501:ffff:100::/64 src=3ffe:501:ffff:104::/64 tdst=3ffe:501:ffff:102::1 tsrc=3ffe:501:ffff:103::11 upperspec=any direction=in protocol=PROTO_IPSEC_ESP mode=Tunnel
14:41:36 vRemote(ipsecSetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecSetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 dst=3ffe:501:ffff:100::/64 src=3ffe:501:ffff:104::/64 tdst=3ffe:501:ffff:102::1 tsrc=3ffe:501:ffff:103::11 upperspec=any direction=in protocol=PROTO_IPSEC_ESP mode=Tunnel ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spdadd 3ffe:501:ffff:104::/64 3ffe:501:ffff:100::/64
       any
       -P in ipsec
       esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
;
spddump;
EOD

? spdadd 3ffe:501:ffff:104::/64 3ffe:501:ffff:100::/64
       any
       -P in ipsec
       esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
;
spddump;
EOD

?        any
?        -P in ipsec
?        esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
? ;
? spddump;
? EOD
3ffe:501:ffff:104::/64[any] 3ffe:501:ffff:100::/64[any] any
        in ipsec
        esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
        created: Mar 16 14:48:46 2006  lastused: Mar 16 14:48:46 2006
        lifetime: 0(s) validtime: 0(s)
        spid=17552 seq=1 pid=1600
        refcnt=1
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:104::/64[any] any
        out ipsec
        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
        created: Mar 16 14:48:40 2006  lastused: Mar 16 14:48:40 2006
        lifetime: 0(s) validtime: 0(s)
        spid=17551 seq=0 pid=1600
        refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspdadd 3ffe:501:ffff:104::/64 3ffe:501:ffff:100::/64       any       -P in ipsec       esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require;spddump;EOD
echo $status
0
~
[EOT]

Target: Set IKE SA entries: dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:104::/64 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=60 ph2_p1_t1_lt_unit=seconds ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA
14:41:42 vRemote(ikeSetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeSetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:104::/64 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=60 ph2_p1_t1_lt_unit=seconds ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA ''
Connected

target1# 
target1# ~[set] echocheck

target1# 
target1# ~[put] freebsd-i386.psk.txt /tmp/psk.txt
Dtarget1# 
target1# 
target1# /bin/chmod 600 /tmp/psk.txt
target1# echo $status
0
target1# ~[set] echocheck

target1# 
target1# ~[put] freebsd-i386.ike.conf /tmp/ike.conf
Dtarget1# 
target1# 
target1# test -f /var/run/racoon.pid &&kill -TERM `head -1 /var/run/racoon.pid`

target1# 
target1# echo $status
1
target1# /usr/local/sbin/racoon -f /tmp/ike.conf

target1# 
target1# echo $status
0
~
[EOT]
14:41:56 vRemote(ikeEnable.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeEnable.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 ''


*** Target initialization phase ***
14:41:57Start Capturing Packets (Link0)
14:41:57Start Capturing Packets (Link1)

*** Echo Request message send ***
14:41:57Clear Captured Packets (Link0)
14:41:57Clear Captured Packets (Link1)
14:41:57 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Target pre-test seaquence ***
14:41:57Clear Captured Packets (Link0)

*** Phase-1 1st message recv ***
14:41:57 vRecv(Link0,isakmp_phase1_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:10 cntLimit:0 seektime:0
Receive Neighbor Solicitation from SGW1(NUT)
14:42:03 vSend(Link0,router_na)
Send Neighbor Advertisement(TN)
14:42:03 vRecv(Link0,isakmp_phase1_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:10 cntLimit:0 seektime:0
Recv 1st message from HOST1(NUT)

OK payload_check
*** Phase-1 2nd message send ***
14:42:07Clear Captured Packets (Link0)
14:42:07 vSend(Link0,isakmp_phase1_send_2nd)
Send 2nd message from HOST2(TN)

*** Phase-1 3rd message recv ***
14:42:08 vRecv(Link0,isakmp_phase1_recv_3rd router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv 3rd message from HOST1(NUT)

OK payload_check
*** Phase-1 4th message send ***
14:42:08Clear Captured Packets (Link0)
14:42:09 vSend(Link0,isakmp_phase1_send_4th)
Send 4th message from HOST2(TN)

*** Phase-1 5th message recv ***
14:42:09 vRecv(Link0,isakmp_phase1_recv_5th router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv 5th message from HOST1(NUT)

OK payload_check
*** Phase-1 6th message send ***
14:42:09Clear Captured Packets (Link0)
14:42:09 vSend(Link0,isakmp_phase1_send_6th)
Send 6th message from HOST2(TN)

*** Target testing phase start ***
*** Phase-2 1st message recv ***
14:42:10 vRecv(Link0,isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
recv unexpect packet at 14:42:09
Recv Phase-2 1st message (HDR*, HASH(1), SA, Ni, *, *) from HOST1(NUT)

OK payload_check
*** Phase-2 2nd message send ***
14:42:10Clear Captured Packets (Link0)
14:42:10 vSend(Link0,isakmp_phase2_send_2nd)
Send Phase-2 2nd message (HDR*, HASH(2), SA, Nr) from HOST2(TN)

*** Phase-2 3rd message recv ***
14:42:11 vRecv(Link0,isakmp_phase2_recv_3rd router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv Phase-2 3rd message HDR*, HASH(3) from HOST1(NUT)

OK payload_check
*** 1st IPsec SA is esatblished ***
14:42:11 vRecv(Link0,echo_request_send_net0host1_net4host2 router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
14:42:14Clear Captured Packets (Link0)
14:42:14Clear Captured Packets (Link1)

*** Echo Request message send ***
14:42:14 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)
14:42:15 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:1 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 1 ***
*** Re-key testing phase start ***
*** Echo Request message send ***
14:42:15Clear Captured Packets (Link1)
14:42:15Clear Captured Packets (Link0)
14:42:15 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 4 ##
14:42:15 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 2 ***
## 1st SA elapsed time: 4 ##
14:42:16 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:19Clear Captured Packets (Link1)
14:42:19Clear Captured Packets (Link0)
14:42:19 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 8 ##
14:42:19 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 3 ***
## 1st SA elapsed time: 8 ##
14:42:19 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:23Clear Captured Packets (Link1)
14:42:23Clear Captured Packets (Link0)
14:42:23 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 12 ##
14:42:23 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 4 ***
## 1st SA elapsed time: 12 ##
14:42:23 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:26Clear Captured Packets (Link1)
14:42:26Clear Captured Packets (Link0)
14:42:27 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 16 ##
14:42:27 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 5 ***
## 1st SA elapsed time: 16 ##
14:42:27 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Receive Neighbor Solicitation from SGW1(NUT)
14:42:28 vSend(Link0,router_na)
Send Neighbor Advertisement(TN)
14:42:28 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:31Clear Captured Packets (Link1)
14:42:31Clear Captured Packets (Link0)
14:42:31 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 20 ##
14:42:31 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 6 ***
## 1st SA elapsed time: 21 ##
14:42:32 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:35Clear Captured Packets (Link1)
14:42:35Clear Captured Packets (Link0)
14:42:35 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 24 ##
14:42:35 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 7 ***
## 1st SA elapsed time: 24 ##
14:42:36 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:39Clear Captured Packets (Link1)
14:42:39Clear Captured Packets (Link0)
14:42:39 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 28 ##
14:42:39 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 8 ***
## 1st SA elapsed time: 28 ##
14:42:39 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:43Clear Captured Packets (Link1)
14:42:43Clear Captured Packets (Link0)
14:42:43 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 32 ##
14:42:43 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 9 ***
## 1st SA elapsed time: 32 ##
14:42:43 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:46Clear Captured Packets (Link1)
14:42:46Clear Captured Packets (Link0)
14:42:47 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 36 ##
14:42:47 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 10 ***
## 1st SA elapsed time: 36 ##
14:42:47 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:50Clear Captured Packets (Link1)
14:42:50Clear Captured Packets (Link0)
14:42:50 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 40 ##
14:42:51 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 11 ***
## 1st SA elapsed time: 40 ##
14:42:51 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Receive Neighbor Solicitation from SGW1(NUT)
14:42:52 vSend(Link0,router_na)
Send Neighbor Advertisement(TN)
14:42:52 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:55Clear Captured Packets (Link1)
14:42:55Clear Captured Packets (Link0)
14:42:55 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 44 ##
14:42:55 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 12 ***
## 1st SA elapsed time: 45 ##
14:42:56 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
vRecv() return status=1

NG:Receive no packets
*** Echo Request message send ***
14:42:59Clear Captured Packets (Link1)
14:42:59Clear Captured Packets (Link0)
14:42:59 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

## 1st SA elapsed time: 48 ##
14:42:59 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
Received Encapsulated Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)

*** Encrypted Echo Request message recv 13 ***
## 1st SA elapsed time: 48 ##
14:43:00 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:3 cntLimit:0 seektime:0
!!! ISAKMP PayloadLength decode(57195) over remain size(168)
Recv Phase-2 1st message (HDR*, HASH(1), SA, Ni, *, *) from HOST1(NUT)

OK payload_check
*** Re-Key 1st message recv ***
*** Re-Key 2nd message send ***
14:43:00Clear Captured Packets (Link0)
14:43:00 vSend(Link0,isakmp_phase2_send_2nd)
Send Phase-2 2nd message (HDR*, HASH(2), SA, Nr) from HOST2(TN)

*** Re-Key 3rd message recv ***
14:43:01 vRecv(Link0,isakmp_phase2_recv_3rd router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv Phase-2 3rd message HDR*, HASH(3) from HOST1(NUT)

OK payload_check
*** 2nd IPsec SA is esatblished ***
*** Echo Request message send ***
14:43:01Clear Captured Packets (Link0)
14:43:01Clear Captured Packets (Link1)
14:43:01 vSend(Link1,echo_request_send_net0host1_net4host2)
Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT)
14:43:01 vRecv(Link0,echo_request_recv_esp_tunnel_net2sgw1_net3sgw2 router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:1 seektime:0
!!! ESP Padding size(234) over remain size(62)
recv unexpect packet at 14:43:01
vRecv() return status=2

Target: Reset IKE SA entries: saddump
14:43:02 vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
dump;
flush;
EOD? dump;
? 
flush;
? EOD

3ffe:501:ffff:102::1 3ffe:501:ffff:103::11 
        esp mode=tunnel spi=4097(0x00001001) reqid=0(0x00000000)
        E: 3des-cbc  2ab3fdea 656de56c ca22eb80 49e8129a bd604145 60f2db87
        A: hmac-sha1  687301db 65af9ac9 52ebe603 933e237e 493055c6
        seq=0x00000000 replay=4 flags=0x00000000 state=mature 
        created: Mar 16 14:50:09 2006   current: Mar 16 14:50:11 2006
        diff: 2(s)      hard: 60(s)     soft: 48(s)
        last:                           hard: 0(s)      soft: 0(s)
        current: 0(bytes)       hard: 0(bytes)  soft: 0(bytes)
        allocated: 0    hard: 0 soft: 0
        sadb_seq=2 pid=1610 refcnt=1
3ffe:501:ffff:102::1 3ffe:501:ffff:103::11 
        esp mode=tunnel spi=4096(0x00001000) reqid=0(0x00000000)
        E: 3des-cbc  27fbf339 cd4f1a82 02990e33 827f5451 7992f2a2 8e8098cb
        A: hmac-sha1  a3ef2e9a f3a1edfe 5e0b056a e96c3358 81bb84b3
        seq=0x0000000e replay=4 flags=0x00000000 state=dying 
        created: Mar 16 14:49:19 2006   current: Mar 16 14:50:11 2006
        diff: 52(s)     hard: 60(s)     soft: 48(s)
        last: Mar 16 14:50:10 2006      hard: 0(s)      soft: 0(s)
        current: 1848(bytes)    hard: 0(bytes)  soft: 0(bytes)
        allocated: 14   hard: 0 soft: 0
        sadb_seq=1 pid=1610 refcnt=2
3ffe:501:ffff:103::11 3ffe:501:ffff:102::1 
        esp mode=tunnel spi=133730541(0x07f890ed) reqid=0(0x00000000)
        E: 3des-cbc  98847f51 c633d24e 0fe76c62 2cd01ade e79a01f1 c13d37fd
        A: hmac-sha1  4ed8ca76 feb1be1b 74791611 89ff1709 c662cd06
        seq=0x00000000 replay=4 flags=0x00000000 state=mature 
        created: Mar 16 14:50:09 2006   current: Mar 16 14:50:12 2006
        diff: 3(s)      hard: 60(s)     soft: 48(s)
        last:                           hard: 0(s)      soft: 0(s)
        current: 0(bytes)       hard: 0(bytes)  soft: 0(bytes)
        allocated: 0    hard: 0 soft: 0
        sadb_seq=0 pid=1610 refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD
echo $status
0
target1# kill -TERM `head -1 /var/run/racoon.pid`

target1# 
target1# echo $status
0
target1# /bin/rm -f /var/run/racoon.pid

target1# 
target1# echo $status
0
~
[EOT]

Target: Clear SPD entries: spddump
14:43:08 vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spddump;
spdflush? spddump;
;
EOD

? spdflush;
EOD

? EOD
3ffe:501:ffff:104::/64[any] 3ffe:501:ffff:100::/64[any] any
        in ipsec
        esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
        created: Mar 16 14:48:46 2006  lastused: Mar 16 14:48:46 2006
        lifetime: 0(s) validtime: 0(s)
        spid=17552 seq=1 pid=1613
        refcnt=1
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:104::/64[any] any
        out ipsec
        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
        created: Mar 16 14:48:40 2006  lastused: Mar 16 14:50:10 2006
        lifetime: 0(s) validtime: 0(s)
        spid=17551 seq=0 pid=1613
        refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD
echo $status
0
~
[EOT]
14:43:14End

Packet Reverse Log