Test Information

TitleESP_3DES and HMAC-SHA(Tunnel mode vs HOST) ***
CommandLine./SGW/SG_R_H_RFC2409_5_9.seq -pkt ./SGW/SG_R_H_RFC2409_5_9.def test_phase=2 test_type=BASIC -log 242.html -ti ESP_3DES and HMAC-SHA(Tunnel mode vs HOST) ***
TestVersionundefined
ToolVersionREL_3_0_8
Start2006/03/16 16:13:04
Tn/usr/local/v6eval//etc//tn.def
Nu/usr/local/v6eval//etc//nut.def
Pkt./SGW/SG_R_H_RFC2409_5_9.def
Systemfreebsd-i386
TargetNameFreeBSD 5.4-RELEASE
HostNametarget1.tahi.org
Typerouter

Test Sequence Execution Log

16:13:04Start

*** Target IKE initialization phase ***
Target: Reset IKE SA entries: saddump
16:13:05 vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
dump;
flush;? dump;

EOD

? flush;
EOD

? EOD
The result of line 1: No SAD entries.
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD
echo $status
0
target1# kill -TERM `head -1 /var/run/racoon.pid`
head: /var/run/racoon.pid: No such file or directory

target1# 
target1# echo $status
1
target1# /bin/rm -f /var/run/racoon.pid

target1# 
target1# echo $status
0
~
[EOT]

Target: Clear SPD entries: spddump
16:13:12 vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spddump;
spd? spddump;
flush;
EOD

? spdflush;
EOD

? EOD
The result of line 1: No SPD entries.
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD
echo $status
0
~
[EOT]

Target: Set SPD entries: src=3ffe:501:ffff:100::/64 dst=3ffe:501:ffff:103::11 tsrc=3ffe:501:ffff:102::1 tdst=3ffe:501:ffff:103::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Tunnel
16:13:18 vRemote(ipsecSetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecSetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 src=3ffe:501:ffff:100::/64 dst=3ffe:501:ffff:103::11 tsrc=3ffe:501:ffff:102::1 tdst=3ffe:501:ffff:103::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Tunnel ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:103::11
       any
       -P out ipsec
       esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
;
spddump;
EOD

? spdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:103::11
       any
       -P out ipsec
       esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
;
spddump;
EOD

?        any
?        -P out ipsec
?        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
? ;
? spddump;
? EOD
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:103::11[any] any
        out ipsec
        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
        created: Mar 16 16:20:28 2006  lastused: Mar 16 16:20:28 2006
        lifetime: 0(s) validtime: 0(s)
        spid=19282 seq=0 pid=3160
        refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:103::11       any       -P out ipsec       esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require;spddump;EOD
echo $status
0
~
[EOT]

Target: Set SPD entries: dst=3ffe:501:ffff:100::/64 src=3ffe:501:ffff:103::11 tdst=3ffe:501:ffff:102::1 tsrc=3ffe:501:ffff:103::11 upperspec=any direction=in protocol=PROTO_IPSEC_ESP mode=Tunnel
16:13:24 vRemote(ipsecSetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecSetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 dst=3ffe:501:ffff:100::/64 src=3ffe:501:ffff:103::11 tdst=3ffe:501:ffff:102::1 tsrc=3ffe:501:ffff:103::11 upperspec=any direction=in protocol=PROTO_IPSEC_ESP mode=Tunnel ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spdadd 3ffe:501:ffff:103::11 3ffe:501:ffff:100::/64
       any
       -P in ipsec
       esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
;
spddump;
EOD

? spdadd 3ffe:501:ffff:103::11 3ffe:501:ffff:100::/64
       any
       -P in ipsec
       esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
;
spddump;
EOD

?        any
?        -P in ipsec
?        esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
? ;
? spddump;
? EOD
3ffe:501:ffff:103::11[any] 3ffe:501:ffff:100::/64[any] any
        in ipsec
        esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
        created: Mar 16 16:20:34 2006  lastused: Mar 16 16:20:34 2006
        lifetime: 0(s) validtime: 0(s)
        spid=19283 seq=1 pid=3161
        refcnt=1
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:103::11[any] any
        out ipsec
        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
        created: Mar 16 16:20:28 2006  lastused: Mar 16 16:20:28 2006
        lifetime: 0(s) validtime: 0(s)
        spid=19282 seq=0 pid=3161
        refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspdadd 3ffe:501:ffff:103::11 3ffe:501:ffff:100::/64       any       -P in ipsec       esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require;spddump;EOD
echo $status
0
~
[EOT]

Target: Set IKE SA entries: dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:103::11 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA
16:13:31 vRemote(ikeSetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeSetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:103::11 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA ''
Connected

target1# 
target1# ~[set] echocheck

target1# 
target1# ~[put] freebsd-i386.psk.txt /tmp/psk.txt
Dtarget1# 
target1# 
target1# /bin/chmod 600 /tmp/psk.txt
target1# echo $status
0
target1# ~[set] echocheck

target1# 
target1# ~[put] freebsd-i386.ike.conf /tmp/ike.conf
Dtarget1# 
target1# 
target1# test -f /var/run/racoon.pid &&kill -TERM `head -1 /var/run/racoon.pid`

target1# 
target1# echo $status
1
target1# /usr/local/sbin/racoon -f /tmp/ike.conf

target1# 
target1# echo $status
0
~
[EOT]
16:13:44 vRemote(ikeEnable.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeEnable.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 ''


*** Target initialization phase ***
16:13:45Start Capturing Packets (Link0)
16:13:45Start Capturing Packets (Link1)

*** Target pre-test seaquence ***
*** Phase-1 1st message send ***
16:13:45Clear Captured Packets (Link0)
16:13:45 vSend(Link0,isakmp_phase1_send_1st)
Send 1st message from HOST2(TN)

*** Phase-1 2nd message recieve ***
16:13:46 vRecv(Link0,isakmp_phase1_recv_2nd router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv 2nd message from HOST1(NUT)

OK payload_check
*** Phase-1 3rd message send ***
16:13:46Clear Captured Packets (Link0)
16:13:46 vSend(Link0,isakmp_phase1_send_3rd)
Send 3rd message from HOST2(TN)

*** Phase-1 4th message recieve ***
16:13:46 vRecv(Link0,isakmp_phase1_recv_4th router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv 4th message from HOST1(NUT)

OK payload_check
*** Phase-1 5th message send ***
16:13:47Clear Captured Packets (Link0)
16:13:47 vSend(Link0,isakmp_phase1_send_5th)
Send 5th message from HOST2(TN)

*** Phase-1 6th message recieve ***
16:13:48 vRecv(Link0,isakmp_phase1_recv_6th router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv 6th message from HOST1(NUT)

OK payload_check
*** Target testing phase start ***
*** Phase-2 1st message send ***
16:13:48Clear Captured Packets (Link1)
16:13:48Clear Captured Packets (Link0)
16:13:48 vSend(Link0,isakmp_phase2_send)
Send Phase-2 1st message (HDR*, HASH(1), SA, Ni) from HOST2(TN)

*** Phase-2 2nd message recv ***
16:13:48 vRecv(Link0,isakmp_phase2_recv_2nd router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Recv Phase-2 2nd message (HDR*, HASH(2), SA, Ni) from HOST1(NUT)

****OK payload_check payload_check_Hash
****OK payload_check payload_check_Proposal
****OK payload_check payload_check_Transform
****OK payload_check payload_check_Nonce
****OK payload_check payload_check_ID
****OK payload_check payload_check_ID
OK payload_check
OK calcHashPhase2Hash2 hash(2) value is correct
*** Phase-2 3rd message send ***
16:13:49Clear Captured Packets (Link0)
16:13:49 vSend(Link0,isakmp_phase2_send_3rd)
Send Phase-2 3rd message HDR*, HASH(3) from HOST2(TN)
16:13:49 Wait 1 second

*** IPsec SA is esatblished ***
*** Encapulated Echo Request/Reply message send/recv ***
16:13:50Clear Captured Packets (Link1)
16:13:50Clear Captured Packets (Link0)
16:13:51 vSend(Link0,echo_request_send_esp_tunnel_net3host2_net2sgw1)
Send Encrypted Echo Request from HOST-2(TN)
16:13:51 vRecv(Link1,echo_request_recv_net3host2_net0host1 router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0
Receive Echo Request from HOST-2(TN) via SGW1(NUT)

Implementation of Quick Mode(ESP_3DES and HMAC-SHA(Tunnel mode to HOST)) is correct
*** Target test finish ***
16:13:51Stop Capturing Packets (Link1)
16:13:51Stop Capturing Packets (Link0)

Target: Reset IKE SA entries: saddump
16:13:51 vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
dump;
flush;
EOD
? dump;
? 
flush;
? EOD
3ffe:501:ffff:102::1 3ffe:501:ffff:103::11 
        esp mode=tunnel spi=4096(0x00001000) reqid=0(0x00000000)
        E: 3des-cbc  b75089e2 d92d729e a315f35a 36941c3a b9e7229e 09675cf9
        A: hmac-sha1  1ebcd551 f75ad379 ce2dcfaf b6658948 060c775a
        seq=0x00000000 replay=4 flags=0x00000000 state=mature 
        created: Mar 16 16:20:58 2006   current: Mar 16 16:21:01 2006
        diff: 3(s)      hard: 28800(s)  soft: 23040(s)
        last:                           hard: 0(s)      soft: 0(s)
        current: 0(bytes)       hard: 0(bytes)  soft: 0(bytes)
        allocated: 0    hard: 0 soft: 0
        sadb_seq=1 pid=3168 refcnt=1
3ffe:501:ffff:103::11 3ffe:501:ffff:102::1 
        esp mode=tunnel spi=209492156(0x0c7c98bc) reqid=0(0x00000000)
        E: 3des-cbc  ffca2c61 d57a57dd 5e40a01f 5f2e680f 0e911bbe c8eea13d
        A: hmac-sha1  25c363e1 30283967 c11dcec0 eec44566 67eb3cd6
        seq=0x00000001 replay=4 flags=0x00000000 state=mature 
        created: Mar 16 16:20:58 2006   current: Mar 16 16:21:01 2006
        diff: 3(s)      hard: 28800(s)  soft: 23040(s)
        last: Mar 16 16:21:00 2006      hard: 0(s)      soft: 0(s)
        current: 56(bytes)      hard: 0(bytes)  soft: 0(bytes)
        allocated: 1    hard: 0 soft: 0
        sadb_seq=0 pid=3168 refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD
echo $status
0
target1# kill -TERM `head -1 /var/run/racoon.pid`

target1# 
target1# echo $status
0
target1# /bin/rm -f /var/run/racoon.pid

target1# 
target1# echo $status
0
~
[EOT]

Target: Clear SPD entries: spddump
16:13:57 vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected

target1# 
target1# /usr/sbin/setkey -c <<EOD
spddump;
spdflush;? spddump;

EOD

? spdflush;
EOD

? EOD
3ffe:501:ffff:103::11[any] 3ffe:501:ffff:100::/64[any] any
        in ipsec
        esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
        created: Mar 16 16:20:34 2006  lastused: Mar 16 16:21:00 2006
        lifetime: 0(s) validtime: 0(s)
        spid=19283 seq=1 pid=3171
        refcnt=1
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:103::11[any] any
        out ipsec
        esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
        created: Mar 16 16:20:28 2006  lastused: Mar 16 16:20:28 2006
        lifetime: 0(s) validtime: 0(s)
        spid=19282 seq=0 pid=3171
        refcnt=1
target1# 
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD
echo $status
0
~
[EOT]

OK
16:14:03End

Packet Reverse Log