| Title | Key Exchange Payload Format + DH2 ** |
| CommandLine | ./SGW/SG_R_RFC2409_5_13_2.seq -pkt ./SGW/SG_R_RFC2409_5_13_2.def test_type=BASIC -log 154.html -ti Key Exchange Payload Format + DH2 ** |
| TestVersion | undefined |
| ToolVersion | REL_3_0_8 |
| Start | 2006/03/13 15:33:46 |
| Tn | /usr/local/v6eval//etc//tn.def |
| Nu | /usr/local/v6eval//etc//nut.def |
| Pkt | ./SGW/SG_R_RFC2409_5_13_2.def |
| System | freebsd-i386 |
| TargetName | FreeBSD 5.4-RELEASE |
| HostName | target1.tahi.org |
| Type | router |
| 15:33:46 | Start |
|
*** Target IKE initialization phase *** Target: Reset IKE SA entries: saddump |
|
| 15:33:47 |
vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected target1# target1# /usr/sbin/setkey -c <<EOD dump; flush; EOD ? dump; ? flush; ? EOD The result of line 1: No SAD entries. target1# target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD echo $status 0 target1# kill -TERM `head -1 /var/run/racoon.pid` head: /var/run/racoon.pid: No such file or directory target1# target1# echo $status 1 target1# /bin/rm -f /var/run/racoon.pid target1# target1# echo $status 0 ~ [EOT] |
| Target: Clear SPD entries: spddump | |
| 15:33:54 |
vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected target1# target1# /usr/sbin/setkey -c <<EOD spddump; spdflush? spddump; ; EOD ? spdflush; EOD ? EOD The result of line 1: No SPD entries. target1# target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD echo $status 0 ~ [EOT] |
| Target: Set SPD entries: dst=3ffe:501:ffff:100::/64 src=3ffe:501:ffff:104::/64 tdst=3ffe:501:ffff:102::1 tsrc=3ffe:501:ffff:103::11 direction=in protocol=PROTO_IPSEC_ESP mode=Tunnel | |
| 15:34:00 |
vRemote(ipsecSetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecSetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 dst=3ffe:501:ffff:100::/64 src=3ffe:501:ffff:104::/64 tdst=3ffe:501:ffff:102::1 tsrc=3ffe:501:ffff:103::11 direction=in protocol=PROTO_IPSEC_ESP mode=Tunnel ''
Connected
target1#
target1# /usr/sbin/setkey -c <<EOD
spdadd 3ffe:501:ffff:104::/64 3ffe:501:ffff:100::/64
any
-P in ipsec
esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
;
spddump;
EOD
? spdadd 3ffe:501:ffff:104::/64 3ffe:501:ffff:100::/64
any
-P in ipsec
esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
;
spddump;
EOD
? any
? -P in ipsec
? esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
? ;
? spddump;
? EOD
3ffe:501:ffff:104::/64[any] 3ffe:501:ffff:100::/64[any] any
in ipsec
esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
created: Mar 13 15:40:38 2006 lastused: Mar 13 15:40:38 2006
lifetime: 0(s) validtime: 0(s)
spid=18245 seq=0 pid=2250
refcnt=1
target1#
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspdadd 3ffe:501:ffff:104::/64 3ffe:501:ffff:100::/64 any -P in ipsec esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require;spddump;EOD
echo $status
0
~
[EOT]
|
| Target: Set IKE SA entries: dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x30 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:104::/64 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA | |
| 15:34:06 |
vRemote(ikeSetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeSetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x30 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:104::/64 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA ''
Connected target1# target1# ~[set] echocheck target1# target1# ~[put] freebsd-i386.psk.txt /tmp/psk.txt Dtarget1# target1# target1# /bin/chmod 600 /tmp/psk.txt target1# echo $status 0 target1# ~[set] echocheck target1# target1# ~[put] freebsd-i386.ike.conf /tmp/ike.conf Dtarget1# target1# target1# test -f /var/run/racoon.pid &&kill -TERM `head -1 /var/run/racoon.pid` target1# target1# echo $status 1 target1# /usr/local/sbin/racoon -f /tmp/ike.conf target1# target1# echo $status 0 ~ [EOT] |
| 15:34:20 | vRemote(ikeEnable.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeEnable.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 '' |
|
*** Target initialization phase *** |
|
| 15:34:21 | Start Capturing Packets (Link0) |
| 15:34:21 | Start Capturing Packets (Link1) |
|
*** Target testing phase *** *** Phase-1 1st message send *** |
|
| 15:34:21 | Clear Captured Packets (Link0) |
| 15:34:21 | Clear Captured Packets (Link1) |
| 15:34:21 |
vSend(Link0,isakmp_phase1_send_1st) Send 1st message from HOST2(TN) |
|
*** Phase-1 2nd message receive *** |
|
| 15:34:21 | vRecv(Link0,isakmp_phase1_recv_2nd router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0 Recv 2nd message from HOST1(NUT) |
|
OK payload_check *** Phase-1 3rd message send *** |
|
| 15:34:22 | Clear Captured Packets (Link0) |
| 15:34:22 | Clear Captured Packets (Link1) |
| 15:34:22 |
vSend(Link0,isakmp_phase1_send_3rd) Send 3rd message from HOST2(TN) |
|
*** Phase-1 4th message receive *** |
|
| 15:34:22 | vRecv(Link0,isakmp_phase1_recv_4th router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0 Recv 4th message from HOST1(NUT) |
|
****OK payload_check payload_check_KE OK payload_check Key Exchange Payload Format(DH2) is correct *** Target test finish *** |
|
| 15:34:22 | Stop Capturing Packets (Link0) |
| 15:34:22 | Stop Capturing Packets (Link1) |
| Target: Reset IKE SA entries: saddump | |
| 15:34:23 |
vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected target1# target1# /usr/sbin/setkey -c <<EOD dump; flush; EOD? dump; ? flush; ? EOD The result of line 1: No SAD entries. target1# target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD echo $status 0 target1# kill -TERM `head -1 /var/run/racoon.pid` target1# target1# echo $status 0 target1# /bin/rm -f /var/run/racoon.pid target1# target1# echo $status 0 ~ [EOT] |
| Target: Clear SPD entries: spddump | |
| 15:34:29 |
vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected
target1#
target1# /usr/sbin/setkey -c <<EOD
spddump;
spdf? spddump;
lush;
EOD
? spdflush;
EOD
? EOD
3ffe:501:ffff:104::/64[any] 3ffe:501:ffff:100::/64[any] any
in ipsec
esp/tunnel/3ffe:501:ffff:103::11-3ffe:501:ffff:102::1/require
created: Mar 13 15:40:38 2006 lastused: Mar 13 15:40:38 2006
lifetime: 0(s) validtime: 0(s)
spid=18245 seq=0 pid=2260
refcnt=1
target1#
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD
echo $status
0
~
[EOT]
|
|
OK |
|
| 15:34:35 | End |
Frame_Ether (length:146) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:02:00:27:cd | | SourceAddress = 00:00:00:00:00:11 | | Type = 34525 | Packet_IPv6 (length:132) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 92 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:103::11 | | | DestinationAddress = 3ffe:501:ffff:102::1 | | Upp_UDP (length:92) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 92 | | | | Checksum = 39381 calc(39381) | | | Udp_ISAKMP (length:84) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 915eb40d5507444c | | | | | ResponderCookie = 0000000000000000 | | | | | NextPayload = 1 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 84 | | | | Pld_ISAKMP_SA_IPsec_IDonly (length:56) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 56 | | | | | DOI = 1 | | | | | Situation = 1 | | | | | Pld_ISAKMP_P_ISAKMP (length:44) | | | | | | NextPayload = 0 | | | | | | Reserved1 = 0 | | | | | | PayloadLength = 44 | | | | | | ProposalNumber = 1 | | | | | | ProtocolID = 1 | | | | | | SPIsize = 0 | | | | | | NumOfTransforms = 1 | | | | | | SPI = | | | | | | Pld_ISAKMP_T (length:36) | | | | | | | NextPayload = 0 | | | | | | | Reserved1 = 0 | | | | | | | PayloadLength = 36 | | | | | | | TransformNumber = 1 | | | | | | | TransformID = 1 | | | | | | | Reserved2 = 0 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 1 | | | | | | | | Value = 5 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 2 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 3 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 4 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 11 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TLV (length:8) | | | | | | | | AF = 0 | | | | | | | | Type = 12 | | | | | | | | Length = 4 | | | | | | | | Value = 00007080
Frame_Ether (length:166) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:00:00:00:11 | | SourceAddress = 00:00:02:00:27:cd | | Type = 34525 | Packet_IPv6 (length:152) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 112 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:102::1 | | | DestinationAddress = 3ffe:501:ffff:103::11 | | Upp_UDP (length:112) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 112 | | | | Checksum = 20705 calc(20705) | | | Udp_ISAKMP (length:104) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 915eb40d5507444c | | | | | ResponderCookie = 3b9c2ed751a38c52 | | | | | NextPayload = 1 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 104 | | | | Pld_ISAKMP_SA_IPsec_IDonly (length:56) | | | | | NextPayload = 13 | | | | | Reserved1 = 0 | | | | | PayloadLength = 56 | | | | | DOI = 1 | | | | | Situation = 1 | | | | | Pld_ISAKMP_P_ISAKMP (length:44) | | | | | | NextPayload = 0 | | | | | | Reserved1 = 0 | | | | | | PayloadLength = 44 | | | | | | ProposalNumber = 1 | | | | | | ProtocolID = 1 | | | | | | SPIsize = 0 | | | | | | NumOfTransforms = 1 | | | | | | SPI = | | | | | | Pld_ISAKMP_T (length:36) | | | | | | | NextPayload = 0 | | | | | | | Reserved1 = 0 | | | | | | | PayloadLength = 36 | | | | | | | TransformNumber = 1 | | | | | | | TransformID = 1 | | | | | | | Reserved2 = 0 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 1 | | | | | | | | Value = 5 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 2 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 3 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 4 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 11 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TLV (length:8) | | | | | | | | AF = 0 | | | | | | | | Type = 12 | | | | | | | | Length = 4 | | | | | | | | Value = 00007080 | | | | Pld_ISAKMP_VID (length:20) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | VID = 7003cbc1 097dbe9c 2600ba69 83bc8b35 ===isakmp_phase1_recv_2nd=================================
Frame_Ether (length:242) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:02:00:27:cd | | SourceAddress = 00:00:00:00:00:11 | | Type = 34525 | Packet_IPv6 (length:228) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 188 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:103::11 | | | DestinationAddress = 3ffe:501:ffff:102::1 | | Upp_UDP (length:188) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 188 | | | | Checksum = 28866 calc(28866) | | | Udp_ISAKMP (length:180) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 915eb40d5507444c | | | | | ResponderCookie = 3b9c2ed751a38c52 | | | | | NextPayload = 4 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 180 | | | | Pld_ISAKMP_KE (length:132) | | | | | NextPayload = 10 | | | | | Reserved1 = 0 | | | | | PayloadLength = 132 | | | | | KeyExchangeData = | | | | | 077b990d aa5fc1a9 e483c1bd 84baae27 bd18579f d5399985 f7258037 8d72c8e7 | | | | | 06d200e7 8238961e c4b2b136 d4630ea2 54c7ad2d 184ce65e 6607ae9c f7baae24 | | | | | c5649123 f5ffb403 6aef3881 d3b564f7 9af8ae7a a0ca9fb4 66f016d1 2cedd210 | | | | | 92fbb1f7 d9cbfcb8 1d082a17 2f38609d 351ded87 8c5f59b2 78476adc ee6aaa1a | | | | Pld_ISAKMP_NONCE (length:20) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | NonceData = 00000000 00000000 00000000 00000000
Frame_Ether (length:262) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:00:00:00:11 | | SourceAddress = 00:00:02:00:27:cd | | Type = 34525 | Packet_IPv6 (length:248) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 208 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:102::1 | | | DestinationAddress = 3ffe:501:ffff:103::11 | | Upp_UDP (length:208) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 208 | | | | Checksum = 51005 calc(51005) | | | Udp_ISAKMP (length:200) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 915eb40d5507444c | | | | | ResponderCookie = 3b9c2ed751a38c52 | | | | | NextPayload = 4 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 200 | | | | Pld_ISAKMP_KE (length:132) | | | | | NextPayload = 10 | | | | | Reserved1 = 0 | | | | | PayloadLength = 132 | | | | | KeyExchangeData = | | | | | 6b438785 922ce01a 6a72f21e 410de2ed 9a18acca 1179e12a edd65a92 93c4a401 | | | | | f8fd2492 4a0b76e6 a6c3be02 8f838864 2007eb94 1eaaee5e aa95b41c 5db01cc8 | | | | | 11215da0 71cec746 3edcf8e7 ee82d713 7e2e0173 1affffae 6e21040d 108966e3 | | | | | d0bf6086 0491bdf8 90ebde04 3c8901fb 2c75cdbe 978413c0 94ebe5cb 8991d44c | | | | Pld_ISAKMP_NONCE (length:20) | | | | | NextPayload = 13 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | NonceData = f878ee94 f677116d e537c6e2 7d6f20eb | | | | Pld_ISAKMP_VID (length:20) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | VID = 7003cbc1 097dbe9c 2600ba69 83bc8b35 ===isakmp_phase1_recv_4th=================================