| Title | Encryption of ISAKMP payload *** |
| CommandLine | ./SGW/SG_I_RFC2409_5_5_1.seq -pkt ./SGW/SG_I_RFC2409_5_5_1.def test_phase=2 test_type=BASIC -log 67.html -ti Encryption of ISAKMP payload *** |
| TestVersion | undefined |
| ToolVersion | REL_3_0_8 |
| Start | 2006/03/13 14:28:47 |
| Tn | /usr/local/v6eval//etc//tn.def |
| Nu | /usr/local/v6eval//etc//nut.def |
| Pkt | ./SGW/SG_I_RFC2409_5_5_1.def |
| System | freebsd-i386 |
| TargetName | FreeBSD 5.4-RELEASE |
| HostName | target1.tahi.org |
| Type | router |
| 14:28:47 | Start |
|
*** Target IKE initialization phase *** Target: Reset IKE SA entries: saddump |
|
| 14:28:48 |
vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected target1# target1# /usr/sbin/setkey -c <<EOD dump; flush; EOD ? dump; ? flush; ? EOD The result of line 1: No SAD entries. target1# target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD echo $status 0 target1# kill -TERM `head -1 /var/run/racoon.pid` head: /var/run/racoon.pid: No such file or directory target1# target1# echo $status 1 target1# /bin/rm -f /var/run/racoon.pid target1# target1# echo $status 0 ~ [EOT] |
| Target: Clear SPD entries: spddump | |
| 14:28:54 |
vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected target1# target1# /usr/sbin/setkey -c <<EOD spddump; spdflu? spddump; sh; EOD ? spdflush; EOD ? EOD The result of line 1: No SPD entries. target1# target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD echo $status 0 ~ [EOT] |
| Target: Set SPD entries: src=3ffe:501:ffff:100::/64 dst=3ffe:501:ffff:104::/64 tsrc=3ffe:501:ffff:102::1 tdst=3ffe:501:ffff:103::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Tunnel | |
| 14:29:01 |
vRemote(ipsecSetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecSetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 src=3ffe:501:ffff:100::/64 dst=3ffe:501:ffff:104::/64 tsrc=3ffe:501:ffff:102::1 tdst=3ffe:501:ffff:103::11 upperspec=any direction=out protocol=PROTO_IPSEC_ESP mode=Tunnel ''
Connected
target1#
target1# /usr/sbin/setkey -c <<EOD
spdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:104::/64
any
-P out ipsec
esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
;
spddump;
EOD
? spdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:104::/64
any
-P out ipsec
esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
;
spddump;
EOD
? any
? -P out ipsec
? esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
? ;
? spddump;
? EOD
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:104::/64[any] any
out ipsec
esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
created: Mar 13 14:35:39 2006 lastused: Mar 13 14:35:39 2006
lifetime: 0(s) validtime: 0(s)
spid=17205 seq=0 pid=1298
refcnt=1
target1#
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspdadd 3ffe:501:ffff:100::/64 3ffe:501:ffff:104::/64 any -P out ipsec esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require;spddump;EOD
echo $status
0
~
[EOT]
|
| Target: Set IKE SA entries: dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:104::/64 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA | |
| 14:29:07 |
vRemote(ikeSetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeSetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 dst=3ffe:501:ffff:103::11 dst_port=500 exchange_mode=main doi=ipsec_doi situation=identity_only isakmp_src_id_type=address isakmp_src_id=3ffe:501:ffff:102::1 dh_group=2 lifetime=28800 lifetime_unit=seconds encryption_algorithm=3des hash_algorithm=sha1 authentication_method=pre_shared_key key_id=3ffe:501:ffff:103::11 key_value=0x494b452d54455354 ph2_id_type=address ph2_src_id=3ffe:501:ffff:100::/64 ph2_dst_id=3ffe:501:ffff:104::/64 ph2_src_upper=any ph2_dst_upper=any ipsec_p_num=1 ipsec_p1_t_num=1 ph2_p1_t1_lt=8 ph2_p1_t1_lt_unit=hour ph2_p1_t1_enc_alg=ESP_3DES ph2_p1_t1_auth_mtd=HMAC_SHA ''
Connected target1# target1# ~[set] echocheck target1# target1# ~[put] freebsd-i386.psk.txt /tmp/psk.txt Dtarget1# target1# target1# /bin/chmod 600 /tmp/psk.txt target1# echo $status 0 target1# ~[set] echocheck target1# target1# ~[put] freebsd-i386.ike.conf /tmp/ike.conf Dtarget1# target1# target1# test -f /var/run/racoon.pid &&kill -TERM `head -1 /var/run/racoon.pid` target1# target1# echo $status 1 target1# /usr/local/sbin/racoon -f /tmp/ike.conf target1# target1# echo $status 0 ~ [EOT] |
| 14:29:21 | vRemote(ikeEnable.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeEnable.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 '' |
|
*** Target initialization phase *** |
|
| 14:29:22 | Start Capturing Packets (Link0) |
| 14:29:22 | Start Capturing Packets (Link1) |
| 14:29:22 | Clear Captured Packets (Link0) |
| 14:29:22 | Clear Captured Packets (Link1) |
| 14:29:22 |
vSend(Link1,echo_request_send_net0host1_net4host2) Send Echo Request from Host-1(TN) to Host-2(TN) via SGW1(NUT) |
|
*** Target pre-test seaquence *** |
|
| 14:29:22 | Clear Captured Packets (Link0) |
|
*** Phase-1 1st message recv *** |
|
| 14:29:22 | vRecv(Link0,isakmp_phase1_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:10 cntLimit:0 seektime:0 Receive Neighbor Solicitation from SGW1(NUT) |
| 14:29:27 |
vSend(Link0,router_na) Send Neighbor Advertisement(TN) |
| 14:29:28 | vRecv(Link0,isakmp_phase1_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:10 cntLimit:0 seektime:0 Recv 1st message from HOST1(NUT) |
|
OK payload_check *** Phase-1 2nd message send *** |
|
| 14:29:32 | Clear Captured Packets (Link0) |
| 14:29:32 |
vSend(Link0,isakmp_phase1_send_2nd) Send 2nd message from HOST2(TN) |
|
*** Phase-1 3rd message recv *** |
|
| 14:29:33 | vRecv(Link0,isakmp_phase1_recv_3rd router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0 Recv 3rd message from HOST1(NUT) |
|
OK payload_check *** Phase-1 4th message send *** |
|
| 14:29:33 | Clear Captured Packets (Link0) |
| 14:29:34 |
vSend(Link0,isakmp_phase1_send_4th) Send 4th message from HOST2(TN) |
|
*** Phase-1 5th message recv *** |
|
| 14:29:34 | vRecv(Link0,isakmp_phase1_recv_5th router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0 Recv 5th message from HOST1(NUT) |
|
OK payload_check *** Phase-1 6th message send *** |
|
| 14:29:34 | Clear Captured Packets (Link0) |
| 14:29:34 |
vSend(Link0,isakmp_phase1_send_6th) Send 6th message from HOST2(TN) |
|
*** Target testing phase start *** *** Phase-2 1st message recv *** |
|
| 14:29:35 | vRecv(Link0,isakmp_phase2_recv router_ns_multi router_ns_uni_link1 router_ns_uni_tll_sll_link1 router_ns_multi_llt_link1 router_ns_uni_sll router_ns_uni router_ns_multi_llt router_ns_uni_sll_link1 router_ns_multi_link1 router_ns_uni_tll_sll) timeout:5 cntLimit:0 seektime:0 recv unexpect packet at 14:29:35 Recv Phase-2 1st message (HDR*, HASH(1), SA, Ni, *, *) from HOST1(NUT) |
|
OK payload_check Encryption of ISAKMP Payload is correct *** Target test finish *** |
|
| 14:29:36 | Stop Capturing Packets (Link1) |
| 14:29:36 | Stop Capturing Packets (Link0) |
| Target: Reset IKE SA entries: saddump | |
| 14:29:36 |
vRemote(ikeResetSA.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ikeResetSA.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 saddump ''
Connected
target1#
target1# /usr/sbin/setkey -c <<EOD
dump;
flush;
E? dump;
? flush;
OD
? EOD
3ffe:501:ffff:103::11 3ffe:501:ffff:102::1
esp mode=tunnel spi=61717462(0x03adbbd6) reqid=0(0x00000000)
seq=0x00000000 replay=0 flags=0x00000000 state=larval
sadb_seq=0 pid=1305 refcnt=1
target1#
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODdump;flush;EOD
echo $status
0
target1# kill -TERM `head -1 /var/run/racoon.pid`
target1#
target1# echo $status
0
target1# /bin/rm -f /var/run/racoon.pid
target1#
target1# echo $status
0
~
[EOT]
|
| Target: Clear SPD entries: spddump | |
| 14:29:43 |
vRemote(ipsecResetSPD.rmt) ``/usr/local/v6eval//bin/freebsd-i386//ipsecResetSPD.rmt -t freebsd-i386 -u root -p v6eval -d cuad0 -o 1 spddump ''
Connected
target1#
target1# /usr/sbin/setkey -c <<EOD
spddump;
spdfl? spddump;
ush;
EOD
? spdflush;
EOD
? EOD
3ffe:501:ffff:100::/64[any] 3ffe:501:ffff:104::/64[any] any
out ipsec
esp/tunnel/3ffe:501:ffff:102::1-3ffe:501:ffff:103::11/require
created: Mar 13 14:35:39 2006 lastused: Mar 13 14:35:59 2006
lifetime: 0(s) validtime: 0(s)
spid=17205 seq=0 pid=1308
refcnt=1
target1#
target1# sendMessagesSync: never got /usr/sbin/setkey -c <<EODspddump;spdflush;EOD
echo $status
0
~target1#
[EOT]
|
|
OK |
|
| 14:29:49 | End |
Frame_Ether (length:70) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:02:00:26:ba | | SourceAddress = 00:00:00:00:00:10 | | Type = 34525 | Packet_IPv6 (length:56) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 16 | | | NextHeader = 58 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:100::13 | | | DestinationAddress = 3ffe:501:ffff:104::11 | | ICMPv6_EchoRequest (length:16) | | | Type = 128 | | | Code = 0 | | | Checksum = 36089 calc(36089) | | | Identifier = 0 | | | SequenceNumber = 0 | | | Payload (length:8) | | | | data = 4563686f 44617461
Frame_Ether (length:86)
| Hdr_Ether (length:14)
| | DestinationAddress = 00:00:00:00:00:11
| | SourceAddress = 00:00:02:00:27:cd
| | Type = 34525
| Packet_IPv6 (length:72)
| | Hdr_IPv6 (length:40)
| | | Version = 6
| | | TrafficClass = 0
| | | FlowLabel = 0
| | | PayloadLength = 32
| | | NextHeader = 58
| | | HopLimit = 255
| | | SourceAddress = 3ffe:501:ffff:102::1
| | | DestinationAddress = 3ffe:501:ffff:102::11
| | ICMPv6_NS (length:32)
| | | Type = 135
| | | Code = 0
| | | Checksum = 31664 calc(31664)
| | | Reserved = 0
| | | TargetAddress = 3ffe:501:ffff:102::11
| | | Opt_ICMPv6_SLL (length:8)
| | | | Type = 1
| | | | Length = 1
| | | | LinkLayerAddress = 00:00:02:00:27:cd
===isakmp_phase1_recv=================================
ng compare _HDR_IPV6_isakmp_phase1_recv.NextHeader received:58 = 17
ng compare _HDR_IPV6_isakmp_phase1_recv.DestinationAddress received:3ffe:501:ffff:102::11 = 3ffe:501:ffff:103::11
ng meta Packet_IPv6.Upp_UDP != Packet_IPv6.ICMPv6_NS
===router_ns_multi=================================
ng compare _HETHER_nut2tnA11solnode.DestinationAddress received:00:00:00:00:00:11 = 33:33:ff:00:00:11
ng compare _HDR_IPV6_router_ns_multi.DestinationAddress received:3ffe:501:ffff:102::11 = ff02::1:ff00:11
===router_ns_uni_link1=================================
ng compare _HETHER_nut2tnA10.DestinationAddress received:00:00:00:00:00:11 = 00:00:00:00:00:10
ng compare _HETHER_nut2tnA10.SourceAddress received:00:00:02:00:27:cd = 00:00:02:00:26:ba
ng compare _HDR_IPV6_router_ns_uni_link1.SourceAddress received:3ffe:501:ffff:102::1 = oneof(nutv6("Link1"),v6("3ffe:501:ffff:101::1"))
ng compare _HDR_IPV6_router_ns_uni_link1.DestinationAddress received:3ffe:501:ffff:102::11 = 3ffe:501:ffff:101::11
ng compare _ICMPV6_router_ns_uni_link1.TargetAddress received:3ffe:501:ffff:102::11 = 3ffe:501:ffff:101::11
ng count Packet_IPv6.ICMPv6_NS != Packet_IPv6.ICMPv6_NS
===router_ns_uni_tll_sll_link1=================================
ng compare _HETHER_nut2tnA10.DestinationAddress received:00:00:00:00:00:11 = 00:00:00:00:00:10
ng compare _HETHER_nut2tnA10.SourceAddress received:00:00:02:00:27:cd = 00:00:02:00:26:ba
ng compare _HDR_IPV6_router_ns_uni_tll_sll_link1.SourceAddress received:3ffe:501:ffff:102::1 = fe80::200:2ff:fe00:26ba
ng compare _HDR_IPV6_router_ns_uni_tll_sll_link1.DestinationAddress received:3ffe:501:ffff:102::11 = fe80::11
ng compare _ICMPV6_router_ns_uni_tll_sll_link1.TargetAddress received:3ffe:501:ffff:102::11 = fe80::11
===router_ns_multi_llt_link1=================================
ng compare _HETHER_nut2tnA10solnode.DestinationAddress received:00:00:00:00:00:11 = 33:33:ff:00:00:11
ng compare _HETHER_nut2tnA10solnode.SourceAddress received:00:00:02:00:27:cd = 00:00:02:00:26:ba
ng compare _HDR_IPV6_router_ns_multi_llt_link1.SourceAddress received:3ffe:501:ffff:102::1 = oneof(nutv6("Link1"),v6("3ffe:501:ffff:101::1"))
ng compare _HDR_IPV6_router_ns_multi_llt_link1.DestinationAddress received:3ffe:501:ffff:102::11 = ff02::1:ff00:11
ng compare _ICMPV6_router_ns_multi_llt_link1.TargetAddress received:3ffe:501:ffff:102::11 = fe80::11
===router_ns_uni_sll=================================
Frame_Ether (length:86) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:02:00:27:cd | | SourceAddress = 00:00:00:00:00:11 | | Type = 34525 | Packet_IPv6 (length:72) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 32 | | | NextHeader = 58 | | | HopLimit = 255 | | | SourceAddress = 3ffe:501:ffff:102::11 | | | DestinationAddress = 3ffe:501:ffff:102::1 | | ICMPv6_NA (length:32) | | | Type = 136 | | | Code = 0 | | | Checksum = 50027 calc(50027) | | | RFlag = 1 | | | SFlag = 1 | | | OFlag = 1 | | | Reserved = 0 | | | TargetAddress = 3ffe:501:ffff:102::11 | | | Opt_ICMPv6_TLL (length:8) | | | | Type = 2 | | | | Length = 1 | | | | LinkLayerAddress = 00:00:00:00:00:11
Frame_Ether (length:142) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:00:00:00:11 | | SourceAddress = 00:00:02:00:27:cd | | Type = 34525 | Packet_IPv6 (length:128) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 88 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:102::1 | | | DestinationAddress = 3ffe:501:ffff:103::11 | | Upp_UDP (length:88) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 88 | | | | Checksum = 17070 calc(17070) | | | Udp_ISAKMP (length:80) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 04ec7b4b7dc5b805 | | | | | ResponderCookie = 0000000000000000 | | | | | NextPayload = 1 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 80 | | | | Pld_ISAKMP_SA_IPsec_IDonly (length:52) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 52 | | | | | DOI = 1 | | | | | Situation = 1 | | | | | Pld_ISAKMP_P_ISAKMP (length:40) | | | | | | NextPayload = 0 | | | | | | Reserved1 = 0 | | | | | | PayloadLength = 40 | | | | | | ProposalNumber = 1 | | | | | | ProtocolID = 1 | | | | | | SPIsize = 0 | | | | | | NumOfTransforms = 1 | | | | | | SPI = | | | | | | Pld_ISAKMP_T (length:32) | | | | | | | NextPayload = 0 | | | | | | | Reserved1 = 0 | | | | | | | PayloadLength = 32 | | | | | | | TransformNumber = 1 | | | | | | | TransformID = 1 | | | | | | | Reserved2 = 0 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 11 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 12 | | | | | | | | Value = 28800 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 1 | | | | | | | | Value = 5 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 3 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 2 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 4 | | | | | | | | Value = 2 ===isakmp_phase1_recv=================================
Frame_Ether (length:146) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:02:00:27:cd | | SourceAddress = 00:00:00:00:00:11 | | Type = 34525 | Packet_IPv6 (length:132) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 92 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:103::11 | | | DestinationAddress = 3ffe:501:ffff:102::1 | | Upp_UDP (length:92) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 92 | | | | Checksum = 5474 calc(5474) | | | Udp_ISAKMP (length:84) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 04ec7b4b7dc5b805 | | | | | ResponderCookie = 0a1d6584c44b7943 | | | | | NextPayload = 1 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 84 | | | | Pld_ISAKMP_SA_IPsec_IDonly (length:56) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 56 | | | | | DOI = 1 | | | | | Situation = 1 | | | | | Pld_ISAKMP_P_ISAKMP (length:44) | | | | | | NextPayload = 0 | | | | | | Reserved1 = 0 | | | | | | PayloadLength = 44 | | | | | | ProposalNumber = 1 | | | | | | ProtocolID = 1 | | | | | | SPIsize = 0 | | | | | | NumOfTransforms = 1 | | | | | | SPI = | | | | | | Pld_ISAKMP_T (length:36) | | | | | | | NextPayload = 0 | | | | | | | Reserved1 = 0 | | | | | | | PayloadLength = 36 | | | | | | | TransformNumber = 1 | | | | | | | TransformID = 1 | | | | | | | Reserved2 = 0 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 1 | | | | | | | | Value = 5 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 2 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 3 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 4 | | | | | | | | Value = 2 | | | | | | | Attr_ISAKMP_TV (length:4) | | | | | | | | AF = 1 | | | | | | | | Type = 11 | | | | | | | | Value = 1 | | | | | | | Attr_ISAKMP_TLV (length:8) | | | | | | | | AF = 0 | | | | | | | | Type = 12 | | | | | | | | Length = 4 | | | | | | | | Value = 00007080
Frame_Ether (length:262) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:00:00:00:11 | | SourceAddress = 00:00:02:00:27:cd | | Type = 34525 | Packet_IPv6 (length:248) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 208 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:102::1 | | | DestinationAddress = 3ffe:501:ffff:103::11 | | Upp_UDP (length:208) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 208 | | | | Checksum = 14526 calc(14526) | | | Udp_ISAKMP (length:200) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 04ec7b4b7dc5b805 | | | | | ResponderCookie = 0a1d6584c44b7943 | | | | | NextPayload = 4 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 200 | | | | Pld_ISAKMP_KE (length:132) | | | | | NextPayload = 10 | | | | | Reserved1 = 0 | | | | | PayloadLength = 132 | | | | | KeyExchangeData = | | | | | 2d86d759 4302a52d 0c6b565e 1608ea71 22bbee64 7919d580 29940d69 cfd4cc0d | | | | | eaeb911c 5a25e947 4a53b867 7b80f7f5 823f3932 6b1db4c3 b42ecffe 640a19eb | | | | | 68a09ce9 ef37e5f2 50bab557 dd2199ac f89ad086 b61f0a5e 82f929dc 15089565 | | | | | aeb13306 6fc46214 42ba8214 46d01ccf 9a782c28 c7edfc36 c4fb97b1 3a1ec80e | | | | Pld_ISAKMP_NONCE (length:20) | | | | | NextPayload = 13 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | NonceData = a211f1a7 592afb84 2c59b43f ec5f771d | | | | Pld_ISAKMP_VID (length:20) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | VID = 7003cbc1 097dbe9c 2600ba69 83bc8b35 ===isakmp_phase1_recv_3rd=================================
Frame_Ether (length:242) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:02:00:27:cd | | SourceAddress = 00:00:00:00:00:11 | | Type = 34525 | Packet_IPv6 (length:228) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 188 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:103::11 | | | DestinationAddress = 3ffe:501:ffff:102::1 | | Upp_UDP (length:188) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 188 | | | | Checksum = 59025 calc(59025) | | | Udp_ISAKMP (length:180) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 04ec7b4b7dc5b805 | | | | | ResponderCookie = 0a1d6584c44b7943 | | | | | NextPayload = 4 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 0 | | | | | MessageID = 0 | | | | | Length = 180 | | | | Pld_ISAKMP_KE (length:132) | | | | | NextPayload = 10 | | | | | Reserved1 = 0 | | | | | PayloadLength = 132 | | | | | KeyExchangeData = | | | | | 8db25fa1 3258ce8f 30799352 23db3a6e bb45b39a 322276de a9ec809d 28c327da | | | | | 98398da9 90ce384f ac589f6c bafa9b71 9bf67641 1f057e89 cff55517 ea4c2e40 | | | | | 7ea0c27e c07d792c b28f485b 36d82e4a 4bdb9c66 f6b2de5f 7b6682ce e3308864 | | | | | 63a33edd 2573113c c3993686 d38cbafa f5fd1919 4f8a51a1 4d8c676c 8390a4d1 | | | | Pld_ISAKMP_NONCE (length:20) | | | | | NextPayload = 0 | | | | | Reserved1 = 0 | | | | | PayloadLength = 20 | | | | | NonceData = 00000000 00000000 00000000 00000000
===ALGORITHM LISTS BEGIN====================
--------------------------------------------
frame=isakmp_phase1_recv_5th
ESP=alg_isakmp_phase1_recv_5th
crypt=ike_des3cbc(hexstr("5461528f07facaff6c169bb7638a9e2c07f8aa3a2f1e539c5de0559a522bc3df86fa560be832496e4aee86645294656b39e2a2707021470b0501f7a9",24),p1_iv("sha1",hexstr("2d86d7594302a52d0c6b565e1608ea7122bbee647919d58029940d69cfd4cc0deaeb911c5a25e9474a53b8677b80f7f5823f39326b1db4c3b42ecffe640a19eb68a09ce9ef37e5f250bab557dd2199acf89ad086b61f0a5e82f929dc15089565aeb133066fc4621442ba821446d01ccf9a782c28c7edfc36c4fb97b13a1ec80e"),hexstr("8DB25FA13258CE8F3079935223DB3A6EBB45B39A322276DEA9EC809D28C327DA98398DA990CE384FAC589F6CBAFA9B719BF676411F057E89CFF55517EA4C2E407EA0C27EC07D792CB28F485B36D82E4A4BDB9C66F6B2DE5F7B6682CEE330886463A33EDD2573113CC3993686D38CBAFAF5FD19194F8A51A14D8C676C8390A4D1"),8))
--------------------------------------------
===ALGORITHM LISTS END======================
Frame_Ether (length:146)
| Hdr_Ether (length:14)
| | DestinationAddress = 00:00:00:00:00:11
| | SourceAddress = 00:00:02:00:27:cd
| | Type = 34525
| Packet_IPv6 (length:132)
| | Hdr_IPv6 (length:40)
| | | Version = 6
| | | TrafficClass = 0
| | | FlowLabel = 0
| | | PayloadLength = 92
| | | NextHeader = 17
| | | HopLimit = 64
| | | SourceAddress = 3ffe:501:ffff:102::1
| | | DestinationAddress = 3ffe:501:ffff:103::11
| | Upp_UDP (length:92)
| | | Hdr_UDP (length:8)
| | | | SourcePort = 500
| | | | DestinationPort = 500
| | | | Length = 92
| | | | Checksum = 43265 calc(43265)
| | | Udp_ISAKMP (length:84)
| | | | Hdr_ISAKMP (length:28)
| | | | | InitiatorCookie = 04ec7b4b7dc5b805
| | | | | ResponderCookie = 0a1d6584c44b7943
| | | | | NextPayload = 5
| | | | | MjVer = 1
| | | | | MnVer = 0
| | | | | ExchangeType = 2
| | | | | Reserved = 0
| | | | | AFlag = 0
| | | | | CFlag = 0
| | | | | EFlag = 1
| | | | | MessageID = 0
| | | | | Length = 84
| | | | ISAKMP_Encryption (length:56)
| | | | | algorithm = alg_isakmp_phase1_recv_5th
| | | | | IVEC = 90cbd80b 34e9a8ab
| | | | | Decrypted (length:56)
| | | | | | PlainText (length:48)
| | | | | | | Pld_ISAKMP_ID_IPV6_ADDR (length:24)
| | | | | | | | NextPayload = 8
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 24
| | | | | | | | IDtype = 5
| | | | | | | | ProtocolID = 17
| | | | | | | | Port = 500
| | | | | | | | ID = 3ffe:501:ffff:102::1
| | | | | | | Pld_ISAKMP_HASH (length:24)
| | | | | | | | NextPayload = 0
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 24
| | | | | | | | HashData =
| | | | | | | | 9cdaa3e2 655a7940 d9a677d5 2f9640b9 b5479d66
| | | | | | Padding = 8fffaa7d 2e670a07
===isakmp_phase1_recv_5th=================================
applied algorithms={alg_isakmp_phase1_recv_5th}
Frame_Ether (length:146) | Hdr_Ether (length:14) | | DestinationAddress = 00:00:02:00:27:cd | | SourceAddress = 00:00:00:00:00:11 | | Type = 34525 | Packet_IPv6 (length:132) | | Hdr_IPv6 (length:40) | | | Version = 6 | | | TrafficClass = 0 | | | FlowLabel = 0 | | | PayloadLength = 92 | | | NextHeader = 17 | | | HopLimit = 64 | | | SourceAddress = 3ffe:501:ffff:103::11 | | | DestinationAddress = 3ffe:501:ffff:102::1 | | Upp_UDP (length:92) | | | Hdr_UDP (length:8) | | | | SourcePort = 500 | | | | DestinationPort = 500 | | | | Length = 92 | | | | Checksum = 11688 calc(11688) | | | Udp_ISAKMP (length:84) | | | | Hdr_ISAKMP (length:28) | | | | | InitiatorCookie = 04ec7b4b7dc5b805 | | | | | ResponderCookie = 0a1d6584c44b7943 | | | | | NextPayload = 5 | | | | | MjVer = 1 | | | | | MnVer = 0 | | | | | ExchangeType = 2 | | | | | Reserved = 0 | | | | | AFlag = 0 | | | | | CFlag = 0 | | | | | EFlag = 1 | | | | | MessageID = 0 | | | | | Length = 84 | | | | ISAKMP_Encryption (length:56) | | | | | algorithm = alg_isakmp_phase1_send_6th | | | | | IVEC = bda0f686 98dd48fb | | | | | Decrypted (length:56) | | | | | | PlainText (length:48) | | | | | | | Pld_ISAKMP_ID_IPV6_ADDR (length:24) | | | | | | | | NextPayload = 8 | | | | | | | | Reserved1 = 0 | | | | | | | | PayloadLength = 24 | | | | | | | | IDtype = 5 | | | | | | | | ProtocolID = 17 | | | | | | | | Port = 500 | | | | | | | | ID = 3ffe:501:ffff:103::11 | | | | | | | Pld_ISAKMP_HASH (length:24) | | | | | | | | NextPayload = 0 | | | | | | | | Reserved1 = 0 | | | | | | | | PayloadLength = 24 | | | | | | | | HashData = | | | | | | | | a12c6ef5 17a3fa42 5ec28114 24f35e2e 23b0da6a | | | | | | Padding = 00000000 00000007
===ALGORITHM LISTS BEGIN====================
--------------------------------------------
frame=isakmp_phase2_recv
ESP=alg_isakmp_phase2_recv_1st
crypt=ike_des3cbc(hexstr("5461528f07facaff6c169bb7638a9e2c07f8aa3a2f1e539c5de0559a522bc3df86fa560be832496e4aee86645294656b39e2a2707021470b0501f7a9",24),p2_iv("sha1",hexstr("bda0f68698dd48fb",8),8))
--------------------------------------------
===ALGORITHM LISTS END======================
Frame_Ether (length:146)
| Hdr_Ether (length:14)
| | DestinationAddress = 00:00:00:00:00:11
| | SourceAddress = 00:00:02:00:27:cd
| | Type = 34525
| Packet_IPv6 (length:132)
| | Hdr_IPv6 (length:40)
| | | Version = 6
| | | TrafficClass = 0
| | | FlowLabel = 0
| | | PayloadLength = 92
| | | NextHeader = 17
| | | HopLimit = 64
| | | SourceAddress = 3ffe:501:ffff:102::1
| | | DestinationAddress = 3ffe:501:ffff:103::11
| | Upp_UDP (length:92)
| | | Hdr_UDP (length:8)
| | | | SourcePort = 500
| | | | DestinationPort = 500
| | | | Length = 92
| | | | Checksum = 35465 calc(35465)
| | | Udp_ISAKMP (length:84)
| | | | Hdr_ISAKMP (length:28)
| | | | | InitiatorCookie = 04ec7b4b7dc5b805
| | | | | ResponderCookie = 0a1d6584c44b7943
| | | | | NextPayload = 8
| | | | | MjVer = 1
| | | | | MnVer = 0
| | | | | ExchangeType = 5
| | | | | Reserved = 0
| | | | | AFlag = 0
| | | | | CFlag = 0
| | | | | EFlag = 1
| | | | | MessageID = 2854205310
| | | | | Length = 84
| | | | ISAKMP_Encryption (length:56)
| | | | | algorithm = alg_isakmp_phase2_recv_1st
| | | | | IVEC = 97d594ee c8e92fd1
| | | | | Decrypted (length:56)
| | | | | | PlainText (length:52)
| | | | | | | Pld_ISAKMP_HASH (length:24)
| | | | | | | | NextPayload = 11
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 24
| | | | | | | | HashData =
| | | | | | | | 0363aba1 810eefc1 ca961663 2b5acd63 9e40a895
| | | | | | | Pld_ISAKMP_N_IPsec_ANY (length:28)
| | | | | | | | NextPayload = 0
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 28
| | | | | | | | DOI = 1
| | | | | | | | ProtocolID = 1
| | | | | | | | SPIsize = 16
| | | | | | | | NotifyMessageType = 24578
| | | | | | | | SPI = 04ec7b4b 7dc5b805 0a1d6584 c44b7943
| | | | | | | | NotificationData =
| | | | | | Padding = b50c7e03
===isakmp_phase2_recv=================================
applied algorithms={alg_isakmp_phase2_recv_1st}
ng compare hdr_isakmp_phase2_recv_1st.ExchangeType received:5 = 32
Frame_Ether (length:266)
| Hdr_Ether (length:14)
| | DestinationAddress = 00:00:00:00:00:11
| | SourceAddress = 00:00:02:00:27:cd
| | Type = 34525
| Packet_IPv6 (length:252)
| | Hdr_IPv6 (length:40)
| | | Version = 6
| | | TrafficClass = 0
| | | FlowLabel = 0
| | | PayloadLength = 212
| | | NextHeader = 17
| | | HopLimit = 64
| | | SourceAddress = 3ffe:501:ffff:102::1
| | | DestinationAddress = 3ffe:501:ffff:103::11
| | Upp_UDP (length:212)
| | | Hdr_UDP (length:8)
| | | | SourcePort = 500
| | | | DestinationPort = 500
| | | | Length = 212
| | | | Checksum = 1643 calc(1643)
| | | Udp_ISAKMP (length:204)
| | | | Hdr_ISAKMP (length:28)
| | | | | InitiatorCookie = 04ec7b4b7dc5b805
| | | | | ResponderCookie = 0a1d6584c44b7943
| | | | | NextPayload = 8
| | | | | MjVer = 1
| | | | | MnVer = 0
| | | | | ExchangeType = 32
| | | | | Reserved = 0
| | | | | AFlag = 0
| | | | | CFlag = 0
| | | | | EFlag = 1
| | | | | MessageID = 4147993533
| | | | | Length = 204
| | | | ISAKMP_Encryption (length:176)
| | | | | algorithm = alg_isakmp_phase2_recv_1st
| | | | | IVEC = 09bbdffc 63c862ae
| | | | | Decrypted (length:176)
| | | | | | PlainText (length:172)
| | | | | | | Pld_ISAKMP_HASH (length:24)
| | | | | | | | NextPayload = 1
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 24
| | | | | | | | HashData =
| | | | | | | | a5b0bb19 7f56feef 6f2daba4 b61c7450 d233088b
| | | | | | | Pld_ISAKMP_SA_IPsec_IDonly (length:48)
| | | | | | | | NextPayload = 10
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 48
| | | | | | | | DOI = 1
| | | | | | | | Situation = 1
| | | | | | | | Pld_ISAKMP_P_IPsec_ESP (length:36)
| | | | | | | | | NextPayload = 0
| | | | | | | | | Reserved1 = 0
| | | | | | | | | PayloadLength = 36
| | | | | | | | | ProposalNumber = 1
| | | | | | | | | ProtocolID = 3
| | | | | | | | | SPIsize = 4
| | | | | | | | | NumOfTransforms = 1
| | | | | | | | | SPI = 61717462
| | | | | | | | | Pld_ISAKMP_T (length:24)
| | | | | | | | | | NextPayload = 0
| | | | | | | | | | Reserved1 = 0
| | | | | | | | | | PayloadLength = 24
| | | | | | | | | | TransformNumber = 1
| | | | | | | | | | TransformID = 3
| | | | | | | | | | Reserved2 = 0
| | | | | | | | | | Attr_ISAKMP_TV (length:4)
| | | | | | | | | | | AF = 1
| | | | | | | | | | | Type = 1
| | | | | | | | | | | Value = 1
| | | | | | | | | | Attr_ISAKMP_TV (length:4)
| | | | | | | | | | | AF = 1
| | | | | | | | | | | Type = 2
| | | | | | | | | | | Value = 28800
| | | | | | | | | | Attr_ISAKMP_TV (length:4)
| | | | | | | | | | | AF = 1
| | | | | | | | | | | Type = 4
| | | | | | | | | | | Value = 1
| | | | | | | | | | Attr_ISAKMP_TV (length:4)
| | | | | | | | | | | AF = 1
| | | | | | | | | | | Type = 5
| | | | | | | | | | | Value = 2
| | | | | | | Pld_ISAKMP_NONCE (length:20)
| | | | | | | | NextPayload = 5
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 20
| | | | | | | | NonceData = c49ebea3 36510588 c483e7e7 f2f1d7ec
| | | | | | | Pld_ISAKMP_ID_IPV6_ADDR_SUBNET (length:40)
| | | | | | | | NextPayload = 5
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 40
| | | | | | | | IDtype = 6
| | | | | | | | ProtocolID = 0
| | | | | | | | Port = 0
| | | | | | | | ID1 = 3ffe:501:ffff:100::
| | | | | | | | ID2 = ffff:ffff:ffff:ffff::
| | | | | | | Pld_ISAKMP_ID_IPV6_ADDR_SUBNET (length:40)
| | | | | | | | NextPayload = 0
| | | | | | | | Reserved1 = 0
| | | | | | | | PayloadLength = 40
| | | | | | | | IDtype = 6
| | | | | | | | ProtocolID = 0
| | | | | | | | Port = 0
| | | | | | | | ID1 = 3ffe:501:ffff:104::
| | | | | | | | ID2 = ffff:ffff:ffff:ffff::
| | | | | | Padding = 8cdd6303
===isakmp_phase2_recv=================================
applied algorithms={alg_isakmp_phase2_recv_1st}