Advertisement
Guest User

Untitled

a guest
Aug 13th, 2013
131
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 58.55 KB | None | 0 0
  1. ipsec01
  2. Tue Aug 13 16:51:47 CEST 2013
  3. + _________________________ version
  4. +
  5. + ipsec --version
  6. Linux Openswan U2.6.37-g955aaafb-dirty/K3.2.0-4-amd64 (netkey)
  7. See `ipsec --copyright' for copyright information.
  8. + _________________________ /proc/version
  9. +
  10. + cat /proc/version
  11. Linux version 3.2.0-4-amd64 (debian-kernel@lists.debian.org) (gcc version 4.6.3 (Debian 4.6.3-14) ) #1 SMP Debian 3.2.46-1
  12. + _________________________ /proc/net/ipsec_eroute
  13. +
  14. + test -r /proc/net/ipsec_eroute
  15. + _________________________ netstat-rn
  16. +
  17. + netstat -nr
  18. + head -n 100
  19. Kernel IP routing table
  20. Destination Gateway Genmask Flags MSS Window irtt Iface
  21. 0.0.0.0 yyy.yyy.27.137 0.0.0.0 UG 0 0 0 eth0
  22. 192.168.210.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
  23. yyy.yyy.27.136 0.0.0.0 255.255.255.248 U 0 0 0 eth0
  24. + _________________________ /proc/net/ipsec_spi
  25. +
  26. + test -r /proc/net/ipsec_spi
  27. + _________________________ /proc/net/ipsec_spigrp
  28. +
  29. + test -r /proc/net/ipsec_spigrp
  30. + _________________________ /proc/net/ipsec_tncfg
  31. +
  32. + test -r /proc/net/ipsec_tncfg
  33. + _________________________ /proc/net/pfkey
  34. +
  35. + test -r /proc/net/pfkey
  36. + cat /proc/net/pfkey
  37. sk RefCnt Rmem Wmem User Inode
  38. + _________________________ ip-xfrm-state
  39. +
  40. + ip xfrm state
  41. src zzz.zzz.2.74 dst yyy.yyy.27.141
  42. proto esp spi 0xc9d8f36d reqid 16385 mode tunnel
  43. replay-window 32 flag af-unspec
  44. auth-trunc hmac(sha1) 0x7f963e15ad3ed8d676c69a63b4e9f1472cec6a59 96
  45. enc cbc(des3_ede) 0x8c17a8e99b2134d12b64832b82d108e6dd2d04b9bb4d40af
  46. src yyy.yyy.27.141 dst zzz.zzz.2.74
  47. proto esp spi 0x179eb620 reqid 16385 mode tunnel
  48. replay-window 32 flag af-unspec
  49. auth-trunc hmac(sha1) 0xf27cf79a13d2ce96b784ddec7b86355c98de2a17 96
  50. enc cbc(des3_ede) 0xcaac99cb56872c820e7232e0fb9bef0db92b864827ede51e
  51. + _________________________ ip-xfrm-policy
  52. +
  53. + ip xfrm policy
  54. src 192.168.210.0/24 dst 10.41.35.0/24
  55. dir out priority 2344 ptype main
  56. tmpl src yyy.yyy.27.141 dst zzz.zzz.2.74
  57. proto esp reqid 16385 mode tunnel
  58. src 10.41.35.0/24 dst 192.168.210.0/24
  59. dir fwd priority 2344 ptype main
  60. tmpl src zzz.zzz.2.74 dst yyy.yyy.27.141
  61. proto esp reqid 16385 mode tunnel
  62. src 10.41.35.0/24 dst 192.168.210.0/24
  63. dir in priority 2344 ptype main
  64. tmpl src zzz.zzz.2.74 dst yyy.yyy.27.141
  65. proto esp reqid 16385 mode tunnel
  66. src ::/0 dst ::/0
  67. socket out priority 0 ptype main
  68. src ::/0 dst ::/0
  69. socket in priority 0 ptype main
  70. src 0.0.0.0/0 dst 0.0.0.0/0
  71. socket out priority 0 ptype main
  72. src 0.0.0.0/0 dst 0.0.0.0/0
  73. socket in priority 0 ptype main
  74. src 0.0.0.0/0 dst 0.0.0.0/0
  75. socket out priority 0 ptype main
  76. src 0.0.0.0/0 dst 0.0.0.0/0
  77. socket in priority 0 ptype main
  78. src 0.0.0.0/0 dst 0.0.0.0/0
  79. socket out priority 0 ptype main
  80. src 0.0.0.0/0 dst 0.0.0.0/0
  81. socket in priority 0 ptype main
  82. src 0.0.0.0/0 dst 0.0.0.0/0
  83. socket out priority 0 ptype main
  84. src 0.0.0.0/0 dst 0.0.0.0/0
  85. socket in priority 0 ptype main
  86. src 0.0.0.0/0 dst 0.0.0.0/0
  87. socket out priority 0 ptype main
  88. src 0.0.0.0/0 dst 0.0.0.0/0
  89. socket in priority 0 ptype main
  90. src 0.0.0.0/0 dst 0.0.0.0/0
  91. socket out priority 0 ptype main
  92. src 0.0.0.0/0 dst 0.0.0.0/0
  93. socket in priority 0 ptype main
  94. + _________________________ /proc/crypto
  95. +
  96. + test -r /proc/crypto
  97. + cat /proc/crypto
  98. name : authenc(hmac(sha1),cbc(des3_ede))
  99. driver : authenc(hmac(sha1-ssse3),cbc(des3_ede-generic))
  100. module : authenc
  101. priority : 150
  102. refcnt : 3
  103. selftest : passed
  104. type : aead
  105. async : no
  106. blocksize : 8
  107. ivsize : 8
  108. maxauthsize : 20
  109. geniv : <built-in>
  110.  
  111. name : cbc(des3_ede)
  112. driver : cbc(des3_ede-generic)
  113. module : kernel
  114. priority : 0
  115. refcnt : 3
  116. selftest : passed
  117. type : givcipher
  118. async : no
  119. blocksize : 8
  120. min keysize : 24
  121. max keysize : 24
  122. ivsize : 8
  123. geniv : eseqiv
  124.  
  125. name : rfc3686(ctr(aes))
  126. driver : rfc3686(ctr(aes-aesni))
  127. module : ctr
  128. priority : 300
  129. refcnt : 1
  130. selftest : passed
  131. type : blkcipher
  132. blocksize : 1
  133. min keysize : 20
  134. max keysize : 36
  135. ivsize : 8
  136. geniv : seqiv
  137.  
  138. name : ctr(aes)
  139. driver : ctr(aes-aesni)
  140. module : ctr
  141. priority : 300
  142. refcnt : 1
  143. selftest : passed
  144. type : blkcipher
  145. blocksize : 1
  146. min keysize : 16
  147. max keysize : 32
  148. ivsize : 16
  149. geniv : chainiv
  150.  
  151. name : cbc(camellia)
  152. driver : cbc(camellia-generic)
  153. module : cbc
  154. priority : 100
  155. refcnt : 1
  156. selftest : passed
  157. type : blkcipher
  158. blocksize : 16
  159. min keysize : 16
  160. max keysize : 32
  161. ivsize : 16
  162. geniv : <default>
  163.  
  164. name : cbc(serpent)
  165. driver : cbc(serpent-generic)
  166. module : cbc
  167. priority : 0
  168. refcnt : 1
  169. selftest : passed
  170. type : blkcipher
  171. blocksize : 16
  172. min keysize : 0
  173. max keysize : 32
  174. ivsize : 16
  175. geniv : <default>
  176.  
  177. name : cbc(aes)
  178. driver : cbc(aes-aesni)
  179. module : cbc
  180. priority : 300
  181. refcnt : 1
  182. selftest : passed
  183. type : blkcipher
  184. blocksize : 16
  185. min keysize : 16
  186. max keysize : 32
  187. ivsize : 16
  188. geniv : <default>
  189.  
  190. name : cbc(cast5)
  191. driver : cbc(cast5-generic)
  192. module : cbc
  193. priority : 0
  194. refcnt : 1
  195. selftest : passed
  196. type : blkcipher
  197. blocksize : 8
  198. min keysize : 5
  199. max keysize : 16
  200. ivsize : 8
  201. geniv : <default>
  202.  
  203. name : cbc(des3_ede)
  204. driver : cbc(des3_ede-generic)
  205. module : cbc
  206. priority : 0
  207. refcnt : 3
  208. selftest : passed
  209. type : blkcipher
  210. blocksize : 8
  211. min keysize : 24
  212. max keysize : 24
  213. ivsize : 8
  214. geniv : <default>
  215.  
  216. name : cbc(des)
  217. driver : cbc(des-generic)
  218. module : cbc
  219. priority : 0
  220. refcnt : 1
  221. selftest : passed
  222. type : blkcipher
  223. blocksize : 8
  224. min keysize : 8
  225. max keysize : 8
  226. ivsize : 8
  227. geniv : <default>
  228.  
  229. name : xcbc(aes)
  230. driver : xcbc(aes-aesni)
  231. module : xcbc
  232. priority : 300
  233. refcnt : 1
  234. selftest : passed
  235. type : shash
  236. blocksize : 16
  237. digestsize : 16
  238.  
  239. name : hmac(rmd160)
  240. driver : hmac(rmd160-generic)
  241. module : hmac
  242. priority : 0
  243. refcnt : 1
  244. selftest : passed
  245. type : shash
  246. blocksize : 64
  247. digestsize : 20
  248.  
  249. name : rmd160
  250. driver : rmd160-generic
  251. module : rmd160
  252. priority : 0
  253. refcnt : 1
  254. selftest : passed
  255. type : shash
  256. blocksize : 64
  257. digestsize : 20
  258.  
  259. name : hmac(sha512)
  260. driver : hmac(sha512-generic)
  261. module : hmac
  262. priority : 0
  263. refcnt : 1
  264. selftest : passed
  265. type : shash
  266. blocksize : 128
  267. digestsize : 64
  268.  
  269. name : hmac(sha384)
  270. driver : hmac(sha384-generic)
  271. module : hmac
  272. priority : 0
  273. refcnt : 1
  274. selftest : passed
  275. type : shash
  276. blocksize : 128
  277. digestsize : 48
  278.  
  279. name : hmac(sha256)
  280. driver : hmac(sha256-generic)
  281. module : hmac
  282. priority : 0
  283. refcnt : 1
  284. selftest : passed
  285. type : shash
  286. blocksize : 64
  287. digestsize : 32
  288.  
  289. name : hmac(sha1)
  290. driver : hmac(sha1-ssse3)
  291. module : hmac
  292. priority : 150
  293. refcnt : 5
  294. selftest : passed
  295. type : shash
  296. blocksize : 64
  297. digestsize : 20
  298.  
  299. name : sha1
  300. driver : sha1-ssse3
  301. module : sha1_ssse3
  302. priority : 150
  303. refcnt : 3
  304. selftest : passed
  305. type : shash
  306. blocksize : 64
  307. digestsize : 20
  308.  
  309. name : sha1
  310. driver : sha1-generic
  311. module : sha1_generic
  312. priority : 0
  313. refcnt : 1
  314. selftest : passed
  315. type : shash
  316. blocksize : 64
  317. digestsize : 20
  318.  
  319. name : hmac(md5)
  320. driver : hmac(md5-generic)
  321. module : hmac
  322. priority : 0
  323. refcnt : 1
  324. selftest : passed
  325. type : shash
  326. blocksize : 64
  327. digestsize : 16
  328.  
  329. name : compress_null
  330. driver : compress_null-generic
  331. module : crypto_null
  332. priority : 0
  333. refcnt : 1
  334. selftest : passed
  335. type : compression
  336.  
  337. name : digest_null
  338. driver : digest_null-generic
  339. module : crypto_null
  340. priority : 0
  341. refcnt : 1
  342. selftest : passed
  343. type : shash
  344. blocksize : 1
  345. digestsize : 0
  346.  
  347. name : ecb(cipher_null)
  348. driver : ecb-cipher_null
  349. module : crypto_null
  350. priority : 100
  351. refcnt : 1
  352. selftest : passed
  353. type : blkcipher
  354. blocksize : 1
  355. min keysize : 0
  356. max keysize : 0
  357. ivsize : 0
  358. geniv : <default>
  359.  
  360. name : cipher_null
  361. driver : cipher_null-generic
  362. module : crypto_null
  363. priority : 0
  364. refcnt : 1
  365. selftest : passed
  366. type : cipher
  367. blocksize : 1
  368. min keysize : 0
  369. max keysize : 0
  370.  
  371. name : camellia
  372. driver : camellia-generic
  373. module : camellia
  374. priority : 100
  375. refcnt : 1
  376. selftest : passed
  377. type : cipher
  378. blocksize : 16
  379. min keysize : 16
  380. max keysize : 32
  381.  
  382. name : lzo
  383. driver : lzo-generic
  384. module : lzo
  385. priority : 0
  386. refcnt : 1
  387. selftest : passed
  388. type : compression
  389.  
  390. name : cast6
  391. driver : cast6-generic
  392. module : cast6
  393. priority : 0
  394. refcnt : 1
  395. selftest : passed
  396. type : cipher
  397. blocksize : 16
  398. min keysize : 16
  399. max keysize : 32
  400.  
  401. name : cast5
  402. driver : cast5-generic
  403. module : cast5
  404. priority : 0
  405. refcnt : 1
  406. selftest : passed
  407. type : cipher
  408. blocksize : 8
  409. min keysize : 5
  410. max keysize : 16
  411.  
  412. name : deflate
  413. driver : deflate-generic
  414. module : deflate
  415. priority : 0
  416. refcnt : 1
  417. selftest : passed
  418. type : compression
  419.  
  420. name : tnepres
  421. driver : tnepres-generic
  422. module : serpent
  423. priority : 0
  424. refcnt : 1
  425. selftest : passed
  426. type : cipher
  427. blocksize : 16
  428. min keysize : 0
  429. max keysize : 32
  430.  
  431. name : serpent
  432. driver : serpent-generic
  433. module : serpent
  434. priority : 0
  435. refcnt : 1
  436. selftest : passed
  437. type : cipher
  438. blocksize : 16
  439. min keysize : 0
  440. max keysize : 32
  441.  
  442. name : blowfish
  443. driver : blowfish-generic
  444. module : blowfish_generic
  445. priority : 100
  446. refcnt : 1
  447. selftest : passed
  448. type : cipher
  449. blocksize : 8
  450. min keysize : 4
  451. max keysize : 56
  452.  
  453. name : ctr(blowfish)
  454. driver : ctr-blowfish-asm
  455. module : blowfish_x86_64
  456. priority : 300
  457. refcnt : 1
  458. selftest : passed
  459. type : blkcipher
  460. blocksize : 1
  461. min keysize : 4
  462. max keysize : 56
  463. ivsize : 8
  464. geniv : <default>
  465.  
  466. name : cbc(blowfish)
  467. driver : cbc-blowfish-asm
  468. module : blowfish_x86_64
  469. priority : 300
  470. refcnt : 1
  471. selftest : passed
  472. type : blkcipher
  473. blocksize : 8
  474. min keysize : 4
  475. max keysize : 56
  476. ivsize : 8
  477. geniv : <default>
  478.  
  479. name : ecb(blowfish)
  480. driver : ecb-blowfish-asm
  481. module : blowfish_x86_64
  482. priority : 300
  483. refcnt : 1
  484. selftest : passed
  485. type : blkcipher
  486. blocksize : 8
  487. min keysize : 4
  488. max keysize : 56
  489. ivsize : 0
  490. geniv : <default>
  491.  
  492. name : blowfish
  493. driver : blowfish-asm
  494. module : blowfish_x86_64
  495. priority : 200
  496. refcnt : 1
  497. selftest : passed
  498. type : cipher
  499. blocksize : 8
  500. min keysize : 4
  501. max keysize : 56
  502.  
  503. name : twofish
  504. driver : twofish-generic
  505. module : twofish_generic
  506. priority : 100
  507. refcnt : 1
  508. selftest : passed
  509. type : cipher
  510. blocksize : 16
  511. min keysize : 16
  512. max keysize : 32
  513.  
  514. name : ctr(twofish)
  515. driver : ctr-twofish-3way
  516. module : twofish_x86_64_3way
  517. priority : 300
  518. refcnt : 1
  519. selftest : passed
  520. type : blkcipher
  521. blocksize : 1
  522. min keysize : 16
  523. max keysize : 32
  524. ivsize : 16
  525. geniv : <default>
  526.  
  527. name : cbc(twofish)
  528. driver : cbc-twofish-3way
  529. module : twofish_x86_64_3way
  530. priority : 300
  531. refcnt : 1
  532. selftest : passed
  533. type : blkcipher
  534. blocksize : 16
  535. min keysize : 16
  536. max keysize : 32
  537. ivsize : 16
  538. geniv : <default>
  539.  
  540. name : ecb(twofish)
  541. driver : ecb-twofish-3way
  542. module : twofish_x86_64_3way
  543. priority : 300
  544. refcnt : 1
  545. selftest : passed
  546. type : blkcipher
  547. blocksize : 16
  548. min keysize : 16
  549. max keysize : 32
  550. ivsize : 0
  551. geniv : <default>
  552.  
  553. name : twofish
  554. driver : twofish-asm
  555. module : twofish_x86_64
  556. priority : 200
  557. refcnt : 1
  558. selftest : passed
  559. type : cipher
  560. blocksize : 16
  561. min keysize : 16
  562. max keysize : 32
  563.  
  564. name : sha256
  565. driver : sha256-generic
  566. module : sha256_generic
  567. priority : 0
  568. refcnt : 1
  569. selftest : passed
  570. type : shash
  571. blocksize : 64
  572. digestsize : 32
  573.  
  574. name : sha224
  575. driver : sha224-generic
  576. module : sha256_generic
  577. priority : 0
  578. refcnt : 1
  579. selftest : passed
  580. type : shash
  581. blocksize : 64
  582. digestsize : 28
  583.  
  584. name : sha512
  585. driver : sha512-generic
  586. module : sha512_generic
  587. priority : 0
  588. refcnt : 1
  589. selftest : passed
  590. type : shash
  591. blocksize : 128
  592. digestsize : 64
  593.  
  594. name : sha384
  595. driver : sha384-generic
  596. module : sha512_generic
  597. priority : 0
  598. refcnt : 1
  599. selftest : passed
  600. type : shash
  601. blocksize : 128
  602. digestsize : 48
  603.  
  604. name : des3_ede
  605. driver : des3_ede-generic
  606. module : des_generic
  607. priority : 0
  608. refcnt : 3
  609. selftest : passed
  610. type : cipher
  611. blocksize : 8
  612. min keysize : 24
  613. max keysize : 24
  614.  
  615. name : des
  616. driver : des-generic
  617. module : des_generic
  618. priority : 0
  619. refcnt : 1
  620. selftest : passed
  621. type : cipher
  622. blocksize : 8
  623. min keysize : 8
  624. max keysize : 8
  625.  
  626. name : crc32c
  627. driver : crc32c-intel
  628. module : crc32c_intel
  629. priority : 200
  630. refcnt : 1
  631. selftest : passed
  632. type : shash
  633. blocksize : 1
  634. digestsize : 4
  635.  
  636. name : __ghash
  637. driver : cryptd(__ghash-pclmulqdqni)
  638. module : cryptd
  639. priority : 50
  640. refcnt : 1
  641. selftest : passed
  642. type : ahash
  643. async : yes
  644. blocksize : 16
  645. digestsize : 16
  646.  
  647. name : ghash
  648. driver : ghash-clmulni
  649. module : ghash_clmulni_intel
  650. priority : 400
  651. refcnt : 1
  652. selftest : passed
  653. type : ahash
  654. async : yes
  655. blocksize : 16
  656. digestsize : 16
  657.  
  658. name : __ghash
  659. driver : __ghash-pclmulqdqni
  660. module : ghash_clmulni_intel
  661. priority : 0
  662. refcnt : 1
  663. selftest : passed
  664. type : shash
  665. blocksize : 16
  666. digestsize : 16
  667.  
  668. name : xts(aes)
  669. driver : xts-aes-aesni
  670. module : aesni_intel
  671. priority : 400
  672. refcnt : 1
  673. selftest : passed
  674. type : ablkcipher
  675. async : yes
  676. blocksize : 16
  677. min keysize : 32
  678. max keysize : 64
  679. ivsize : 16
  680. geniv : <default>
  681.  
  682. name : pcbc(aes)
  683. driver : pcbc-aes-aesni
  684. module : aesni_intel
  685. priority : 400
  686. refcnt : 1
  687. selftest : passed
  688. type : ablkcipher
  689. async : yes
  690. blocksize : 16
  691. min keysize : 16
  692. max keysize : 32
  693. ivsize : 16
  694. geniv : <default>
  695.  
  696. name : lrw(aes)
  697. driver : lrw-aes-aesni
  698. module : aesni_intel
  699. priority : 400
  700. refcnt : 1
  701. selftest : passed
  702. type : ablkcipher
  703. async : yes
  704. blocksize : 16
  705. min keysize : 32
  706. max keysize : 48
  707. ivsize : 16
  708. geniv : <default>
  709.  
  710. name : rfc3686(ctr(aes))
  711. driver : rfc3686-ctr-aes-aesni
  712. module : aesni_intel
  713. priority : 400
  714. refcnt : 1
  715. selftest : passed
  716. type : ablkcipher
  717. async : yes
  718. blocksize : 1
  719. min keysize : 20
  720. max keysize : 36
  721. ivsize : 8
  722. geniv : seqiv
  723.  
  724. name : rfc4106(gcm(aes))
  725. driver : rfc4106-gcm-aesni
  726. module : aesni_intel
  727. priority : 400
  728. refcnt : 1
  729. selftest : passed
  730. type : nivaead
  731. async : yes
  732. blocksize : 1
  733. ivsize : 8
  734. maxauthsize : 16
  735. geniv : seqiv
  736.  
  737. name : __gcm-aes-aesni
  738. driver : __driver-gcm-aes-aesni
  739. module : aesni_intel
  740. priority : 0
  741. refcnt : 1
  742. selftest : passed
  743. type : aead
  744. async : no
  745. blocksize : 1
  746. ivsize : 0
  747. maxauthsize : 0
  748. geniv : <built-in>
  749.  
  750. name : ctr(aes)
  751. driver : ctr-aes-aesni
  752. module : aesni_intel
  753. priority : 400
  754. refcnt : 1
  755. selftest : passed
  756. type : ablkcipher
  757. async : yes
  758. blocksize : 1
  759. min keysize : 16
  760. max keysize : 32
  761. ivsize : 16
  762. geniv : chainiv
  763.  
  764. name : __ctr-aes-aesni
  765. driver : __driver-ctr-aes-aesni
  766. module : aesni_intel
  767. priority : 0
  768. refcnt : 1
  769. selftest : passed
  770. type : blkcipher
  771. blocksize : 1
  772. min keysize : 16
  773. max keysize : 32
  774. ivsize : 16
  775. geniv : <default>
  776.  
  777. name : cbc(aes)
  778. driver : cbc-aes-aesni
  779. module : aesni_intel
  780. priority : 400
  781. refcnt : 1
  782. selftest : passed
  783. type : ablkcipher
  784. async : yes
  785. blocksize : 16
  786. min keysize : 16
  787. max keysize : 32
  788. ivsize : 16
  789. geniv : <default>
  790.  
  791. name : __ecb-aes-aesni
  792. driver : cryptd(__driver-ecb-aes-aesni)
  793. module : cryptd
  794. priority : 50
  795. refcnt : 1
  796. selftest : passed
  797. type : ablkcipher
  798. async : yes
  799. blocksize : 16
  800. min keysize : 16
  801. max keysize : 32
  802. ivsize : 0
  803. geniv : <default>
  804.  
  805. name : ecb(aes)
  806. driver : ecb-aes-aesni
  807. module : aesni_intel
  808. priority : 400
  809. refcnt : 1
  810. selftest : passed
  811. type : ablkcipher
  812. async : yes
  813. blocksize : 16
  814. min keysize : 16
  815. max keysize : 32
  816. ivsize : 0
  817. geniv : <default>
  818.  
  819. name : __cbc-aes-aesni
  820. driver : __driver-cbc-aes-aesni
  821. module : aesni_intel
  822. priority : 0
  823. refcnt : 1
  824. selftest : passed
  825. type : blkcipher
  826. blocksize : 16
  827. min keysize : 16
  828. max keysize : 32
  829. ivsize : 0
  830. geniv : <default>
  831.  
  832. name : __ecb-aes-aesni
  833. driver : __driver-ecb-aes-aesni
  834. module : aesni_intel
  835. priority : 0
  836. refcnt : 1
  837. selftest : passed
  838. type : blkcipher
  839. blocksize : 16
  840. min keysize : 16
  841. max keysize : 32
  842. ivsize : 0
  843. geniv : <default>
  844.  
  845. name : __aes-aesni
  846. driver : __driver-aes-aesni
  847. module : aesni_intel
  848. priority : 0
  849. refcnt : 1
  850. selftest : passed
  851. type : cipher
  852. blocksize : 16
  853. min keysize : 16
  854. max keysize : 32
  855.  
  856. name : aes
  857. driver : aes-aesni
  858. module : aesni_intel
  859. priority : 300
  860. refcnt : 1
  861. selftest : passed
  862. type : cipher
  863. blocksize : 16
  864. min keysize : 16
  865. max keysize : 32
  866.  
  867. name : aes
  868. driver : aes-asm
  869. module : aes_x86_64
  870. priority : 200
  871. refcnt : 1
  872. selftest : passed
  873. type : cipher
  874. blocksize : 16
  875. min keysize : 16
  876. max keysize : 32
  877.  
  878. name : aes
  879. driver : aes-generic
  880. module : aes_generic
  881. priority : 100
  882. refcnt : 1
  883. selftest : passed
  884. type : cipher
  885. blocksize : 16
  886. min keysize : 16
  887. max keysize : 32
  888.  
  889. name : stdrng
  890. driver : krng
  891. module : kernel
  892. priority : 200
  893. refcnt : 2
  894. selftest : passed
  895. type : rng
  896. seedsize : 0
  897.  
  898. name : md5
  899. driver : md5-generic
  900. module : kernel
  901. priority : 0
  902. refcnt : 1
  903. selftest : passed
  904. type : shash
  905. blocksize : 64
  906. digestsize : 16
  907.  
  908. + __________________________/proc/sys/net/core/xfrm-star
  909. /usr/lib/ipsec/barf: 190: /usr/lib/ipsec/barf: __________________________/proc/sys/net/core/xfrm-star: not found
  910. + echo -n /proc/sys/net/core/xfrm_acq_expires:
  911. /proc/sys/net/core/xfrm_acq_expires: + cat /proc/sys/net/core/xfrm_acq_expires
  912. 30
  913. + echo -n /proc/sys/net/core/xfrm_aevent_etime:
  914. /proc/sys/net/core/xfrm_aevent_etime: + cat /proc/sys/net/core/xfrm_aevent_etime
  915. 10
  916. + echo -n /proc/sys/net/core/xfrm_aevent_rseqth:
  917. /proc/sys/net/core/xfrm_aevent_rseqth: + cat /proc/sys/net/core/xfrm_aevent_rseqth
  918. 2
  919. + echo -n /proc/sys/net/core/xfrm_larval_drop:
  920. /proc/sys/net/core/xfrm_larval_drop: + cat /proc/sys/net/core/xfrm_larval_drop
  921. 1
  922. + _________________________ /proc/sys/net/ipsec-star
  923. +
  924. + test -d /proc/sys/net/ipsec
  925. + _________________________ ipsec/status
  926. +
  927. + ipsec auto --status
  928. 000 using kernel interface: netkey
  929. 000 interface lo/lo ::1
  930. 000 interface lo/lo 127.0.0.1
  931. 000 interface lo/lo 127.0.0.1
  932. 000 interface eth0:1/eth0:1 192.168.210.166
  933. 000 interface eth0:1/eth0:1 192.168.210.166
  934. 000 interface eth0/eth0 yyy.yyy.27.141
  935. 000 interface eth0/eth0 yyy.yyy.27.141
  936. 000 %myid = (none)
  937. 000 debug none
  938. 000
  939. 000 virtual_private (%priv):
  940. 000 - allowed 6 subnets: 10.0.0.0/8, 192.168.0.0/16, 172.16.0.0/12, 25.0.0.0/8, fd00::/8, fe80::/10
  941. 000 - disallowed 0 subnets:
  942. 000 WARNING: Disallowed subnets in virtual_private= is empty. If you have
  943. 000 private address space in internal use, it should be excluded!
  944. 000
  945. 000 algorithm ESP encrypt: id=2, name=ESP_DES, ivlen=8, keysizemin=64, keysizemax=64
  946. 000 algorithm ESP encrypt: id=3, name=ESP_3DES, ivlen=8, keysizemin=192, keysizemax=192
  947. 000 algorithm ESP encrypt: id=6, name=ESP_CAST, ivlen=8, keysizemin=40, keysizemax=128
  948. 000 algorithm ESP encrypt: id=7, name=ESP_BLOWFISH, ivlen=8, keysizemin=40, keysizemax=448
  949. 000 algorithm ESP encrypt: id=11, name=ESP_NULL, ivlen=0, keysizemin=0, keysizemax=0
  950. 000 algorithm ESP encrypt: id=12, name=ESP_AES, ivlen=8, keysizemin=128, keysizemax=256
  951. 000 algorithm ESP encrypt: id=13, name=ESP_AES_CTR, ivlen=8, keysizemin=160, keysizemax=288
  952. 000 algorithm ESP encrypt: id=14, name=ESP_AES_CCM_A, ivlen=8, keysizemin=128, keysizemax=256
  953. 000 algorithm ESP encrypt: id=15, name=ESP_AES_CCM_B, ivlen=8, keysizemin=128, keysizemax=256
  954. 000 algorithm ESP encrypt: id=16, name=ESP_AES_CCM_C, ivlen=8, keysizemin=128, keysizemax=256
  955. 000 algorithm ESP encrypt: id=18, name=ESP_AES_GCM_A, ivlen=8, keysizemin=128, keysizemax=256
  956. 000 algorithm ESP encrypt: id=19, name=ESP_AES_GCM_B, ivlen=8, keysizemin=128, keysizemax=256
  957. 000 algorithm ESP encrypt: id=20, name=ESP_AES_GCM_C, ivlen=8, keysizemin=128, keysizemax=256
  958. 000 algorithm ESP encrypt: id=22, name=ESP_CAMELLIA, ivlen=8, keysizemin=128, keysizemax=256
  959. 000 algorithm ESP encrypt: id=252, name=ESP_SERPENT, ivlen=8, keysizemin=128, keysizemax=256
  960. 000 algorithm ESP encrypt: id=253, name=ESP_TWOFISH, ivlen=8, keysizemin=128, keysizemax=256
  961. 000 algorithm ESP auth attr: id=1, name=AUTH_ALGORITHM_HMAC_MD5, keysizemin=128, keysizemax=128
  962. 000 algorithm ESP auth attr: id=2, name=AUTH_ALGORITHM_HMAC_SHA1, keysizemin=160, keysizemax=160
  963. 000 algorithm ESP auth attr: id=5, name=AUTH_ALGORITHM_HMAC_SHA2_256, keysizemin=256, keysizemax=256
  964. 000 algorithm ESP auth attr: id=6, name=AUTH_ALGORITHM_HMAC_SHA2_384, keysizemin=384, keysizemax=384
  965. 000 algorithm ESP auth attr: id=7, name=AUTH_ALGORITHM_HMAC_SHA2_512, keysizemin=512, keysizemax=512
  966. 000 algorithm ESP auth attr: id=8, name=AUTH_ALGORITHM_HMAC_RIPEMD, keysizemin=160, keysizemax=160
  967. 000 algorithm ESP auth attr: id=9, name=AUTH_ALGORITHM_AES_CBC, keysizemin=128, keysizemax=128
  968. 000 algorithm ESP auth attr: id=251, name=(null), keysizemin=0, keysizemax=0
  969. 000
  970. 000 algorithm IKE encrypt: id=0, name=(null), blocksize=16, keydeflen=131
  971. 000 algorithm IKE encrypt: id=5, name=OAKLEY_3DES_CBC, blocksize=8, keydeflen=192
  972. 000 algorithm IKE encrypt: id=7, name=OAKLEY_AES_CBC, blocksize=16, keydeflen=128
  973. 000 algorithm IKE hash: id=1, name=OAKLEY_MD5, hashsize=16
  974. 000 algorithm IKE hash: id=2, name=OAKLEY_SHA1, hashsize=20
  975. 000 algorithm IKE dh group: id=2, name=OAKLEY_GROUP_MODP1024, bits=1024
  976. 000 algorithm IKE dh group: id=5, name=OAKLEY_GROUP_MODP1536, bits=1536
  977. 000 algorithm IKE dh group: id=14, name=OAKLEY_GROUP_MODP2048, bits=2048
  978. 000 algorithm IKE dh group: id=15, name=OAKLEY_GROUP_MODP3072, bits=3072
  979. 000 algorithm IKE dh group: id=16, name=OAKLEY_GROUP_MODP4096, bits=4096
  980. 000 algorithm IKE dh group: id=17, name=OAKLEY_GROUP_MODP6144, bits=6144
  981. 000 algorithm IKE dh group: id=18, name=OAKLEY_GROUP_MODP8192, bits=8192
  982. 000 algorithm IKE dh group: id=22, name=OAKLEY_GROUP_DH22, bits=1024
  983. 000 algorithm IKE dh group: id=23, name=OAKLEY_GROUP_DH23, bits=2048
  984. 000 algorithm IKE dh group: id=24, name=OAKLEY_GROUP_DH24, bits=2048
  985. 000
  986. 000 stats db_ops: {curr_cnt, total_cnt, maxsz} :context={0,2,64} trans={0,2,3072} attrs={0,2,2048}
  987. 000
  988. 000 "net1": 192.168.210.0/24===yyy.yyy.27.141<yyy.yyy.27.141>[+S=C]---yyy.yyy.27.137...zzz.zzz.2.74<zzz.zzz.2.74>[+S=C]===10.41.35.0/24; erouted; eroute owner: #2
  989. 000 "net1": myip=unset; hisip=unset;
  990. 000 "net1": ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
  991. 000 "net1": policy: PSK+ENCRYPT+TUNNEL+PFS+UP+IKEv2ALLOW+SAREFTRACK+lKOD+rKOD; prio: 24,24; interface: eth0;
  992. 000 "net1": newest ISAKMP SA: #1; newest IPsec SA: #2;
  993. 000 "net1": IKE algorithms wanted: 3DES_CBC(5)_000-SHA1(2)_000-MODP1536(5), 3DES_CBC(5)_000-SHA1(2)_000-MODP1024(2); flags=-strict
  994. 000 "net1": IKE algorithms found: 3DES_CBC(5)_192-SHA1(2)_160-MODP1536(5), 3DES_CBC(5)_192-SHA1(2)_160-MODP1024(2)
  995. 000 "net1": IKE algorithm newest: 3DES_CBC_192-SHA1-MODP1024
  996. 000 "net1": ESP algorithms wanted: 3DES(3)_000-SHA1(2)_000; flags=-strict
  997. 000 "net1": ESP algorithms loaded: 3DES(3)_192-SHA1(2)_160
  998. 000 "net1": ESP algorithm newest: 3DES_000-HMAC_SHA1; pfsgroup=<Phase1>
  999. 000
  1000. 000 #2: "net1":500 STATE_QUICK_I2 (sent QI2, IPsec SA established); EVENT_SA_REPLACE in 27846s; newest IPSEC; eroute owner; isakmp#1; idle; import:admin initiate
  1001. 000 #2: "net1" esp.179eb620@zzz.zzz.2.74 esp.c9d8f36d@yyy.yyy.27.141 tun.0@zzz.zzz.2.74 tun.0@yyy.yyy.27.141 ref=0 refhim=4294901761
  1002. 000 #1: "net1":500 STATE_MAIN_I4 (ISAKMP SA established); EVENT_SA_REPLACE in 2262s; newest ISAKMP; lastdpd=-1s(seq in:0 out:0); idle; import:admin initiate
  1003. 000
  1004. + _________________________ ifconfig-a
  1005. +
  1006. + ifconfig -a
  1007. eth0 Link encap:Ethernet HWaddr ac:16:2d:00:f4:be
  1008. inet addr:yyy.yyy.27.141 Bcast:yyy.yyy.27.143 Mask:255.255.255.248
  1009. inet6 addr: fe80::ae16:2dff:fe00:f4be/64 Scope:Link
  1010. UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
  1011. RX packets:26825 errors:0 dropped:0 overruns:0 frame:0
  1012. TX packets:24098 errors:0 dropped:0 overruns:0 carrier:0
  1013. collisions:0 txqueuelen:1000
  1014. RX bytes:8137237 (7.7 MiB) TX bytes:10516102 (10.0 MiB)
  1015. Interrupt:20 Memory:f7c00000-f7c20000
  1016.  
  1017. eth0:1 Link encap:Ethernet HWaddr ac:16:2d:00:f4:be
  1018. inet addr:192.168.210.166 Bcast:192.168.210.255 Mask:255.255.255.0
  1019. UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
  1020. Interrupt:20 Memory:f7c00000-f7c20000
  1021.  
  1022. lo Link encap:Local Loopback
  1023. inet addr:127.0.0.1 Mask:255.0.0.0
  1024. inet6 addr: ::1/128 Scope:Host
  1025. UP LOOPBACK RUNNING MTU:16436 Metric:1
  1026. RX packets:0 errors:0 dropped:0 overruns:0 frame:0
  1027. TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
  1028. collisions:0 txqueuelen:0
  1029. RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
  1030.  
  1031. + _________________________ ip-addr-list
  1032. +
  1033. + ip addr list
  1034. 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
  1035. link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
  1036. inet 127.0.0.1/8 scope host lo
  1037. inet6 ::1/128 scope host
  1038. valid_lft forever preferred_lft forever
  1039. 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
  1040. link/ether ac:16:2d:00:f4:be brd ff:ff:ff:ff:ff:ff
  1041. inet 192.168.210.166/24 brd 192.168.210.255 scope global eth0:1
  1042. inet yyy.yyy.27.141/29 brd yyy.yyy.27.143 scope global eth0
  1043. inet6 fe80::ae16:2dff:fe00:f4be/64 scope link
  1044. valid_lft forever preferred_lft forever
  1045. + _________________________ ip-route-list
  1046. +
  1047. + ip route list
  1048. default via yyy.yyy.27.137 dev eth0
  1049. 192.168.210.0/24 dev eth0 proto kernel scope link src 192.168.210.166
  1050. yyy.yyy.27.136/29 dev eth0 proto kernel scope link src yyy.yyy.27.141
  1051. + _________________________ ip-rule-list
  1052. +
  1053. + ip rule list
  1054. 0: from all lookup local
  1055. 32766: from all lookup main
  1056. 32767: from all lookup default
  1057. + _________________________ ipsec_verify
  1058. +
  1059. + ipsec verify --nocolour
  1060. Checking your system to see if IPsec got installed and started correctly:
  1061. Version check and ipsec on-path [OK]
  1062. Linux Openswan U2.6.37-g955aaafb-dirty/K3.2.0-4-amd64 (netkey)
  1063. Checking for IPsec support in kernel [OK]
  1064. SAref kernel support [N/A]
  1065. NETKEY: Testing XFRM related proc values [OK]
  1066. [OK]
  1067. [OK]
  1068. Checking that pluto is running [OK]
  1069. Pluto listening for IKE on udp 500 [OK]
  1070. Pluto listening for NAT-T on udp 4500 [OK]
  1071. Checking for 'ip' command [OK]
  1072. Checking /bin/sh is not /bin/dash [WARNING]
  1073. Checking for 'iptables' command [OK]
  1074. Opportunistic Encryption Support [DISABLED]
  1075. + _________________________ mii-tool
  1076. +
  1077. + [ -x /sbin/mii-tool ]
  1078. + /sbin/mii-tool -v
  1079. SIOCGMIIREG on eth0 failed: Input/output error
  1080. SIOCGMIIREG on eth0 failed: Input/output error
  1081. eth0: negotiated 100baseTx-FD, link ok
  1082. product info: vendor 00:55:00, model 9 rev 0
  1083. basic mode: autonegotiation enabled
  1084. basic status: autonegotiation complete, link ok
  1085. capabilities: 1000baseT-FD 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD
  1086. advertising: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD flow-control
  1087. link partner: 1000baseT-FD 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD
  1088. + _________________________ ipsec/directory
  1089. +
  1090. + ipsec --directory
  1091. /usr/lib/ipsec
  1092. + _________________________ hostname/fqdn
  1093. +
  1094. + hostname --fqdn
  1095. ipsec01
  1096. + _________________________ hostname/ipaddress
  1097. +
  1098. + hostname --ip-address
  1099. 127.0.1.1
  1100. + _________________________ uptime
  1101. +
  1102. + uptime
  1103. 16:51:47 up 1:30, 3 users, load average: 0.00, 0.01, 0.05
  1104. + _________________________ ps
  1105. +
  1106. + ps alxwf
  1107. egrep -i ppid|pluto|ipsec|klips
  1108. F UID PID PPID PRI NI VSZ RSS WCHAN STAT TTY TIME COMMAND
  1109. 0 0 5646 5238 20 0 4176 700 - S+ pts/0 0:00 \_ /bin/sh /usr/lib/ipsec/barf
  1110. 0 0 5733 5646 20 0 6296 596 - S+ pts/0 0:00 \_ egrep -i ppid|pluto|ipsec|klips
  1111. 1 0 5549 1 20 0 4176 292 - S pts/0 0:00 /bin/sh /usr/lib/ipsec/_plutorun --debug --uniqueids yes --force_busy no --nocrsend no --strictcrlpolicy no --nat_traversal yes --keep_alive --protostack netkey --force_keepalive no --disable_port_floating no --virtual_private %v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:25.0.0.0/8,%v6:fd00::/8,%v6:fe80::/10 --listen --crlcheckinterval 0 --ocspuri --nhelpers --dump /var/run/pluto/ --opts --stderrlog /var/log/pluto.log --wait no --pre --post --log daemon.error --plutorestartoncrash true --pid /var/run/pluto/pluto.pid
  1112. 1 0 5551 5549 20 0 4176 316 - S pts/0 0:00 \_ /bin/sh /usr/lib/ipsec/_plutorun --debug --uniqueids yes --force_busy no --nocrsend no --strictcrlpolicy no --nat_traversal yes --keep_alive --protostack netkey --force_keepalive no --disable_port_floating no --virtual_private %v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:25.0.0.0/8,%v6:fd00::/8,%v6:fe80::/10 --listen --crlcheckinterval 0 --ocspuri --nhelpers --dump /var/run/pluto/ --opts --stderrlog /var/log/pluto.log --wait no --pre --post --log daemon.error --plutorestartoncrash true --pid /var/run/pluto/pluto.pid
  1113. 4 0 5555 5551 20 0 70028 3628 - S pts/0 0:00 | \_ /usr/lib/ipsec/pluto --nofork --secretsfile /etc/ipsec.secrets --ipsecdir /etc/ipsec.d --use-netkey --uniqueids --nat_traversal --virtual_private %v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:25.0.0.0/8,%v6:fd00::/8,%v6:fe80::/10 --stderrlog
  1114. 1 0 5559 5555 30 10 70036 1172 - SN pts/0 0:00 | \_ pluto helper # 0
  1115. 1 0 5560 5555 30 10 70036 1172 - SN pts/0 0:00 | \_ pluto helper # 1
  1116. 1 0 5561 5555 30 10 70036 1168 - SN pts/0 0:00 | \_ pluto helper # 2
  1117. 0 0 5586 5555 20 0 6080 344 - S pts/0 0:00 | \_ _pluto_adns
  1118. 0 0 5552 5549 20 0 4176 672 - S pts/0 0:00 \_ /bin/sh /usr/lib/ipsec/_plutoload --wait no --post
  1119. 0 0 5550 1 20 0 4084 644 - S pts/0 0:00 logger -s -p daemon.error -t ipsec__plutorun
  1120. + _________________________ ipsec/showdefaults
  1121. +
  1122. + ipsec showdefaults
  1123. routephys=eth0
  1124. routevirt=none
  1125. routeaddr=192.168.210.166
  1126. routenexthop=yyy.yyy.27.137
  1127. + _________________________ ipsec/conf
  1128. +
  1129. + ipsec _include /etc/ipsec.conf
  1130. + ipsec _keycensor
  1131.  
  1132. #< /etc/ipsec.conf 1
  1133. version 2.0 # conforms to second version of ipsec.conf specification
  1134. config setup
  1135. dumpdir=/var/run/pluto/
  1136. nat_traversal=yes
  1137. virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:25.0.0.0/8,%v6:fd00::/8,%v6:fe80::/10
  1138. oe=off
  1139. protostack=netkey
  1140. plutostderrlog=/var/log/pluto.log
  1141.  
  1142.  
  1143. conn net1
  1144. # connection
  1145. authby=secret
  1146. auto=start
  1147. keylife=8h
  1148.  
  1149.  
  1150. # phase 1 IKA
  1151. #ike=3des-sha1;modp1028
  1152. ike=3des-sha1
  1153.  
  1154. # phase 2
  1155.  
  1156. type=tunnel
  1157. phase2=esp
  1158. #phase2alg=3des-sha1;modp1028
  1159. phase2alg=3des-sha1
  1160. #psf=yes
  1161.  
  1162.  
  1163. #keyexchange=ike
  1164. # esp=3des-sha1
  1165.  
  1166.  
  1167. # Linux openswan
  1168. left=yyy.yyy.27.141
  1169. leftsubnet=192.168.210.0/24
  1170. #leftnexthop=yyy.yyy.27.137
  1171. leftnexthop=%defaultroute
  1172. # juniper ISG 2000 at net1 networks
  1173. right=zzz.zzz.2.74
  1174. rightsubnet=10.41.35.0/24
  1175. # rightnexthop=%defaultroute
  1176.  
  1177.  
  1178. + _________________________ ipsec/secrets
  1179. +
  1180. + ipsec _include /etc/ipsec.secrets
  1181. + ipsec _secretcensor
  1182.  
  1183. #< /etc/ipsec.secrets 1
  1184. # This file holds shared secrets or RSA private keys for inter-Pluto
  1185. # authentication. See ipsec_pluto(8) manpage, and HTML documentation.
  1186.  
  1187. # RSA private key for this host, authenticating it to any other host
  1188. # which knows the public part. Suitable public keys, for ipsec.conf, DNS,
  1189. # or configuration of other implementations, can be extracted conveniently
  1190. # with "[sums to ef67...]".
  1191.  
  1192. # this file is managed with debconf and will contain the automatically created RSA keys
  1193.  
  1194. #< /var/lib/openswan/ipsec.secrets.inc 1
  1195. yyy.yyy.27.141 zzz.zzz.2.74: PSK "[sums to c825...]"
  1196.  
  1197.  
  1198. #> /etc/ipsec.secrets 11
  1199. + _________________________ ipsec/listall
  1200. +
  1201. + ipsec auto --listall
  1202. 000
  1203. 000 List of Public Keys:
  1204. 000
  1205. 000 List of Pre-shared secrets (from /etc/ipsec.secrets)
  1206. 000 1: PSK zzz.zzz.2.74 yyy.yyy.27.141
  1207. + [ /etc/ipsec.d/policies ]
  1208. + basename /etc/ipsec.d/policies/block
  1209. + base=block
  1210. + _________________________ ipsec/policies/block
  1211. +
  1212. + cat /etc/ipsec.d/policies/block
  1213. # This file defines the set of CIDRs (network/mask-length) to which
  1214. # communication should never be allowed.
  1215. #
  1216. # See /usr/share/doc/openswan/policygroups.html for details.
  1217. #
  1218. # $Id: block.in,v 1.4 2003/02/17 02:22:15 mcr Exp $
  1219. #
  1220.  
  1221. + basename /etc/ipsec.d/policies/clear
  1222. + base=clear
  1223. + _________________________ ipsec/policies/clear
  1224. +
  1225. + cat /etc/ipsec.d/policies/clear
  1226. # This file defines the set of CIDRs (network/mask-length) to which
  1227. # communication should always be in the clear.
  1228. #
  1229. # See /usr/share/doc/openswan/policygroups.html for details.
  1230. #
  1231.  
  1232. # root name servers should be in the clear
  1233. 192.58.128.30/32
  1234. 198.41.0.4/32
  1235. 192.228.79.201/32
  1236. 192.33.4.12/32
  1237. 128.8.10.90/32
  1238. 192.203.230.10/32
  1239. 192.5.5.241/32
  1240. 192.112.36.4/32
  1241. 128.63.2.53/32
  1242. 192.36.148.17/32
  1243. 193.0.14.129/32
  1244. 199.7.83.42/32
  1245. 202.12.27.33/32
  1246. + basename /etc/ipsec.d/policies/clear-or-private
  1247. + base=clear-or-private
  1248. + _________________________ ipsec/policies/clear-or-private
  1249. +
  1250. + cat /etc/ipsec.d/policies/clear-or-private
  1251. # This file defines the set of CIDRs (network/mask-length) to which
  1252. # we will communicate in the clear, or, if the other side initiates IPSEC,
  1253. # using encryption. This behaviour is also called "Opportunistic Responder".
  1254. #
  1255. # See /usr/share/doc/openswan/policygroups.html for details.
  1256. #
  1257. # $Id: clear-or-private.in,v 1.4 2003/02/17 02:22:15 mcr Exp $
  1258. #
  1259. + basename /etc/ipsec.d/policies/private
  1260. + base=private
  1261. + _________________________ ipsec/policies/private
  1262. +
  1263. + cat /etc/ipsec.d/policies/private
  1264. # This file defines the set of CIDRs (network/mask-length) to which
  1265. # communication should always be private (i.e. encrypted).
  1266. # See /usr/share/doc/openswan/policygroups.html for details.
  1267. #
  1268. # $Id: private.in,v 1.4 2003/02/17 02:22:15 mcr Exp $
  1269. #
  1270. + basename /etc/ipsec.d/policies/private-or-clear
  1271. + base=private-or-clear
  1272. + _________________________ ipsec/policies/private-or-clear
  1273. +
  1274. + cat /etc/ipsec.d/policies/private-or-clear
  1275. # This file defines the set of CIDRs (network/mask-length) to which
  1276. # communication should be private, if possible, but in the clear otherwise.
  1277. #
  1278. # If the target has a TXT (later IPSECKEY) record that specifies
  1279. # authentication material, we will require private (i.e. encrypted)
  1280. # communications. If no such record is found, communications will be
  1281. # in the clear.
  1282. #
  1283. # See /usr/share/doc/openswan/policygroups.html for details.
  1284. #
  1285. # $Id: private-or-clear.in,v 1.5 2003/02/17 02:22:15 mcr Exp $
  1286. #
  1287.  
  1288. 0.0.0.0/0
  1289. + _________________________ ipsec/ls-libdir
  1290. +
  1291. + ls -l /usr/lib/ipsec
  1292. total 2432
  1293. -rwxr-xr-x 1 root root 10576 May 27 2012 _copyright
  1294. -rwxr-xr-x 1 root root 2430 May 27 2012 _include
  1295. -rwxr-xr-x 1 root root 1475 May 27 2012 _keycensor
  1296. -rwxr-xr-x 1 root root 14512 May 27 2012 _pluto_adns
  1297. -rwxr-xr-x 1 root root 2567 May 27 2012 _plutoload
  1298. -rwxr-xr-x 1 root root 8299 May 27 2012 _plutorun
  1299. -rwxr-xr-x 1 root root 13684 May 27 2012 _realsetup
  1300. -rwxr-xr-x 1 root root 1975 May 27 2012 _secretcensor
  1301. -rwxr-xr-x 1 root root 12347 May 27 2012 _startklips
  1302. -rwxr-xr-x 1 root root 6188 May 27 2012 _startnetkey
  1303. -rwxr-xr-x 1 root root 4911 May 27 2012 _updown
  1304. -rwxr-xr-x 1 root root 17776 May 27 2012 _updown.klips
  1305. -rwxr-xr-x 1 root root 17537 May 27 2012 _updown.mast
  1306. -rwxr-xr-x 1 root root 12700 May 27 2012 _updown.netkey
  1307. -rwxr-xr-x 1 root root 234088 May 27 2012 addconn
  1308. -rwxr-xr-x 1 root root 6167 May 27 2012 auto
  1309. -rwxr-xr-x 1 root root 11317 May 27 2012 barf
  1310. -rwxr-xr-x 1 root root 97992 May 27 2012 eroute
  1311. -rwxr-xr-x 1 root root 30888 May 27 2012 ikeping
  1312. -rwxr-xr-x 1 root root 77800 May 27 2012 klipsdebug
  1313. -rwxr-xr-x 1 root root 2783 May 27 2012 look
  1314. -rwxr-xr-x 1 root root 2189 May 27 2012 newhostkey
  1315. -rwxr-xr-x 1 root root 73224 May 27 2012 pf_key
  1316. -rwxr-xr-x 1 root root 982248 May 27 2012 pluto
  1317. -rwxr-xr-x 1 root root 12349 May 27 2012 policy
  1318. -rwxr-xr-x 1 root root 10552 May 27 2012 ranbits
  1319. -rwxr-xr-x 1 root root 27360 May 27 2012 rsasigkey
  1320. -rwxr-xr-x 1 root root 704 May 27 2012 secrets
  1321. lrwxrwxrwx 1 root root 17 May 27 2012 setup -> /etc/init.d/ipsec
  1322. -rwxr-xr-x 1 root root 1126 May 27 2012 showdefaults
  1323. -rwxr-xr-x 1 root root 292312 May 27 2012 showhostkey
  1324. -rwxr-xr-x 1 root root 180736 May 27 2012 spi
  1325. -rwxr-xr-x 1 root root 85656 May 27 2012 spigrp
  1326. -rwxr-xr-x 1 root root 81192 May 27 2012 tncfg
  1327. -rwxr-xr-x 1 root root 14674 May 27 2012 verify
  1328. -rwxr-xr-x 1 root root 64056 May 27 2012 whack
  1329. + _________________________ ipsec/ls-execdir
  1330. +
  1331. + ls -l /usr/lib/ipsec
  1332. total 2432
  1333. -rwxr-xr-x 1 root root 10576 May 27 2012 _copyright
  1334. -rwxr-xr-x 1 root root 2430 May 27 2012 _include
  1335. -rwxr-xr-x 1 root root 1475 May 27 2012 _keycensor
  1336. -rwxr-xr-x 1 root root 14512 May 27 2012 _pluto_adns
  1337. -rwxr-xr-x 1 root root 2567 May 27 2012 _plutoload
  1338. -rwxr-xr-x 1 root root 8299 May 27 2012 _plutorun
  1339. -rwxr-xr-x 1 root root 13684 May 27 2012 _realsetup
  1340. -rwxr-xr-x 1 root root 1975 May 27 2012 _secretcensor
  1341. -rwxr-xr-x 1 root root 12347 May 27 2012 _startklips
  1342. -rwxr-xr-x 1 root root 6188 May 27 2012 _startnetkey
  1343. -rwxr-xr-x 1 root root 4911 May 27 2012 _updown
  1344. -rwxr-xr-x 1 root root 17776 May 27 2012 _updown.klips
  1345. -rwxr-xr-x 1 root root 17537 May 27 2012 _updown.mast
  1346. -rwxr-xr-x 1 root root 12700 May 27 2012 _updown.netkey
  1347. -rwxr-xr-x 1 root root 234088 May 27 2012 addconn
  1348. -rwxr-xr-x 1 root root 6167 May 27 2012 auto
  1349. -rwxr-xr-x 1 root root 11317 May 27 2012 barf
  1350. -rwxr-xr-x 1 root root 97992 May 27 2012 eroute
  1351. -rwxr-xr-x 1 root root 30888 May 27 2012 ikeping
  1352. -rwxr-xr-x 1 root root 77800 May 27 2012 klipsdebug
  1353. -rwxr-xr-x 1 root root 2783 May 27 2012 look
  1354. -rwxr-xr-x 1 root root 2189 May 27 2012 newhostkey
  1355. -rwxr-xr-x 1 root root 73224 May 27 2012 pf_key
  1356. -rwxr-xr-x 1 root root 982248 May 27 2012 pluto
  1357. -rwxr-xr-x 1 root root 12349 May 27 2012 policy
  1358. -rwxr-xr-x 1 root root 10552 May 27 2012 ranbits
  1359. -rwxr-xr-x 1 root root 27360 May 27 2012 rsasigkey
  1360. -rwxr-xr-x 1 root root 704 May 27 2012 secrets
  1361. lrwxrwxrwx 1 root root 17 May 27 2012 setup -> /etc/init.d/ipsec
  1362. -rwxr-xr-x 1 root root 1126 May 27 2012 showdefaults
  1363. -rwxr-xr-x 1 root root 292312 May 27 2012 showhostkey
  1364. -rwxr-xr-x 1 root root 180736 May 27 2012 spi
  1365. -rwxr-xr-x 1 root root 85656 May 27 2012 spigrp
  1366. -rwxr-xr-x 1 root root 81192 May 27 2012 tncfg
  1367. -rwxr-xr-x 1 root root 14674 May 27 2012 verify
  1368. -rwxr-xr-x 1 root root 64056 May 27 2012 whack
  1369. + _________________________ /proc/net/dev
  1370. +
  1371. + cat /proc/net/dev
  1372. Inter-| Receive | Transmit
  1373. face |bytes packets errs drop fifo frame compressed multicast|bytes packets errs drop fifo colls carrier compressed
  1374. lo: 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
  1375. eth0: 8137723 26829 0 0 0 0 0 150 10516468 24102 0 0 0 0 0 0
  1376. + _________________________ /proc/net/route
  1377. +
  1378. + cat /proc/net/route
  1379. Iface Destination Gateway Flags RefCnt Use Metric Mask MTU Window IRTT
  1380. eth0 00000000 891BF3C3 0003 0 0 0 00000000 0 0 0
  1381. eth0 00D2A8C0 00000000 0001 0 0 0 00FFFFFF 0 0 0
  1382. eth0 881BF3C3 00000000 0001 0 0 0 F8FFFFFF 0 0 0
  1383. + _________________________ /proc/sys/net/ipv4/ip_no_pmtu_disc
  1384. +
  1385. + cat /proc/sys/net/ipv4/ip_no_pmtu_disc
  1386. 0
  1387. + _________________________ /proc/sys/net/ipv4/ip_forward
  1388. +
  1389. + cat /proc/sys/net/ipv4/ip_forward
  1390. 1
  1391. + _________________________ /proc/sys/net/ipv4/tcp_ecn
  1392. +
  1393. + cat /proc/sys/net/ipv4/tcp_ecn
  1394. 2
  1395. + _________________________ /proc/sys/net/ipv4/conf/star-rp_filter
  1396. +
  1397. + cd /proc/sys/net/ipv4/conf
  1398. + egrep ^ all/rp_filter default/rp_filter eth0/rp_filter lo/rp_filter
  1399. all/rp_filter:0
  1400. default/rp_filter:0
  1401. eth0/rp_filter:0
  1402. lo/rp_filter:0
  1403. + _________________________ /proc/sys/net/ipv4/conf/star-star-redirects
  1404. +
  1405. + cd /proc/sys/net/ipv4/conf
  1406. + egrep ^ all/accept_redirects all/secure_redirects all/send_redirects default/accept_redirects default/secure_redirects default/send_redirects eth0/accept_redirects eth0/secure_redirects eth0/send_redirects lo/accept_redirects lo/secure_redirects lo/send_redirects
  1407. all/accept_redirects:0
  1408. all/secure_redirects:1
  1409. all/send_redirects:0
  1410. default/accept_redirects:0
  1411. default/secure_redirects:1
  1412. default/send_redirects:0
  1413. eth0/accept_redirects:0
  1414. eth0/secure_redirects:1
  1415. eth0/send_redirects:0
  1416. lo/accept_redirects:0
  1417. lo/secure_redirects:1
  1418. lo/send_redirects:0
  1419. + _________________________ /proc/sys/net/ipv4/tcp_window_scaling
  1420. +
  1421. + cat /proc/sys/net/ipv4/tcp_window_scaling
  1422. 1
  1423. + _________________________ /proc/sys/net/ipv4/tcp_adv_win_scale
  1424. +
  1425. + cat /proc/sys/net/ipv4/tcp_adv_win_scale
  1426. 1
  1427. + _________________________ uname-a
  1428. +
  1429. + uname -a
  1430. Linux ipsec01 3.2.0-4-amd64 #1 SMP Debian 3.2.46-1 x86_64 GNU/Linux
  1431. + _________________________ config-built-with
  1432. +
  1433. + test -r /proc/config_built_with
  1434. + _________________________ distro-release
  1435. +
  1436. + test -f /etc/redhat-release
  1437. + test -f /etc/debian-release
  1438. + test -f /etc/SuSE-release
  1439. + test -f /etc/mandrake-release
  1440. + test -f /etc/mandriva-release
  1441. + test -f /etc/gentoo-release
  1442. + _________________________ /proc/net/ipsec_version
  1443. +
  1444. + test -r /proc/net/ipsec_version
  1445. + test -r /proc/net/pfkey
  1446. + uname -r
  1447. + echo NETKEY (3.2.0-4-amd64) support detected
  1448. NETKEY (3.2.0-4-amd64) support detected
  1449. + _________________________ iptables
  1450. +
  1451. + test -r /sbin/iptables-save
  1452. + iptables-save
  1453. # Generated by iptables-save v1.4.14 on Tue Aug 13 16:51:47 2013
  1454. *filter
  1455. :INPUT ACCEPT [7439:429177]
  1456. :FORWARD ACCEPT [0:0]
  1457. :OUTPUT ACCEPT [6918:2681120]
  1458. -A FORWARD -i eth0:0 -j ACCEPT
  1459. COMMIT
  1460. # Completed on Tue Aug 13 16:51:47 2013
  1461. # Generated by iptables-save v1.4.14 on Tue Aug 13 16:51:47 2013
  1462. *mangle
  1463. :PREROUTING ACCEPT [9309:667224]
  1464. :INPUT ACCEPT [9309:667224]
  1465. :FORWARD ACCEPT [0:0]
  1466. :OUTPUT ACCEPT [8235:3066592]
  1467. :POSTROUTING ACCEPT [8235:3066592]
  1468. COMMIT
  1469. # Completed on Tue Aug 13 16:51:47 2013
  1470. # Generated by iptables-save v1.4.14 on Tue Aug 13 16:51:47 2013
  1471. *nat
  1472. :PREROUTING ACCEPT [7:445]
  1473. :INPUT ACCEPT [7:445]
  1474. :OUTPUT ACCEPT [30:1968]
  1475. :POSTROUTING ACCEPT [0:0]
  1476. -A POSTROUTING -j MASQUERADE
  1477. -A POSTROUTING -o eth0 -j MASQUERADE
  1478. COMMIT
  1479. # Completed on Tue Aug 13 16:51:47 2013
  1480. + _________________________ iptables-nat
  1481. +
  1482. + iptables-save -t nat
  1483. # Generated by iptables-save v1.4.14 on Tue Aug 13 16:51:47 2013
  1484. *nat
  1485. :PREROUTING ACCEPT [7:445]
  1486. :INPUT ACCEPT [7:445]
  1487. :OUTPUT ACCEPT [30:1968]
  1488. :POSTROUTING ACCEPT [0:0]
  1489. -A POSTROUTING -j MASQUERADE
  1490. -A POSTROUTING -o eth0 -j MASQUERADE
  1491. COMMIT
  1492. # Completed on Tue Aug 13 16:51:47 2013
  1493. + _________________________ iptables-mangle
  1494. +
  1495. + iptables-save -t mangle
  1496. # Generated by iptables-save v1.4.14 on Tue Aug 13 16:51:47 2013
  1497. *mangle
  1498. :PREROUTING ACCEPT [9309:667224]
  1499. :INPUT ACCEPT [9309:667224]
  1500. :FORWARD ACCEPT [0:0]
  1501. :OUTPUT ACCEPT [8235:3066592]
  1502. :POSTROUTING ACCEPT [8235:3066592]
  1503. COMMIT
  1504. # Completed on Tue Aug 13 16:51:47 2013
  1505. + _________________________ ip6tables
  1506. +
  1507. + test -r /sbin/ip6tables-save
  1508. + ip6tables-save
  1509. # Generated by ip6tables-save v1.4.14 on Tue Aug 13 16:51:47 2013
  1510. *mangle
  1511. :PREROUTING ACCEPT [0:0]
  1512. :INPUT ACCEPT [0:0]
  1513. :FORWARD ACCEPT [0:0]
  1514. :OUTPUT ACCEPT [0:0]
  1515. :POSTROUTING ACCEPT [0:0]
  1516. COMMIT
  1517. # Completed on Tue Aug 13 16:51:47 2013
  1518. + _________________________ ip6tables-mangle
  1519. +
  1520. + ip6tables-save -t mangle
  1521. # Generated by ip6tables-save v1.4.14 on Tue Aug 13 16:51:47 2013
  1522. *mangle
  1523. :PREROUTING ACCEPT [0:0]
  1524. :INPUT ACCEPT [0:0]
  1525. :FORWARD ACCEPT [0:0]
  1526. :OUTPUT ACCEPT [0:0]
  1527. :POSTROUTING ACCEPT [0:0]
  1528. COMMIT
  1529. # Completed on Tue Aug 13 16:51:47 2013
  1530. + _________________________ ip6tables
  1531. +
  1532. + _________________________ /proc/modules
  1533. +
  1534. + test -f /proc/modules
  1535. + cat /proc/modules
  1536. xfrm_user 27310 2 - Live 0xffffffffa051e000
  1537. ah6 12802 0 - Live 0xffffffffa0519000
  1538. ah4 12755 0 - Live 0xffffffffa0514000
  1539. esp6 12796 0 - Live 0xffffffffa050f000
  1540. esp4 12792 2 - Live 0xffffffffa050a000
  1541. xfrm4_mode_beet 12475 0 - Live 0xffffffffa0505000
  1542. xfrm4_tunnel 12617 0 - Live 0xffffffffa0500000
  1543. xfrm4_mode_tunnel 12496 4 - Live 0xffffffffa04f6000
  1544. xfrm4_mode_transport 12490 0 - Live 0xffffffffa04f1000
  1545. xfrm6_mode_transport 12490 0 - Live 0xffffffffa04ec000
  1546. xfrm6_mode_ro 12430 0 - Live 0xffffffffa04e7000
  1547. xfrm6_mode_beet 12522 0 - Live 0xffffffffa04e2000
  1548. xfrm6_mode_tunnel 12581 2 - Live 0xffffffffa04dd000
  1549. ipcomp 12507 0 - Live 0xffffffffa04d8000
  1550. ipcomp6 12507 0 - Live 0xffffffffa04d3000
  1551. xfrm6_tunnel 13032 1 ipcomp6, Live 0xffffffffa04ce000
  1552. tunnel6 12592 1 xfrm6_tunnel, Live 0xffffffffa04bf000
  1553. xfrm_ipcomp 12600 2 ipcomp,ipcomp6, Live 0xffffffffa04c9000
  1554. af_key 31759 0 - Live 0xffffffffa04b6000
  1555. iptable_filter 12536 1 - Live 0xffffffffa0608000
  1556. ip6table_mangle 12540 0 - Live 0xffffffffa0603000
  1557. ip6_tables 22175 1 ip6table_mangle, Live 0xffffffffa05f8000
  1558. iptable_mangle 12536 0 - Live 0xffffffffa05e4000
  1559. nfnetlink_log 17212 0 - Live 0xffffffffa05f2000
  1560. nfnetlink 12906 1 nfnetlink_log, Live 0xffffffffa05e9000
  1561. authenc 13417 2 - Live 0xffffffffa05d4000
  1562. rmd160 16640 0 - Live 0xffffffffa05d9000
  1563. sha1_ssse3 16983 2 - Live 0xffffffffa05ce000
  1564. sha1_generic 12582 1 sha1_ssse3, Live 0xffffffffa05c9000
  1565. hmac 12835 4 - Live 0xffffffffa05c4000
  1566. crypto_null 12732 0 - Live 0xffffffffa05bf000
  1567. camellia 29068 0 - Live 0xffffffffa05b6000
  1568. lzo 12531 0 - Live 0xffffffffa05b1000
  1569. cast6 16681 0 - Live 0xffffffffa05ab000
  1570. cast5 24829 0 - Live 0xffffffffa05a3000
  1571. deflate 12551 0 - Live 0xffffffffa059e000
  1572. zlib_deflate 25638 1 deflate, Live 0xffffffffa0596000
  1573. cts 12811 0 - Live 0xffffffffa0591000
  1574. ctr 12979 0 - Live 0xffffffffa058c000
  1575. gcm 19077 0 - Live 0xffffffffa0582000
  1576. ccm 17727 0 - Live 0xffffffffa057c000
  1577. serpent 29015 0 - Live 0xffffffffa0573000
  1578. blowfish_generic 12464 0 - Live 0xffffffffa056e000
  1579. blowfish_x86_64 21201 0 - Live 0xffffffffa0567000
  1580. blowfish_common 16487 2 blowfish_generic,blowfish_x86_64, Live 0xffffffffa0561000
  1581. twofish_generic 16569 0 - Live 0xffffffffa055b000
  1582. twofish_x86_64_3way 25167 0 - Live 0xffffffffa0553000
  1583. twofish_x86_64 12541 1 twofish_x86_64_3way, Live 0xffffffffa054e000
  1584. twofish_common 20544 3 twofish_generic,twofish_x86_64_3way,twofish_x86_64, Live 0xffffffffa0547000
  1585. ecb 12737 0 - Live 0xffffffffa0542000
  1586. xcbc 12709 0 - Live 0xffffffffa053d000
  1587. cbc 12754 2 - Live 0xffffffffa0538000
  1588. sha256_generic 16797 0 - Live 0xffffffffa0532000
  1589. sha512_generic 12625 0 - Live 0xffffffffa0526000
  1590. des_generic 20851 2 - Live 0xffffffffa052b000
  1591. tunnel4 12629 1 xfrm4_tunnel, Live 0xffffffffa04fb000
  1592. rng_core 12652 0 - Live 0xffffffffa04c4000
  1593. ipt_MASQUERADE 12594 2 - Live 0xffffffffa04b1000
  1594. iptable_nat 12928 1 - Live 0xffffffffa045f000
  1595. nf_nat 18242 2 ipt_MASQUERADE,iptable_nat, Live 0xffffffffa04ab000
  1596. nf_conntrack_ipv4 14078 3 iptable_nat,nf_nat, Live 0xffffffffa045a000
  1597. nf_defrag_ipv4 12483 1 nf_conntrack_ipv4, Live 0xffffffffa044d000
  1598. nf_conntrack 52720 4 ipt_MASQUERADE,iptable_nat,nf_nat,nf_conntrack_ipv4, Live 0xffffffffa049d000
  1599. ip_tables 22042 3 iptable_filter,iptable_mangle,iptable_nat, Live 0xffffffffa0453000
  1600. x_tables 19118 7 iptable_filter,ip6table_mangle,ip6_tables,iptable_mangle,ipt_MASQUERADE,iptable_nat,ip_tables, Live 0xffffffffa0379000
  1601. nfsd 216170 2 - Live 0xffffffffa0467000
  1602. nfs 308313 0 - Live 0xffffffffa0400000
  1603. nfs_acl 12511 2 nfsd,nfs, Live 0xffffffffa0374000
  1604. auth_rpcgss 37143 2 nfsd,nfs, Live 0xffffffffa03f5000
  1605. fscache 36739 1 nfs, Live 0xffffffffa036a000
  1606. lockd 67306 2 nfsd,nfs, Live 0xffffffffa03e3000
  1607. sunrpc 173730 6 nfsd,nfs,nfs_acl,auth_rpcgss,lockd, Live 0xffffffffa03b7000
  1608. loop 22641 0 - Live 0xffffffffa02f8000
  1609. snd_hda_codec_hdmi 30824 1 - Live 0xffffffffa02ef000
  1610. snd_hda_codec_realtek 188858 1 - Live 0xffffffffa0383000
  1611. tpm_infineon 12985 0 - Live 0xffffffffa02d5000
  1612. i915 378417 1 - Live 0xffffffffa030c000
  1613. hp_wmi 13329 0 - Live 0xffffffffa0307000
  1614. coretemp 12898 0 - Live 0xffffffffa0302000
  1615. crc32c_intel 12747 0 - Live 0xffffffffa02b0000
  1616. snd_hda_intel 26259 0 - Live 0xffffffffa0268000
  1617. snd_hda_codec 78031 3 snd_hda_codec_hdmi,snd_hda_codec_realtek,snd_hda_intel, Live 0xffffffffa02da000
  1618. drm_kms_helper 31370 1 i915, Live 0xffffffffa02ba000
  1619. sparse_keymap 12760 1 hp_wmi, Live 0xffffffffa02b5000
  1620. ghash_clmulni_intel 13173 0 - Live 0xffffffffa025c000
  1621. drm 183952 2 i915,drm_kms_helper, Live 0xffffffffa0282000
  1622. snd_hwdep 13186 1 snd_hda_codec, Live 0xffffffffa0229000
  1623. snd_pcm 68083 3 snd_hda_codec_hdmi,snd_hda_intel,snd_hda_codec, Live 0xffffffffa02c3000
  1624. aesni_intel 50667 0 - Live 0xffffffffa024e000
  1625. i2c_i801 16870 0 - Live 0xffffffffa0223000
  1626. iTCO_wdt 17081 0 - Live 0xffffffffa022f000
  1627. i2c_algo_bit 12841 1 i915, Live 0xffffffffa027d000
  1628. snd_page_alloc 13003 2 snd_hda_intel,snd_pcm, Live 0xffffffffa0274000
  1629. snd_timer 22917 1 snd_pcm, Live 0xffffffffa0261000
  1630. iTCO_vendor_support 12704 1 iTCO_wdt, Live 0xffffffffa01f0000
  1631. i2c_core 23876 5 i915,drm_kms_helper,drm,i2c_i801,i2c_algo_bit, Live 0xffffffffa0247000
  1632. aes_x86_64 16843 1 aesni_intel, Live 0xffffffffa0217000
  1633. psmouse 69265 0 - Live 0xffffffffa0235000
  1634. evdev 17562 6 - Live 0xffffffffa021d000
  1635. serio_raw 12931 0 - Live 0xffffffffa020c000
  1636. tpm_tis 17454 0 - Live 0xffffffffa0211000
  1637. rfkill 19012 1 hp_wmi, Live 0xffffffffa01ff000
  1638. acpi_cpufreq 12935 0 - Live 0xffffffffa01eb000
  1639. mperf 12453 1 acpi_cpufreq, Live 0xffffffffa010e000
  1640. pcspkr 12579 0 - Live 0xffffffffa01c8000
  1641. tpm 17862 2 tpm_infineon,tpm_tis, Live 0xffffffffa0143000
  1642. tpm_bios 12948 1 tpm, Live 0xffffffffa0109000
  1643. aes_generic 33026 2 aesni_intel,aes_x86_64, Live 0xffffffffa01f5000
  1644. snd 52889 7 snd_hda_codec_hdmi,snd_hda_codec_realtek,snd_hda_intel,snd_hda_codec,snd_hwdep,snd_pcm,snd_timer, Live 0xffffffffa01d8000
  1645. cryptd 14517 2 ghash_clmulni_intel,aesni_intel, Live 0xffffffffa01e6000
  1646. soundcore 13065 1 snd, Live 0xffffffffa00c1000
  1647. video 17683 1 i915, Live 0xffffffffa0206000
  1648. processor 28157 1 acpi_cpufreq, Live 0xffffffffa01d0000
  1649. button 12937 1 i915, Live 0xffffffffa00d1000
  1650. wmi 13243 1 hp_wmi, Live 0xffffffffa00bc000
  1651. ext4 350763 1 - Live 0xffffffffa0171000
  1652. crc16 12343 1 ext4, Live 0xffffffffa0098000
  1653. jbd2 62115 1 ext4, Live 0xffffffffa0160000
  1654. mbcache 13114 1 ext4, Live 0xffffffffa004d000
  1655. usb_storage 43870 0 - Live 0xffffffffa0137000
  1656. usbhid 36418 0 - Live 0xffffffffa00ff000
  1657. hid 81328 1 usbhid, Live 0xffffffffa0083000
  1658. sg 25874 0 - Live 0xffffffffa007b000
  1659. sr_mod 21899 0 - Live 0xffffffffa0070000
  1660. cdrom 35401 1 sr_mod, Live 0xffffffffa0066000
  1661. sd_mod 36136 3 - Live 0xffffffffa0043000
  1662. crc_t10dif 12348 1 sd_mod, Live 0xffffffffa0028000
  1663. ahci 24997 2 - Live 0xffffffffa005e000
  1664. libahci 22860 1 ahci, Live 0xffffffffa0053000
  1665. thermal 17383 0 - Live 0xffffffffa003d000
  1666. libata 140630 2 ahci,libahci, Live 0xffffffffa0113000
  1667. fan 12674 0 - Live 0xffffffffa0038000
  1668. thermal_sys 18040 4 video,processor,thermal,fan, Live 0xffffffffa002e000
  1669. xhci_hcd 73434 0 - Live 0xffffffffa014d000
  1670. scsi_mod 162269 5 usb_storage,sg,sr_mod,sd_mod,libata, Live 0xffffffffa00d6000
  1671. e1000e 120822 0 - Live 0xffffffffa009d000
  1672. ehci_hcd 40215 0 - Live 0xffffffffa00c6000
  1673. usbcore 128741 5 usb_storage,usbhid,xhci_hcd,ehci_hcd, Live 0xffffffffa0007000
  1674. usb_common 12354 1 usbcore, Live 0xffffffffa0000000
  1675. + _________________________ /proc/meminfo
  1676. +
  1677. + cat /proc/meminfo
  1678. MemTotal: 3933684 kB
  1679. MemFree: 3691832 kB
  1680. Buffers: 11864 kB
  1681. Cached: 157020 kB
  1682. SwapCached: 0 kB
  1683. Active: 99296 kB
  1684. Inactive: 84012 kB
  1685. Active(anon): 14460 kB
  1686. Inactive(anon): 5792 kB
  1687. Active(file): 84836 kB
  1688. Inactive(file): 78220 kB
  1689. Unevictable: 0 kB
  1690. Mlocked: 0 kB
  1691. SwapTotal: 8129532 kB
  1692. SwapFree: 8129532 kB
  1693. Dirty: 0 kB
  1694. Writeback: 0 kB
  1695. AnonPages: 14308 kB
  1696. Mapped: 7048 kB
  1697. Shmem: 5828 kB
  1698. Slab: 23396 kB
  1699. SReclaimable: 9428 kB
  1700. SUnreclaim: 13968 kB
  1701. KernelStack: 912 kB
  1702. PageTables: 2476 kB
  1703. NFS_Unstable: 0 kB
  1704. Bounce: 0 kB
  1705. WritebackTmp: 0 kB
  1706. CommitLimit: 10096372 kB
  1707. Committed_AS: 62508 kB
  1708. VmallocTotal: 34359738367 kB
  1709. VmallocUsed: 361380 kB
  1710. VmallocChunk: 34359373364 kB
  1711. HardwareCorrupted: 0 kB
  1712. AnonHugePages: 0 kB
  1713. HugePages_Total: 0
  1714. HugePages_Free: 0
  1715. HugePages_Rsvd: 0
  1716. HugePages_Surp: 0
  1717. Hugepagesize: 2048 kB
  1718. DirectMap4k: 61440 kB
  1719. DirectMap2M: 4016128 kB
  1720. + _________________________ /proc/net/ipsec-ls
  1721. +
  1722. + test -f /proc/net/ipsec_version
  1723. + _________________________ usr/src/linux/.config
  1724. +
  1725. + test -f /proc/config.gz
  1726. + uname -r
  1727. + test -f /lib/modules/3.2.0-4-amd64/build/.config
  1728. + echo no .config file found, cannot list kernel properties
  1729. no .config file found, cannot list kernel properties
  1730. + _________________________ etc/syslog.conf
  1731. +
  1732. + _________________________ etc/syslog-ng/syslog-ng.conf
  1733. +
  1734. + cat /etc/syslog-ng/syslog-ng.conf
  1735. cat: /etc/syslog-ng/syslog-ng.conf: No such file or directory
  1736. + cat /etc/syslog.conf
  1737. cat: /etc/syslog.conf: No such file or directory
  1738. + _________________________ etc/resolv.conf
  1739. +
  1740. + cat /etc/resolv.conf
  1741. nameserver 8.8.8.8
  1742. nameserver 8.8.4.4
  1743. + _________________________ lib/modules-ls
  1744. +
  1745. + ls -ltr /lib/modules
  1746. total 4
  1747. drwxr-xr-x 3 root root 4096 Aug 13 08:57 3.2.0-4-amd64
  1748. + _________________________ fipscheck
  1749. +
  1750. + cat /proc/sys/crypto/fips_enabled
  1751. 0
  1752. + _________________________ /proc/ksyms-netif_rx
  1753. +
  1754. + test -r /proc/ksyms
  1755. + test -r /proc/kallsyms
  1756. + egrep netif_rx /proc/kallsyms
  1757. ffffffff8128fa05 T netif_rx
  1758. ffffffff8128fbc9 T netif_rx_ni
  1759. + _________________________ lib/modules-netif_rx
  1760. +
  1761. + modulegoo kernel/net/ipv4/ipip.o netif_rx
  1762. + set +x
  1763. 3.2.0-4-amd64:
  1764. + _________________________ kern.debug
  1765. +
  1766. + test -f /var/log/kern.debug
  1767. + _________________________ klog
  1768. +
  1769. + sed -n 6069,$p /var/log/syslog
  1770. + egrep+ i ipsec|klips|pluto
  1771. cat
  1772. Aug 13 16:45:55 ipsec01 ipsec_setup: Starting Openswan IPsec U2.6.37-g955aaafb-dirty/K3.2.0-4-amd64...
  1773. Aug 13 16:45:55 ipsec01 kernel: [ 5047.149018] NET: Registered protocol family 15
  1774. Aug 13 16:45:55 ipsec01 ipsec_setup: Using NETKEY(XFRM) stack
  1775. Aug 13 16:45:55 ipsec01 kernel: [ 5047.220877] Initializing XFRM netlink socket
  1776. Aug 13 16:45:55 ipsec01 ipsec_setup: multiple ip addresses, using 192.168.210.166 on eth0
  1777. Aug 13 16:45:55 ipsec01 ipsec_setup: ...Openswan IPsec started
  1778. Aug 13 16:45:55 ipsec01 pluto: adjusting ipsec.d to /etc/ipsec.d
  1779. Aug 13 16:45:55 ipsec01 ipsec__plutorun: 002 added connection description "net1"
  1780. Aug 13 16:45:55 ipsec01 ipsec__plutorun: 104 "net1" #1: STATE_MAIN_I1: initiate
  1781. + _________________________ plog
  1782. +
  1783. + sed -n 1,$p /var/log/auth.log
  1784. + egrep -i pluto
  1785. + cat
  1786. Aug 13 16:45:55 ipsec01 ipsec__plutorun: Starting Pluto subsystem...
  1787. + _________________________ date
  1788. +
  1789. + date
  1790. Tue Aug 13 16:51:47 CEST 2013
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement