Guest User

charon_debug.log

a guest
Aug 8th, 2017
338
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 22.94 KB | None | 0 0
  1. Tue, 2017-08-08 14:18 00[DMN] Starting IKE charon daemon (strongSwan 5.5.3, Linux 4.12.4-1-ARCH, x86_64)
  2. Tue, 2017-08-08 14:18 00[LIB] plugin 'aesni': loaded successfully
  3. Tue, 2017-08-08 14:18 00[LIB] plugin 'aes': loaded successfully
  4. Tue, 2017-08-08 14:18 00[LIB] plugin 'des': loaded successfully
  5. Tue, 2017-08-08 14:18 00[LIB] plugin 'rc2': loaded successfully
  6. Tue, 2017-08-08 14:18 00[LIB] plugin 'sha2': loaded successfully
  7. Tue, 2017-08-08 14:18 00[LIB] plugin 'sha3': loaded successfully
  8. Tue, 2017-08-08 14:18 00[LIB] plugin 'sha1': loaded successfully
  9. Tue, 2017-08-08 14:18 00[LIB] plugin 'md5': loaded successfully
  10. Tue, 2017-08-08 14:18 00[LIB] plugin 'mgf1': loaded successfully
  11. Tue, 2017-08-08 14:18 00[LIB] plugin 'random': loaded successfully
  12. Tue, 2017-08-08 14:18 00[LIB] plugin 'nonce': loaded successfully
  13. Tue, 2017-08-08 14:18 00[LIB] plugin 'x509': loaded successfully
  14. Tue, 2017-08-08 14:18 00[LIB] plugin 'revocation': loaded successfully
  15. Tue, 2017-08-08 14:18 00[LIB] plugin 'constraints': loaded successfully
  16. Tue, 2017-08-08 14:18 00[LIB] plugin 'pubkey': loaded successfully
  17. Tue, 2017-08-08 14:18 00[LIB] plugin 'pkcs1': loaded successfully
  18. Tue, 2017-08-08 14:18 00[LIB] plugin 'pkcs7': loaded successfully
  19. Tue, 2017-08-08 14:18 00[LIB] plugin 'pkcs8': loaded successfully
  20. Tue, 2017-08-08 14:18 00[LIB] plugin 'pkcs12': loaded successfully
  21. Tue, 2017-08-08 14:18 00[LIB] plugin 'pgp': loaded successfully
  22. Tue, 2017-08-08 14:18 00[LIB] plugin 'dnskey': loaded successfully
  23. Tue, 2017-08-08 14:18 00[LIB] plugin 'sshkey': loaded successfully
  24. Tue, 2017-08-08 14:18 00[LIB] plugin 'dnscert': loaded successfully
  25. Tue, 2017-08-08 14:18 00[LIB] plugin 'pem': loaded successfully
  26. Tue, 2017-08-08 14:18 00[LIB] plugin 'openssl': loaded successfully
  27. Tue, 2017-08-08 14:18 00[LIB] plugin 'fips-prf': loaded successfully
  28. Tue, 2017-08-08 14:18 00[LIB] plugin 'gmp': loaded successfully
  29. Tue, 2017-08-08 14:18 00[LIB] plugin 'curve25519': loaded successfully
  30. Tue, 2017-08-08 14:18 00[LIB] plugin 'agent': loaded successfully
  31. Tue, 2017-08-08 14:18 00[LIB] plugin 'chapoly': loaded successfully
  32. Tue, 2017-08-08 14:18 00[LIB] plugin 'xcbc': loaded successfully
  33. Tue, 2017-08-08 14:18 00[LIB] plugin 'cmac': loaded successfully
  34. Tue, 2017-08-08 14:18 00[LIB] plugin 'hmac': loaded successfully
  35. Tue, 2017-08-08 14:18 00[LIB] plugin 'ntru': loaded successfully
  36. Tue, 2017-08-08 14:18 00[LIB] plugin 'newhope': loaded successfully
  37. Tue, 2017-08-08 14:18 00[LIB] plugin 'bliss': loaded successfully
  38. Tue, 2017-08-08 14:18 00[LIB] plugin 'curl': loaded successfully
  39. Tue, 2017-08-08 14:18 00[LIB] using SQLite 3.20.0, thread safety 1
  40. Tue, 2017-08-08 14:18 00[LIB] plugin 'sqlite': loaded successfully
  41. Tue, 2017-08-08 14:18 00[LIB] plugin 'attr': loaded successfully
  42. Tue, 2017-08-08 14:18 00[LIB] plugin 'attr-sql': loaded successfully
  43. Tue, 2017-08-08 14:18 00[LIB] plugin 'kernel-netlink': loaded successfully
  44. Tue, 2017-08-08 14:18 00[LIB] plugin 'resolve': loaded successfully
  45. Tue, 2017-08-08 14:18 00[LIB] plugin 'socket-default': loaded successfully
  46. Tue, 2017-08-08 14:18 00[LIB] plugin 'connmark': loaded successfully
  47. Tue, 2017-08-08 14:18 00[LIB] plugin 'forecast': loaded successfully
  48. Tue, 2017-08-08 14:18 00[LIB] plugin 'farp': loaded successfully
  49. Tue, 2017-08-08 14:18 00[LIB] plugin 'stroke': loaded successfully
  50. Tue, 2017-08-08 14:18 00[LIB] plugin 'vici': loaded successfully
  51. Tue, 2017-08-08 14:18 00[LIB] plugin 'sql': loaded successfully
  52. Tue, 2017-08-08 14:18 00[LIB] plugin 'updown': loaded successfully
  53. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-identity': loaded successfully
  54. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-sim': loaded successfully
  55. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-sim-file': loaded successfully
  56. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-aka': loaded successfully
  57. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-aka-3gpp2': loaded successfully
  58. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-simaka-pseudonym': loaded successfully
  59. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-simaka-reauth': loaded successfully
  60. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-md5': loaded successfully
  61. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-gtc': loaded successfully
  62. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-mschapv2': loaded successfully
  63. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-dynamic': loaded successfully
  64. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-radius': loaded successfully
  65. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-tls': loaded successfully
  66. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-ttls': loaded successfully
  67. Tue, 2017-08-08 14:18 00[LIB] plugin 'eap-peap': loaded successfully
  68. Tue, 2017-08-08 14:18 00[LIB] plugin 'xauth-generic': loaded successfully
  69. Tue, 2017-08-08 14:18 00[LIB] plugin 'xauth-eap': loaded successfully
  70. Tue, 2017-08-08 14:18 00[LIB] plugin 'xauth-pam': loaded successfully
  71. Tue, 2017-08-08 14:18 00[LIB] plugin 'xauth-noauth': loaded successfully
  72. Tue, 2017-08-08 14:18 00[LIB] plugin 'dhcp': loaded successfully
  73. Tue, 2017-08-08 14:18 00[LIB] plugin 'ha': loaded successfully
  74. Tue, 2017-08-08 14:18 00[LIB] plugin 'ext-auth': loaded successfully
  75. Tue, 2017-08-08 14:18 00[LIB] plugin 'radattr': loaded successfully
  76. Tue, 2017-08-08 14:18 00[LIB] plugin 'unity': loaded successfully
  77. Tue, 2017-08-08 14:18 00[LIB] feature PUBKEY:DSA in plugin 'pem' has unmet dependency: PUBKEY:DSA
  78. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:dnscert in plugin 'dnscert' has unmet dependency: RESOLVER
  79. Tue, 2017-08-08 14:18 00[LIB] feature PRIVKEY:DSA in plugin 'pem' has unmet dependency: PRIVKEY:DSA
  80. Tue, 2017-08-08 14:18 00[LIB] feature CERT_DECODE:OCSP_REQUEST in plugin 'pem' has unmet dependency: CERT_DECODE:OCSP_REQUEST
  81. Tue, 2017-08-08 14:18 00[CFG] attr-sql plugin: database URI not set
  82. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:attr-sql in plugin 'attr-sql' failed to load
  83. Tue, 2017-08-08 14:18 00[NET] using forecast interface wlp3s0
  84. Tue, 2017-08-08 14:18 00[CFG] joining forecast multicast groups: 224.0.0.1,224.0.0.22,224.0.0.251,224.0.0.252,239.255.255.250
  85. Tue, 2017-08-08 14:18 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts'
  86. Tue, 2017-08-08 14:18 00[CFG] loaded ca certificate "C=CH, O=strongSwan, CN=strongSwan Root CA" from '/etc/ipsec.d/cacerts/strongswanCert.pem'
  87. Tue, 2017-08-08 14:18 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts'
  88. Tue, 2017-08-08 14:18 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts'
  89. Tue, 2017-08-08 14:18 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts'
  90. Tue, 2017-08-08 14:18 00[CFG] loading crls from '/etc/ipsec.d/crls'
  91. Tue, 2017-08-08 14:18 00[CFG] loading secrets from '/etc/ipsec.secrets'
  92. Tue, 2017-08-08 14:18 00[CFG] loaded IKE secret for %any
  93. Tue, 2017-08-08 14:18 00[CFG] loaded EAP secret for 10.0.0.1 company@SRX100-local.de
  94. Tue, 2017-08-08 14:18 00[LIB] opening '/etc/ipsec.d/private/{' failed: No such file or directory
  95. Tue, 2017-08-08 14:18 00[LIB] building CRED_PRIVATE_KEY - RSA failed, tried 9 builders
  96. Tue, 2017-08-08 14:18 00[CFG] loading private key from '/etc/ipsec.d/private/{' failed
  97. Tue, 2017-08-08 14:18 00[CFG] line 9: missing ' : ' separator
  98. Tue, 2017-08-08 14:18 00[CFG] sql plugin: database URI not set
  99. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:sql in plugin 'sql' failed to load
  100. Tue, 2017-08-08 14:18 00[CFG] opening triplet file /etc/ipsec.d/triplets.dat failed: No such file or directory
  101. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:eap-sim-file-triplets in plugin 'eap-sim-file' failed to load
  102. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:sim-card in plugin 'eap-sim-file' has unmet dependency: CUSTOM:eap-sim-file-triplets
  103. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:sim-provider in plugin 'eap-sim-file' has unmet dependency: CUSTOM:eap-sim-file-triplets
  104. Tue, 2017-08-08 14:18 00[CFG] loaded 0 RADIUS server configurations
  105. Tue, 2017-08-08 14:18 00[CFG] HA config misses local/remote address
  106. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:ha in plugin 'ha' failed to load
  107. Tue, 2017-08-08 14:18 00[CFG] no script for ext-auth script defined, disabled
  108. Tue, 2017-08-08 14:18 00[LIB] feature CUSTOM:ext_auth in plugin 'ext-auth' failed to load
  109. Tue, 2017-08-08 14:18 00[LIB] unloading plugin 'dnscert' without loaded features
  110. Tue, 2017-08-08 14:18 00[LIB] unloading plugin 'attr-sql' without loaded features
  111. Tue, 2017-08-08 14:18 00[LIB] unloading plugin 'sql' without loaded features
  112. Tue, 2017-08-08 14:18 00[LIB] unloading plugin 'eap-sim-file' without loaded features
  113. Tue, 2017-08-08 14:18 00[LIB] unloading plugin 'ha' without loaded features
  114. Tue, 2017-08-08 14:18 00[LIB] unloading plugin 'ext-auth' without loaded features
  115. Tue, 2017-08-08 14:18 00[LIB] loaded plugins: charon aesni aes des rc2 sha2 sha3 sha1 md5 mgf1 random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey pem openssl fips-prf gmp curve25519 agent chapoly xcbc cmac hmac ntru newhope bliss curl sqlite attr kernel-netlink resolve socket-default connmark forecast farp stroke vici updown eap-identity eap-sim eap-aka eap-aka-3gpp2 eap-simaka-pseudonym eap-simaka-reauth eap-md5 eap-gtc eap-mschapv2 eap-dynamic eap-radius eap-tls eap-ttls eap-peap xauth-generic xauth-eap xauth-pam xauth-noauth dhcp radattr unity
  116. Tue, 2017-08-08 14:18 00[LIB] unable to load 11 plugin features (6 due to unmet dependencies)
  117. Tue, 2017-08-08 14:18 00[LIB] dropped capabilities, running as uid 0, gid 0
  118. Tue, 2017-08-08 14:18 00[JOB] spawning 16 worker threads
  119. Tue, 2017-08-08 14:18 01[LIB] created thread 01 [11209]
  120. Tue, 2017-08-08 14:18 02[LIB] created thread 02 [11210]
  121. Tue, 2017-08-08 14:18 03[LIB] created thread 03 [11211]
  122. Tue, 2017-08-08 14:18 04[LIB] created thread 04 [11212]
  123. Tue, 2017-08-08 14:18 05[LIB] created thread 05 [11213]
  124. Tue, 2017-08-08 14:18 06[LIB] created thread 06 [11214]
  125. Tue, 2017-08-08 14:18 07[LIB] created thread 07 [11215]
  126. Tue, 2017-08-08 14:18 08[LIB] created thread 08 [11216]
  127. Tue, 2017-08-08 14:18 09[LIB] created thread 09 [11217]
  128. Tue, 2017-08-08 14:18 10[LIB] created thread 10 [11218]
  129. Tue, 2017-08-08 14:18 11[LIB] created thread 11 [11219]
  130. Tue, 2017-08-08 14:18 12[LIB] created thread 12 [11220]
  131. Tue, 2017-08-08 14:18 13[LIB] created thread 13 [11221]
  132. Tue, 2017-08-08 14:18 14[LIB] created thread 14 [11222]
  133. Tue, 2017-08-08 14:18 15[LIB] created thread 15 [11223]
  134. Tue, 2017-08-08 14:18 16[LIB] created thread 16 [11224]
  135. Tue, 2017-08-08 14:18 05[CFG] received stroke: add connection 'isoware'
  136. Tue, 2017-08-08 14:18 05[CFG] conn isoware
  137. Tue, 2017-08-08 14:18 05[CFG] left=%any
  138. Tue, 2017-08-08 14:18 05[CFG] leftauth=psk
  139. Tue, 2017-08-08 14:18 05[CFG] leftauth2=xauth
  140. Tue, 2017-08-08 14:18 05[CFG] leftid=company@SRX100-local.de
  141. Tue, 2017-08-08 14:18 05[CFG] leftupdown=ipsec _updown iptables
  142. Tue, 2017-08-08 14:18 05[CFG] right=muc.isoware.com
  143. Tue, 2017-08-08 14:18 05[CFG] rightsubnet=192.168.32.0/24
  144. Tue, 2017-08-08 14:18 05[CFG] rightauth=psk
  145. Tue, 2017-08-08 14:18 05[CFG] rightid=10.0.0.1
  146. Tue, 2017-08-08 14:18 05[CFG] xauth_identity=USER
  147. Tue, 2017-08-08 14:18 05[CFG] ike=aes256-sha2_256-modp1536
  148. Tue, 2017-08-08 14:18 05[CFG] esp=aes256-sha1-modp1536
  149. Tue, 2017-08-08 14:18 05[CFG] dpddelay=30
  150. Tue, 2017-08-08 14:18 05[CFG] dpdtimeout=150
  151. Tue, 2017-08-08 14:18 05[CFG] sha256_96=no
  152. Tue, 2017-08-08 14:18 05[CFG] mediation=no
  153. Tue, 2017-08-08 14:18 05[CFG] keyexchange=ikev1
  154. Tue, 2017-08-08 14:18 17[LIB] created thread 17 [11225]
  155. Tue, 2017-08-08 14:18 06[CFG] received stroke: initiate 'isoware'
  156. Tue, 2017-08-08 14:18 06[CFG] no config named 'isoware'
  157. Tue, 2017-08-08 14:18 05[CFG] added configuration 'isoware'
  158. Tue, 2017-08-08 14:18 08[CFG] received stroke: initiate 'isoware'
  159. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> queueing ISAKMP_VENDOR task
  160. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> queueing ISAKMP_CERT_PRE task
  161. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> queueing AGGRESSIVE_MODE task
  162. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> queueing ISAKMP_CERT_POST task
  163. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> queueing ISAKMP_NATD task
  164. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> queueing QUICK_MODE task
  165. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> activating new tasks
  166. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> activating ISAKMP_VENDOR task
  167. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> activating ISAKMP_CERT_PRE task
  168. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> activating AGGRESSIVE_MODE task
  169. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> activating ISAKMP_CERT_POST task
  170. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> activating ISAKMP_NATD task
  171. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> sending XAuth vendor ID
  172. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> sending DPD vendor ID
  173. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> sending FRAGMENTATION vendor ID
  174. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> sending NAT-T (RFC 3947) vendor ID
  175. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> sending draft-ietf-ipsec-nat-t-ike-02\n vendor ID
  176. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> initiating Aggressive Mode IKE_SA isoware[1] to 10.0.0.1
  177. Tue, 2017-08-08 14:18 10[IKE] <isoware|1> IKE_SA isoware[1] state change: CREATED => CONNECTING
  178. Tue, 2017-08-08 14:18 10[CFG] <isoware|1> configured proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1536, IKE:AES_CBC_128/AES_CBC_192/AES_CBC_256/AES_CTR_128/AES_CTR_192/AES_CTR_256/CAMELLIA_CBC_128/CAMELLIA_CBC_192/CAMELLIA_CBC_256/3DES_CBC/HMAC_SHA2_256_128/HMAC_SHA2_384_192/HMAC_SHA2_512_256/AES_XCBC_96/AES_CMAC_96/HMAC_MD5_96/HMAC_SHA1_96/PRF_AES128_XCBC/PRF_AES128_CMAC/PRF_HMAC_SHA2_256/PRF_HMAC_SHA2_384/PRF_HMAC_SHA2_512/PRF_HMAC_MD5/PRF_HMAC_SHA1/ECP_256/ECP_384/ECP_521/ECP_256_BP/ECP_384_BP/ECP_512_BP/CURVE_25519/NTRU_128/NTRU_192/NTRU_256/NEWHOPE_128/MODP_3072/MODP_4096/MODP_8192/MODP_2048/MODP_1024, IKE:AES_CCM_16_128/AES_CCM_16_192/AES_CCM_16_256/AES_GCM_16_128/AES_GCM_16_192/AES_GCM_16_256/CHACHA20_POLY1305_256/AES_CCM_8_128/AES_CCM_8_192/AES_CCM_8_256/AES_CCM_12_128/AES_CCM_12_192/AES_CCM_12_256/AES_GCM_8_128/AES_GCM_8_192/AES_GCM_8_256/AES_GCM_12_128/AES_GCM_12_192/AES_GCM_12_256/PRF_AES128_XCBC/PRF_AES128_CMAC/PRF_HMAC_SHA2_256/PRF_HMAC_SHA2_384/PRF_HMAC_SHA2_512/PRF_HMAC_MD5/PRF_HMAC_SHA1/ECP_256/ECP_384/ECP_521/ECP_256_BP/ECP_384_BP/ECP_512_BP/CURVE_25519/NTRU_128/NTRU_192/NTRU_256/NEWHOPE_128/MODP_3072/MODP_4096/MODP_8192/MODP_2048/MODP_1024
  179. Tue, 2017-08-08 14:18 10[LIB] <isoware|1> size of DH secret exponent: 1535 bits
  180. Tue, 2017-08-08 14:18 10[ENC] <isoware|1> generating AGGRESSIVE request 0 [ SA KE No ID V V V V V ]
  181. Tue, 2017-08-08 14:18 10[NET] <isoware|1> sending packet: from 192.168.1.204[500] to 10.0.0.1[500] (503 bytes)
  182. Tue, 2017-08-08 14:18 11[NET] <isoware|1> received packet: from 10.0.0.1[500] to 192.168.1.204[500] (492 bytes)
  183. Tue, 2017-08-08 14:18 11[ENC] <isoware|1> parsed AGGRESSIVE response 0 [ SA KE No ID HASH V V V NAT-D NAT-D ]
  184. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> received DPD vendor ID
  185. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> received NAT-T (RFC 3947) vendor ID
  186. Tue, 2017-08-08 14:18 11[ENC] <isoware|1> received unknown vendor ID: 69:93:69:22:87:41:c6:d4:ca:09:4c:93:e2:42:c9:de:19:e7:b7:c6:00:00:00:05:00:00:05:00
  187. Tue, 2017-08-08 14:18 11[CFG] <isoware|1> selecting proposal:
  188. Tue, 2017-08-08 14:18 11[CFG] <isoware|1> proposal matches
  189. Tue, 2017-08-08 14:18 11[CFG] <isoware|1> received proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1536
  190. Tue, 2017-08-08 14:18 11[CFG] <isoware|1> configured proposals: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1536, IKE:AES_CBC_128/AES_CBC_192/AES_CBC_256/AES_CTR_128/AES_CTR_192/AES_CTR_256/CAMELLIA_CBC_128/CAMELLIA_CBC_192/CAMELLIA_CBC_256/3DES_CBC/HMAC_SHA2_256_128/HMAC_SHA2_384_192/HMAC_SHA2_512_256/AES_XCBC_96/AES_CMAC_96/HMAC_MD5_96/HMAC_SHA1_96/PRF_AES128_XCBC/PRF_AES128_CMAC/PRF_HMAC_SHA2_256/PRF_HMAC_SHA2_384/PRF_HMAC_SHA2_512/PRF_HMAC_MD5/PRF_HMAC_SHA1/ECP_256/ECP_384/ECP_521/ECP_256_BP/ECP_384_BP/ECP_512_BP/CURVE_25519/NTRU_128/NTRU_192/NTRU_256/NEWHOPE_128/MODP_3072/MODP_4096/MODP_8192/MODP_2048/MODP_1024, IKE:AES_CCM_16_128/AES_CCM_16_192/AES_CCM_16_256/AES_GCM_16_128/AES_GCM_16_192/AES_GCM_16_256/CHACHA20_POLY1305_256/AES_CCM_8_128/AES_CCM_8_192/AES_CCM_8_256/AES_CCM_12_128/AES_CCM_12_192/AES_CCM_12_256/AES_GCM_8_128/AES_GCM_8_192/AES_GCM_8_256/AES_GCM_12_128/AES_GCM_12_192/AES_GCM_12_256/PRF_AES128_XCBC/PRF_AES128_CMAC/PRF_HMAC_SHA2_256/PRF_HMAC_SHA2_384/PRF_HMAC_SHA2_512/PRF_HMAC_MD5/PRF_HMAC_SHA1/ECP_256/ECP_384/ECP_521/ECP_256_BP/ECP_384_BP/ECP_512_BP/CURVE_25519/NTRU_128/NTRU_192/NTRU_256/NEWHOPE_128/MODP_3072/MODP_4096/MODP_8192/MODP_2048/MODP_1024
  191. Tue, 2017-08-08 14:18 11[CFG] <isoware|1> selected proposal: IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1536
  192. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> local host is behind NAT, sending keep alives
  193. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> reinitiating already active tasks
  194. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> ISAKMP_VENDOR task
  195. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> AGGRESSIVE_MODE task
  196. Tue, 2017-08-08 14:18 11[ENC] <isoware|1> generating AGGRESSIVE request 0 [ HASH NAT-D NAT-D ]
  197. Tue, 2017-08-08 14:18 11[NET] <isoware|1> sending packet: from 192.168.1.204[4500] to 10.0.0.1[4500] (140 bytes)
  198. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> activating new tasks
  199. Tue, 2017-08-08 14:18 11[IKE] <isoware|1> nothing to initiate
  200. Tue, 2017-08-08 14:18 12[NET] <isoware|1> received packet: from 10.0.0.1[4500] to 192.168.1.204[4500] (92 bytes)
  201. Tue, 2017-08-08 14:18 12[ENC] <isoware|1> parsed TRANSACTION request 4202125993 [ HASH CPRQ(X_USER X_PWD) ]
  202. Tue, 2017-08-08 14:18 12[ENC] <isoware|1> generating TRANSACTION response 4202125993 [ HASH CPRP(X_USER X_PWD) ]
  203. Tue, 2017-08-08 14:18 12[NET] <isoware|1> sending packet: from 192.168.1.204[4500] to 10.0.0.1[4500] (108 bytes)
  204. Tue, 2017-08-08 14:18 13[NET] <isoware|1> received packet: from 10.0.0.1[4500] to 192.168.1.204[4500] (76 bytes)
  205. Tue, 2017-08-08 14:18 13[ENC] <isoware|1> parsed TRANSACTION request 2039778700 [ HASH CPS(X_STATUS) ]
  206. Tue, 2017-08-08 14:18 13[IKE] <isoware|1> XAuth authentication of 'USER' (myself) successful
  207. Tue, 2017-08-08 14:18 13[IKE] <isoware|1> IKE_SA isoware[1] established between 192.168.1.204[company@SRX100-local.de]...10.0.0.1[10.0.0.1]
  208. Tue, 2017-08-08 14:18 13[IKE] <isoware|1> IKE_SA isoware[1] state change: CONNECTING => ESTABLISHED
  209. Tue, 2017-08-08 14:18 13[IKE] <isoware|1> scheduling reauthentication in 3377s
  210. Tue, 2017-08-08 14:18 13[IKE] <isoware|1> maximum IKE_SA lifetime 3557s
  211. Tue, 2017-08-08 14:18 13[ENC] <isoware|1> generating TRANSACTION response 2039778700 [ HASH CPA(X_STATUS) ]
  212. Tue, 2017-08-08 14:18 13[NET] <isoware|1> sending packet: from 192.168.1.204[4500] to 10.0.0.1[4500] (92 bytes)
  213. Tue, 2017-08-08 14:18 13[IKE] <isoware|1> activating new tasks
  214. Tue, 2017-08-08 14:18 13[IKE] <isoware|1> activating QUICK_MODE task
  215. Tue, 2017-08-08 14:18 13[CFG] <isoware|1> configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ, ESP:AES_CBC_128/AES_CBC_192/AES_CBC_256/3DES_CBC/BLOWFISH_CBC_256/HMAC_SHA2_256_128/HMAC_SHA2_384_192/HMAC_SHA2_512_256/HMAC_SHA1_96/AES_XCBC_96/HMAC_MD5_96/NO_EXT_SEQ
  216. Tue, 2017-08-08 14:18 13[CFG] <isoware|1> configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ, ESP:AES_CBC_128/AES_CBC_192/AES_CBC_256/3DES_CBC/BLOWFISH_CBC_256/HMAC_SHA2_256_128/HMAC_SHA2_384_192/HMAC_SHA2_512_256/HMAC_SHA1_96/AES_XCBC_96/HMAC_MD5_96/NO_EXT_SEQ
  217. Tue, 2017-08-08 14:18 13[LIB] <isoware|1> size of DH secret exponent: 1535 bits
  218. Tue, 2017-08-08 14:18 13[CFG] <isoware|1> proposing traffic selectors for us:
  219. Tue, 2017-08-08 14:18 13[CFG] <isoware|1> 192.168.1.204/32
  220. Tue, 2017-08-08 14:18 13[CFG] <isoware|1> proposing traffic selectors for other:
  221. Tue, 2017-08-08 14:18 13[CFG] <isoware|1> 192.168.32.0/24
  222. Tue, 2017-08-08 14:18 13[ENC] <isoware|1> generating QUICK_MODE request 2905969012 [ HASH SA No KE ID ID ]
  223. Tue, 2017-08-08 14:18 13[NET] <isoware|1> sending packet: from 192.168.1.204[4500] to 10.0.0.1[4500] (396 bytes)
  224. Tue, 2017-08-08 14:18 14[NET] <isoware|1> received packet: from 10.0.0.1[4500] to 192.168.1.204[4500] (124 bytes)
  225. Tue, 2017-08-08 14:18 14[IKE] <isoware|1> queueing TRANSACTION request as tasks still active
  226. Tue, 2017-08-08 14:18 04[NET] <isoware|1> received packet: from 10.0.0.1[4500] to 192.168.1.204[4500] (364 bytes)
  227. Tue, 2017-08-08 14:18 04[ENC] <isoware|1> parsed QUICK_MODE response 2905969012 [ HASH SA No KE ID ID ]
  228. Tue, 2017-08-08 14:18 04[CFG] <isoware|1> selecting proposal:
  229. Tue, 2017-08-08 14:18 04[CFG] <isoware|1> proposal matches
  230. Tue, 2017-08-08 14:18 04[CFG] <isoware|1> received proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ
  231. Tue, 2017-08-08 14:18 04[CFG] <isoware|1> configured proposals: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ, ESP:AES_CBC_128/AES_CBC_192/AES_CBC_256/3DES_CBC/BLOWFISH_CBC_256/HMAC_SHA2_256_128/HMAC_SHA2_384_192/HMAC_SHA2_512_256/HMAC_SHA1_96/AES_XCBC_96/HMAC_MD5_96/NO_EXT_SEQ
  232. Tue, 2017-08-08 14:18 04[CFG] <isoware|1> selected proposal: ESP:AES_CBC_256/HMAC_SHA1_96/MODP_1536/NO_EXT_SEQ
  233. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> CHILD_SA isoware{1} state change: CREATED => INSTALLING
  234. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> using AES_CBC for encryption
  235. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> using HMAC_SHA1_96 for integrity
  236. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> adding inbound ESP SA
  237. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> SPI 0xc615b8e0, src 10.0.0.1 dst 192.168.1.204
  238. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> adding outbound ESP SA
  239. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> SPI 0xb6287a68, src 192.168.1.204 dst 10.0.0.1
  240. Tue, 2017-08-08 14:18 04[CHD] <isoware|1> CHILD_SA isoware{1} state change: INSTALLING => INSTALLED
  241. Tue, 2017-08-08 14:18 04[IKE] <isoware|1> CHILD_SA isoware{1} established with SPIs c615b8e0_i b6287a68_o and TS 192.168.1.204/32 === 192.168.32.0/24
  242. Tue, 2017-08-08 14:18 04[IKE] <isoware|1> reinitiating already active tasks
  243. Tue, 2017-08-08 14:18 04[IKE] <isoware|1> QUICK_MODE task
  244. Tue, 2017-08-08 14:18 04[ENC] <isoware|1> generating QUICK_MODE request 2905969012 [ HASH ]
  245. Tue, 2017-08-08 14:18 04[NET] <isoware|1> sending packet: from 192.168.1.204[4500] to 10.0.0.1[4500] (76 bytes)
  246. Tue, 2017-08-08 14:18 04[IKE] <isoware|1> activating new tasks
  247. Tue, 2017-08-08 14:18 04[IKE] <isoware|1> nothing to initiate
  248. Tue, 2017-08-08 14:18 05[NET] <isoware|1> received packet: from 10.0.0.1[4500] to 192.168.1.204[4500] (124 bytes)
  249. Tue, 2017-08-08 14:18 05[ENC] <isoware|1> parsed TRANSACTION request 1127061354 [ HASH CPS(ADDR MASK DNS NBNS SUBNET) ]
  250. Tue, 2017-08-08 14:18 05[IKE] <isoware|1> processing INTERNAL_IP4_ADDRESS attribute
  251. Tue, 2017-08-08 14:18 05[IKE] <isoware|1> processing INTERNAL_IP4_NETMASK attribute
  252. Tue, 2017-08-08 14:18 05[IKE] <isoware|1> processing INTERNAL_IP4_DNS attribute
  253. Tue, 2017-08-08 14:18 05[IKE] <isoware|1> processing INTERNAL_IP4_NBNS attribute
  254. Tue, 2017-08-08 14:18 05[IKE] <isoware|1> processing INTERNAL_IP4_SUBNET attribute
  255. Tue, 2017-08-08 14:18 05[IKE] <isoware|1> peer requested virtual IP 192.168.31.79
  256. Tue, 2017-08-08 14:18 05[IKE] <isoware|1> no virtual IP found for 192.168.31.79 requested by '10.0.0.1'
  257. Tue, 2017-08-08 14:18 05[ENC] <isoware|1> generating TRANSACTION response 1127061354 [ HASH CP ]
  258. Tue, 2017-08-08 14:18 05[NET] <isoware|1> sending packet: from 192.168.1.204[4500] to 10.0.0.1[4500] (76 bytes)
Add Comment
Please, Sign In to add comment