east:~# TESTING=${TESTING:-/testing} east:~# PATH=${TESTING}/pluto/bin:$PATH export PATH east:~# TESTNAME=aggr-unit-02 east:~# export PLUTO="ipsec pluto" east:~# export WHACK="ipsec whack" east:~# ${TESTING}/pluto/bin/ifconfigs up east:~# . CONFIG east:~# cd /tmp east:/tmp# mkdir -p $TESTNAME east:/tmp# cd $TESTNAME east:/tmp/aggr-unit-02# export HELPERS="--nhelpers 0 " east:/tmp/aggr-unit-02# mkdir -p log.ref east:/tmp/aggr-unit-02# mkdir -p log east:/tmp/aggr-unit-02# LD=log east:/tmp/aggr-unit-02# ln -s ${TESTING}/pluto/$TESTNAME/isakmp-aggr-psk-east.txt log.ref/pr-log east:/tmp/aggr-unit-02# ln -s ${TESTING}/pluto/$TESTNAME/isakmp-aggr-psk-west.txt log.ref/pi-log east:/tmp/aggr-unit-02# ln -s ${TESTING}/pluto/$TESTNAME/isakmp-aggr-psk-whack.txt log.ref/wi-log east:/tmp/aggr-unit-02# ln -s ${TESTING}/pluto/ipsec.secrets . east:/tmp/aggr-unit-02# ln -s ${TESTING}/pluto/ipsec.d/west . east:/tmp/aggr-unit-02# ln -s ${TESTING}/pluto/ipsec.d/east . east:/tmp/aggr-unit-02# ulimit -c unlimited east:/tmp/aggr-unit-02# $DOPLUTO west >$LD/pi-log 2>&1 east:/tmp/aggr-unit-02# $DOPLUTO east >$LD/pr-log 2>&1 east:/tmp/aggr-unit-02# $DOWHACK listen whackwest --listen 002 listening for IKE messages 002 adding interface virtual127.95.7.1/lo:w 127.95.7.1:8500 002 loading secrets from "/tmp/aggr-unit-02/ipsec.secrets/west" whackeast --listen 002 listening for IKE messages 002 adding interface virtual127.95.7.2/lo:e 127.95.7.2:8500 002 loading secrets from "/tmp/aggr-unit-02/ipsec.secrets/east" east:/tmp/aggr-unit-02# sh $TESTING/pluto/$TESTNAME/dowhack.sh whackwest --name isakmp-aggr2-psk --psk --aggrmode --ike=3des-sha1 --host 127.95.7.2 --ikeport 8500 --updown silly --to --updown sally --host 127.95.7.1 --ikeport 8500 --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "isakmp-aggr2-psk" whackeast --name isakmp-aggr2-psk --psk --aggrmode --ike=3des-sha1 --host 127.95.7.2 --ikeport 8500 --updown silly --to --updown sally --host 127.95.7.1 --ikeport 8500 --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "isakmp-aggr2-psk" whackwest --name isakmp-aggr2-psk --initiate 003 "isakmp-aggr2-psk" #1: multiple transforms were set in aggressive mode. Only first one used. 003 "isakmp-aggr2-psk" #1: transform (5,2,2,0) ignored. 002 "isakmp-aggr2-psk" #1: initiating Aggressive Mode #1, connection "isakmp-aggr2-psk" 003 "isakmp-aggr2-psk" #1: multiple transforms were set in aggressive mode. Only first one used. 003 "isakmp-aggr2-psk" #1: transform (5,2,2,0) ignored. 112 "isakmp-aggr2-psk" #1: STATE_AGGR_I1: initiate 003 "isakmp-aggr2-psk" #1: received Vendor ID payload [Dead Peer Detection] 002 "isakmp-aggr2-psk" #1: Aggressive mode peer ID is ID_IPV4_ADDR: '127.95.7.2' 002 "isakmp-aggr2-psk" #1: Aggressive mode peer ID is ID_IPV4_ADDR: '127.95.7.2' 002 "isakmp-aggr2-psk" #1: transition from state STATE_AGGR_I1 to state STATE_AGGR_I2 004 "isakmp-aggr2-psk" #1: STATE_AGGR_I2: sent AI2, ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192 prf=oakley_sha group=modp1536} whackwest --shutdown 002 shutting down whackeast --shutdown 002 shutting down east:/tmp/aggr-unit-02# export HELPERS="--nhelpers 1 " east:/tmp/aggr-unit-02# $DOPLUTO west >$LD/pi-log 2>&1 east:/tmp/aggr-unit-02# $DOPLUTO east >$LD/pr-log 2>&1 east:/tmp/aggr-unit-02# $DOWHACK listen whackwest --listen 002 listening for IKE messages 002 adding interface virtual127.95.7.1/lo:w 127.95.7.1:8500 002 loading secrets from "/tmp/aggr-unit-02/ipsec.secrets/west" whackeast --listen 002 listening for IKE messages 002 adding interface virtual127.95.7.2/lo:e 127.95.7.2:8500 002 loading secrets from "/tmp/aggr-unit-02/ipsec.secrets/east" east:/tmp/aggr-unit-02# sh $TESTING/pluto/$TESTNAME/dowhack.sh whackwest --name isakmp-aggr2-psk --psk --aggrmode --ike=3des-sha1 --host 127.95.7.2 --ikeport 8500 --updown silly --to --updown sally --host 127.95.7.1 --ikeport 8500 --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "isakmp-aggr2-psk" whackeast --name isakmp-aggr2-psk --psk --aggrmode --ike=3des-sha1 --host 127.95.7.2 --ikeport 8500 --updown silly --to --updown sally --host 127.95.7.1 --ikeport 8500 --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "isakmp-aggr2-psk" whackwest --name isakmp-aggr2-psk --initiate 003 "isakmp-aggr2-psk" #1: multiple transforms were set in aggressive mode. Only first one used. 003 "isakmp-aggr2-psk" #1: transform (5,2,2,0) ignored. 002 "isakmp-aggr2-psk" #1: initiating Aggressive Mode #1, connection "isakmp-aggr2-psk" 003 "isakmp-aggr2-psk" #1: multiple transforms were set in aggressive mode. Only first one used. 003 "isakmp-aggr2-psk" #1: transform (5,2,2,0) ignored. 112 "isakmp-aggr2-psk" #1: STATE_AGGR_I1: initiate 003 "isakmp-aggr2-psk" #1: received Vendor ID payload [Dead Peer Detection] 002 "isakmp-aggr2-psk" #1: Aggressive mode peer ID is ID_IPV4_ADDR: '127.95.7.2' 002 "isakmp-aggr2-psk" #1: Aggressive mode peer ID is ID_IPV4_ADDR: '127.95.7.2' 002 "isakmp-aggr2-psk" #1: transition from state STATE_AGGR_I1 to state STATE_AGGR_I2 004 "isakmp-aggr2-psk" #1: STATE_AGGR_I2: sent AI2, ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192 prf=oakley_sha group=modp1536} whackwest --shutdown 002 shutting down whackeast --shutdown 002 shutting down