NOTE: failure is expected because we use the wrong key whackwest --name ipsec-rsa --delete --rsa --host 128.95.7.2 --ikeport 8500 --client 128.95.7.20/30 --dnskeyondemand --updown silly --to --updown sally --dnskeyondemand --host 128.95.7.1 --ikeport 8500 --client 128.95.7.8/30 --authenticate --encrypt --pfs --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "ipsec-rsa" whackeast --name ipsec-rsa --delete --rsa --host 128.95.7.2 --ikeport 8500 --client 128.95.7.20/30 --dnskeyondemand --updown silly --to --updown sally --dnskeyondemand --host 128.95.7.1 --ikeport 8500 --client 128.95.7.8/30 --authenticate --encrypt --pfs --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "ipsec-rsa" whackwest --listen 002 listening for IKE messages 002 adding interface virtual128.95.7.1/lo:w 128.95.7.1:8500 002 loading secrets from "/tmp/ipsec.secrets/west" whackeast --listen 002 listening for IKE messages 002 adding interface virtual128.95.7.2/lo:e 128.95.7.2 002 loading secrets from "/tmp/ipsec.secrets/east" whackwest --keyid 128.95.7.2 --pubkeyrsa 0sAQOKe6+kbDtp4PB8NZshjCBw8z5wuGCAddokgSDATW47tNmQhUvzlnT1ia1ZsyiRFph1LJkz+A0bkbOhPr1vWUJHK6/s+Y8Rf7GSZC0Fi5Fr4DgpWwswzFaLl4baRfeu8z4k147dtSoG4K/6UfQ+IbqML5lwm92uRqONszbn/PDDPQ== whackwest --keyid @east.example.com --pubkeyrsa 0sAQOKe6+kbDtp4PB8NZshjCBw8z5wuGCAddokgSDATW47tNmQhUvzlnT1ia1ZsyiRFph1LJkz+A0bkbOhPr1vWUJHK6/s+Y8Rf7GSZC0Fi5Fr4DgpWwswzFaLl4baRfeu8z4k147dtSoG4K/6UfQ+IbqML5lwm92uRqONszbn/PDDPQ== whackwest --name ipsec-rsa --initiate 002 "ipsec-rsa" #1: initiating Main Mode 104 "ipsec-rsa" #1: STATE_MAIN_I1: initiate 106 "ipsec-rsa" #1: STATE_MAIN_I2: sent MI2, expecting MR2 108 "ipsec-rsa" #1: STATE_MAIN_I3: sent MI3, expecting MR3 003 "ipsec-rsa" #1: Signature check (on 128.95.7.2) failed (wrong key?); tried *AQOKe6+kb 217 "ipsec-rsa" #1: STATE_MAIN_I3: INVALID_KEY_INFORMATION 010 "ipsec-rsa" #1: STATE_MAIN_I3: retransmission; will wait 20s for response 003 "ipsec-rsa" #1: Signature check (on 128.95.7.2) failed (wrong key?); tried *AQOKe6+kb 217 "ipsec-rsa" #1: STATE_MAIN_I3: INVALID_KEY_INFORMATION 010 "ipsec-rsa" #1: STATE_MAIN_I3: retransmission; will wait 40s for response 003 "ipsec-rsa" #1: Signature check (on 128.95.7.2) failed (wrong key?); tried *AQOKe6+kb 217 "ipsec-rsa" #1: STATE_MAIN_I3: INVALID_KEY_INFORMATION 031 "ipsec-rsa" #1: max number of retransmissions (2) reached STATE_MAIN_I3. Possible authentication failure: no acceptable response to our first encrypted message 000 "ipsec-rsa" #1: starting keying attempt 2 of at most 2, but releasing whack RC: 31 whackwest --shutdown 002 shutting down whackeast --shutdown 002 shutting down