whackwest --name oe --delete --rsa --pfs --host 128.95.7.1 --ikeport 8500 --nexthop 128.95.7.254 --updown silly --to --updown sally --host %opportunisticdefaultgroup --ikeport 8500 --encrypt --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "oe" whackeast --name oe --delete --rsa --pfs --host 128.95.7.2 --ikeport 8500 --nexthop 128.95.7.254 --updown silly --to --updown sally --host %opportunisticdefaultgroup --ikeport 8500 --encrypt --rekeymargin 350 --ikelifetime 900 --ipseclifetime 800 --keyingtries 2 002 added connection description "oe" whackwest --listen 002 listening for IKE messages 002 adding interface virtual128.95.7.1/lo:w 128.95.7.1:8500 002 loading secrets from "/tmp/ipsec.secrets/west" 002 loading group "./ipsec.d/west/oe" whackeast --listen 002 listening for IKE messages 002 adding interface virtual128.95.7.2/lo:e 128.95.7.2 002 loading secrets from "/tmp/ipsec.secrets/east" whackwest --route --name oe whackeast --route --name oe whackwest --status 000 interface virtual128.95.7.1/lo:w 128.95.7.1:8500 000 000 "oe": 128.95.7.1:8500---128.95.7.254...%opportunisticgroup:8500 000 "oe": ike_life: 900s; ipsec_life: 800s; rekey_margin: 350s; rekey_fuzz: 100%; keyingtries: 2 000 "oe": policy: RSASIG+ENCRYPT+TUNNEL+PFS+OPPORTUNISTIC+GROUP+DEFAULT+GROUTED+rKOD; interface: lo:w; unrouted 000 "oe": newest ISAKMP SA: #0; newest IPsec SA: #0; eroute owner: #0 000 "oe#128.0.0.0/15": 128.95.7.1:8500---128.95.7.254...%opportunistic:8500===128.0.0.0/15 000 "oe#128.0.0.0/15": ike_life: 900s; ipsec_life: 800s; rekey_margin: 350s; rekey_fuzz: 100%; keyingtries: 2 000 "oe#128.0.0.0/15": policy: RSASIG+ENCRYPT+TUNNEL+PFS+OPPORTUNISTIC+rKOD; interface: lo:w; prospective erouted 000 "oe#128.0.0.0/15": newest ISAKMP SA: #0; newest IPsec SA: #0; eroute owner: #0 000 000 whackeast --status 000 interface virtual128.95.7.2/lo:e 128.95.7.2 000 000 "oe": 128.95.7.2:8500---128.95.7.254...%opportunisticgroup:8500 000 "oe": ike_life: 900s; ipsec_life: 800s; rekey_margin: 350s; rekey_fuzz: 100%; keyingtries: 2 000 "oe": policy: RSASIG+ENCRYPT+TUNNEL+PFS+OPPORTUNISTIC+GROUP+DEFAULT+GROUTED+rKOD; interface: lo:e; unrouted 000 "oe": newest ISAKMP SA: #0; newest IPsec SA: #0; eroute owner: #0 000 "oe#0.0.0.0/0": 128.95.7.2:8500---128.95.7.254...%opportunistic:8500 000 "oe#0.0.0.0/0": ike_life: 900s; ipsec_life: 800s; rekey_margin: 350s; rekey_fuzz: 100%; keyingtries: 2 000 "oe#0.0.0.0/0": policy: RSASIG+ENCRYPT+TUNNEL+PFS+OPPORTUNISTIC+rKOD; interface: lo:e; prospective erouted 000 "oe#0.0.0.0/0": newest ISAKMP SA: #0; newest IPsec SA: #0; eroute owner: #0 000 000 whackwest --shutdown 002 shutting down whackeast --shutdown 002 shutting down