Aug 3 00:25:10 moon charon: 00[DMN] Starting IKEv2 charon daemon (strongSwan 4.5.3) Aug 3 00:25:10 moon charon: 00[CFG] loading ca certificates from '/etc/ipsec.d/cacerts' Aug 3 00:25:10 moon charon: 00[CFG] loaded ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" from '/etc/ipsec.d/cacerts/strongswanCert.pem' Aug 3 00:25:10 moon charon: 00[CFG] loading aa certificates from '/etc/ipsec.d/aacerts' Aug 3 00:25:10 moon charon: 00[CFG] loading ocsp signer certificates from '/etc/ipsec.d/ocspcerts' Aug 3 00:25:10 moon charon: 00[CFG] loading attribute certificates from '/etc/ipsec.d/acerts' Aug 3 00:25:10 moon charon: 00[CFG] loading crls from '/etc/ipsec.d/crls' Aug 3 00:25:10 moon charon: 00[CFG] loading secrets from '/etc/ipsec.secrets' Aug 3 00:25:10 moon charon: 00[CFG] loaded RSA private key from '/etc/ipsec.d/private/moonKey.pem' Aug 3 00:25:10 moon charon: 00[KNL] listening on interfaces: Aug 3 00:25:10 moon charon: 00[KNL] eth0 Aug 3 00:25:10 moon charon: 00[KNL] 192.168.0.1 Aug 3 00:25:10 moon charon: 00[KNL] fec0::1 Aug 3 00:25:10 moon charon: 00[KNL] fe80::fcfd:c0ff:fea8:1 Aug 3 00:25:10 moon charon: 00[KNL] eth1 Aug 3 00:25:10 moon charon: 00[KNL] 10.1.0.1 Aug 3 00:25:10 moon charon: 00[KNL] fec1::1 Aug 3 00:25:10 moon charon: 00[KNL] fe80::fcfd:aff:fe01:1 Aug 3 00:25:10 moon charon: 00[DMN] loaded plugins: curl aes des sha1 sha2 md5 pem pkcs1 gmp random x509 revocation hmac xcbc stroke kernel-netlink socket-default updown attr farp dhcp Aug 3 00:25:10 moon charon: 00[JOB] spawning 16 worker threads Aug 3 00:25:10 moon charon: 13[CFG] received stroke: add connection 'rw' Aug 3 00:25:10 moon charon: 13[CFG] loaded certificate "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" from 'moonCert.pem' Aug 3 00:25:10 moon charon: 13[CFG] added configuration 'rw' Aug 3 00:25:12 moon charon: 06[NET] received packet: from 192.168.0.100[500] to 192.168.0.1[500] Aug 3 00:25:12 moon charon: 06[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ] Aug 3 00:25:12 moon charon: 06[IKE] 192.168.0.100 is initiating an IKE_SA Aug 3 00:25:13 moon charon: 06[IKE] sending cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:13 moon charon: 06[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(MULT_AUTH) ] Aug 3 00:25:13 moon charon: 06[NET] sending packet: from 192.168.0.1[500] to 192.168.0.100[500] Aug 3 00:25:13 moon charon: 05[NET] received packet: from 192.168.0.100[4500] to 192.168.0.1[4500] Aug 3 00:25:13 moon charon: 05[ENC] parsed IKE_AUTH request 1 [ IDi CERT N(INIT_CONTACT) CERTREQ IDr AUTH CP(ADDR DNS) SA TSi TSr N(MOBIKE_SUP) N(ADD_6_ADDR) N(MULT_AUTH) N(EAP_ONLY) ] Aug 3 00:25:13 moon charon: 05[IKE] received cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:13 moon charon: 05[IKE] received end entity cert "C=CH, O=Linux strongSwan, OU=Research, CN=carol@strongswan.org" Aug 3 00:25:13 moon charon: 05[CFG] looking for peer configs matching 192.168.0.1[moon.strongswan.org]...192.168.0.100[carol@strongswan.org] Aug 3 00:25:13 moon charon: 05[CFG] selected peer config 'rw' Aug 3 00:25:13 moon charon: 05[CFG] using certificate "C=CH, O=Linux strongSwan, OU=Research, CN=carol@strongswan.org" Aug 3 00:25:13 moon charon: 05[CFG] using trusted ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:13 moon charon: 05[CFG] checking certificate status of "C=CH, O=Linux strongSwan, OU=Research, CN=carol@strongswan.org" Aug 3 00:25:13 moon charon: 05[CFG] fetching crl from 'http://crl.strongswan.org/strongswan.crl' ... Aug 3 00:25:13 moon charon: 05[CFG] using trusted certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:13 moon charon: 05[CFG] crl correctly signed by "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:13 moon charon: 05[CFG] crl is valid: until Sep 01 21:49:28 2011 Aug 3 00:25:13 moon charon: 05[CFG] certificate status is good Aug 3 00:25:13 moon charon: 05[CFG] reached self-signed root ca with a path length of 0 Aug 3 00:25:13 moon charon: 05[IKE] authentication of 'carol@strongswan.org' with RSA signature successful Aug 3 00:25:13 moon charon: 05[IKE] peer supports MOBIKE Aug 3 00:25:13 moon charon: 05[IKE] authentication of 'moon.strongswan.org' (myself) with RSA signature successful Aug 3 00:25:13 moon charon: 05[IKE] IKE_SA rw[1] established between 192.168.0.1[moon.strongswan.org]...192.168.0.100[carol@strongswan.org] Aug 3 00:25:13 moon charon: 05[IKE] scheduling reauthentication in 3335s Aug 3 00:25:13 moon charon: 05[IKE] maximum IKE_SA lifetime 3515s Aug 3 00:25:13 moon charon: 05[IKE] sending end entity cert "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" Aug 3 00:25:13 moon charon: 05[IKE] peer requested virtual IP %any Aug 3 00:25:13 moon charon: 05[CFG] sending DHCP DISCOVER to 10.1.255.255 Aug 3 00:25:13 moon charon: 12[CFG] received DHCP OFFER 10.1.0.30 from 10.1.0.20 Aug 3 00:25:13 moon charon: 05[CFG] sending DHCP REQUEST for 10.1.0.30 to 10.1.0.20 Aug 3 00:25:13 moon charon: 12[CFG] received DHCP ACK for 10.1.0.30 Aug 3 00:25:13 moon charon: 05[IKE] assigning virtual IP 10.1.0.30 to peer 'carol@strongswan.org' Aug 3 00:25:13 moon charon: 05[IKE] CHILD_SA rw{1} established with SPIs c92c67f6_i c7e3865d_o and TS 10.1.0.0/16 === 10.1.0.30/32 Aug 3 00:25:14 moon charon: 05[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH CP(ADDR DNS NBNS) SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_6_ADDR) N(ADD_6_ADDR) ] Aug 3 00:25:14 moon charon: 05[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] Aug 3 00:25:14 moon charon: 04[NET] received packet: from 192.168.0.200[500] to 192.168.0.1[500] Aug 3 00:25:14 moon charon: 04[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) ] Aug 3 00:25:14 moon charon: 04[IKE] 192.168.0.200 is initiating an IKE_SA Aug 3 00:25:14 moon charon: 04[IKE] sending cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:14 moon charon: 04[ENC] generating IKE_SA_INIT response 0 [ SA KE No N(NATD_S_IP) N(NATD_D_IP) CERTREQ N(MULT_AUTH) ] Aug 3 00:25:14 moon charon: 04[NET] sending packet: from 192.168.0.1[500] to 192.168.0.200[500] Aug 3 00:25:14 moon charon: 03[NET] received packet: from 192.168.0.200[4500] to 192.168.0.1[4500] Aug 3 00:25:14 moon charon: 03[ENC] parsed IKE_AUTH request 1 [ IDi CERT N(INIT_CONTACT) CERTREQ IDr AUTH CP(ADDR DNS) SA TSi TSr N(MOBIKE_SUP) N(ADD_6_ADDR) N(MULT_AUTH) N(EAP_ONLY) ] Aug 3 00:25:14 moon charon: 03[IKE] received cert request for "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:14 moon charon: 03[IKE] received end entity cert "C=CH, O=Linux strongSwan, OU=Accounting, CN=dave@strongswan.org" Aug 3 00:25:14 moon charon: 03[CFG] looking for peer configs matching 192.168.0.1[moon.strongswan.org]...192.168.0.200[dave@strongswan.org] Aug 3 00:25:14 moon charon: 03[CFG] selected peer config 'rw' Aug 3 00:25:14 moon charon: 03[CFG] using certificate "C=CH, O=Linux strongSwan, OU=Accounting, CN=dave@strongswan.org" Aug 3 00:25:14 moon charon: 03[CFG] using trusted ca certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:14 moon charon: 03[CFG] checking certificate status of "C=CH, O=Linux strongSwan, OU=Accounting, CN=dave@strongswan.org" Aug 3 00:25:14 moon charon: 03[CFG] using trusted certificate "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:14 moon charon: 03[CFG] crl correctly signed by "C=CH, O=Linux strongSwan, CN=strongSwan Root CA" Aug 3 00:25:14 moon charon: 03[CFG] crl is valid: until Sep 01 21:49:28 2011 Aug 3 00:25:14 moon charon: 03[CFG] using cached crl Aug 3 00:25:14 moon charon: 03[CFG] certificate status is good Aug 3 00:25:14 moon charon: 03[CFG] reached self-signed root ca with a path length of 0 Aug 3 00:25:14 moon charon: 03[IKE] authentication of 'dave@strongswan.org' with RSA signature successful Aug 3 00:25:14 moon charon: 03[IKE] peer supports MOBIKE Aug 3 00:25:15 moon charon: 03[IKE] authentication of 'moon.strongswan.org' (myself) with RSA signature successful Aug 3 00:25:15 moon charon: 03[IKE] IKE_SA rw[2] established between 192.168.0.1[moon.strongswan.org]...192.168.0.200[dave@strongswan.org] Aug 3 00:25:15 moon charon: 03[IKE] scheduling reauthentication in 3256s Aug 3 00:25:15 moon charon: 03[IKE] maximum IKE_SA lifetime 3436s Aug 3 00:25:15 moon charon: 03[IKE] sending end entity cert "C=CH, O=Linux strongSwan, CN=moon.strongswan.org" Aug 3 00:25:15 moon charon: 03[IKE] peer requested virtual IP %any Aug 3 00:25:15 moon charon: 03[CFG] sending DHCP DISCOVER to 10.1.255.255 Aug 3 00:25:15 moon charon: 12[CFG] received DHCP OFFER 10.1.0.40 from 10.1.0.20 Aug 3 00:25:15 moon charon: 03[CFG] sending DHCP REQUEST for 10.1.0.40 to 10.1.0.20 Aug 3 00:25:15 moon charon: 12[CFG] received DHCP ACK for 10.1.0.40 Aug 3 00:25:15 moon charon: 03[IKE] assigning virtual IP 10.1.0.40 to peer 'dave@strongswan.org' Aug 3 00:25:15 moon charon: 03[IKE] CHILD_SA rw{2} established with SPIs c0196e5a_i c886bde5_o and TS 10.1.0.0/16 === 10.1.0.40/32 Aug 3 00:25:15 moon charon: 03[ENC] generating IKE_AUTH response 1 [ IDr CERT AUTH CP(ADDR DNS NBNS) SA TSi TSr N(AUTH_LFT) N(MOBIKE_SUP) N(ADD_4_ADDR) N(ADD_6_ADDR) N(ADD_6_ADDR) ] Aug 3 00:25:15 moon charon: 03[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.200[4500] Aug 3 00:25:28 moon charon: 00[DMN] signal of type SIGINT received. Shutting down Aug 3 00:25:28 moon charon: 00[IKE] deleting IKE_SA rw[1] between 192.168.0.1[moon.strongswan.org]...192.168.0.100[carol@strongswan.org] Aug 3 00:25:28 moon charon: 00[IKE] sending DELETE for IKE_SA rw[1] Aug 3 00:25:28 moon charon: 00[ENC] generating INFORMATIONAL request 0 [ D ] Aug 3 00:25:28 moon charon: 00[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.100[4500] Aug 3 00:25:29 moon charon: 00[IKE] deleting IKE_SA rw[2] between 192.168.0.1[moon.strongswan.org]...192.168.0.200[dave@strongswan.org] Aug 3 00:25:29 moon charon: 00[IKE] sending DELETE for IKE_SA rw[2] Aug 3 00:25:29 moon charon: 00[ENC] generating INFORMATIONAL request 0 [ D ] Aug 3 00:25:29 moon charon: 00[NET] sending packet: from 192.168.0.1[4500] to 192.168.0.200[4500] Aug 3 00:25:29 moon charon: 00[CFG] sending DHCP RELEASE for 10.1.0.30 to 10.1.0.20 Aug 3 00:25:29 moon charon: 00[CFG] sending DHCP RELEASE for 10.1.0.40 to 10.1.0.20