localhost.localdomain
Wed Jan  8 18:13:52 CET 2003
+ _________________________ version
+ ipsec --version
Linux FreeS/WAN 1.99
See `ipsec --copyright' for copyright information.
+ _________________________ proc/version
+ cat /proc/version
Linux version 2.4.19 (root@localhost.localdomain) (gcc version 2.96 20000731 (Red Hat Linux 7.1 2.96-98)) #13 mar jan 7 11:52:23 CET 2003
+ _________________________ proc/net/ipsec_eroute
+ sort +3 /proc/net/ipsec_eroute
+ _________________________ netstart-rn
+ netstat -nr
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
172.16.128.0    0.0.0.0         255.255.240.0   U        40 0          0 eth0
172.16.128.0    0.0.0.0         255.255.240.0   U        40 0          0 ipsec0
127.0.0.0       0.0.0.0         255.0.0.0       U        40 0          0 lo
0.0.0.0         172.16.128.254  0.0.0.0         UG       40 0          0 eth0
+ _________________________ proc/net/ipsec_spi
+ cat /proc/net/ipsec_spi
+ _________________________ proc/net/ipsec_spigrp
+ cat /proc/net/ipsec_spigrp
+ _________________________ proc/net/ipsec_tncfg
+ cat /proc/net/ipsec_tncfg
ipsec0 -> eth0 mtu=16260(1500) -> 1500
ipsec1 -> NULL mtu=0(0) -> 0
ipsec2 -> NULL mtu=0(0) -> 0
ipsec3 -> NULL mtu=0(0) -> 0
+ _________________________ proc/net/pf_key
+ cat /proc/net/pf_key
    sock   pid   socket     next     prev e n p sndbf    Flags     Type St
c13b1240  6832 c6b3a7a0        0        0 0 0 2 65535 00000000        3  1
+ _________________________ proc/net/pf_key-star
+ cd /proc/net
+ egrep '^' pf_key_registered pf_key_supported
pf_key_registered:satype   socket   pid       sk
pf_key_registered:     2 c6b3a7a0  6832 c13b1240
pf_key_registered:     3 c6b3a7a0  6832 c13b1240
pf_key_registered:     9 c6b3a7a0  6832 c13b1240
pf_key_registered:    10 c6b3a7a0  6832 c13b1240
pf_key_supported:satype exttype alg_id ivlen minbits maxbits
pf_key_supported:     2      14      3     0     160     160
pf_key_supported:     2      14      2     0     128     128
pf_key_supported:     3      15      3   128     168     168
pf_key_supported:     3      14      3     0     160     160
pf_key_supported:     3      14      2     0     128     128
pf_key_supported:     9      15      1     0      32      32
pf_key_supported:    10      15      2     0       1       1
+ _________________________ proc/sys/net/ipsec-star
+ cd /proc/sys/net/ipsec
+ egrep '^' debug_ah debug_eroute debug_esp debug_ipcomp debug_netlink debug_pfkey debug_radij debug_rcv debug_spi debug_tunnel debug_verbose debug_xform icmp inbound_policy_check tos
debug_ah:-1
debug_eroute:-1
debug_esp:-1
debug_ipcomp:-1
debug_netlink:2147483647
debug_pfkey:-1
debug_radij:-1
debug_rcv:-1
debug_spi:-1
debug_tunnel:-1
debug_verbose:0
debug_xform:-1
icmp:1
inbound_policy_check:1
tos:1
+ _________________________ ipsec/status
+ ipsec auto --status
000 interface ipsec0/eth0 172.16.128.1
000  
000 "essai_preshared": 172.16.128.1:17/1701...172.16.136.9:17/1701
000 "essai_preshared":   ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "essai_preshared":   policy: PSK+ENCRYPT+TUNNEL; interface: eth0; unrouted
000 "essai_preshared":   newest ISAKMP SA: #1; newest IPsec SA: #0; eroute owner: #0
000  
000 #1: "essai_preshared" STATE_MAIN_R3 (sent MR3, ISAKMP SA established); EVENT_SA_REPLACE in 2761s; newest ISAKMP
000  
+ _________________________ ifconfig-a
+ ifconfig -a
eth0      Link encap:Ethernet  HWaddr 00:50:FC:29:01:C8  
          inet addr:172.16.128.1  Bcast:172.16.143.255  Mask:255.255.240.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:6100 errors:0 dropped:0 overruns:0 frame:0
          TX packets:3461 errors:0 dropped:0 overruns:0 carrier:0
          collisions:399 txqueuelen:100 
          RX bytes:2469961 (2.3 Mb)  TX bytes:346584 (338.4 Kb)
          Interrupt:9 Base address:0x7000 

ipsec0    Link encap:Ethernet  HWaddr 00:50:FC:29:01:C8  
          inet addr:172.16.128.1  Mask:255.255.240.0
          UP RUNNING NOARP  MTU:16260  Metric:1
          RX packets:12 errors:0 dropped:12 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:10 
          RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)

ipsec1    Link encap:IPIP Tunnel  HWaddr   
          NOARP  MTU:0  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:10 
          RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)

ipsec2    Link encap:IPIP Tunnel  HWaddr   
          NOARP  MTU:0  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:10 
          RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)

ipsec3    Link encap:IPIP Tunnel  HWaddr   
          NOARP  MTU:0  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:10 
          RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)

lo        Link encap:Local Loopback  
          inet addr:127.0.0.1  Mask:255.0.0.0
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:409 errors:0 dropped:0 overruns:0 frame:0
          TX packets:409 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 
          RX bytes:29975 (29.2 Kb)  TX bytes:29975 (29.2 Kb)

+ _________________________ ipsec/directory
+ ipsec --directory
/usr/local/lib/ipsec
+ _________________________ hostname/fqdn
+ hostname --fqdn
localhost.localdomain
+ _________________________ hostname/ipaddress
+ hostname --ip-address
127.0.0.1 
+ _________________________ uptime
+ uptime
  6:13pm  up  8:01, 12 users,  load average: 0.40, 0.19, 0.08
+ _________________________ ps
+ ps alxwf
+ egrep -i 'ppid|pluto|ipsec|klips'
  F   UID   PID  PPID PRI  NI   VSZ  RSS WCHAN  STAT TTY        TIME COMMAND
100     0  7078  6082   9   0  2240 1004 wait4  S    pts/8      0:00  |   |           \_ /bin/sh /usr/local/sbin/ipsec barf
100     0  7079  7078  11   0  2272 1056 wait4  S    pts/8      0:00  |   |               \_ /bin/sh /usr/local/lib/ipsec/barf
000     0  7171  7079  11   0  1448  456 pipe_w S    pts/8      0:00  |   |                   \_ egrep -i ppid|pluto|ipsec|klips
040     0  6825     1   9   0  1976  868 wait4  S    pts/10     0:00 /bin/sh /usr/local/lib/ipsec/_plutorun --debug none --uniqueids
040     0  6830  6825   9   0  1976  856 wait4  S    pts/10     0:00  \_ /bin/sh /usr/local/lib/ipsec/_plutorun --debug none --uniqu
100     0  6832  6830   9   0  2016  964 do_sel S    pts/10     0:00  |   \_ /usr/local/lib/ipsec/pluto --nofork --debug-none --uniq
000     0  6838  6832   9   0  1424  308 do_sel S    pts/10     0:00  |       \_ _pluto_adns 7 10
100     0  6831  6825   8   0  1952  916 pipe_w S    pts/10     0:00  \_ /bin/sh /usr/local/lib/ipsec/_plutoload --load %search --st
000     0  6826     1   9   0  1364  516 pipe_w S    pts/10     0:00 logger -p daemon.error -t ipsec__plutorun
+ _________________________ ipsec/showdefaults
+ ipsec showdefaults
#dr: no default route
# no default route
# no default route
+ _________________________ ipsec/conf
+ ipsec _include /etc/ipsec.conf
+ ipsec _keycensor

#< /etc/ipsec.conf 1
# /etc/ipsec.conf - FreeS/WAN IPsec configuration file

# More elaborate and more varied sample configurations can be found
# in FreeS/WAN's doc/examples file, and in the HTML documentation.



# basic configuration
config setup
	# THIS SETTING MUST BE CORRECT or almost nothing will work;
	# %defaultroute is okay for most simple cases.
	interfaces="ipsec0=eth0"
	# Debug-logging controls:  "none" for (almost) none, "all" for lots.
	klipsdebug=all
	plutodebug=none
	# Use auto= parameters in conn descriptions to control startup actions.
	plutoload=%search
	plutostart=%search
	# Close down old connection when new one using same ID shows up.
	uniqueids=yes



# defaults for subsequent connection descriptions
# (these defaults will soon go away)
conn %default
	keyingtries=0
	disablearrivalcheck=no
	
conn essai
	authby=rsasig
	left=172.16.136.9                # gateway IP address
        leftsubnet=10.0.0.0/24   # the office network
        leftid=@gateway.example.com
        leftrsasigkey=[keyid AQNWMgiAw]
	right=172.16.128.1
        rightid=@xy.example.com
	rightnexthop=172.16.128.254
	rightrsasigkey=[keyid AQNmCV1am]
	keyingtries=0
	#auto=add

conn essai_preshared
	authby=secret
	pfs=no
	left=172.16.136.9                # gateway IP address
	right=172.16.128.1
	keyingtries=0
	leftprotoport=udp/1701 
	rightprotoport=udp/1701 
	auto=add
+ _________________________ ipsec/secrets
+ ipsec _include /etc/ipsec.secrets
+ ipsec _secretcensor

#< /etc/ipsec.secrets 1
: PSK "[sums to 80f9...]"
# This file holds shared secrets or RSA private keys for inter-Pluto
# authentication.  See ipsec_pluto(8) manpage, and HTML documentation.

# RSA private key for this host, authenticating it to any other host
# which knows the public part.  Suitable public keys, for ipsec.conf, DNS,
# or configuration of other implementations, can be extracted conveniently
# with "[sums to ef67...]".
: RSA	{
	# RSA 2192 bits   localhost.localdomain   Tue Jan  7 08:15:48 2003
	# for signatures only, UNSAFE FOR ENCRYPTION
	#pubkey=[keyid AQPDyHOdL]
	#IN KEY 0x4200 4 1 [keyid AQPDyHOdL]
	# (0x4200 = auth-only host-level, 4 = IPSec, 1 = RSA)
	Modulus: [...]
	PublicExponent: [...]
	# everything after this point is secret
	PrivateExponent: [...]
	Prime1: [...]
	Prime2: [...]
	Exponent1: [...]
	Exponent2: [...]
	Coefficient: [...]
	}
# do not change the indenting of that "[sums to 7d9d...]"
+ _________________________ ipsec/ls-dir
+ ls -l /usr/local/lib/ipsec
total 3959
-rwxr-xr-x    1 root     root        11183 Jan  8 16:08 _confread
-rwxr-xr-x    1 root     root        11102 Jan  8 09:19 _confread.old
-rwxr-xr-x    1 root     root        46785 Jan  8 16:08 _copyright
-rwxr-xr-x    1 root     root        46769 Jan  8 09:19 _copyright.old
-rwxr-xr-x    1 root     root         2163 Jan  8 16:08 _include
-rwxr-xr-x    1 root     root         2163 Jan  8 09:19 _include.old
-rwxr-xr-x    1 root     root         1472 Jan  8 16:08 _keycensor
-rwxr-xr-x    1 root     root         1472 Jan  8 09:19 _keycensor.old
-rwxr-xr-x    1 root     root        71765 Jan  8 16:08 _pluto_adns
-rwxr-xr-x    1 root     root        71749 Jan  7 08:17 _pluto_adns.old
-rwxr-xr-x    1 root     root         3565 Jan  8 16:08 _plutoload
-rwxr-xr-x    1 root     root         3565 Jan  8 09:19 _plutoload.old
-rwxr-xr-x    1 root     root         4753 Jan  8 16:08 _plutorun
-rwxr-xr-x    1 root     root         4358 Jan  8 09:19 _plutorun.old
-rwxr-xr-x    1 root     root         7530 Jan  8 16:08 _realsetup
-rwxr-xr-x    1 root     root         7450 Jan  8 09:19 _realsetup.old
-rwxr-xr-x    1 root     root         1971 Jan  8 16:08 _secretcensor
-rwxr-xr-x    1 root     root         1971 Jan  8 09:19 _secretcensor.old
-rwxr-xr-x    1 root     root         7062 Jan  8 16:08 _startklips
-rwxr-xr-x    1 root     root         7062 Jan  8 09:19 _startklips.old
-rwxr-xr-x    1 root     root         5014 Jan  8 16:08 _updown
-rwxr-xr-x    1 root     root         5014 Jan  8 09:19 _updown.old
-rwxr-xr-x    1 root     root         7572 Jan  8 16:08 _updown.x509
-rwxr-xr-x    1 root     root        13335 Jan  8 16:08 auto
-rwxr-xr-x    1 root     root        11404 Jan  8 09:19 auto.old
-rwxr-xr-x    1 root     root         7198 Jan  8 16:08 barf
-rwxr-xr-x    1 root     root         7198 Jan  8 09:19 barf.old
-rwxr-xr-x    1 root     root          816 Jan  8 16:08 calcgoo
-rwxr-xr-x    1 root     root          816 Jan  8 09:19 calcgoo.old
-rwxr-xr-x    1 root     root       232915 Jan  8 16:08 eroute
-rwxr-xr-x    1 root     root        98864 Jan  8 16:08 ikeping
-rwxr-xr-x    1 root     root        98532 Jan  7 08:17 ikeping.old
-rwxr-xr-x    1 root     root         2915 Jan  8 16:08 ipsec
-rwxr-xr-x    1 root     root         2915 Jan  8 09:19 ipsec.old
-rw-r--r--    1 root     root         1950 Jan  8 16:08 ipsec_pr.template
-rwxr-xr-x    1 root     root       164207 Jan  8 16:08 klipsdebug
-rwxr-xr-x    1 root     root         2437 Jan  8 16:08 look
-rwxr-xr-x    1 root     root         2437 Jan  8 09:19 look.old
-rwxr-xr-x    1 root     root        16157 Jan  8 16:08 manual
-rwxr-xr-x    1 root     root        16157 Jan  8 09:19 manual.old
-rwxr-xr-x    1 root     root         1847 Jan  8 16:08 newhostkey
-rwxr-xr-x    1 root     root         1847 Jan  8 09:19 newhostkey.old
-rwxr-xr-x    1 root     root       142710 Jan  8 16:08 pf_key
-rwxr-xr-x    1 root     root       904275 Jan  8 16:08 pluto
-rwxr-xr-x    1 root     root       792431 Jan  7 08:17 pluto.old
-rwxr-xr-x    1 root     root        53098 Jan  8 16:08 ranbits
-rwxr-xr-x    1 root     root        53082 Jan  8 09:19 ranbits.old
-rwxr-xr-x    1 root     root        76562 Jan  8 16:08 rsasigkey
-rwxr-xr-x    1 root     root        76546 Jan  8 09:19 rsasigkey.old
-rwxr-xr-x    1 root     root        16671 Jan  8 16:08 send-pr
-rwxr-xr-x    1 root     root        16671 Jan  8 09:19 send-pr.old
lrwxrwxrwx    1 root     root           22 Jan  8 16:08 setup -> /etc/rc.d/init.d/ipsec
-rwxr-xr-x    1 root     root         1041 Jan  8 16:08 showdefaults
-rwxr-xr-x    1 root     root         1041 Jan  8 09:19 showdefaults.old
-rwxr-xr-x    1 root     root         4205 Jan  8 16:08 showhostkey
-rwxr-xr-x    1 root     root         4205 Jan  8 09:19 showhostkey.old
-rwxr-xr-x    1 root     root       249439 Jan  8 16:08 spi
-rwxr-xr-x    1 root     root       205323 Jan  8 16:08 spigrp
-rwxr-xr-x    1 root     root        71247 Jan  8 16:08 tncfg
-rwxr-xr-x    1 root     root        17032 Jan  8 16:08 uml_netjig
-rwxr-xr-x    1 root     root         3353 Jan  8 16:08 verify
-rwxr-xr-x    1 root     root         3353 Jan  8 09:19 verify.old
-rwxr-xr-x    1 root     root       143105 Jan  8 16:08 whack
-rwxr-xr-x    1 root     root       136103 Jan  7 08:17 whack.old
+ _________________________ ipsec/updowns
++ ls /usr/local/lib/ipsec
++ egrep updown
+ cat /usr/local/lib/ipsec/_updown
#! /bin/sh
# default updown script
# Copyright (C) 2000, 2001  D. Hugh Redelmeier, Henry Spencer
# 
# This program is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation; either version 2 of the License, or (at your
# option) any later version.  See <http://www.fsf.org/copyleft/gpl.txt>.
# 
# This program is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
# or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
# for more details.
#
# RCSID $Id: barf.txt,v 1.2 2004/12/17 14:34:07 bfo Exp $



# CAUTION:  Installing a new version of FreeS/WAN will install a new
# copy of this script, wiping out any custom changes you make.  If
# you need changes, make a copy of this under another name, and customize
# that, and use the (left/right)updown parameters in ipsec.conf to make
# FreeS/WAN use yours instead of this default one.



# check interface version
case "$PLUTO_VERSION" in
1.[0])	# Older Pluto?!?  Play it safe, script may be using new features.
	echo "$0: obsolete interface version \`$PLUTO_VERSION'," >&2
	echo "$0: 	called by obsolete Pluto?" >&2
	exit 2
	;;
1.*)	;;
*)	echo "$0: unknown interface version \`$PLUTO_VERSION'" >&2
	exit 2
	;;
esac

# check parameter(s)
case "$1:$*" in
':')			# no parameters
	;;
ipfwadm:ipfwadm)	# due to (left/right)firewall; for default script only
	;;
custom:*)		# custom parameters (see above CAUTION comment)
	;;
*)	echo "$0: unknown parameters \`$*'" >&2
	exit 2
	;;
esac

# utility functions for route manipulation
# Meddling with this stuff should not be necessary and requires great care.
uproute() {
	doroute add
}
downroute() {
	doroute del
}
doroute() {
	parms="-net $PLUTO_PEER_CLIENT_NET netmask $PLUTO_PEER_CLIENT_MASK"
	parms2="dev $PLUTO_INTERFACE gw $PLUTO_NEXT_HOP"
	case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
	"0.0.0.0/0.0.0.0")
		# horrible kludge for obscure routing bug with opportunistic
		it="route $1 -net 0.0.0.0 netmask 128.0.0.0 $parms2 &&
			route $1 -net 128.0.0.0 netmask 128.0.0.0 $parms2"
		;;
	*)	it="route $1 $parms $parms2"
		;;
	esac
	eval $it
	st=$?
	if test $st -ne 0
	then
		# route has already given its own cryptic message
		echo "$0: \`$it' failed" >&2
		if test " $1 $st" = " add 7"
		then
			# another totally undocumented interface -- 7 and
			# "SIOCADDRT: Network is unreachable" means that
			# the gateway isn't reachable.
			echo "$0: (incorrect or missing nexthop setting??)" >&2
		fi
	fi
	return $st
}



# the big choice
case "$PLUTO_VERB:$1" in
prepare-host:*|prepare-client:*)
	# delete possibly-existing route (preliminary to adding a route)
	case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
	"0.0.0.0/0.0.0.0")
		# horrible kludge for obscure routing bug with opportunistic
		it="route del -net 0.0.0.0 netmask 128.0.0.0 2>&1 ;
			route del -net 128.0.0.0 netmask 128.0.0.0 2>&1"
		;;
	*)
		it="route del -net $PLUTO_PEER_CLIENT_NET \
					netmask $PLUTO_PEER_CLIENT_MASK 2>&1"
		;;
	esac
	oops="`eval $it`"
	status="$?"
	if test " $oops" = " " -a " $status" != " 0"
	then
		oops="silent error, exit status $status"
	fi
	case "$oops" in
	'SIOCDELRT: No such process'*)
		# This is what route (currently -- not documented!) gives
		# for "could not find such a route".
		oops=
		status=0
		;;
	esac
	if test " $oops" != " " -o " $status" != " 0"
	then
		echo "$0: \`$it' failed ($oops)" >&2
	fi
	exit $status
	;;
route-host:*|route-client:*)
	# connection to me or my client subnet being routed
	uproute
	;;
unroute-host:*|unroute-client:*)
	# connection to me or my client subnet being unrouted
	downroute
	;;
up-host:*)
	# connection to me coming up
	# If you are doing a custom version, firewall commands go here.
	;;
down-host:*)
	# connection to me going down
	# If you are doing a custom version, firewall commands go here.
	;;
up-client:)
	# connection to my client subnet coming up
	# If you are doing a custom version, firewall commands go here.
	;;
down-client:)
	# connection to my client subnet going down
	# If you are doing a custom version, firewall commands go here.
	;;
up-client:ipfwadm)
	# connection to client subnet, with (left/right)firewall=yes, coming up
	# This is used only by the default updown script, not by your custom
	# ones, so do not mess with it; see CAUTION comment up at top.
	ipfwadm -F -i accept -b -S $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
		-D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
	;;
down-client:ipfwadm)
	# connection to client subnet, with (left/right)firewall=yes, going down
	# This is used only by the default updown script, not by your custom
	# ones, so do not mess with it; see CAUTION comment up at top.
	ipfwadm -F -d accept -b -S $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
		-D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
	;;
*)	echo "$0: unknown verb \`$PLUTO_VERB' or parameter \`$1'" >&2
	exit 1
	;;
esac
+ cat /usr/local/lib/ipsec/_updown.old
#! /bin/sh
# default updown script
# Copyright (C) 2000, 2001  D. Hugh Redelmeier, Henry Spencer
# 
# This program is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published by the
# Free Software Foundation; either version 2 of the License, or (at your
# option) any later version.  See <http://www.fsf.org/copyleft/gpl.txt>.
# 
# This program is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
# or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
# for more details.
#
# RCSID $Id: barf.txt,v 1.2 2004/12/17 14:34:07 bfo Exp $



# CAUTION:  Installing a new version of FreeS/WAN will install a new
# copy of this script, wiping out any custom changes you make.  If
# you need changes, make a copy of this under another name, and customize
# that, and use the (left/right)updown parameters in ipsec.conf to make
# FreeS/WAN use yours instead of this default one.



# check interface version
case "$PLUTO_VERSION" in
1.[0])	# Older Pluto?!?  Play it safe, script may be using new features.
	echo "$0: obsolete interface version \`$PLUTO_VERSION'," >&2
	echo "$0: 	called by obsolete Pluto?" >&2
	exit 2
	;;
1.*)	;;
*)	echo "$0: unknown interface version \`$PLUTO_VERSION'" >&2
	exit 2
	;;
esac

# check parameter(s)
case "$1:$*" in
':')			# no parameters
	;;
ipfwadm:ipfwadm)	# due to (left/right)firewall; for default script only
	;;
custom:*)		# custom parameters (see above CAUTION comment)
	;;
*)	echo "$0: unknown parameters \`$*'" >&2
	exit 2
	;;
esac

# utility functions for route manipulation
# Meddling with this stuff should not be necessary and requires great care.
uproute() {
	doroute add
}
downroute() {
	doroute del
}
doroute() {
	parms="-net $PLUTO_PEER_CLIENT_NET netmask $PLUTO_PEER_CLIENT_MASK"
	parms2="dev $PLUTO_INTERFACE gw $PLUTO_NEXT_HOP"
	case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
	"0.0.0.0/0.0.0.0")
		# horrible kludge for obscure routing bug with opportunistic
		it="route $1 -net 0.0.0.0 netmask 128.0.0.0 $parms2 &&
			route $1 -net 128.0.0.0 netmask 128.0.0.0 $parms2"
		;;
	*)	it="route $1 $parms $parms2"
		;;
	esac
	eval $it
	st=$?
	if test $st -ne 0
	then
		# route has already given its own cryptic message
		echo "$0: \`$it' failed" >&2
		if test " $1 $st" = " add 7"
		then
			# another totally undocumented interface -- 7 and
			# "SIOCADDRT: Network is unreachable" means that
			# the gateway isn't reachable.
			echo "$0: (incorrect or missing nexthop setting??)" >&2
		fi
	fi
	return $st
}



# the big choice
case "$PLUTO_VERB:$1" in
prepare-host:*|prepare-client:*)
	# delete possibly-existing route (preliminary to adding a route)
	case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
	"0.0.0.0/0.0.0.0")
		# horrible kludge for obscure routing bug with opportunistic
		it="route del -net 0.0.0.0 netmask 128.0.0.0 2>&1 ;
			route del -net 128.0.0.0 netmask 128.0.0.0 2>&1"
		;;
	*)
		it="route del -net $PLUTO_PEER_CLIENT_NET \
					netmask $PLUTO_PEER_CLIENT_MASK 2>&1"
		;;
	esac
	oops="`eval $it`"
	status="$?"
	if test " $oops" = " " -a " $status" != " 0"
	then
		oops="silent error, exit status $status"
	fi
	case "$oops" in
	'SIOCDELRT: No such process'*)
		# This is what route (currently -- not documented!) gives
		# for "could not find such a route".
		oops=
		status=0
		;;
	esac
	if test " $oops" != " " -o " $status" != " 0"
	then
		echo "$0: \`$it' failed ($oops)" >&2
	fi
	exit $status
	;;
route-host:*|route-client:*)
	# connection to me or my client subnet being routed
	uproute
	;;
unroute-host:*|unroute-client:*)
	# connection to me or my client subnet being unrouted
	downroute
	;;
up-host:*)
	# connection to me coming up
	# If you are doing a custom version, firewall commands go here.
	;;
down-host:*)
	# connection to me going down
	# If you are doing a custom version, firewall commands go here.
	;;
up-client:)
	# connection to my client subnet coming up
	# If you are doing a custom version, firewall commands go here.
	;;
down-client:)
	# connection to my client subnet going down
	# If you are doing a custom version, firewall commands go here.
	;;
up-client:ipfwadm)
	# connection to client subnet, with (left/right)firewall=yes, coming up
	# This is used only by the default updown script, not by your custom
	# ones, so do not mess with it; see CAUTION comment up at top.
	ipfwadm -F -i accept -b -S $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
		-D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
	;;
down-client:ipfwadm)
	# connection to client subnet, with (left/right)firewall=yes, going down
	# This is used only by the default updown script, not by your custom
	# ones, so do not mess with it; see CAUTION comment up at top.
	ipfwadm -F -d accept -b -S $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
		-D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
	;;
*)	echo "$0: unknown verb \`$PLUTO_VERB' or parameter \`$1'" >&2
	exit 1
	;;
esac
+ cat /usr/local/lib/ipsec/_updown.x509
#! /bin/sh
#
# customized updown script
#

# logging of VPN connections
#
# tag put in front of each log entry:
TAG=vpn
#
# syslog facility and priority used:
FAC_PRIO=local0.notice
#
# to create a special vpn logging file, put the following line into
# the syslog configuration file /etc/syslog.conf:
#
# local0.notice                   -/var/log/vpn
#
# check interface version
case "$PLUTO_VERSION" in
1.[0])	# Older Pluto?!?  Play it safe, script may be using new features.
	echo "$0: obsolete interface version \`$PLUTO_VERSION'," >&2
	echo "$0: 	called by obsolete Pluto?" >&2
	exit 2
	;;
1.*)	;;
*)	echo "$0: unknown interface version \`$PLUTO_VERSION'" >&2
	exit 2
	;;
esac

# check parameter(s)
case "$1:$*" in
':')			# no parameters
	;;
ipfwadm:ipfwadm)	# due to (left/right)firewall; for default script only
	;;
custom:*)		# custom parameters (see above CAUTION comment)
	;;
*)	echo "$0: unknown parameters \`$*'" >&2
	exit 2
	;;
esac

# utility functions for route manipulation
# Meddling with this stuff should not be necessary and requires great care.
uproute() {
	doroute add
}
downroute() {
	doroute del
}
doroute() {
	parms="-net $PLUTO_PEER_CLIENT_NET netmask $PLUTO_PEER_CLIENT_MASK"
	parms2="dev $PLUTO_INTERFACE gw $PLUTO_NEXT_HOP"
	case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
	"0.0.0.0/0.0.0.0")
		# horrible kludge for obscure routing bug with opportunistic
		it="route $1 -net 0.0.0.0 netmask 128.0.0.0 $parms2 &&"
		it="$it route $1 -net 128.0.0.0 netmask 128.0.0.0 $parms2"
		route $1 -net 0.0.0.0 netmask 128.0.0.0 $parms2 &&
			route $1 -net 128.0.0.0 netmask 128.0.0.0 $parms2
		;;
	*)	it="route $1 $parms $parms2"
		route $1 $parms $parms2
		;;
	esac
	st=$?
	if test $st -ne 0
	then
		# route has already given its own cryptic message
		echo "$0: \`$it' failed" >&2
		if test " $1 $st" = " add 7"
		then
			# another totally undocumented interface -- 7 and
			# "SIOCADDRT: Network is unreachable" means that
			# the gateway isn't reachable.
			echo "$0: (incorrect or missing nexthop setting??)" >&2
		fi
	fi
	return $st
}

# are there port numbers?
if [ "$PLUTO_MY_PORT" != 0 ]
then
	S_MY_PORT="--sport $PLUTO_MY_PORT"
	D_MY_PORT="--dport $PLUTO_MY_PORT"
fi
if [ "$PLUTO_PEER_PORT" != 0 ]
then
	S_PEER_PORT="--sport $PLUTO_PEER_PORT"
	D_PEER_PORT="--dport $PLUTO_PEER_PORT"
fi

# the big choice
case "$PLUTO_VERB:$1" in
prepare-host:*|prepare-client:*)
	# delete possibly-existing route (preliminary to adding a route)
	case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
	"0.0.0.0/0.0.0.0")
		# horrible kludge for obscure routing bug with opportunistic
		parms1="-net 0.0.0.0 netmask 128.0.0.0"
		parms2="-net 128.0.0.0 netmask 128.0.0.0"
		it="route del $parms1 2>&1 ; route del $parms2 2>&1"
		oops="`route del $parms1 2>&1 ; route del $parms2 2>&1`"
		;;
	*)
		parms="-net $PLUTO_PEER_CLIENT_NET netmask $PLUTO_PEER_CLIENT_MASK"
		it="route del $parms 2>&1"
		oops="`route del $parms 2>&1`"
		;;
	esac
	status="$?"
	if test " $oops" = " " -a " $status" != " 0"
	then
		oops="silent error, exit status $status"
	fi
	case "$oops" in
	'SIOCDELRT: No such process'*)
		# This is what route (currently -- not documented!) gives
		# for "could not find such a route".
		oops=
		status=0
		;;
	esac
	if test " $oops" != " " -o " $status" != " 0"
	then
		echo "$0: \`$it' failed ($oops)" >&2
	fi
	exit $status
	;;
route-host:*|route-client:*)
	# connection to me or my client subnet being routed
	uproute
	;;
unroute-host:*|unroute-client:*)
	# connection to me or my client subnet being unrouted
	downroute
	;;
up-host:*)
	# connection to me coming up
	# If you are doing a custom version, firewall commands go here.
	iptables -I INPUT 1 -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
	    -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
	    -d $PLUTO_ME $D_MY_PORT -j ACCEPT
	iptables -I OUTPUT 1 -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
	    -s $PLUTO_ME $S_MY_PORT \
	    -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $D_PEER_PORT -j ACCEPT
	#
	if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
	then
	  logger -t $TAG -p $FAC_PRIO \
	    "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME"
	else
	  logger -t $TAG -p $FAC_PRIO \
	    "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER -- $PLUTO_ME"
	fi
	;;
down-host:*)
	# connection to me going down
	# If you are doing a custom version, firewall commands go here.
	iptables -D INPUT -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
	    -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
	    -d $PLUTO_ME $D_MY_PORT -j ACCEPT
	iptables -D OUTPUT -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
	    -s $PLUTO_ME $S_MY_PORT \
	    -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $D_PEER_PORT -j ACCEPT
	#
	if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
	then
	  logger -t $TAG -p $FAC_PRIO -- \
	    "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME"
	else
	  logger -t $TAG -p $FAC_PRIO -- \
	  "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER -- $PLUTO_ME"
	fi
	;;
up-client:)
        # connection to my client subnet coming up
	# If you are doing a custom version, firewall commands go here.
	iptables -I FORWARD 1 -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
	    -s $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $S_MY_PORT \
	    -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $D_PEER_PORT -j ACCEPT
	iptables -I FORWARD 1 -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
	    -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
	    -d $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $D_MY_PORT -j ACCEPT
	#
	if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
	then
	  logger -t $TAG -p $FAC_PRIO \
	    "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME == $PLUTO_MY_CLIENT"
	else
	  logger -t $TAG -p $FAC_PRIO \
	    "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER -- $PLUTO_ME == $PLUTO_MY_CLIENT"
	fi
	;;
down-client:)
        # connection to my client subnet going down
        # If you are doing a custom version, firewall commands go here.
	iptables -D FORWARD -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
	    -s $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $S_MY_PORT \
	    -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $D_PEER_PORT -j ACCEPT
	iptables -D FORWARD -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
	    -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
	    -d $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $D_MY_PORT -j ACCEPT
	#
	if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
	then
	  logger -t $TAG -p $FAC_PRIO -- \
	    "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME == $PLUTO_MY_CLIENT"
	else
	  logger -t $TAG -p $FAC_PRIO -- \
	    "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER -- $PLUTO_ME == $PLUTO_MY_CLIENT"
	fi
	;;
up-client:ipfwadm)
	# connection to client subnet, with (left/right)firewall=yes, coming up
	# This is used only by the default updown script, not by your custom
	# ones, so do not mess with it; see CAUTION comment up at top.
	ipfwadm -F -i accept -b -S $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
		-D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
	;;
down-client:ipfwadm)
	# connection to client subnet, with (left/right)firewall=yes, going down
	# This is used only by the default updown script, not by your custom
	# ones, so do not mess with it; see CAUTION comment up at top.
	ipfwadm -F -d accept -b -S $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
		-D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
	;;
*)	echo "$0: unknown verb \`$PLUTO_VERB' or parameter \`$1'" >&2
	exit 1
	;;
esac
+ _________________________ proc/net/dev
+ cat /proc/net/dev
Inter-|   Receive                                                |  Transmit
 face |bytes    packets errs drop fifo frame compressed multicast|bytes    packets errs drop fifo colls carrier compressed
    lo:   29975     409    0    0    0     0          0         0    29975     409    0    0    0     0       0          0
ipsec0:       0      12    0   12    0     0          0         0        0       0    0    0    0     0       0          0
ipsec1:       0       0    0    0    0     0          0         0        0       0    0    0    0     0       0          0
ipsec2:       0       0    0    0    0     0          0         0        0       0    0    0    0     0       0          0
ipsec3:       0       0    0    0    0     0          0         0        0       0    0    0    0     0       0          0
  eth0: 2469961    6100    0    0    0     0          0         0   346584    3461    0    0    0   399       0          0
+ _________________________ proc/net/route
+ cat /proc/net/route
Iface	Destination	Gateway 	Flags	RefCnt	Use	Metric	Mask		MTU	Window	IRTT                                                       
eth0	008010AC	00000000	0001	0	0	0	00F0FFFF	40	0	0                                                                              
ipsec0	008010AC	00000000	0001	0	0	0	00F0FFFF	40	0	0                                                                            
lo	0000007F	00000000	0001	0	0	0	000000FF	40	0	0                                                                                
eth0	00000000	FE8010AC	0003	0	0	0	00000000	40	0	0                                                                              
+ _________________________ proc/sys/net/ipv4/ip_forward
+ cat /proc/sys/net/ipv4/ip_forward
0
+ _________________________ proc/sys/net/ipv4/conf/star-rp_filter
+ cd /proc/sys/net/ipv4/conf
+ egrep '^' all/rp_filter default/rp_filter eth0/rp_filter ipsec0/rp_filter lo/rp_filter
all/rp_filter:0
default/rp_filter:1
eth0/rp_filter:0
ipsec0/rp_filter:1
lo/rp_filter:1
+ _________________________ uname-a
+ uname -a
Linux localhost.localdomain 2.4.19 #13 mar jan 7 11:52:23 CET 2003 i586 unknown
+ _________________________ redhat-release
+ test -r /etc/redhat-release
+ cat /etc/redhat-release
Red Hat Linux release 7.2 (Enigma)
+ _________________________ proc/net/ipsec_version
+ cat /proc/net/ipsec_version
FreeS/WAN version: 1.99
+ _________________________ iptables/list
+ iptables -L -v -n
modprobe: Can't locate module ip_tables
iptables v1.2.3: can't initialize iptables table `filter': iptables who? (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
+ _________________________ ipchains/list
+ ipchains -L -v -n
Chain input (policy ACCEPT: 3226 packets, 1994218 bytes):
 pkts bytes target     prot opt    tosa tosx  ifname     mark       outsize  source                destination           ports
  675  104K ACCEPT     udp  ------ 0xFF 0x00  *                              0.0.0.0/0            0.0.0.0/0             * ->   500
  124 11456 ACCEPT     udp  ------ 0xFF 0x00  *                              172.16.0.3           0.0.0.0/0             53 ->   1025:65535
  409 29975 ACCEPT     all  ------ 0xFF 0x00  lo                             0.0.0.0/0            0.0.0.0/0             n/a
    0     0 REJECT     tcp  -y---- 0xFF 0x00  *                              0.0.0.0/0            0.0.0.0/0             * ->   0:1023
    0     0 REJECT     tcp  -y---- 0xFF 0x00  *                              0.0.0.0/0            0.0.0.0/0             * ->   2049
 1391  240K REJECT     udp  ------ 0xFF 0x00  *                              0.0.0.0/0            0.0.0.0/0             * ->   0:1023
    0     0 REJECT     udp  ------ 0xFF 0x00  *                              0.0.0.0/0            0.0.0.0/0             * ->   2049
    0     0 REJECT     tcp  -y---- 0xFF 0x00  *                              0.0.0.0/0            0.0.0.0/0             * ->   6000:6009
    0     0 REJECT     tcp  -y---- 0xFF 0x00  *                              0.0.0.0/0            0.0.0.0/0             * ->   7100
Chain forward (policy ACCEPT: 0 packets, 0 bytes):
Chain output (policy ACCEPT: 3601 packets, 313576 bytes):
+ _________________________ ipfwadm/forward
+ ipfwadm -F -l -n -e
Chains are empty. (ie. ipfwadm has not been used on them).
+ _________________________ ipfwadm/input
+ ipfwadm -I -l -n -e
Chains are empty. (ie. ipfwadm has not been used on them).
+ _________________________ ipfwadm/output
+ ipfwadm -O -l -n -e
Chains are empty. (ie. ipfwadm has not been used on them).
+ _________________________ iptables/nat
+ iptables -t nat -L -v -n
modprobe: Can't locate module ip_tables
iptables v1.2.3: can't initialize iptables table `nat': iptables who? (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
+ _________________________ ipchains/masq
+ ipchains -M -L -v -n
IP masquerading entries
+ _________________________ ipfwadm/masq
+ ipfwadm -M -l -n -e
IP masquerading entries
+ _________________________ iptables/mangle
+ iptables -t mangle -L -v -n
modprobe: Can't locate module ip_tables
iptables v1.2.3: can't initialize iptables table `mangle': iptables who? (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
+ _________________________ proc/modules
+ cat /proc/modules
usb-storage            20288   0
scsi_mod               80272   1 [usb-storage]
usb-uhci               20320   0 (unused)
usbcore                59744   1 [usb-storage usb-uhci]
+ _________________________ proc/meminfo
+ cat /proc/meminfo
        total:    used:    free:  shared: buffers:  cached:
Mem:  113512448 94953472 18558976        0  1810432 56414208
Swap: 271392768 45940736 225452032
MemTotal:       110852 kB
MemFree:         18124 kB
MemShared:           0 kB
Buffers:          1768 kB
Cached:          51076 kB
SwapCached:       4016 kB
Active:          45472 kB
Inactive:        34432 kB
HighTotal:           0 kB
HighFree:            0 kB
LowTotal:       110852 kB
LowFree:         18124 kB
SwapTotal:      265032 kB
SwapFree:       220168 kB
+ _________________________ dev/ipsec-ls
+ ls -l '/dev/ipsec*'
ls: /dev/ipsec*: No such file or directory
+ _________________________ proc/net/ipsec-ls
+ ls -l /proc/net/ipsec_eroute /proc/net/ipsec_klipsdebug /proc/net/ipsec_spi /proc/net/ipsec_spigrp /proc/net/ipsec_tncfg /proc/net/ipsec_version
-r--r--r--    1 root     root            0 Jan  8 18:13 /proc/net/ipsec_eroute
-r--r--r--    1 root     root            0 Jan  8 18:13 /proc/net/ipsec_klipsdebug
-r--r--r--    1 root     root            0 Jan  8 18:13 /proc/net/ipsec_spi
-r--r--r--    1 root     root            0 Jan  8 18:13 /proc/net/ipsec_spigrp
-r--r--r--    1 root     root            0 Jan  8 18:13 /proc/net/ipsec_tncfg
-r--r--r--    1 root     root            0 Jan  8 18:13 /proc/net/ipsec_version
+ _________________________ usr/src/linux/.config
+ test -f /usr/src/linux/.config
+ _________________________ etc/syslog.conf
+ cat /etc/syslog.conf
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*							/dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none		/var/log/messages

# The authpriv file has restricted access.
authpriv.*						/var/log/secure

# Log all the mail messages in one place.
mail.*							/var/log/maillog


# Log cron stuff
cron.*							/var/log/cron

# Everybody gets emergency messages
*.emerg							*

# Save news errors of level crit and higher in a special file.
uucp,news.crit						/var/log/spooler

# Save boot messages also to boot.log
local7.*						/var/log/boot.log
+ _________________________ etc/resolv.conf
+ cat /etc/resolv.conf
nameserver 172.16.0.3
search localdomain
+ _________________________ lib/modules-ls
+ ls -ltr /lib/modules
total 2
drwxr-xr-x    4 root     root         1024 Jun  4  2002 2.4.7-10
drwxr-xr-x    5 root     root         1024 Jan  7 11:14 2.4.19
+ _________________________ proc/ksyms-netif_rx
+ egrep netif_rx /proc/ksyms
c01e123d netif_rx_R93713dd7
+ _________________________ lib/modules-netif_rx
+ modulegoo kernel/net/ipv4/ipip.o netif_rx
+ set +x
2.4.19: 
2.4.7-10:          U netif_rx_R05e81a15
+ _________________________ kern.debug
+ test -f /var/log/kern.debug
+ _________________________ klog
+ sed -n '130,$p' /var/log/messages
+ egrep -i 'ipsec|klips|pluto'
+ cat
jan  8 18:02:50 localhost ipsec_setup: Starting FreeS/WAN IPsec 1.99...
Jan  8 18:02:50 localhost ipsec_setup: KLIPS debug `all'
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_x_debug_process: set
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 16 with msg_parser c0225933.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_x_msg_debug_parse: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_release: sock=c5d6f920 sk=c68bb720
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_remove_socket: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_remove_socket: succeeded.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: pfkey_remove_socket called.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: sk(c68bb720)->(&c68bb774)receive_queue.{next=c68bb774,prev=c68bb774}.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: destroyed.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_list_remove_socket: removing sock=c5d6f920
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_release: succeeded.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_create: sock=c5d6f920 type:3 state:1 flags:0 protocol:2
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_create: sock->fasync_list=00000000 sk->sleep=c5d6f93c.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_insert_socket: sk=c68bb720
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_list_insert_socket: socketp=c5d6f920
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_create: Socket sock=c5d6f920 sk=c68bb720 initialised.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=15, errno=0, satype=0(UNKNOWN), len=4, res=0, seq=1, pid=6802.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c5005e2c.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c32fb9b0 with processor c0220f53.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 15 with msg_parser c0225457.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_x_delflow_parse: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_x_delflow_parse: CLEARFLOW flag set, calling cleareroutes.
Jan  8 18:02:50 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:02:50 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:02:50 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_release: sock=c5d6f920 sk=c68bb720
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_remove_socket: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_remove_socket: succeeded.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: pfkey_remove_socket called.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: sk(c68bb720)->(&c68bb774)receive_queue.{next=c68bb774,prev=c68bb774}.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: destroyed.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_list_remove_socket: removing sock=c5d6f920
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_release: succeeded.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_create: sock=c5d6f920 type:3 state:1 flags:0 protocol:2
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_create: sock->fasync_list=00000000 sk->sleep=c5d6f93c.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_insert_socket: sk=c68bb720
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_list_insert_socket: socketp=c5d6f920
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_create: Socket sock=c5d6f920 sk=c68bb720 initialised.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=9, errno=0, satype=0(UNKNOWN), len=2, res=0, seq=1, pid=6804.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c5005e2c.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 9 with msg_parser c0224679.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_flush_parse: flushing type 0 SAs
Jan  8 18:02:50 localhost kernel: klips_debug:ipsec_tdbcleanup: cleaning up proto=0.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_upmsg: allocating 16 bytes...
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c33cb160.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_flush_parse: sending up flush reply message for satype=0(UNKNOWN) to socket=c5d6f920 succeeded.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_release: sock=c5d6f920 sk=c68bb720
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_remove_socket: .
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_remove_socket: succeeded.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: pfkey_remove_socket called.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: sk(c68bb720)->(&c68bb774)receive_queue.{next=c33cb160,prev=c33cb160}.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: skb=c33cb160 freed.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_destroy_socket: destroyed.
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_list_remove_socket: removing sock=c5d6f920
Jan  8 18:02:50 localhost kernel: klips_debug:pfkey_release: succeeded.
Jan  8 18:02:50 localhost ipsec_setup: KLIPS ipsec0 on eth0 172.16.128.1/255.255.240.0 broadcast 172.16.143.255 
Jan  8 18:02:50 localhost kernel: klips_debug:ipsec_tunnel_ioctl: tncfg service call #35312 for dev=ipsec0
Jan  8 18:02:50 localhost kernel: klips_debug:ipsec_tunnel_ioctl: calling ipsec_tunnel_attatch...
Jan  8 18:02:50 localhost kernel: klips_debug:ipsec_tunnel_attach: physical device eth0 being attached has HW address:  0:50:fc:29:01:c8
Jan  8 18:02:50 localhost kernel: klips_debug:ipsec_tunnel_open: dev = ipsec0, prv->dev = eth0
Jan  8 18:02:50 localhost kernel: klips_debug:ipsec_device_event: NETDEV_UP dev=ipsec0
Jan  8 18:02:51 localhost ipsec_setup: ...FreeS/WAN IPsec started
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_create: sock=c6b3a7a0 type:3 state:1 flags:0 protocol:2
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_create: sock->fasync_list=00000000 sk->sleep=c6b3a7bc.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_insert_socket: sk=c13b1240
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_list_insert_socket: socketp=c6b3a7a0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_create: Socket sock=c6b3a7a0 sk=c13b1240 initialised.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=7, errno=0, satype=2(AH), len=2, res=0, seq=1, pid=6832.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 7 with msg_parser c0224112.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_list_insert_socket: socketp=c6b3a7a0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: SATYPE=02(AH) successfully registered by KMd (pid=6832).
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: pfkey_supported_list[2]=c113cc00
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: checking supported=c113cc00
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: adding auth alg.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: checking supported=c113cbe0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: adding auth alg.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: found satype=2(AH) exttype=14 id=3 ivlen=0 minbits=160 maxbits=160.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: found satype=2(AH) exttype=14 id=2 ivlen=0 minbits=128 maxbits=128.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=00000000.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=c32fbb40.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c29483a0 allocated 40 bytes, &(extensions[0])=c4dedd9c
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[14]=c32fb380 to=c29483b0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=0000c001, seen=00004001, required=00000001.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: allocating 40 bytes...
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c550cb40.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: sending up register reply message for satype=2(AH) to socket=c6b3a7a0 succeeded.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=7, errno=0, satype=3(ESP), len=2, res=0, seq=2, pid=6832.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 7 with msg_parser c0224112.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_list_insert_socket: socketp=c6b3a7a0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: SATYPE=03(ESP) successfully registered by KMd (pid=6832).
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: pfkey_supported_list[3]=c113cc60
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: checking supported=c113cc60
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: adding encrypt alg.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: checking supported=c113cc40
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: adding auth alg.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: checking supported=c113cc20
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: adding auth alg.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: found satype=3(ESP) exttype=15 id=3 ivlen=128 minbits=168 maxbits=168.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: found satype=3(ESP) exttype=14 id=3 ivlen=0 minbits=160 maxbits=160.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: found satype=3(ESP) exttype=14 id=2 ivlen=0 minbits=128 maxbits=128.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=00000000.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=c32fb3a0.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c29483a0 allocated 56 bytes, &(extensions[0])=c4dedd9c
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[14]=c32fbf40 to=c29483b0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[15]=c32fb2a0 to=c29483c8
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=0000c001, seen=0000c001, required=00000001.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: allocating 56 bytes...
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c550cb40.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: sending up register reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=7, errno=0, satype=10(COMP), len=2, res=0, seq=3, pid=6832.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 7 with msg_parser c0224112.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_list_insert_socket: socketp=c6b3a7a0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: SATYPE=10(COMP) successfully registered by KMd (pid=6832).
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: pfkey_supported_list[10]=c113cc80
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: checking supported=c113cc80
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: adding encrypt alg.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: found satype=10(COMP) exttype=15 id=2 ivlen=0 minbits=1 maxbits=1.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=00000000.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=c32fb3a0.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c32fb380 allocated 32 bytes, &(extensions[0])=c4dedd9c
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[15]=c32fbb40 to=c32fb390
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=0000c001, seen=00008001, required=00000001.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: allocating 32 bytes...
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c550cb40.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: sending up register reply message for satype=10(COMP) to socket=c6b3a7a0 succeeded.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=7, errno=0, satype=9(IPIP), len=2, res=0, seq=4, pid=6832.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 7 with msg_parser c0224112.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: .
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_list_insert_socket: socketp=c6b3a7a0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: SATYPE=09(IPIP) successfully registered by KMd (pid=6832).
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: pfkey_supported_list[9]=c113cca0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: checking supported=c113cca0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: adding encrypt alg.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: found satype=9(IPIP) exttype=15 id=1 ivlen=0 minbits=32 maxbits=32.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=00000000.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd68 pfkey_ext=c4dedd9c *pfkey_ext=c32fb380.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c32fbd80 allocated 32 bytes, &(extensions[0])=c4dedd9c
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[15]=c32fbf40 to=c32fbd90
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=0000c001, seen=00008001, required=00000001.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: allocating 32 bytes...
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c550cb40.
Jan  8 18:02:51 localhost kernel: klips_debug:pfkey_register_parse: sending up register reply message for satype=9(IPIP) to socket=c6b3a7a0 succeeded.
Jan  8 18:02:51 localhost ipsec__plutorun: Database load
Jan  8 18:02:51 localhost ipsec__plutorun: ipsec add essai_preshared
Jan  8 18:02:51 localhost ipsec__plutorun: ipsec auto --ready
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=3, errno=0, satype=3(ESP), len=18, res=0, seq=5, pid=6832.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c69c6a90 with processor c0220f53.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c69c6aa0 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c69c6ab8 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.128.1.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 8 c69c6ad0 with processor c02215e8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 9 c69c6af0 with processor c02215e8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 3 with msg_parser c0223184.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: .
Jan  8 18:04:24 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:24 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: existing Tunnel Descriptor Block not found (this is good) for SAesp0xe6b2b9d7@172.16.128.1, in-bound, allocating.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_ipsec_sa_init: (pfkey defined) called for SA:esp0xe6b2b9d7@172.16.128.1
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_ipsec_sa_init: calling init routine of ESP_3DES_HMAC_SHA1
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=c32fb880.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_build: spi=e6b2b9d7 replay=64 sa_state=1 auth=3 encrypt=3 flags=1
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c5f58d60 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb600 to=c5f58d70
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fbd80 to=c5f58d80
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fb3a0 to=c5f58d98
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00001c7b, seen=00000063, required=00000063.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c550cb40.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: sending up add reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: successful for SA: esp0xe6b2b9d7@172.16.128.1
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=3, errno=0, satype=3(ESP), len=18, res=0, seq=6, pid=6832.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73a00.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c69c6590 with processor c0220f53.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c69c65a0 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c69c65b8 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.136.9.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 8 c69c65d0 with processor c02215e8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 9 c69c65f0 with processor c02215e8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 3 with msg_parser c0223184.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: .
Jan  8 18:04:24 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9 requested.
Jan  8 18:04:24 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: existing Tunnel Descriptor Block not found (this is good) for SAesp0x3efddb43@172.16.136.9, out-bound, allocating.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_ipsec_sa_init: (pfkey defined) called for SA:esp0x3efddb43@172.16.136.9
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_ipsec_sa_init: calling init routine of ESP_3DES_HMAC_SHA1
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=c32fbd80.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_build: spi=3efddb43 replay=64 sa_state=1 auth=3 encrypt=3 flags=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c3c86160 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb600 to=c3c86170
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fbc40 to=c3c86180
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fbb00 to=c3c86198
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00001c7b, seen=00000063, required=00000063.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c3376300.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: sending up add reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_add_parse: successful for SA: esp0x3efddb43@172.16.136.9
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=14, errno=0, satype=3(ESP), len=23, res=0, seq=7, pid=6832.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73200.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: message parsing failed with error -22.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: pfkey_msg_parse returns -22.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: sending up error=-22 message=c32fbb00 to socket=c6b3a7a0.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: allocating 16 bytes...
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c3376300.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: sending up error message to socket=c6b3a7a0 succeeded.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=4, errno=0, satype=3(ESP), len=10, res=0, seq=8, pid=6832.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73200.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c3c860f0 with processor c0220f53.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c3c86100 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c3c86118 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.136.9.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 4 with msg_parser c022372a.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_delete_parse: .
Jan  8 18:04:24 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9 requested.
Jan  8 18:04:24 localhost kernel: klips_debug:deltdbchain: passed SA:esp0x3efddb43@172.16.136.9
Jan  8 18:04:24 localhost kernel: klips_debug:deltdbchain: unlinking and delting SA:esp0x3efddb43@172.16.136.9<6>.
Jan  8 18:04:24 localhost kernel: klips_debug:deltdb: deleting SA:esp0x3efddb43@172.16.136.9, hashval=37.
Jan  8 18:04:24 localhost kernel: klips_debug:deltdb: successfully deleted first tdb in chain.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=c32fb880.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_build: spi=3efddb43 replay=0 sa_state=0 auth=0 encrypt=0 flags=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c3c86960 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb3a0 to=c3c86970
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fb380 to=c3c86980
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fb600 to=c3c86998
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00000063, seen=00000063, required=00000063.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c550c780.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_delete_parse: sending up delete reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=4, errno=0, satype=3(ESP), len=10, res=0, seq=9, pid=6832.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73200.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c3c86170 with processor c0220f53.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c3c86180 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c3c86198 with processor c02211f8.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.128.1.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 4 with msg_parser c022372a.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_delete_parse: .
Jan  8 18:04:24 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:24 localhost kernel: klips_debug:deltdbchain: passed SA:esp0xe6b2b9d7@172.16.128.1
Jan  8 18:04:24 localhost kernel: klips_debug:deltdbchain: unlinking and delting SA:esp0xe6b2b9d7@172.16.128.1<6>.
Jan  8 18:04:24 localhost kernel: klips_debug:deltdb: deleting SA:esp0xe6b2b9d7@172.16.128.1, hashval=98.
Jan  8 18:04:24 localhost kernel: klips_debug:deltdb: successfully deleted first tdb in chain.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=c32fb4a0.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_sa_build: spi=e6b2b9d7 replay=0 sa_state=0 auth=0 encrypt=0 flags=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c3c86560 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb6a0 to=c3c86570
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fbf40 to=c3c86580
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fb600 to=c3c86598
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00000063, seen=00000063, required=00000063.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c550c780.
Jan  8 18:04:24 localhost kernel: klips_debug:pfkey_delete_parse: sending up delete reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:25 localhost kernel: klips_debug:ipsec_rcv: <<< Info -- skb->dev=eth0 dev=eth0 
Jan  8 18:04:25 localhost kernel: klips_debug:ipsec_rcv: assigning packet ownership to virtual device ipsec0 from physical device eth0.
Jan  8 18:04:25 localhost kernel: klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:192 id:59172 frag_off:0 ttl:128 proto:50 chk:62139 saddr:172.16.136.9 daddr:172.16.128.1
Jan  8 18:04:25 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:25 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:25 localhost kernel: klips_debug:ipsec_rcv: no Tunnel Descriptor Block for SA:esp0xe6b2b9d7@172.16.128.1: incoming packet with no SA dropped
Jan  8 18:04:27 localhost kernel: klips_debug:ipsec_rcv: <<< Info -- skb->dev=eth0 dev=eth0 
Jan  8 18:04:27 localhost kernel: klips_debug:ipsec_rcv: assigning packet ownership to virtual device ipsec0 from physical device eth0.
Jan  8 18:04:27 localhost kernel: klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:192 id:59940 frag_off:0 ttl:128 proto:50 chk:61371 saddr:172.16.136.9 daddr:172.16.128.1
Jan  8 18:04:27 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:27 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:27 localhost kernel: klips_debug:ipsec_rcv: no Tunnel Descriptor Block for SA:esp0xe6b2b9d7@172.16.128.1: incoming packet with no SA dropped
Jan  8 18:04:32 localhost kernel: klips_debug:ipsec_rcv: <<< Info -- skb->dev=eth0 dev=eth0 
Jan  8 18:04:32 localhost kernel: klips_debug:ipsec_rcv: assigning packet ownership to virtual device ipsec0 from physical device eth0.
Jan  8 18:04:32 localhost kernel: klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:192 id:60708 frag_off:0 ttl:128 proto:50 chk:60603 saddr:172.16.136.9 daddr:172.16.128.1
Jan  8 18:04:32 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:32 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:32 localhost kernel: klips_debug:ipsec_rcv: no Tunnel Descriptor Block for SA:esp0xe6b2b9d7@172.16.128.1: incoming packet with no SA dropped
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=3, errno=0, satype=3(ESP), len=18, res=0, seq=10, pid=6832.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73200.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c69c6690 with processor c0220f53.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c69c66a0 with processor c02211f8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c69c66b8 with processor c02211f8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.136.9.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 8 c69c66d0 with processor c02215e8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 9 c69c66f0 with processor c02215e8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 3 with msg_parser c0223184.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_add_parse: .
Jan  8 18:04:34 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9 requested.
Jan  8 18:04:34 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_add_parse: existing Tunnel Descriptor Block not found (this is good) for SAesp0x3efddb43@172.16.136.9, out-bound, allocating.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_ipsec_sa_init: (pfkey defined) called for SA:esp0x3efddb43@172.16.136.9
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_ipsec_sa_init: calling init routine of ESP_3DES_HMAC_SHA1
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=c32fbf40.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sa_build: spi=3efddb43 replay=64 sa_state=1 auth=3 encrypt=3 flags=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c5f58d60 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb6a0 to=c5f58d70
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fb380 to=c5f58d80
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fb3a0 to=c5f58d98
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00001c7b, seen=00000063, required=00000063.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c32d44a0.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_add_parse: sending up add reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_add_parse: successful for SA: esp0x3efddb43@172.16.136.9
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=14, errno=0, satype=3(ESP), len=23, res=0, seq=11, pid=6832.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73c00.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: message parsing failed with error -22.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: pfkey_msg_parse returns -22.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: sending up error=-22 message=c32fb3a0 to socket=c6b3a7a0.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: allocating 16 bytes...
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c32d44a0.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: sending up error message to socket=c6b3a7a0 succeeded.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=4, errno=0, satype=3(ESP), len=10, res=0, seq=12, pid=6832.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73c00.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c3c86970 with processor c0220f53.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c3c86980 with processor c02211f8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c3c86998 with processor c02211f8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.136.9.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 4 with msg_parser c022372a.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_delete_parse: .
Jan  8 18:04:34 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9 requested.
Jan  8 18:04:34 localhost kernel: klips_debug:deltdbchain: passed SA:esp0x3efddb43@172.16.136.9
Jan  8 18:04:34 localhost kernel: klips_debug:deltdbchain: unlinking and delting SA:esp0x3efddb43@172.16.136.9<6>.
Jan  8 18:04:34 localhost kernel: klips_debug:deltdb: deleting SA:esp0x3efddb43@172.16.136.9, hashval=37.
Jan  8 18:04:34 localhost kernel: klips_debug:deltdb: successfully deleted first tdb in chain.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=c32fb4a0.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sa_build: spi=3efddb43 replay=0 sa_state=0 auth=0 encrypt=0 flags=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c3c86ae0 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb600 to=c3c86af0
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fbb00 to=c3c86b00
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fb380 to=c3c86b18
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00000063, seen=00000063, required=00000063.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c3376300.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_delete_parse: sending up delete reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=4, errno=0, satype=3(ESP), len=10, res=0, seq=13, pid=6832.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73c00.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c3c860f0 with processor c0220f53.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c3c86100 with processor c02211f8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c3c86118 with processor c02211f8.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.128.1.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 4 with msg_parser c022372a.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_delete_parse: .
Jan  8 18:04:34 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:34 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_delete_parse: Tunnel Descriptor Block not found for SA:esp0xe6b2b9d7@172.16.128.1, could not delete.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_msg_interp: message parsing failed with error -3.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: pfkey_msg_parse returns -3.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: sending up error=-3 message=c32fbc40 to socket=c6b3a7a0.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: allocating 16 bytes...
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c3376300.
Jan  8 18:04:34 localhost kernel: klips_debug:pfkey_sendmsg: sending up error message to socket=c6b3a7a0 succeeded.
Jan  8 18:04:39 localhost kernel: klips_debug:ipsec_rcv: <<< Info -- skb->dev=eth0 dev=eth0 
Jan  8 18:04:39 localhost kernel: klips_debug:ipsec_rcv: assigning packet ownership to virtual device ipsec0 from physical device eth0.
Jan  8 18:04:39 localhost kernel: klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:192 id:62244 frag_off:0 ttl:128 proto:50 chk:59067 saddr:172.16.136.9 daddr:172.16.128.1
Jan  8 18:04:39 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:39 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:39 localhost kernel: klips_debug:ipsec_rcv: no Tunnel Descriptor Block for SA:esp0xe6b2b9d7@172.16.128.1: incoming packet with no SA dropped
Jan  8 18:04:47 localhost kernel: klips_debug:ipsec_rcv: <<< Info -- skb->dev=eth0 dev=eth0 
Jan  8 18:04:47 localhost kernel: klips_debug:ipsec_rcv: assigning packet ownership to virtual device ipsec0 from physical device eth0.
Jan  8 18:04:47 localhost kernel: klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:192 id:63524 frag_off:0 ttl:128 proto:50 chk:57787 saddr:172.16.136.9 daddr:172.16.128.1
Jan  8 18:04:47 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:47 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:47 localhost kernel: klips_debug:ipsec_rcv: no Tunnel Descriptor Block for SA:esp0xe6b2b9d7@172.16.128.1: incoming packet with no SA dropped
Jan  8 18:04:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee60 key = 00000000->00000000 @mask = 00000000
Jan  8 18:04:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee6c key = ffffffff->ffffffff @mask = 00000000
Jan  8 18:04:51 localhost kernel: klips_debug: off = 0
Jan  8 18:04:51 localhost kernel: klips_debug:ipsec_eroute_get_info: buffer=0xc1e33000, *start=0x0, offset=0, length=3072
Jan  8 18:04:51 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:04:51 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:04:51 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=3, errno=0, satype=3(ESP), len=18, res=0, seq=14, pid=6832.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73c00.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c69c6590 with processor c0220f53.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c69c65a0 with processor c02211f8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c69c65b8 with processor c02211f8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.136.9.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 8 c69c65d0 with processor c02215e8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 9 c69c65f0 with processor c02215e8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_key_process: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_key_process: success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 3 with msg_parser c0223184.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_add_parse: .
Jan  8 18:04:54 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9 requested.
Jan  8 18:04:54 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_add_parse: existing Tunnel Descriptor Block not found (this is good) for SAesp0x3efddb43@172.16.136.9, out-bound, allocating.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_ipsec_sa_init: (pfkey defined) called for SA:esp0x3efddb43@172.16.136.9
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_ipsec_sa_init: calling init routine of ESP_3DES_HMAC_SHA1
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd44 pfkey_ext=c4dedd6c *pfkey_ext=c32fb4a0.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sa_build: spi=3efddb43 replay=64 sa_state=1 auth=3 encrypt=3 flags=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c5f58d60 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb6a0 to=c5f58d70
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fb880 to=c5f58d80
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fbd80 to=c5f58d98
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00001c7b, seen=00000063, required=00000063.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c6f6b3a0.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_add_parse: sending up add reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_add_parse: successful for SA: esp0x3efddb43@172.16.136.9
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=14, errno=0, satype=3(ESP), len=23, res=0, seq=15, pid=6832.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: message parsing failed with error -22.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: pfkey_msg_parse returns -22.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: sending up error=-22 message=c32fbd80 to socket=c6b3a7a0.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: allocating 16 bytes...
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c6f6b3a0.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: sending up error message to socket=c6b3a7a0 succeeded.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=4, errno=0, satype=3(ESP), len=10, res=0, seq=16, pid=6832.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c3c86170 with processor c0220f53.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c3c86180 with processor c02211f8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c3c86198 with processor c02211f8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.136.9.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 4 with msg_parser c022372a.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_delete_parse: .
Jan  8 18:04:54 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=37 of SA:esp0x3efddb43@172.16.136.9 requested.
Jan  8 18:04:54 localhost kernel: klips_debug:deltdbchain: passed SA:esp0x3efddb43@172.16.136.9
Jan  8 18:04:54 localhost kernel: klips_debug:deltdbchain: unlinking and delting SA:esp0x3efddb43@172.16.136.9<6>.
Jan  8 18:04:54 localhost kernel: klips_debug:deltdb: deleting SA:esp0x3efddb43@172.16.136.9, hashval=37.
Jan  8 18:04:54 localhost kernel: klips_debug:deltdb: successfully deleted first tdb in chain.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_hdr_build:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_entry &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=00000000.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_hdr_build: on_exit &pfkey_ext=c4dedd48 pfkey_ext=c4dedd6c *pfkey_ext=c32fbf40.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sa_build: spi=3efddb43 replay=0 sa_state=0 auth=0 encrypt=0 flags=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: exttype=5 proto=0 prefixlen=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.128.1:1701.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: exttype=6 proto=0 prefixlen=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address family AF_INET.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: found address=172.16.136.9:1701.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_build: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build: error=0
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_safe_build:success.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: pfkey_msg=c3c86560 allocated 80 bytes, &(extensions[0])=c4dedd6c
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: copying 16 bytes from extensions[1]=c32fb600 to=c3c86570
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[5]=c32fbc40 to=c3c86580
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: copying 24 bytes from extensions[6]=c32fb880 to=c3c86598
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_build: extensions permitted=00000063, seen=00000063, required=00000063.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: allocating 80 bytes...
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c32d44a0.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_delete_parse: sending up delete reply message for satype=3(ESP) to socket=c6b3a7a0 succeeded.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=4, errno=0, satype=3(ESP), len=10, res=0, seq=17, pid=6832.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c5f58d70 with processor c0220f53.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c5f58d80 with processor c02211f8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c5f58d98 with processor c02211f8.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.128.1.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 4 with msg_parser c022372a.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_delete_parse: .
Jan  8 18:04:54 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:54 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_delete_parse: Tunnel Descriptor Block not found for SA:esp0xe6b2b9d7@172.16.128.1, could not delete.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_msg_interp: message parsing failed with error -3.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: pfkey_msg_parse returns -3.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: sending up error=-3 message=c32fb3a0 to socket=c6b3a7a0.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: allocating 16 bytes...
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c32d44a0.
Jan  8 18:04:54 localhost kernel: klips_debug:pfkey_sendmsg: sending up error message to socket=c6b3a7a0 succeeded.
Jan  8 18:04:54 localhost kernel: klips_debug:ipsec_rcv: <<< Info -- skb->dev=eth0 dev=eth0 
Jan  8 18:04:54 localhost kernel: klips_debug:ipsec_rcv: assigning packet ownership to virtual device ipsec0 from physical device eth0.
Jan  8 18:04:54 localhost kernel: klips_debug:   IP: ihl:20 ver:4 tos:0 tlen:192 id:65060 frag_off:0 ttl:128 proto:50 chk:56251 saddr:172.16.136.9 daddr:172.16.128.1
Jan  8 18:04:54 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:04:54 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:04:54 localhost kernel: klips_debug:ipsec_rcv: no Tunnel Descriptor Block for SA:esp0xe6b2b9d7@172.16.128.1: incoming packet with no SA dropped
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_sendmsg: .
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_sendmsg: msg sent for parsing.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message ver=2, type=4, errno=0, satype=3(ESP), len=10, res=0, seq=18, pid=6832.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_alloc_ipsec_sa: allocated tdb struct=c4dede2c.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: allocated extr->tdb=c4f73e00.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: satype 3 lookups to proto=50.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 1 c5f58d70 with processor c0220f53.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_sa_process: .
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 5 c5f58d80 with processor c02211f8.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.136.9.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process: found src address.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: processing ext 6 c5f58d98 with processor c02211f8.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process:
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process: found address family=2, AF_INET, 172.16.128.1.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process: found dst address.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process: tdb_said.dst set to 172.16.128.1.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_address_process: successful.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: parsing message type 4 with msg_parser c022372a.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_delete_parse: .
Jan  8 18:05:34 localhost kernel: klips_debug:gettdb: linked entry in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1 requested.
Jan  8 18:05:34 localhost kernel: klips_debug:gettdb: no entries in tdb table for hash=98 of SA:esp0xe6b2b9d7@172.16.128.1.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_delete_parse: Tunnel Descriptor Block not found for SA:esp0xe6b2b9d7@172.16.128.1, could not delete.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_msg_interp: message parsing failed with error -3.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_sendmsg: pfkey_msg_parse returns -3.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_sendmsg: sending up error=-3 message=c32fb6a0 to socket=c6b3a7a0.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_upmsg: allocating 16 bytes...
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_upmsg: ...allocated at c6f6b4e0.
Jan  8 18:05:34 localhost kernel: klips_debug:pfkey_sendmsg: sending up error message to socket=c6b3a7a0 succeeded.
Jan  8 18:06:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee60 key = 00000000->00000000 @mask = 00000000
Jan  8 18:06:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee6c key = ffffffff->ffffffff @mask = 00000000
Jan  8 18:06:51 localhost kernel: klips_debug: off = 0
Jan  8 18:06:51 localhost kernel: klips_debug:ipsec_eroute_get_info: buffer=0xc627e000, *start=0x0, offset=0, length=3072
Jan  8 18:06:51 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:06:51 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:06:51 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:08:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee60 key = 00000000->00000000 @mask = 00000000
Jan  8 18:08:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee6c key = ffffffff->ffffffff @mask = 00000000
Jan  8 18:08:51 localhost kernel: klips_debug: off = 0
Jan  8 18:08:51 localhost kernel: klips_debug:ipsec_eroute_get_info: buffer=0xc627e000, *start=0x0, offset=0, length=3072
Jan  8 18:08:51 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:08:51 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:08:51 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:10:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee60 key = 00000000->00000000 @mask = 00000000
Jan  8 18:10:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee6c key = ffffffff->ffffffff @mask = 00000000
Jan  8 18:10:51 localhost kernel: klips_debug: off = 0
Jan  8 18:10:51 localhost kernel: klips_debug:ipsec_eroute_get_info: buffer=0xc627e000, *start=0x0, offset=0, length=3072
Jan  8 18:10:51 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:10:51 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:10:51 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:12:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee60 key = 00000000->00000000 @mask = 00000000
Jan  8 18:12:51 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee6c key = ffffffff->ffffffff @mask = 00000000
Jan  8 18:12:51 localhost kernel: klips_debug: off = 0
Jan  8 18:12:51 localhost kernel: klips_debug:ipsec_eroute_get_info: buffer=0xc627e000, *start=0x0, offset=0, length=3072
Jan  8 18:12:51 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:12:51 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:12:51 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:13:04 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc2661000, *start=0x0, offset=0, length=3072
Jan  8 18:13:04 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc2661000, *start=0x0, offset=24, length=3072
Jan  8 18:13:04 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee60 key = 00000000->00000000 @mask = 00000000
Jan  8 18:13:04 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee6c key = ffffffff->ffffffff @mask = 00000000
Jan  8 18:13:04 localhost kernel: klips_debug: off = 0
Jan  8 18:13:04 localhost kernel: klips_debug:ipsec_eroute_get_info: buffer=0xc1c7a000, *start=0x0, offset=0, length=3072
Jan  8 18:13:04 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:13:04 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:13:04 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:13:04 localhost kernel: klips_debug:ipsec_spi_get_info: buffer=0xc1916000, *start=0x0, offset=0, length=3072
Jan  8 18:13:04 localhost kernel: klips_debug:ipsec_spigrp_get_info: buffer=0xc361d000, *start=0x0, offset=0, length=3072
Jan  8 18:13:04 localhost kernel: klips_debug:ipsec_tncfg_get_info: buffer=0xc361d000, *start=0x0, offset=0, length=3072
Jan  8 18:13:04 localhost kernel: klips_debug:ipsec_tncfg_get_info: buffer=0xc64e6000, *start=0x0, offset=126, length=3072
Jan  8 18:13:07 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc3356000, *start=0x0, offset=0, length=3072
Jan  8 18:13:07 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc3356000, *start=0x0, offset=24, length=3072
Jan  8 18:13:52 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc6c37000, *start=0x0, offset=0, length=3072
Jan  8 18:13:52 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc6c37000, *start=0x0, offset=24, length=3072
Jan  8 18:13:53 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee60 key = 00000000->00000000 @mask = 00000000
Jan  8 18:13:53 localhost kernel: klips_debug:@ flags = 6 @key = c6fbee6c key = ffffffff->ffffffff @mask = 00000000
Jan  8 18:13:53 localhost kernel: klips_debug: off = 0
Jan  8 18:13:53 localhost kernel: klips_debug:ipsec_eroute_get_info: buffer=0xc3238000, *start=0x0, offset=0, length=3072
Jan  8 18:13:53 localhost kernel: klips_debug:rj_walktree: for: rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:13:53 localhost kernel: klips_debug:rj_walktree: processing leaves, rn=c6f6c778 rj_b=-3 rj_flags=6 leaf key = ffffffff->ffffffff
Jan  8 18:13:53 localhost kernel: klips_debug:rj_walktree: while: base=00000000 rn=c6f6c748 rj_b=-3 rj_flags=6 leaf key = 00000000->00000000
Jan  8 18:13:53 localhost kernel: klips_debug:ipsec_spi_get_info: buffer=0xc4e6d000, *start=0x0, offset=0, length=3072
Jan  8 18:13:53 localhost kernel: klips_debug:ipsec_spigrp_get_info: buffer=0xc4576000, *start=0x0, offset=0, length=3072
Jan  8 18:13:53 localhost kernel: klips_debug:ipsec_tncfg_get_info: buffer=0xc4576000, *start=0x0, offset=0, length=3072
Jan  8 18:13:53 localhost kernel: klips_debug:ipsec_tncfg_get_info: buffer=0xc2313000, *start=0x0, offset=126, length=3072
Jan  8 18:13:54 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc5311000, *start=0x0, offset=0, length=3072
Jan  8 18:13:54 localhost kernel: klips_debug:ipsec_version_get_info: buffer=0xc5c1f000, *start=0x0, offset=24, length=3072
+ _________________________ plog
+ sed -n '28,$p' /var/log/messages
+ egrep -i pluto
+ cat
jan  8 16:09:10 localhost ipsec_setup: Attempt to shut Pluto down failed!  Trying kill:
Jan  8 16:09:17 localhost ipsec__plutorun: Database load
Jan  8 16:09:17 localhost ipsec__plutorun: ipsec add essai_preshared
Jan  8 16:09:17 localhost ipsec__plutorun: ipsec auto --ready
Jan  8 16:09:21 localhost ipsec__plutorun: Database load
Jan  8 16:09:21 localhost ipsec__plutorun: ipsec add essai_preshared
Jan  8 16:09:21 localhost ipsec__plutorun: ipsec auto --ready
Jan  8 17:12:30 localhost ipsec__plutorun: Database load
Jan  8 17:12:30 localhost ipsec__plutorun: ipsec add essai_preshared
Jan  8 17:12:30 localhost ipsec__plutorun: ipsec auto --ready
Jan  8 17:47:50 localhost ipsec__plutorun: Database load
Jan  8 17:47:50 localhost ipsec__plutorun: ipsec add essai_preshared
Jan  8 17:47:51 localhost ipsec__plutorun: ipsec auto --ready
Jan  8 17:49:58 localhost ipsec__plutorun: Database load
Jan  8 17:49:58 localhost ipsec__plutorun: ipsec add essai_preshared
Jan  8 17:49:58 localhost ipsec__plutorun: ipsec auto --ready
Jan  8 18:02:51 localhost ipsec__plutorun: Database load
Jan  8 18:02:51 localhost ipsec__plutorun: ipsec add essai_preshared
Jan  8 18:02:51 localhost ipsec__plutorun: ipsec auto --ready
+ _________________________ date
+ date
Wed Jan  8 18:13:54 CET 2003
