adapted scenarios to new crypto proposal output

This commit is contained in:
Andreas Steffen
2009-05-20 07:51:25 +02:00
parent 80cbbfed36
commit 706fd144fe
41 changed files with 97 additions and 93 deletions
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite
<b>BLOWFISH_CBC_256-SHA2_512-MODP4096</b> for the IKE protocol and <b>BLOWFISH_CBC_256 / HMAC_SHA2_512 / MODP_4096</b> for the IKE protocol and
<b>BLOWFISH_256-HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to <b>BLOWFISH_CBC_256 / HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to
<b>alice</b> successfully checks the established tunnel. <b>alice</b> successfully checks the established tunnel.
@@ -1,9 +1,9 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::IKE algorithm newest: BLOWFISH_CBC_256-SHA2_512-MODP4096::YES carol::ipsec statusall::IKE proposal: BLOWFISH_CBC_256/HMAC_SHA2_512/MODP_4096::YES
moon::ipsec statusall::IKE algorithm newest: BLOWFISH_CBC_256-SHA2_512-MODP4096::YES moon::ipsec statusall::IKE proposal: BLOWFISH_CBC_256/HMAC_SHA2_512/MODP_4096::YES
carol::ipsec statusall::ESP algorithm newest: BLOWFISH_256-HMAC_SHA2_256::YES carol::ipsec statusall::ESP proposal: BLOWFISH_CBC_256/HMAC_SHA2_256::YES
moon::ipsec statusall::ESP algorithm newest: BLOWFISH_256-HMAC_SHA2_256::YES moon::ipsec statusall::ESP proposal: BLOWFISH_CBC_256/HMAC_SHA2_256::YES
carol::ip xfrm state::enc cbc(blowfish)::YES carol::ip xfrm state::enc cbc(blowfish)::YES
moon::ip xfrm state::enc cbc(blowfish)::YES moon::ip xfrm state::enc cbc(blowfish)::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite
<b>SERPENT_CBC_256-SHA2_512-MODP4096</b> for the IKE protocol and <b>SERPENT_CBC_256 / HMAC_SHA2_512 / MODP_4096</b> for the IKE protocol and
<b>SERPENT_256-HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to <b>SERPENT_CBC_256 / HMAC_SHA2_256 </b> for ESP packets. A ping from <b>carol</b> to
<b>alice</b> successfully checks the established tunnel. <b>alice</b> successfully checks the established tunnel.
+4 -4
View File
@@ -1,9 +1,9 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::IKE algorithm newest: SERPENT_CBC_256-SHA2_512-MODP4096::YES carol::ipsec statusall::IKE proposal: SERPENT_CBC_256/HMAC_SHA2_512/MODP_4096::YES
moon::ipsec statusall::IKE algorithm newest: SERPENT_CBC_256-SHA2_512-MODP4096::YES moon::ipsec statusall::IKE proposal: SERPENT_CBC_256/HMAC_SHA2_512/MODP_4096::YES
carol::ipsec statusall::ESP algorithm newest: SERPENT_256-HMAC_SHA2_256::YES carol::ipsec statusall::ESP proposal: SERPENT_CBC_256/HMAC_SHA2_256::YES
moon::ipsec statusall::ESP algorithm newest: SERPENT_256-HMAC_SHA2_256::YES moon::ipsec statusall::ESP proposal: SERPENT_CBC_256/HMAC_SHA2_256::YES
carol::ip xfrm state::enc cbc(serpent)::YES carol::ip xfrm state::enc cbc(serpent)::YES
moon::ip xfrm state::enc cbc(serpent)::YES moon::ip xfrm state::enc cbc(serpent)::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the rather strong cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the rather strong cipher suite
<b>AES_CBC_128-SHA2_256-MODP1536</b> for the IKE protocol and <b>AES_CBC_128 / HMAC_SHA2_256 / MODP_1536</b> for the IKE protocol and
<b>AES_128-HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to <b>AES_CBC_128 / HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to
<b>alice</b> successfully checks the established tunnel. <b>alice</b> successfully checks the established tunnel.
@@ -1,10 +1,10 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::IKE algorithm newest: AES_CBC_128-SHA2_256-MODP1536::YES carol::ipsec statusall::IKE proposal: AES_CBC_128/HMAC_SHA2_256/MODP_1536::YES
moon::ipsec statusall::IKE algorithm newest: AES_CBC_128-SHA2_256-MODP1536::YES moon::ipsec statusall::IKE proposal: AES_CBC_128/HMAC_SHA2_256/MODP_1536::YES
carol::ipsec statusall::ESP algorithm newest: AES_128-HMAC_SHA2_256::YES carol::ipsec statusall::ESP proposal: AES_CBC_128/HMAC_SHA2_256::YES
moon::ipsec statusall::ESP algorithm newest: AES_128-HMAC_SHA2_256::YES moon::ipsec statusall::ESP proposal: AES_CBC_128/HMAC_SHA2_256::YES
carol::ip xfrm state::auth hmac(sha256)::YES carol::ip xfrm state::auth hmac(sha256)::YES
moon::ip xfrm state::auth hmac(sha256)::YES moon::ip xfrm state::auth hmac(sha256)::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite
<b>TWOFISH_CBC_256-SHA2_512-MODP4096</b> for the IKE protocol and <b>TWOFISH_CBC_256 / HMAC_SHA2_512 / MODP_4096</b> for the IKE protocol and
<b>TWOFISH_256-HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to <b>TWOFISH_CBC_256 / HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to
<b>alice</b> successfully checks the established tunnel. <b>alice</b> successfully checks the established tunnel.
+4 -4
View File
@@ -1,9 +1,9 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::IKE algorithm newest: TWOFISH_CBC_256-SHA2_512-MODP4096::YES carol::ipsec statusall::IKE proposal: TWOFISH_CBC_256/HMAC_SHA2_512/MODP_4096::YES
moon::ipsec statusall::IKE algorithm newest: TWOFISH_CBC_256-SHA2_512-MODP4096::YES moon::ipsec statusall::IKE proposal: TWOFISH_CBC_256/HMAC_SHA2_512/MODP_4096::YES
carol::ipsec statusall::ESP algorithm newest: TWOFISH_256-HMAC_SHA2_256::YES carol::ipsec statusall::ESP proposal: TWOFISH_CBC_256/HMAC_SHA2_256::YES
moon::ipsec statusall::ESP algorithm newest: TWOFISH_256-HMAC_SHA2_256::YES moon::ipsec statusall::ESP proposal: TWOFISH_CBC_256/HMAC_SHA2_256::YES
carol::ip xfrm state::enc cbc(twofish)::YES carol::ip xfrm state::enc cbc(twofish)::YES
moon::ip xfrm state::enc cbc(twofish)::YES moon::ip xfrm state::enc cbc(twofish)::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,5 +1,5 @@
In IKE phase 2 the roadwarrior <b>carol</b> proposes to gateway <b>moon</b> In IKE phase 2 the roadwarrior <b>carol</b> proposes to gateway <b>moon</b>
the ESP AES 128 bit encryption algorithm combined with AH SHA-1 authentication. the ESP AES 128 bit encryption algorithm combined with AH HMAC_SHA1 authentication.
In order to accept the AH and ESP encapsulated plaintext packets, the iptables firewall In order to accept the AH and ESP encapsulated plaintext packets, the iptables firewall
marks all incoming AH packets with the ESP mark. The transport mode connection is marks all incoming AH packets with the ESP mark. The transport mode connection is
tested by <b>carol</b> sending a ping to gateway <b>moon</b>. tested by <b>carol</b> sending a ping to gateway <b>moon</b>.
@@ -1,7 +1,7 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::ESP algorithm newest: AES_128-;::YES carol::ipsec statusall::ESP/AH proposal: AES_CBC_128/HMAC_SHA1::YES
moon::ipsec statusall::ESP algorithm newest: AES_128-;::YES moon::ipsec statusall::ESP/AH proposal: AES_CBC_128/HMAC_SHA1::YES
carol::ping -c 1 -s 120 -p deadbeef PH_IP_MOON::128 bytes from PH_IP_MOON: icmp_seq=1::YES carol::ping -c 1 -s 120 -p deadbeef PH_IP_MOON::128 bytes from PH_IP_MOON: icmp_seq=1::YES
carol::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*transport::YES carol::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*transport::YES
moon::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*transport::YES moon::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*transport::YES
@@ -1,5 +1,5 @@
In IKE phase 2 the roadwarrior <b>carol</b> proposes to gateway <b>moon</b> In IKE phase 2 the roadwarrior <b>carol</b> proposes to gateway <b>moon</b>
the ESP AES 128 bit encryption algorithm combined with AH SHA-1 authentication. the ESP AES 128 bit encryption algorithm combined with AH HMAC_SHA1 authentication.
In order to accept the AH and ESP encapsulated plaintext packets, the iptables firewall In order to accept the AH and ESP encapsulated plaintext packets, the iptables firewall
marks all incoming AH packets with the ESP mark. The tunnel mode connection is marks all incoming AH packets with the ESP mark. The tunnel mode connection is
tested by <b>carol</b> sending a ping to client <b>alice</b> hiding behind tested by <b>carol</b> sending a ping to client <b>alice</b> hiding behind
@@ -1,7 +1,7 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::ESP algorithm newest: AES_128-;::YES carol::ipsec statusall::ESP/AH proposal: AES_CBC_128/HMAC_SHA1::YES
moon::ipsec statusall::ESP algorithm newest: AES_128-;::YES moon::ipsec statusall::ESP/AH proposal: AES_CBC_128/HMAC_SHA1::YES
carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_seq=1::YES
carol::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*tunnel::YES carol::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*tunnel::YES
moon::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*tunnel::YES moon::ipsec status::ah\..*ah\..*esp\..*ago.*esp\..*ago.*tunnel::YES
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the ESP cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the ESP cipher suite
<b>AES_256/AES_XCBC_MAC</b> by defining <b>esp=aes256-aesxcbc-modp2048</b> <b>AES_CBC_256 / AES_XCBC_96</b> by defining <b>esp=aes256-aesxcbc</b>
in ipsec.conf. A ping from <b>carol</b> to <b>alice</b> successfully checks in ipsec.conf. A ping from <b>carol</b> to <b>alice</b> successfully checks
the established tunnel. the established tunnel.
@@ -1,8 +1,8 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::ESP algorithm newest: AES_256-AES_XCBC_MAC::YES carol::ipsec statusall::ESP proposal: AES_CBC_256/AES_XCBC_96::YES
moon::ipsec statusall::ESP algorithm newest: AES_256-AES_XCBC_MAC::YES moon::ipsec statusall::ESP proposal: AES_CBC_256/AES_XCBC_96::YES
carol::ip xfrm state::auth xcbc(aes)::YES carol::ip xfrm state::auth xcbc(aes)::YES
moon::ip xfrm state::auth xcbc(aes)::YES moon::ip xfrm state::auth xcbc(aes)::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the ESP cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the ESP cipher suite
<b>CAMELLIA_192/HMAC_SHA2_256</b> by defining <b>esp=camellia192-sha2_256-modp2048</b> <b>CAMELLIA_CBC_192 / HMAC_SHA2_256</b> by defining <b>esp=camellia192-sha2_256</b>
in ipsec.conf. A ping from <b>carol</b> to <b>alice</b> successfully checks in ipsec.conf. A ping from <b>carol</b> to <b>alice</b> successfully checks
the established tunnel. the established tunnel.
@@ -1,7 +1,7 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
carol::ipsec statusall::ESP algorithm newest: CAMELLIA_192-HMAC_SHA2_256::YES carol::ipsec statusall::ESP proposal: CAMELLIA_CBC_192/HMAC_SHA2_256::YES
moon::ipsec statusall::ESP algorithm newest: CAMELLIA_192-HMAC_SHA2_256::YES moon::ipsec statusall::ESP proposal: CAMELLIA_CBC_192/HMAC_SHA2_256::YES
carol::ip xfrm state::enc cbc(camellia)::YES carol::ip xfrm state::enc cbc(camellia)::YES
moon::ip xfrm state::enc cbc(camellia)::YES moon::ip xfrm state::enc cbc(camellia)::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
+4 -2
View File
@@ -1,6 +1,8 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
moon::ipsec statusall::ESP algorithm newest: DES_0-HMAC_MD5::YES moon::ipsec statusall::ESP proposal: DES_CBC/HMAC_MD5::YES
carol::ipsec statusall::ESP algorithm newest: DES_0-HMAC_MD5::YES carol::ipsec statusall::ESP proposal: DES_CBC/HMAC_MD5::YES
moon::ip xfrm state::enc cbc(des)::YES
carol::ip xfrm state::enc cbc(des)::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,5 +1,7 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
moon::ipsec statusall::ESP algorithm newest::NULL_0-HMAC_SHA1::YES moon::ipsec statusall::ESP proposal::NULL/HMAC_SHA1::YES
carol::ipsec statusall::ESP algorithm newest::NULL_0-HMAC_SHA1::YES carol::ipsec statusall::ESP proposal::NULL/HMAC_SHA1::YES
moon::ip xfrm state::enc ecb(cipher_null)::YES
carol::ip xfrm state::enc ecb(cipher_null)::YES
carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=aes-128-sha ike=aes-sha1
esp=null-sha1! esp=null-sha1!
conn home conn home
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=aes128-sha! ike=aes-sha1!
esp=null-sha1! esp=null-sha1!
conn rw conn rw
@@ -1,5 +1,5 @@
The roadwarrior <b>carol</b> proposes <b>3DES</b> encryption with SHA-1 authentication The roadwarrior <b>carol</b> proposes <b>3DES_CBC</b> encryption with HMAC_SHA1 authentication
as the only cipher suite for both the ISAKMP and IPsec SA. The gateway <b>moon</b> defines as the only cipher suite for both the ISAKMP and IPsec SA. The gateway <b>moon</b> defines
<b>ike=aes-128-sha</b> only, but will accept any other support algorithm proposed by the peer, <b>ike=aes128-sha1</b> only, but will accept any other support algorithm proposed by the peer,
leading to a successful negotiation of Phase 1. Because for Phase 2 <b>moon</b> enforces leading to a successful negotiation of Phase 1. Because for Phase 2 <b>moon</b> enforces
<b>esp=aes-128-sha1!</b> by using the strict flag '!', the ISAKMP SA will fail. <b>esp=aes128-sha1!</b> by using the strict flag '!', the ISAKMP SA will fail.
@@ -1,9 +1,9 @@
carol::ipsec status::home.*STATE_MAIN_I4.*ISAKMP SA established::YES carol::ipsec status::home.*STATE_MAIN_I4.*ISAKMP SA established::YES
carol::ipsec statusall::IKE algorithm newest: 3DES_CBC_192-SHA::YES carol::ipsec statusall::IKE proposal: 3DES_CBC/HMAC_SHA1::YES
moon::ipsec status::rw.*STATE_MAIN_R3.*ISAKMP SA established::YES moon::ipsec status::rw.*STATE_MAIN_R3.*ISAKMP SA established::YES
moon::ipsec statusall::IKE algorithm newest: 3DES_CBC_192-SHA::YES moon::ipsec statusall::IKE proposal: 3DES_CBC/HMAC_SHA1::YES
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::NO carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::NO
carol::cat /var/log/auth.log::NO_PROPOSAL_CHOSEN::YES carol::cat /var/log/auth.log::NO_PROPOSAL_CHOSEN::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*ISAKMP SA established::NO moon::ipsec status::rw.*STATE_QUICK_R2.*ISAKMP SA established::NO
moon::cat /var/log/auth.log::IPSec Transform.*ESP_3DES (192), AUTH_ALGORITHM_HMAC_SHA1.*refused due to strict flag::YES moon::cat /var/log/auth.log::IPSec Transform.*3DES_CBC (192), HMAC_SHA1.*refused due to strict flag::YES
moon::cat /var/log/auth.log::no acceptable Proposal in IPsec SA::YES moon::cat /var/log/auth.log::no acceptable Proposal in IPsec SA::YES
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=3des-sha ike=3des-sha1
esp=3des-sha1 esp=3des-sha1
conn home conn home
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=aes128-sha ike=aes128-sha1
esp=aes128-sha1! esp=aes128-sha1!
conn rw conn rw
@@ -1,7 +1,7 @@
Roadwarrior <b>carol</b> proposes <b>3DES</b> encryption (together with Roadwarrior <b>carol</b> proposes <b>3DES_CBC</b> encryption (together with
SHA-1 authentication) in the first place and <b>AES-128</b> encryption in HMAC_SHA1 authentication) in the first place and <b>AES_CBC_128</b> encryption in
second place for both the ISAKMP and IPsec SAs. Gateway <b>moon</b> defines second place for both the ISAKMP and IPsec SAs. Gateway <b>moon</b> defines
<b>ike=aes-128-sha</b> but will accept any other supported algorithm proposed <b>ike=aes128-sha1</b> but will accept any other supported algorithm proposed
by the peer during Phase 1. But for ESP encryption <b>moon</b> enforces by the peer during Phase 1. But for ESP encryption <b>moon</b> enforces
<b>esp=aes-128-sha1!</b> by applying the strict flag '!'. <b>esp=aes128-sha1!</b> by applying the strict flag '!'.
@@ -1,7 +1,7 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
moon::cat /var/log/auth.log::IPSec Transform.*ESP_3DES (192), AUTH_ALGORITHM_HMAC_SHA1.*refused due to strict flag::YES moon::cat /var/log/auth.log::IPSec Transform.*3DES_CBC (192), HMAC_SHA1.*refused due to strict flag::YES
moon::ipsec statusall::IKE algorithm newest: 3DES_CBC_192-SHA::YES moon::ipsec statusall::IKE proposal: 3DES_CBC/HMAC_SHA1::YES
moon::ipsec statusall::ESP algorithm newest: AES_128-HMAC_SHA1::YES moon::ipsec statusall::ESP proposal: AES_CBC_128/HMAC_SHA1::YES
carol::ipsec statusall::IKE algorithm newest: 3DES_CBC_192-SHA::YES carol::ipsec statusall::IKE proposal: 3DES_CBC/HMAC_SHA1::YES
carol::ipsec statusall::ESP algorithm newest: AES_128-HMAC_SHA1::YES carol::ipsec statusall::ESP proposal: AES_CBC_128/HMAC_SHA1::YES
@@ -11,8 +11,8 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=3des-sha,aes-128-sha ike=3des-sha,aes128-sha1
esp=3des-sha1,aes-128-sha1 esp=3des-sha1,aes128-sha1
conn home conn home
left=PH_IP_CAROL left=PH_IP_CAROL
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=aes128-sha ike=aes128-sha1
esp=aes128-sha1! esp=aes128-sha1!
conn rw conn rw
@@ -1,4 +1,4 @@
The roadwarrior <b>carol</b> proposes <b>1DES</b> encryption with MD5 authentication The roadwarrior <b>carol</b> proposes <b>DES_CBC</b> encryption with HMAC_MD5 authentication
as the only cipher suite for the IPsec SA. Because gateway <b>moon</b> does as the only cipher suite for the IPsec SA. Because gateway <b>moon</b> does
not use an explicit <b>esp</b> statement any strong encryption algorithm will be not use an explicit <b>esp</b> statement any strong encryption algorithm will be
accepted but any weak key length will be rejected by default and thus the ISAKMP SA accepted but any weak key length will be rejected by default and thus the ISAKMP SA
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the strong cipher suite
<b>AES_CBC_192-SHA2_384-MODP4096</b> for the IKE protocol and <b>AES_CBC_192 / HMAC_SHA2_384 / MODP4096</b> for the IKE protocol and
<b>AES_192-HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to <b>AES_CBC_192 /HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to
<b>alice</b> successfully checks the established tunnel. <b>alice</b> successfully checks the established tunnel.
@@ -1,8 +1,8 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
moon::ipsec statusall::IKE algorithm newest: AES_CBC_192-SHA2_384-MODP4096::YES moon::ipsec statusall::IKE proposal: AES_CBC_192/HMAC_SHA2_384/MODP_4096::YES
carol::ipsec statusall::IKE algorithm newest: AES_CBC_192-SHA2_384-MODP4096::YES carol::ipsec statusall::IKE proposal: AES_CBC_192/HMAC_SHA2_384/MODP_4096::YES
moon::ipsec statusall::ESP algorithm newest: AES_192-HMAC_SHA2_256::YES moon::ipsec statusall::ESP proposal: AES_CBC_192/HMAC_SHA2_256::YES
carol::ipsec statusall::ESP algorithm newest: AES_192-HMAC_SHA2_256::YES carol::ipsec statusall::ESP proposal: AES_CBC_192/HMAC_SHA2_256::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,4 +1,4 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the paranoid cipher suite Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the paranoid cipher suite
<b>AES_CBC_256-SHA2_512-MODP8192</b> for the IKE protocol and <b>AES_CBC_256 / HMAC_SHA2_512 / MODP_8192</b> for the IKE protocol and
<b>AES_256-HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to <b>AES_CBC_256 / HMAC_SHA2_256</b> for ESP packets. A ping from <b>carol</b> to
<b>alice</b> successfully checks the established tunnel. <b>alice</b> successfully checks the established tunnel.
@@ -1,8 +1,8 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
moon::ipsec statusall::IKE algorithm newest: AES_CBC_256-SHA2_512-MODP8192::YES moon::ipsec statusall::IKE proposal: AES_CBC_256/HMAC_SHA2_512/MODP_8192::YES
carol::ipsec statusall::IKE algorithm newest: AES_CBC_256-SHA2_512-MODP8192::YES carol::ipsec statusall::IKE proposal: AES_CBC_256/HMAC_SHA2_512/MODP_8192::YES
moon::ipsec statusall::ESP algorithm newest: AES_256-HMAC_SHA2_256::YES moon::ipsec statusall::ESP proposal: AES_CBC_256/HMAC_SHA2_256::YES
carol::ipsec statusall::ESP algorithm newest: AES_256-HMAC_SHA2_256::YES carol::ipsec statusall::ESP proposal: AES_CBC_256/HMAC_SHA2_256::YES
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
@@ -1,5 +1,5 @@
The roadwarrior <b>carol</b> proposes <b>3DES</b> encryption with SHA-1 authentication The roadwarrior <b>carol</b> proposes <b>3DES_CBC</b> encryption with HMAC_SHA1 authentication
as the only cipher suite for both the ISAKMP and IPsec SA. The gateway <b>moon</b> defines as the only cipher suite for both the ISAKMP and IPsec SA. The gateway <b>moon</b> defines
<b>ike=aes-128-sha</b> only, but will accept any other support algorithm proposed by the peer, <b>ike=aes128-sha1</b> only, but will accept any other support algorithm proposed by the peer,
leading to a successful negotiation of Phase 1. Because for Phase 2 <b>moon</b> enforces leading to a successful negotiation of Phase 1. Because for Phase 2 <b>moon</b> enforces
<b>esp=aes-128-sha1!</b> by using the strict flag '!', the ISAKMP SA will fail. <b>esp=aes128-sha1!</b> by using the strict flag '!', the ISAKMP SA will fail.
@@ -1,5 +1,5 @@
carol::ipsec status::home.*STATE_MAIN_I4.*ISAKMP SA established::NO carol::ipsec status::home.*STATE_MAIN_I4.*ISAKMP SA established::NO
moon::ipsec status::rw.*STATE_MAIN_R3.*ISAKMP SA established::NO moon::ipsec status::rw.*STATE_MAIN_R3.*ISAKMP SA established::NO
carol::cat /var/log/auth.log::NO_PROPOSAL_CHOSEN::YES carol::cat /var/log/auth.log::NO_PROPOSAL_CHOSEN::YES
moon::cat /var/log/auth.log::Oakley Transform.*OAKLEY_3DES_CBC (192), OAKLEY_SHA.*refused due to strict flag::YES moon::cat /var/log/auth.log::Oakley Transform.*3DES_CBC (192), HMAC_SHA1.*refused due to strict flag::YES
moon::cat /var/log/auth.log::no acceptable Oakley Transform::YES moon::cat /var/log/auth.log::no acceptable Oakley Transform::YES
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=3des-sha ike=3des-sha1
esp=3des-sha1 esp=3des-sha1
conn home conn home
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=aes128-sha! ike=aes128-sha1!
esp=aes128-sha1 esp=aes128-sha1
conn rw conn rw
@@ -1,5 +1,5 @@
The roadwarrior <b>carol</b> proposes <b>3DES</b> encryption with <b>SHA-1</b> authentication in the first place The roadwarrior <b>carol</b> proposes <b>3DES_CBC</b> encryption with <b>HMAC_SHA1</b> authentication in the first place
and <b>AES-128</b> encryption with <b>SHA-1</b> authentication in the second place for both the ISAKMP and IPsec SA. and <b>AES_CBC_128</b> encryption with <b>HMAC_SHA1</b> authentication in the second place for both the ISAKMP and IPsec SA.
The gateway <b>moon</b> enforces <b>ike=aes-128-sha!</b> for Phase 1 by using the strict flag '!', The gateway <b>moon</b> enforces <b>ike=aes128-sha!</b> for Phase 1 by using the strict flag '!',
but will accept any other supported algorithm proposed by the peer for Phase 2 , even though <b>moon</b> but will accept any other supported algorithm proposed by the peer for Phase 2 , even though <b>moon</b>
defines itself <b>esp=aes-128-sha1</b> only. defines itself <b>esp=aes128-sha1</b> only.
@@ -1,7 +1,7 @@
carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES carol::ipsec status::home.*STATE_QUICK_I2.*IPsec SA established::YES
moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES moon::ipsec status::rw.*STATE_QUICK_R2.*IPsec SA established::YES
moon::cat /var/log/auth.log::Oakley Transform.*OAKLEY_3DES_CBC (192), OAKLEY_SHA.*refused due to strict flag::YES moon::cat /var/log/auth.log::Oakley Transform.*3DES_CBC (192), HMAC_SHA1.*refused due to strict flag::YES
moon::ipsec statusall::IKE algorithm newest: AES_CBC_128-SHA::YES moon::ipsec statusall::IKE proposal: AES_CBC_128/HMAC_SHA1::YES
moon::ipsec statusall::ESP algorithm newest: 3DES_0-HMAC_SHA1::YES moon::ipsec statusall::ESP proposal: 3DES_CBC/HMAC_SHA1::YES
carol::ipsec statusall::IKE algorithm newest: AES_CBC_128-SHA::YES carol::ipsec statusall::IKE proposal: AES_CBC_128/HMAC_SHA::YES
carol::ipsec statusall::ESP algorithm newest: 3DES_0-HMAC_SHA1::YES carol::ipsec statusall::ESP proposal: 3DES_CBC/HMAC_SHA1::YES
@@ -11,8 +11,8 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=3des-sha,aes-128-sha ike=3des-sha1,aes128-sha1
esp=3des-sha1,aes-128-sha1 esp=3des-sha1,aes128-sha1
conn home conn home
left=PH_IP_CAROL left=PH_IP_CAROL
leftcert=carolCert.pem leftcert=carolCert.pem
@@ -11,7 +11,7 @@ conn %default
keylife=20m keylife=20m
rekeymargin=3m rekeymargin=3m
keyingtries=1 keyingtries=1
ike=aes128-sha! ike=aes128-sha1!
esp=aes128-sha1 esp=aes128-sha1
conn rw conn rw