xref: /openbsd/regress/sbin/ipsecctl/ikefail14.ok (revision fe0dc84e)
1stdin: 10: default peer local mismatch
2stdin: 10: default peer psk mismatch
3stdin: 10: default peer phase 1 mode mismatch
4stdin: 10: default peer srcid mismatch
5stdin: 10: default peer dstid mismatch
6stdin: 11: default peer local mismatch
7stdin: 11: default peer phase 1 auth mismatch
8stdin: 11: default peer srcid mismatch
9stdin: 11: default peer dstid mismatch
10C set [Phase 1]:Default=peer-default force
11C set [peer-default]:Phase=1 force
12C set [peer-default]:Local-address=1.1.1.1 force
13C set [peer-default]:Authentication=secret force
14C set [peer-default]:Configuration=phase1-peer-default force
15C set [phase1-peer-default]:EXCHANGE_TYPE=ID_PROT force
16C add [phase1-peer-default]:Transforms=phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072 force
17C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:AUTHENTICATION_METHOD=PRE_SHARED force
18C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:HASH_ALGORITHM=SHA force
19C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:ENCRYPTION_ALGORITHM=AES_CBC force
20C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:KEY_LENGTH=128,128:256 force
21C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:GROUP_DESCRIPTION=MODP_3072 force
22C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:Life=LIFE_MAIN_MODE force
23C set [peer-default]:ID=id-src.id force
24C set [id-src.id]:ID-type=FQDN force
25C set [id-src.id]:Name=src.id force
26C set [peer-default]:Remote-ID=id-dst.id force
27C set [id-dst.id]:ID-type=FQDN force
28C set [id-dst.id]:Name=dst.id force
29C set [from-0.0.0.0/0-to-0.0.0.0/0]:Phase=2 force
30C set [from-0.0.0.0/0-to-0.0.0.0/0]:ISAKMP-peer=peer-default force
31C set [from-0.0.0.0/0-to-0.0.0.0/0]:Configuration=phase2-from-0.0.0.0/0-to-0.0.0.0/0 force
32C set [from-0.0.0.0/0-to-0.0.0.0/0]:Local-ID=from-0.0.0.0/0 force
33C set [from-0.0.0.0/0-to-0.0.0.0/0]:Remote-ID=to-0.0.0.0/0 force
34C set [phase2-from-0.0.0.0/0-to-0.0.0.0/0]:EXCHANGE_TYPE=QUICK_MODE force
35C set [phase2-from-0.0.0.0/0-to-0.0.0.0/0]:Suites=phase2-suite-from-0.0.0.0/0-to-0.0.0.0/0 force
36C set [phase2-suite-from-0.0.0.0/0-to-0.0.0.0/0]:Protocols=phase2-protocol-from-0.0.0.0/0-to-0.0.0.0/0 force
37C set [phase2-protocol-from-0.0.0.0/0-to-0.0.0.0/0]:PROTOCOL_ID=IPSEC_ESP force
38C set [phase2-protocol-from-0.0.0.0/0-to-0.0.0.0/0]:Transforms=phase2-transform-from-0.0.0.0/0-to-0.0.0.0/0-AES128-SHA2_256-MODP_3072-TUNNEL force
39C set [phase2-transform-from-0.0.0.0/0-to-0.0.0.0/0-AES128-SHA2_256-MODP_3072-TUNNEL]:TRANSFORM_ID=AES force
40C set [phase2-transform-from-0.0.0.0/0-to-0.0.0.0/0-AES128-SHA2_256-MODP_3072-TUNNEL]:KEY_LENGTH=128,128:256 force
41C set [phase2-transform-from-0.0.0.0/0-to-0.0.0.0/0-AES128-SHA2_256-MODP_3072-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
42C set [phase2-transform-from-0.0.0.0/0-to-0.0.0.0/0-AES128-SHA2_256-MODP_3072-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
43C set [phase2-transform-from-0.0.0.0/0-to-0.0.0.0/0-AES128-SHA2_256-MODP_3072-TUNNEL]:GROUP_DESCRIPTION=MODP_3072 force
44C set [phase2-transform-from-0.0.0.0/0-to-0.0.0.0/0-AES128-SHA2_256-MODP_3072-TUNNEL]:Life=LIFE_QUICK_MODE force
45C set [from-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
46C set [from-0.0.0.0/0]:Network=0.0.0.0 force
47C set [from-0.0.0.0/0]:Netmask=0.0.0.0 force
48C set [to-0.0.0.0/0]:ID-type=IPV4_ADDR_SUBNET force
49C set [to-0.0.0.0/0]:Network=0.0.0.0 force
50C set [to-0.0.0.0/0]:Netmask=0.0.0.0 force
51C add [Phase 2]:Connections=from-0.0.0.0/0-to-0.0.0.0/0
52C set [Phase 1]:Default=peer-default force
53C set [peer-default]:Phase=1 force
54C set [peer-default]:Local-address=1.1.1.1 force
55C set [peer-default]:Authentication=secret force
56C set [peer-default]:Configuration=phase1-peer-default force
57C set [phase1-peer-default]:EXCHANGE_TYPE=ID_PROT force
58C add [phase1-peer-default]:Transforms=phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072 force
59C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:AUTHENTICATION_METHOD=PRE_SHARED force
60C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:HASH_ALGORITHM=SHA force
61C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:ENCRYPTION_ALGORITHM=AES_CBC force
62C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:KEY_LENGTH=128,128:256 force
63C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:GROUP_DESCRIPTION=MODP_3072 force
64C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:Life=LIFE_MAIN_MODE force
65C set [peer-default]:ID=id-src.id force
66C set [id-src.id]:ID-type=FQDN force
67C set [id-src.id]:Name=src.id force
68C set [peer-default]:Remote-ID=id-dst.id force
69C set [id-dst.id]:ID-type=FQDN force
70C set [id-dst.id]:Name=dst.id force
71C set [from-::/0-to-::/0]:Phase=2 force
72C set [from-::/0-to-::/0]:ISAKMP-peer=peer-default force
73C set [from-::/0-to-::/0]:Configuration=phase2-from-::/0-to-::/0 force
74C set [from-::/0-to-::/0]:Local-ID=from-::/0 force
75C set [from-::/0-to-::/0]:Remote-ID=to-::/0 force
76C set [phase2-from-::/0-to-::/0]:EXCHANGE_TYPE=QUICK_MODE force
77C set [phase2-from-::/0-to-::/0]:Suites=phase2-suite-from-::/0-to-::/0 force
78C set [phase2-suite-from-::/0-to-::/0]:Protocols=phase2-protocol-from-::/0-to-::/0 force
79C set [phase2-protocol-from-::/0-to-::/0]:PROTOCOL_ID=IPSEC_ESP force
80C set [phase2-protocol-from-::/0-to-::/0]:Transforms=phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL force
81C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:TRANSFORM_ID=AES force
82C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:KEY_LENGTH=128,128:256 force
83C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
84C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
85C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:GROUP_DESCRIPTION=MODP_3072 force
86C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:Life=LIFE_QUICK_MODE force
87C set [from-::/0]:ID-type=IPV6_ADDR_SUBNET force
88C set [from-::/0]:Network=:: force
89C set [from-::/0]:Netmask=:: force
90C set [to-::/0]:ID-type=IPV6_ADDR_SUBNET force
91C set [to-::/0]:Network=:: force
92C set [to-::/0]:Netmask=:: force
93C add [Phase 2]:Connections=from-::/0-to-::/0
94C set [Phase 1]:Default=peer-default force
95C set [peer-default]:Phase=1 force
96C set [peer-default]:Local-address=2.2.2.2 force
97C set [peer-default]:Authentication=insecure force
98C set [peer-default]:Configuration=phase1-peer-default force
99C set [phase1-peer-default]:EXCHANGE_TYPE=AGGRESSIVE force
100C add [phase1-peer-default]:Transforms=phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072 force
101C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:AUTHENTICATION_METHOD=PRE_SHARED force
102C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:HASH_ALGORITHM=SHA force
103C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:ENCRYPTION_ALGORITHM=AES_CBC force
104C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:KEY_LENGTH=128,128:256 force
105C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:GROUP_DESCRIPTION=MODP_3072 force
106C set [phase1-transform-peer-default-PRE_SHARED-SHA-AES128-MODP_3072]:Life=LIFE_MAIN_MODE force
107C set [peer-default]:ID=id-src.wrong force
108C set [id-src.wrong]:ID-type=FQDN force
109C set [id-src.wrong]:Name=src.wrong force
110C set [peer-default]:Remote-ID=id-dst.wrong force
111C set [id-dst.wrong]:ID-type=FQDN force
112C set [id-dst.wrong]:Name=dst.wrong force
113C set [from-::/0-to-::/0]:Phase=2 force
114C set [from-::/0-to-::/0]:ISAKMP-peer=peer-default force
115C set [from-::/0-to-::/0]:Configuration=phase2-from-::/0-to-::/0 force
116C set [from-::/0-to-::/0]:Local-ID=from-::/0 force
117C set [from-::/0-to-::/0]:Remote-ID=to-::/0 force
118C set [phase2-from-::/0-to-::/0]:EXCHANGE_TYPE=QUICK_MODE force
119C set [phase2-from-::/0-to-::/0]:Suites=phase2-suite-from-::/0-to-::/0 force
120C set [phase2-suite-from-::/0-to-::/0]:Protocols=phase2-protocol-from-::/0-to-::/0 force
121C set [phase2-protocol-from-::/0-to-::/0]:PROTOCOL_ID=IPSEC_ESP force
122C set [phase2-protocol-from-::/0-to-::/0]:Transforms=phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL force
123C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:TRANSFORM_ID=AES force
124C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:KEY_LENGTH=128,128:256 force
125C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
126C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
127C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:GROUP_DESCRIPTION=MODP_3072 force
128C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:Life=LIFE_QUICK_MODE force
129C set [from-::/0]:ID-type=IPV6_ADDR_SUBNET force
130C set [from-::/0]:Network=:: force
131C set [from-::/0]:Netmask=:: force
132C set [to-::/0]:ID-type=IPV6_ADDR_SUBNET force
133C set [to-::/0]:Network=:: force
134C set [to-::/0]:Netmask=:: force
135C add [Phase 2]:Connections=from-::/0-to-::/0
136C set [Phase 1]:Default=peer-default force
137C set [peer-default]:Phase=1 force
138C set [peer-default]:Configuration=phase1-peer-default force
139C set [phase1-peer-default]:EXCHANGE_TYPE=ID_PROT force
140C add [phase1-peer-default]:Transforms=phase1-transform-peer-default-RSA_SIG-SHA-AES128-MODP_3072 force
141C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128-MODP_3072]:AUTHENTICATION_METHOD=RSA_SIG force
142C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128-MODP_3072]:HASH_ALGORITHM=SHA force
143C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128-MODP_3072]:ENCRYPTION_ALGORITHM=AES_CBC force
144C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128-MODP_3072]:KEY_LENGTH=128,128:256 force
145C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128-MODP_3072]:GROUP_DESCRIPTION=MODP_3072 force
146C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128-MODP_3072]:Life=LIFE_MAIN_MODE force
147C set [from-::/0-to-::/0]:Phase=2 force
148C set [from-::/0-to-::/0]:ISAKMP-peer=peer-default force
149C set [from-::/0-to-::/0]:Configuration=phase2-from-::/0-to-::/0 force
150C set [from-::/0-to-::/0]:Local-ID=from-::/0 force
151C set [from-::/0-to-::/0]:Remote-ID=to-::/0 force
152C set [phase2-from-::/0-to-::/0]:EXCHANGE_TYPE=QUICK_MODE force
153C set [phase2-from-::/0-to-::/0]:Suites=phase2-suite-from-::/0-to-::/0 force
154C set [phase2-suite-from-::/0-to-::/0]:Protocols=phase2-protocol-from-::/0-to-::/0 force
155C set [phase2-protocol-from-::/0-to-::/0]:PROTOCOL_ID=IPSEC_ESP force
156C set [phase2-protocol-from-::/0-to-::/0]:Transforms=phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL force
157C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:TRANSFORM_ID=AES force
158C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:KEY_LENGTH=128,128:256 force
159C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
160C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
161C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:GROUP_DESCRIPTION=MODP_3072 force
162C set [phase2-transform-from-::/0-to-::/0-AES128-SHA2_256-MODP_3072-TUNNEL]:Life=LIFE_QUICK_MODE force
163C set [from-::/0]:ID-type=IPV6_ADDR_SUBNET force
164C set [from-::/0]:Network=:: force
165C set [from-::/0]:Netmask=:: force
166C set [to-::/0]:ID-type=IPV6_ADDR_SUBNET force
167C set [to-::/0]:Network=:: force
168C set [to-::/0]:Netmask=:: force
169C add [Phase 2]:Connections=from-::/0-to-::/0
170