"road-east" #2: sent Quick Mode request
"road-east" #2: STATE_QUICK_I1: 10 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"road-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road-east" #2: revival: skip scheduling revival event
+IMPAIR: "road-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
road #
../../guestbin/ping-once.sh --error -I 192.0.2.102 192.0.2.254
"road-east" #2: sent Quick Mode request
"road-east" #2: STATE_QUICK_I1: 10 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"road-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road-east" #2: revival: skip scheduling revival event
+IMPAIR: "road-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
road #
../../guestbin/ping-once.sh --error -I 192.0.2.102 192.0.2.254
"road-east" #2: sent Quick Mode request
"road-east" #2: STATE_QUICK_I1: 10 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"road-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road-east" #2: revival: skip scheduling revival event
+IMPAIR: "road-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
road #
../../guestbin/ping-once.sh --error -I 192.0.2.102 192.0.2.254
"road-east" #2: sent Quick Mode request
"road-east" #2: STATE_QUICK_I1: 10 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"road-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road-east" #2: revival: skip scheduling revival event
+IMPAIR: "road-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
road #
../../guestbin/ping-once.sh --error -I 192.0.2.102 192.0.2.254
"westnet-eastnet-ah" #2: sent Quick Mode request
IMPAIR: "westnet-eastnet-ah" #2: retransmit so timing out SA (may retry)
"westnet-eastnet-ah" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ah" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ah" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ah" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
echo done
"westnet-eastnet-aes256" #2: sent Quick Mode request
"westnet-eastnet-aes256" #2: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"westnet-eastnet-aes256" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-aes256" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-aes256" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-aes256" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "westnet-eastnet-aes256" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.45: No such process (errno 3)
west #
# While revival is pending, the kernel policy have transitioned to
# on-demand.
-../../guestbin/wait-for-pluto.sh '#2: revival: skip scheduling revival event'
+../../guestbin/wait-for-pluto.sh '#2: revival: skip scheduling CONNECTION_REVIVAL event'
ipsec _kernel policy
# Now trigger the revival. Since ROAD is down it will fail. And
east #
# on-demand.
east #
- ../../guestbin/wait-for-pluto.sh '#2: revival: skip scheduling revival event'
-IMPAIR: "road-eastnet-ikev2"[1] 192.1.2.254 #2: revival: skip scheduling revival event
+ ../../guestbin/wait-for-pluto.sh '#2: revival: skip scheduling CONNECTION_REVIVAL event'
+IMPAIR: "road-eastnet-ikev2"[1] 192.1.2.254 #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
east #
ipsec _kernel policy
src 192.0.2.0/24 dst 192.1.3.209/32
ipsec whack --deletestate 3
"west-cuckoo" #3: sent INFORMATIONAL request to delete established Child SA using IKE SA #1
"west-cuckoo" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckoo" #3: revival: skip scheduling revival event
+IMPAIR: "west-cuckoo" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckoo" #3: ESP traffic information: in=84B out=84B
west #
../../guestbin/ping-once.sh --up 192.0.2.254
"westnet-eastnet" #1: unable to locate my private key for RSA Signature
"westnet-eastnet" #1: sending notification AUTHENTICATION_FAILED to 192.1.2.23:500
"westnet-eastnet" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet" #1: deleting ISAKMP SA (MAIN_I2) and NOT sending notification
west #
# we should not see any leftover states
"westnet-eastnet-compress" #2: sent Quick Mode request
IMPAIR: "westnet-eastnet-compress" #2: retransmit so timing out SA (may retry)
"westnet-eastnet-compress" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-compress" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-compress" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-compress" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec whack --trafficstatus
"westnet-eastnet-ipcomp" #1: response for Child SA #2 was rejected with NO_PROPOSAL_CHOSEN; initiating delete of Child SA (IKE SA will remain UP)
"westnet-eastnet-ipcomp" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"westnet-eastnet-ipcomp" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipcomp" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipcomp" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "westnet-eastnet-ipcomp" #2: netlink response for Get SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
ERROR: "westnet-eastnet-ipcomp" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
"westnet-eastnet-ikev2" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ikev2" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"westnet-eastnet-aggr" #1: ignoring unsecured informational payload NO_PROPOSAL_CHOSEN, length=12
IMPAIR: "westnet-eastnet-aggr" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-aggr" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-aggr" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-aggr" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-aggr" #1: deleting ISAKMP SA (AGGR_I1) and NOT sending notification
west #
echo done
"westnet-eastnet-ipv4-psk-ikev1" #2: sent Quick Mode request
IMPAIR: "westnet-eastnet-ipv4-psk-ikev1" #2: retransmit so timing out SA (may retry)
"westnet-eastnet-ipv4-psk-ikev1" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev1" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev1" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev1" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
echo done
"westnet-eastnet-ipv4-psk-ikev1" #2: sent Quick Mode request
IMPAIR: "westnet-eastnet-ipv4-psk-ikev1" #2: retransmit so timing out SA (may retry)
"westnet-eastnet-ipv4-psk-ikev1" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev1" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev1" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev1" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
echo done
IMPAIR: "westnet-eastnet" #1: dropping Main Mode I2 packet as per impair
IMPAIR: "westnet-eastnet" #1: retransmit so timing out SA (may retry)
"westnet-eastnet" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet" #1: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
# we are waiting for east to expire the partial IKE state in 1+1+2+4+8+16+32 secs
IMPAIR: "westnet-eastnet-aggr" #1: dropping Aggressive Mode I2 packet as per impair
IMPAIR: "westnet-eastnet-aggr" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-aggr" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-aggr" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-aggr" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-aggr" #1: deleting ISAKMP SA (AGGR_I1) and NOT sending notification
west #
# we are waiting for east to expire the partial IKE state in 1+1+2+4+8+16+32 secs
"westnet-eastnet-ipv4-psk" #1: NSS: shared key calculation using MODP failed: SEC_ERROR_NO_MEMORY: security library: memory allocation failure.
"westnet-eastnet-ipv4-psk" #1: sending notification INVALID_KEY_INFORMATION to 192.1.2.23:500
"westnet-eastnet-ipv4-psk" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk" #1: deleting ISAKMP SA (MAIN_I2) and NOT sending notification
west #
ipsec whack --impair none
"westnet-eastnet-ipv4-psk" #2: NSS: shared key calculation using MODP failed: SEC_ERROR_NO_MEMORY: security library: memory allocation failure.
"westnet-eastnet-ipv4-psk" #2: sending notification INVALID_KEY_INFORMATION to 192.1.2.23:500
"westnet-eastnet-ipv4-psk" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk" #2: deleting ISAKMP SA (MAIN_I2) and NOT sending notification
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #1: sent Main Mode I2
IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-ipv4-psk-ikev2" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting ISAKMP SA (MAIN_I2) and NOT sending notification
west #
ipsec whack --impair none
"westnet-eastnet-ipv4-psk" #1: ignoring unsecured informational payload INVALID_KEY_INFORMATION, length=12
IMPAIR: "westnet-eastnet-ipv4-psk" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-ipv4-psk" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk" #1: deleting ISAKMP SA (MAIN_I2) and NOT sending notification
west #
ipsec auto --delete westnet-eastnet-ipv4-psk
"westnet-eastnet-ipv4-psk" #2: sending notification INVALID_KEY_INFORMATION to 192.1.2.23:500
"westnet-eastnet-ipv4-psk" #2: STATE_MAIN_I2: 60 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our IKEv1 message
"westnet-eastnet-ipv4-psk" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk" #2: deleting ISAKMP SA (MAIN_I2) and NOT sending notification
west #
ipsec auto --delete westnet-eastnet-ipv4-psk
"ikev1" #1: sent Main Mode request
IMPAIR: "ikev1" #1: retransmit so timing out SA (may retry)
"ikev1" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev1" #1: revival: skip scheduling revival event
+IMPAIR: "ikev1" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev1" #1: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
echo done
"ikev1" #1: ignoring unsecured informational payload INVALID_MAJOR_VERSION, length=12
IMPAIR: "ikev1" #1: retransmit so timing out SA (may retry)
"ikev1" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev1" #1: revival: skip scheduling revival event
+IMPAIR: "ikev1" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev1" #1: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
echo done
"road-east" #2: sent Quick Mode request
"road-east" #2: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"road-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road-east" #2: revival: skip scheduling revival event
+IMPAIR: "road-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "road-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.3.209: No such process (errno 3)
road #
"road-east" #2: sent Quick Mode request
"road-east" #2: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"road-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road-east" #2: revival: skip scheduling revival event
+IMPAIR: "road-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "road-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.3.209: No such process (errno 3)
road #
"westnet-eastnet-ikev2" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ikev2" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"westnet-eastnet-ikev2" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ikev2" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ipv4-psk-ikev2" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (sent IKE_AUTH request)
west #
# expect block/acquire stopping traffic
"ipv4-psk-ikev2-transport" #1: response for Child SA #2 was rejected with NO_PROPOSAL_CHOSEN; initiating delete of Child SA (IKE SA will remain UP)
"ipv4-psk-ikev2-transport" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"ipv4-psk-ikev2-transport" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ipv4-psk-ikev2-transport" #2: revival: skip scheduling revival event
+IMPAIR: "ipv4-psk-ikev2-transport" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "ipv4-psk-ikev2-transport" #2: netlink response for Get SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
ERROR: "ipv4-psk-ikev2-transport" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
"ipv4-psk-ikev2-transport" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"ipv4-psk-ikev2-transport" #2: IKE_AUTH response rejected Child SA with NO_PROPOSAL_CHOSEN
"ipv4-psk-ikev2-transport" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ipv4-psk-ikev2-transport" #2: revival: skip scheduling revival event
+IMPAIR: "ipv4-psk-ikev2-transport" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"westnet-eastnet-mismatch" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-mismatch" #2: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"westnet-eastnet-mismatch" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-mismatch" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-mismatch" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
| event_schedule_where: EVENT_v2_EXPIRE@0xXXX timeout in N.N seconds for #1
| event_schedule_where: EVENT_v2_REPLACE@0xXXX timeout in N.N seconds for #3
| #1 is retaining EVENT_v2_EXPIRE with is previously set timeout
-| timer_event_cb: processing EVENT_v2_EXPIRE-event@0xXXX for IKE SA #1 in state ESTABLISHED_IKE_SA
+| timer_event_cb: processing EVENT_v2_EXPIRE-event@0xXXX for IKE SA #1 in state ESTABLISHED_IKE_SA
| #1 deleting EVENT_v2_EXPIRE
road #
: "re-authenticateded. The state number should 3 and 2"
"westnet-eastnet-no-sha1" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-no-sha1" #2: IKE_AUTH response rejected Child SA with NO_PROPOSAL_CHOSEN
"westnet-eastnet-no-sha1" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-no-sha1" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-no-sha1" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"replay" #1: initiator established IKE SA; authenticated peer using preloaded certificate '@east' and 2nnn-bit RSASSA-PSS with SHA2_512 digital signature
"replay" #2: IKE_AUTH response rejected Child SA with NO_PROPOSAL_CHOSEN
"replay" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "replay" #2: revival: skip scheduling revival event
+IMPAIR: "replay" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"westnet-eastnet-ipv4-psk-ikev2" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #2: IKE_AUTH response rejected Child SA with NO_PROPOSAL_CHOSEN
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"westnet-eastnet-ikev2" #1: initiator established IKE SA; authenticated peer using preloaded certificate '@east' and 2nnn-bit RSASSA-PSS with SHA2_512 digital signature
"westnet-eastnet-ikev2" #2: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"westnet-eastnet-ikev2" #1: response for Child SA #2 was rejected with TS_UNACCEPTABLE; initiating delete of Child SA (IKE SA will remain UP)
"westnet-eastnet-ikev2" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "westnet-eastnet-ikev2" #2: netlink response for Get SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
ERROR: "westnet-eastnet-ikev2" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
"westnet-eastnet-ikev2" #1: authentication failed: peer attempted NULL authentication but we want RSASIG
"westnet-eastnet-ikev2" #1: deleting IKE SA (IKE_AUTH_I) and sending notification
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"westnet-eastnet-ikev2" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ikev2" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"westnet-eastnet-ikev2b" #3: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESP <0xESPESP}
IMPAIR: "westnet-eastnet-ikev2a" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-ikev2a" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2a" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2a" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2a" #2: ESP traffic information: in=0B out=0B
"westnet-eastnet-ikev2b" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2b" #3: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2b" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2a" #1: deleting IKE SA (established IKE SA)
west #
echo done
"west" #4: sent CREATE_CHILD_SA request to rekey Child SA #3 using IKE SA #1 {ESP <0xESPESP}
"west" #1: ESTABLISHED_IKE_SA: 15 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our IKEv2 message
"west" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #3: revival: skip scheduling revival event
+IMPAIR: "west" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #3: ESP traffic information: in=0B out=0B
"west" #4: deleting larval Child SA
"west" #1: deleting IKE SA (established IKE SA)
"westnet-eastnet-ikev2b" #3: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESP <0xESPESP}
"westnet-eastnet-ikev2b" #3: CREATE_CHILD_SA failed with error notification TS_UNACCEPTABLE
"westnet-eastnet-ikev2b" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2b" #3: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2b" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec auto --up westnet-eastnet-ikev2c
"westnet-eastnet-ikev2c" #4: initiating Child SA using IKE SA #1
"westnet-eastnet-ikev2c" #4: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESP <0xESPESP}
"westnet-eastnet-ikev2c" #4: CREATE_CHILD_SA failed with error notification TS_UNACCEPTABLE
"westnet-eastnet-ikev2c" #4: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2c" #4: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2c" #4: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
#
west #
"westnet-eastnet-ikev2" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"westnet-eastnet-ikev2" #1: IKE_SA_INIT_I: 5 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our first IKEv2 message
"westnet-eastnet-ikev2" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
west #
grep -e IMPAIR: -e '^packet from ' /tmp/pluto.log
IMPAIR: "westnet-eastnet-ikev2" #1: mangling DDOS cookie sent by peer
-IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
"westnet-eastnet-ikev2" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"westnet-eastnet-ikev2" #1: IKE_SA_INIT_I: 5 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our first IKEv2 message
"westnet-eastnet-ikev2" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
west #
grep -e IMPAIR: -e '^packet from ' /tmp/pluto.log
IMPAIR: "westnet-eastnet-ikev2" #1: adding unsolicited and mangled DDOS cookie
-IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec whack --deletestate 1
"westnet-eastnet-ipv4-psk-ikev2" #1: sent INFORMATIONAL request to delete IKE SA
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #2: ESP traffic information: in=84B out=84B
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --deletestate 2
"west-east-delete1" #2: sent INFORMATIONAL request to delete established Child SA using IKE SA #1
"west-east-delete1" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east-delete1" #2: revival: skip scheduling revival event
+IMPAIR: "west-east-delete1" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east-delete1" #2: ESP traffic information: in=84B out=84B
west #
sleep 2
"westnet-eastnet-ikev2" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ikev2" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #1: NSS: shared key calculation using ECP failed: SEC_ERROR_INVALID_KEY: The key does not support the requested operation.
"westnet-eastnet-ipv4-psk-ikev2" #1: encountered fatal error in state IKE_SA_INIT_I
"westnet-eastnet-ipv4-psk-ikev2" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
# send valid KE
"westnet-eastnet-ipv4-psk-ikev2" #2: NSS: shared key calculation using ECP failed: SEC_ERROR_INVALID_KEY: The key does not support the requested operation.
"westnet-eastnet-ipv4-psk-ikev2" #2: encountered fatal error in state IKE_SA_INIT_I
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"westnet-eastnet-ipv4-psk-ikev2" #2: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #1: ignoring IKE_SA_INIT response containing INVALID_SYNTAX notification (Message ID 0; message payloads N, missing SA,KE,Ni)
IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-ipv4-psk-ikev2" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
# expect slower fail
"westnet-eastnet-ipv4-psk-ikev2" #2: ignoring IKE_SA_INIT response containing IKEV2_FRAGMENTATION_SUPPORTED... notification (Message ID 0; message payloads SA,Ni,N, missing KE)
"westnet-eastnet-ipv4-psk-ikev2" #2: IKE_SA_INIT_I: 60 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our first IKEv2 message
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"westnet-eastnet-ipv4-psk-ikev2" #2: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #1: ignoring IKE_SA_INIT response containing INVALID_SYNTAX notification (Message ID 0; message payloads N, missing SA,KE,Ni)
IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-ipv4-psk-ikev2" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec whack --impair none
"westnet-eastnet-ipv4-psk-ikev2" #2: responder IKE_SA_INIT KE payload is 0 bytes; 64 required
"westnet-eastnet-ipv4-psk-ikev2" #2: encountered fatal error in state IKE_SA_INIT_I
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"westnet-eastnet-ipv4-psk-ikev2" #2: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #3: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #4: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"westnet-eastnet-ipv4-psk-ikev2" #4: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #4: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #4: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec auto --down westnet-eastnet-ipv4-psk-ikev2
"westnet-eastnet-ipv4-psk-ikev2": initiating delete of connection's IKE SA #3
"westnet-eastnet-ipv4-psk-ikev2" #5: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #6: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"westnet-eastnet-ipv4-psk-ikev2" #6: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #6: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #6: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
west #
ipsec auto --down westnet-eastnet-ipv4-psk-ikev2
"westnet-eastnet-ipv4-psk-ikev2": initiating delete of connection's IKE SA #5
"west-cuckoo" #3: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESP <0xESPESP}
"west-cuckoo" #3: CREATE_CHILD_SA failed with error notification INVALID_KE_PAYLOAD response suggesting MODP4096 instead of MODP8192
"west-cuckoo" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckoo" #3: revival: skip scheduling revival event
+IMPAIR: "west-cuckoo" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
"labeled" #1: initiator established IKE SA; authenticated peer using preloaded certificate '@east' and 2nnn-bit RSASSA-PSS with SHA2_512 digital signature
"labeled" #2: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"labeled" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "labeled" #2: revival: skip scheduling revival event
+IMPAIR: "labeled" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"westnet-eastnet-ipv4-psk-ikev2" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #2: IKE_AUTH response rejected Child SA with NO_PROPOSAL_CHOSEN
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo done
done
"westnet-eastnet-ikev2-major" #1: ignoring IKE_SA_INIT response containing INVALID_MAJOR_VERSION notification (Message ID 0; message payloads N, missing SA,KE,Ni)
IMPAIR: "westnet-eastnet-ikev2-major" #1: retransmit so timing out SA (may retry)
"westnet-eastnet-ikev2-major" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2-major" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2-major" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2-major" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
"westnet-eastnet-ipv4-psk-ppk" #1: ignoring IKE_SA_INIT response containing NO_PROPOSAL_CHOSEN notification (Message ID 0; message payloads N, missing SA,KE,Ni)
"westnet-eastnet-ipv4-psk-ppk" #1: IKE_SA_INIT_I: 60 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our first IKEv2 message
"westnet-eastnet-ipv4-psk-ppk" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ppk" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ppk" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ppk" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
"westnet-eastnet-ipv4-psk-ppk" #1: connection has ppk=insist but peer does not support PPK
"westnet-eastnet-ipv4-psk-ppk" #1: encountered fatal error in state IKE_SA_INIT_I
"westnet-eastnet-ipv4-psk-ppk" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ppk" #1: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ppk" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ppk" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
"westnet-eastnet-ipv4-psk-ppk" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ipv4-psk-ppk" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ipv4-psk-ppk" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ppk" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ppk" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ppk" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"north-east" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"north-east" #1: IKE_SA_INIT response redirects to new gateway 192.1.2.44
"north-east" #1: scheduling redirect 1 to 192.1.2.44
-IMPAIR: "north-east" #1: redirect: skip scheduling redirect event
+IMPAIR: "north-east" #1: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"north-east" #1: deleting IKE SA (sent IKE_SA_INIT request)
north #
ipsec whack --impair trigger_revival:1
"north-east" #2: sent IKE_SA_INIT request to 192.1.2.44:UDP/500
IMPAIR: "north-east" #2: retransmit so timing out SA (may retry)
"north-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "north-east" #2: revival: skip scheduling revival event
+IMPAIR: "north-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"north-east" #2: deleting IKE SA (sent IKE_SA_INIT request)
north #
ipsec auto --delete north-east
"north-east" #3: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"north-east" #3: IKE_SA_INIT response redirects to new gateway 192.1.2.46
"north-east" #3: scheduling redirect 1 to 192.1.2.46
-IMPAIR: "north-east" #3: redirect: skip scheduling redirect event
+IMPAIR: "north-east" #3: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"north-east" #3: deleting IKE SA (sent IKE_SA_INIT request)
north #
ipsec whack --impair trigger_revival:2
"north-east" #4: sent IKE_SA_INIT request to 192.1.2.46:UDP/500
IMPAIR: "north-east" #4: retransmit so timing out SA (may retry)
"north-east" #4: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "north-east" #4: revival: skip scheduling revival event
+IMPAIR: "north-east" #4: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"north-east" #4: deleting IKE SA (sent IKE_SA_INIT request)
north #
ipsec auto --delete north-east
"north-east" #5: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"north-east" #5: IKE_SA_INIT response redirects to new gateway 192.1.2.45
"north-east" #5: scheduling redirect 1 to 192.1.2.45
-IMPAIR: "north-east" #5: redirect: skip scheduling redirect event
+IMPAIR: "north-east" #5: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"north-east" #5: deleting IKE SA (sent IKE_SA_INIT request)
north #
ipsec whack --impair trigger_revival:3
"road-east" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"road-east" #1: IKE_SA_INIT response redirects to new gateway 192.1.2.45
"road-east" #1: scheduling redirect 1 to 192.1.2.45
-IMPAIR: "road-east" #1: redirect: skip scheduling redirect event
+IMPAIR: "road-east" #1: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #1: deleting IKE SA (sent IKE_SA_INIT request)
road #
ipsec whack --impair trigger_revival:1
"road-east" #4: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"road-east" #4: IKE_SA_INIT response redirects to new gateway 192.1.2.44
"road-east" #4: scheduling redirect 1 to 192.1.2.44
-IMPAIR: "road-east" #4: redirect: skip scheduling redirect event
+IMPAIR: "road-east" #4: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #4: deleting IKE SA (sent IKE_SA_INIT request)
road #
ipsec whack --impair trigger_revival:2
"road-east" #5: sent IKE_SA_INIT request to 192.1.2.44:UDP/500
IMPAIR: "road-east" #5: retransmit so timing out SA (may retry)
"road-east" #5: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road-east" #5: revival: skip scheduling revival event
+IMPAIR: "road-east" #5: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road-east" #5: deleting IKE SA (sent IKE_SA_INIT request)
road #
ipsec whack --trafficstatus
"westnet-eastnet-ipv4-psk-ikev2" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"westnet-eastnet-ipv4-psk-ikev2" #1: IKE_SA_INIT response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #1: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #1: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #2: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #1: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #2: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #3: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #3: IKE_AUTH response redirects to new gateway 192.1.2.23
"westnet-eastnet-ipv4-psk-ikev2" #4: scheduling redirect 2 to 192.1.2.23
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #4: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #4: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #3: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #5: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #5: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #6: scheduling redirect 3 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #6: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #6: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #5: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #7: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #7: IKE_AUTH response redirects to new gateway 192.1.2.23
"westnet-eastnet-ipv4-psk-ikev2" #8: scheduling redirect 4 to 192.1.2.23
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #8: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #8: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #7: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #9: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #9: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #10: scheduling redirect 5 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #10: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #10: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #9: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #11: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #11: IKE_AUTH redirect exceeds limit; assuming redirect loop
"westnet-eastnet-ipv4-psk-ikev2" #12: connection is supposed to remain up; revival attempt 1 scheduled in 300 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #12: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #12: revival: skip scheduling CONNECTION_REVIVAL event in 300 seconds
"westnet-eastnet-ipv4-psk-ikev2" #11: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #13: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #13: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #14: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #14: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #14: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #13: deleting IKE SA (established IKE SA)
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #1: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #2: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #3: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #3: IKE_AUTH response redirects to new gateway 192.1.2.23
"westnet-eastnet-ipv4-psk-ikev2" #4: scheduling redirect 2 to 192.1.2.23
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #4: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #4: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #3: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #5: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #5: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #6: scheduling redirect 3 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #6: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #6: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #5: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #7: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #7: IKE_AUTH response redirects to new gateway 192.1.2.23
"westnet-eastnet-ipv4-psk-ikev2" #8: scheduling redirect 4 to 192.1.2.23
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #8: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #8: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #7: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #9: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #9: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #10: scheduling redirect 5 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #10: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #10: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #9: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #11: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #11: IKE_AUTH redirect exceeds limit; assuming redirect loop
"westnet-eastnet-ipv4-psk-ikev2" #12: connection is supposed to remain up; revival attempt 1 scheduled in 300 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #12: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #12: revival: skip scheduling CONNECTION_REVIVAL event in 300 seconds
"westnet-eastnet-ipv4-psk-ikev2" #11: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"westnet-eastnet-ipv4-psk-ikev2" #13: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #13: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #14: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #14: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #14: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #13: deleting IKE SA (established IKE SA)
west #
echo done
"westnet-eastnet-ipv4-psk-ikev2" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #1: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #2: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1
"westnet-eastnet-ipv4-psk-ikev2" #3: sent IKE_SA_INIT request to 192.1.3.33:UDP/500
"westnet-eastnet-ipv4-psk-ikev2" #3: IKE_SA_INIT_I: 10 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our first IKEv2 message
"westnet-eastnet-ipv4-psk-ikev2" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #3: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #3: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec whack --impair trigger_revival:1
"westnet-eastnet-ipv4-psk-ikev2" #4: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"westnet-eastnet-ipv4-psk-ikev2" #4: IKE_AUTH response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #5: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #5: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #5: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #4: deleting IKE SA (established IKE SA)
west #
"westnet-eastnet-ipv4-psk-ikev2" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"westnet-eastnet-ipv4-psk-ikev2" #1: IKE_SA_INIT response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #1: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #1: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec whack --impair trigger_revival:1
"westnet-eastnet-ipv4-psk-ikev2" #2: sent IKE_SA_INIT request to 192.1.3.33:UDP/500
"westnet-eastnet-ipv4-psk-ikev2" #2: IKE_SA_INIT_I: 10 second timeout exceeded after 0 retransmits. No response (or no acceptable response) to our first IKEv2 message
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #2: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec whack --impair trigger_revival:1
"westnet-eastnet-ipv4-psk-ikev2" #3: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"westnet-eastnet-ipv4-psk-ikev2" #3: IKE_SA_INIT response redirects to new gateway 192.1.3.33
"westnet-eastnet-ipv4-psk-ikev2" #3: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #3: redirect: skip scheduling redirect event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #3: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #3: deleting IKE SA (sent IKE_SA_INIT request)
west #
# wait for NORTH to block on revival
north #
../../guestbin/wait-for-pluto.sh "IMPAIR: redirect"
-IMPAIR: "north-east" #2: redirect: skip scheduling redirect event
+IMPAIR: "north-east" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
north #
ipsec whack --impair trigger_revival:1
IMPAIR: "north-east": dispatch REVIVAL; redirect attempt 1 from 192.1.2.23 to 192.1.2.45; received Delete/Notify
# wait for ROAD to block on revival
road #
../../guestbin/wait-for-pluto.sh "IMPAIR: redirect"
-IMPAIR: "road-east" #2: redirect: skip scheduling redirect event
+IMPAIR: "road-east" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
road #
ipsec whack --impair trigger_revival:1
IMPAIR: "road-east": dispatch REVIVAL; redirect attempt 1 from 192.1.2.23 to 192.1.2.45; received Delete/Notify
# wait for NORTH to block on revival
north #
../../guestbin/wait-for-pluto.sh "IMPAIR: .*: redirect"
-IMPAIR: "north-east" #2: redirect: skip scheduling redirect event
+IMPAIR: "north-east" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
north #
ipsec whack --impair trigger_revival:1
IMPAIR: "north-east": dispatch REVIVAL; redirect attempt 1 from 192.1.2.23 to 192.1.2.45; received Delete/Notify
# wait for ROAD to block on revival
road #
../../guestbin/wait-for-pluto.sh "IMPAIR: .*: redirect"
-IMPAIR: "road-east" #2: redirect: skip scheduling redirect event
+IMPAIR: "road-east" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
road #
ipsec whack --impair trigger_revival:1
IMPAIR: "road-east": dispatch REVIVAL; redirect attempt 1 from 192.1.2.23 to 192.1.2.45; received Delete/Notify
"west-cuckoo" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"west-cuckoo" #1: IKE_AUTH response redirects to new gateway 192.1.3.33
"west-cuckoo" #2: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "west-cuckoo" #2: redirect: skip scheduling redirect event
+IMPAIR: "west-cuckoo" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckoo" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"west-cuckold" #5: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"west-cuckold" #5: IKE_AUTH response redirects to new gateway 192.1.3.33
"west-cuckold" #6: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "west-cuckold" #6: redirect: skip scheduling redirect event
+IMPAIR: "west-cuckold" #6: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckold" #5: deleting IKE SA (established IKE SA)
west #
# re-initiate the second connection; it will now match the first IKE
"west-cuckoo" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"west-cuckoo" #1: IKE_AUTH response redirects to new gateway 192.1.3.33
"west-cuckoo" #2: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "west-cuckoo" #2: redirect: skip scheduling redirect event
+IMPAIR: "west-cuckoo" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckoo" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1 # sanitize-retransmits
"west-cuckold" #5: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"west-cuckold" #6: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"west-cuckold" #6: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckold" #6: revival: skip scheduling revival event
+IMPAIR: "west-cuckold" #6: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec trafficstatus
#4: "west-cuckoo", type=ESP, add_time=1234567890, inBytes=0, outBytes=0, maxBytes=2^63B, id='@east'
"west-cuckoo" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"west-cuckoo" #1: IKE_SA_INIT response redirects to new gateway 192.1.3.33
"west-cuckoo" #1: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "west-cuckoo" #1: redirect: skip scheduling redirect event
+IMPAIR: "west-cuckoo" #1: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckoo" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec whack --impair trigger_revival:1
"west-cuckold" #4: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"west-cuckold" #4: IKE_SA_INIT response redirects to new gateway 192.1.3.33
"west-cuckold" #4: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "west-cuckold" #4: redirect: skip scheduling redirect event
+IMPAIR: "west-cuckold" #4: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckold" #4: deleting IKE SA (sent IKE_SA_INIT request)
west #
# re-initiate the second connection; it will now match the first IKE
"road/0x2" #3: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x2" #3: CREATE_CHILD_SA failed with error notification TS_UNACCEPTABLE
"road/0x2" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road/0x2" #3: revival: skip scheduling revival event
+IMPAIR: "road/0x2" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
road #
ipsec whack --impair none
road #
"road/0x4" #5: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x4" #5: CREATE_CHILD_SA failed with error notification TS_UNACCEPTABLE
"road/0x4" #5: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road/0x4" #5: revival: skip scheduling revival event
+IMPAIR: "road/0x4" #5: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
road #
ipsec whack --impair none
road #
"road/0x2" #3: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x2" #3: CREATE_CHILD_SA failed with error notification TS_UNACCEPTABLE
"road/0x2" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road/0x2" #3: revival: skip scheduling revival event
+IMPAIR: "road/0x2" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road/0x3" #4: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x3" #4: initiator established Child SA using #1; IPsec tunnel [192.0.3.0/24===192.0.20.0/24] {ESPinUDP/ESN=>0xESPESP <0xESPESP xfrm=AES_GCM_16_256-DH19 NATD=192.1.2.23:4500 DPD=passive}
"road/0x6" #7: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x4" #5: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x4" #5: CREATE_CHILD_SA failed with error notification TS_UNACCEPTABLE
"road/0x4" #5: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road/0x4" #5: revival: skip scheduling revival event
+IMPAIR: "road/0x4" #5: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road/0x5" #6: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x5" #6: initiator established Child SA using #1; IPsec tunnel [192.0.3.0/24===10.0.1.0/24] {ESPinUDP/ESN=>0xESPESP <0xESPESP xfrm=AES_GCM_16_256-DH19 NATD=192.1.2.23:4500 DPD=passive}
"road/0x7" #8: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x3" #4: initiating Child SA using IKE SA #1
"road/0x4" #5: initiating Child SA using IKE SA #1
"road/0x1" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road/0x1" #2: revival: skip scheduling revival event
+IMPAIR: "road/0x1" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"road/0x2" #3: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x2" #3: initiator established Child SA using #1; IPsec tunnel [192.0.3.0/24===192.0.2.0/24] {ESPinUDP/ESN=>0xESPESP <0xESPESP xfrm=AES_GCM_16_256-DH19 NATD=192.1.2.23:4500 DPD=passive}
"road/0x3" #4: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x4" #5: sent CREATE_CHILD_SA request to create Child SA using IKE SA #1 {ESPinUDP <0xESPESP}
"road/0x4" #5: CREATE_CHILD_SA failed with error notification TS_UNACCEPTABLE
"road/0x4" #5: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "road/0x4" #5: revival: skip scheduling revival event
+IMPAIR: "road/0x4" #5: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
road #
# sleep 3
road #
"west" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"west" #1: IKE_SA_INIT_I: 10 second timeout exceeded after 5 retransmits. No response (or no acceptable response) to our first IKEv2 message
"west" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #1: revival: skip scheduling revival event
+IMPAIR: "west" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
../../guestbin/ping-once.sh --down -I 192.0.1.254 192.0.2.254
"west" #2: retransmitting IKE_SA_INIT request; will wait 8 seconds for response
"west" #2: IKE_SA_INIT_I: 10 second timeout exceeded after 5 retransmits. No response (or no acceptable response) to our first IKEv2 message
"west" #2: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "west" #2: revival: skip scheduling revival event
+IMPAIR: "west" #2: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"west" #2: deleting IKE SA (sent IKE_SA_INIT request)
west #
../../guestbin/ping-once.sh --down -I 192.0.1.254 192.0.2.254
"west" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"west" #1: IKE_SA_INIT_I: 10 second timeout exceeded after 5 retransmits. No response (or no acceptable response) to our first IKEv2 message
"west" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #1: revival: skip scheduling revival event
+IMPAIR: "west" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
../../guestbin/ping-once.sh --down -I 192.0.1.254 192.0.2.254
"west" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"west" #1: IKE_SA_INIT_I: 10 second timeout exceeded after 5 retransmits. No response (or no acceptable response) to our first IKEv2 message
"west" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #1: revival: skip scheduling revival event
+IMPAIR: "west" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
../../guestbin/ping-once.sh --down -I 192.0.1.254 192.0.2.254
"west" #2: retransmitting IKE_SA_INIT request; will wait 8 seconds for response
"west" #2: IKE_SA_INIT_I: 10 second timeout exceeded after 5 retransmits. No response (or no acceptable response) to our first IKEv2 message
"west" #2: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "west" #2: revival: skip scheduling revival event
+IMPAIR: "west" #2: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"west" #2: deleting IKE SA (sent IKE_SA_INIT request)
west #
../../guestbin/ping-once.sh --down -I 192.0.1.254 192.0.2.254
"udp" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"udp" #1: IKE_SA_INIT_I: 10 second timeout exceeded after 5 retransmits. No response (or no acceptable response) to our first IKEv2 message
"udp" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "udp" #1: revival: skip scheduling revival event
+IMPAIR: "udp" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"udp" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
"udp" #3: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
"udp" #3: IKE_SA_INIT_I: 10 second timeout exceeded after 5 retransmits. No response (or no acceptable response) to our first IKEv2 message
"udp" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "udp" #3: revival: skip scheduling revival event
+IMPAIR: "udp" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"udp" #3: deleting IKE SA (sent IKE_SA_INIT request)
west #
"west" #1: sent IKE_SA_INIT request to 192.1.2.23:TCP/4500
"west" #1: IKE_SA_INIT response redirects to new gateway 192.1.3.33
"west" #1: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "west" #1: redirect: skip scheduling redirect event
+IMPAIR: "west" #1: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec whack --impair trigger_revival:1
"west" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"west" #1: IKE_AUTH response redirects to new gateway 192.1.3.33
"west" #2: scheduling redirect 1 to 192.1.3.33
-IMPAIR: "west" #2: redirect: skip scheduling redirect event
+IMPAIR: "west" #2: redirect: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (established IKE SA)
west #
ipsec whack --impair trigger_revival:1
"westnet-eastnet-ipv4-psk-ikev2" #3: ignoring IKE_SA_INIT response containing UNSUPPORTED_CRITICAL_PAYLOAD notification (Message ID 0; message payloads N, missing SA,KE,Ni)
IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #3: retransmit so timing out SA (may retry)
"westnet-eastnet-ipv4-psk-ikev2" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #3: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #3: deleting IKE SA (sent IKE_SA_INIT request)
west #
echo done
"san" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"san" #1: encountered fatal error in state IKE_AUTH_I
"san" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "san" #2: revival: skip scheduling revival event
+IMPAIR: "san" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"san" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo "done"
"san" #1: X509: authentication failed; peer certificate subjectAltName extension does not match USER_FQDN 'user-east@testing.libreswan.org'
"san" #1: deleting IKE SA (IKE_AUTH_I) and sending notification
"san" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "san" #2: revival: skip scheduling revival event
+IMPAIR: "san" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo "done"
done
"san" #1: X509: authentication failed; peer ID DER_ASN1_DN 'E=user-east@testing.libreswan.org,CN=east.testing.libreswan.org,OU=Test Department,O=Libreswan,L=Toronto,ST=Ontario,C=CA' does not match expected 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=NOTeast.testing.libreswan.org, E=user-NOTeast@testing.libreswan.org'
"san" #1: deleting IKE SA (IKE_AUTH_I) and sending notification
"san" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "san" #2: revival: skip scheduling revival event
+IMPAIR: "san" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo "done"
done
"ikev2-westnet-eastnet-x509-cr" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"ikev2-westnet-eastnet-x509-cr" #1: encountered fatal error in state IKE_AUTH_I
"ikev2-westnet-eastnet-x509-cr" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling revival event
+IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev2-westnet-eastnet-x509-cr" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo "done"
"westnet-eastnet-ikev2" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"westnet-eastnet-ikev2" #1: encountered fatal error in state IKE_AUTH_I
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ikev2" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"ikev2-westnet-eastnet-x509-cr" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"ikev2-westnet-eastnet-x509-cr" #1: encountered fatal error in state IKE_AUTH_I
"ikev2-westnet-eastnet-x509-cr" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling revival event
+IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev2-westnet-eastnet-x509-cr" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo "done"
"ikev2-westnet-eastnet-x509-cr" #1: X509: certificate payload rejected for this connection
"ikev2-westnet-eastnet-x509-cr" #1: encountered fatal error in state IKE_AUTH_I
"ikev2-westnet-eastnet-x509-cr" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling revival event
+IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev2-westnet-eastnet-x509-cr" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo "done"
"ikev2-westnet-eastnet-x509-cr" #1: authentication failed: no certificate matched RSASSA-PSS with SHA2_512 and 'C=CA, ST=Ontario, L=Toronto, O=Libreswan, OU=Test Department, CN=east.testing.libreswan.org, E=user-east@testing.libreswan.org'
"ikev2-westnet-eastnet-x509-cr" #1: deleting IKE SA (IKE_AUTH_I) and sending notification
"ikev2-westnet-eastnet-x509-cr" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling revival event
+IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
echo "done"
done
"ikev2-westnet-eastnet-x509-cr" #1: X509: certificate payload rejected for this connection
"ikev2-westnet-eastnet-x509-cr" #1: encountered fatal error in state IKE_AUTH_I
"ikev2-westnet-eastnet-x509-cr" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling revival event
+IMPAIR: "ikev2-westnet-eastnet-x509-cr" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev2-westnet-eastnet-x509-cr" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo "done"
"aes128" #3: ignoring unsecured informational payload BAD_PROPOSAL_SYNTAX, length=12
IMPAIR: "aes128" #3: retransmit so timing out SA (may retry)
"aes128" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "aes128" #3: revival: skip scheduling revival event
+IMPAIR: "aes128" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"aes128" #3: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
ipsec whack --impair none
"aes128" #5: sent Quick Mode request
IMPAIR: "aes128" #5: retransmit so timing out SA (may retry)
"aes128" #5: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "aes128" #5: revival: skip scheduling revival event
+IMPAIR: "aes128" #5: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"aes128" #5: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec whack --impair none
"aes128" #6: ignoring unsecured informational payload NO_PROPOSAL_CHOSEN, length=12
IMPAIR: "aes128" #6: retransmit so timing out SA (may retry)
"aes128" #6: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "aes128" #6: revival: skip scheduling revival event
+IMPAIR: "aes128" #6: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"aes128" #6: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
ipsec whack --impair none
"aes128" #8: sent Quick Mode request
IMPAIR: "aes128" #8: retransmit so timing out SA (may retry)
"aes128" #8: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "aes128" #8: revival: skip scheduling revival event
+IMPAIR: "aes128" #8: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"aes128" #8: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec whack --impair none
"aes128" #12: sent Quick Mode request
IMPAIR: "aes128" #12: retransmit so timing out SA (may retry)
"aes128" #12: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "aes128" #12: revival: skip scheduling revival event
+IMPAIR: "aes128" #12: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"aes128" #12: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec whack --impair none
"aes128" #16: sent Quick Mode request
IMPAIR: "aes128" #16: retransmit so timing out SA (may retry)
"aes128" #16: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "aes128" #16: revival: skip scheduling revival event
+IMPAIR: "aes128" #16: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"aes128" #16: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec whack --impair none
"3des" #19: ignoring unsecured informational payload NO_PROPOSAL_CHOSEN, length=12
IMPAIR: "3des" #19: retransmit so timing out SA (may retry)
"3des" #19: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "3des" #19: revival: skip scheduling revival event
+IMPAIR: "3des" #19: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"3des" #19: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
ipsec whack --impair none
"westnet-eastnet-ipv4-psk-ikev2" #2: IKE_AUTH response missing at least one of the Child SA payloads v2SA, v2TSi and v2TSr
"westnet-eastnet-ipv4-psk-ikev2" #1: encountered fatal error in state ESTABLISHED_IKE_SA
"westnet-eastnet-ipv4-psk-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ipv4-psk-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet-ipv4-psk-ikev2" #1: deleting IKE SA (established IKE SA)
west #
echo done
"westnet-eastnet" #4: sent Quick Mode request
"westnet-eastnet" #4: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"westnet-eastnet" #4: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet" #4: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #4: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet" #4: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "westnet-eastnet" #4: netlink response for Del SA esp.ESPSPIi@192.1.2.45: No such process (errno 3)
west #
"westnet-eastnet" #6: sent Quick Mode request
"westnet-eastnet" #6: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"westnet-eastnet" #6: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet" #6: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #6: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet" #6: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "westnet-eastnet" #6: netlink response for Del SA esp.ESPSPIi@192.1.2.45: No such process (errno 3)
west #
"westnet-eastnet" #8: sent Quick Mode request
"westnet-eastnet" #8: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"westnet-eastnet" #8: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet" #8: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #8: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"westnet-eastnet" #8: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "westnet-eastnet" #8: netlink response for Del SA esp.ESPSPIi@192.1.2.45: No such process (errno 3)
west #
| length: 278 (01 16)
"westnet-eastnet" #3: authenticated peer using preloaded certificate '@east' and 2nnn-bit RSA with SHA1 signature
IMPAIR: "westnet-eastnet" #4: omitting HASH payload for outI1
-IMPAIR: "westnet-eastnet" #4: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #4: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
-- start message (ID)
| next payload type: ISAKMP_NEXT_ID (0x5)
| ***parse ISAKMP Signature Payload:
| length: 278 (01 16)
"westnet-eastnet" #5: authenticated peer using preloaded certificate '@east' and 2nnn-bit RSA with SHA1 signature
IMPAIR: "westnet-eastnet" #6: sending HASH payload with no data for outI1
-IMPAIR: "westnet-eastnet" #6: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #6: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
-- start message (ID)
| next payload type: ISAKMP_NEXT_ID (0x5)
| ***parse ISAKMP Signature Payload:
| length: 278 (01 16)
"westnet-eastnet" #7: authenticated peer using preloaded certificate '@east' and 2nnn-bit RSA with SHA1 signature
IMPAIR: "westnet-eastnet" #8: setting HASH payload bytes to 00
-IMPAIR: "westnet-eastnet" #8: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet" #8: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
-- start message (ID)
| next payload type: ISAKMP_NEXT_ID (0x5)
| ***parse ISAKMP Signature Payload:
"west-east" #1: ignoring unsecured informational payload INVALID_COOKIE, length=12
IMPAIR: "west-east" #1: retransmit so timing out SA (may retry)
"west-east" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #1: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
grep IMPAIR: /tmp/pluto.log
IMPAIR: "west-east" #1: forcing IKE initiator SPI to 0x0
IMPAIR: "west-east" #1: retransmit so timing out SA (may retry)
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
grep '^packet from 192.1.2.45' /tmp/pluto.log
west #
"west-east" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
IMPAIR: "west-east" #1: retransmit so timing out SA (may retry)
"west-east" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
grep IMPAIR: /tmp/pluto.log
IMPAIR: "west-east" #1: forcing IKE initiator SPI to 0x0
IMPAIR: "west-east" #1: retransmit so timing out SA (may retry)
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
grep '^packet from 192.1.2.45' /tmp/pluto.log
west #
"west-east" #1: discarding initial packet; already STATE_MAIN_I1
IMPAIR: "west-east" #1: retransmit so timing out SA (may retry)
"west-east" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #1: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
grep IMPAIR: /tmp/pluto.log
IMPAIR: "west-east" #1: retransmit so timing out SA (may retry)
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
grep '^packet from 192.1.2.45' /tmp/pluto.log
west #
"west-east" #1: IKE_SA_INIT response has zero IKE SA Responder SPI; dropping packet
"west-east" #1: encountered fatal error in state IKE_SA_INIT_I
"west-east" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec down west-east
"west-east" #3: initiator established Child SA using #2; IPsec tunnel [192.0.1.0/24===192.0.2.0/24] {ESP/ESN=>0xESPESP <0xESPESP xfrm=AES_GCM_16_256 DPD=passive}
west #
grep IMPAIR: /tmp/pluto.log
-IMPAIR: "west-east" #1: revival: skip scheduling revival event
+IMPAIR: "west-east" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
IMPAIR: "west-east" #2: IKE_SA_INIT response has zero IKE SA Responder SPI; allowing anyway
west #
grep '^packet from 192.1.2.45' /tmp/pluto.log
"west" #2: sent Quick Mode request
"west" #2: STATE_QUICK_I1: 60 second timeout exceeded after 7 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"west" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #2: revival: skip scheduling revival event
+IMPAIR: "west" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "west" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.45: No such process (errno 3)
west #
"west" #2: sent Quick Mode request
IMPAIR: "west" #2: retransmit so timing out SA (may retry)
"west" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #2: revival: skip scheduling revival event
+IMPAIR: "west" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec whack --impair v1_emit_quick_id:1
"west" #3: sent Quick Mode request
IMPAIR: "west" #3: retransmit so timing out SA (may retry)
"west" #3: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "west" #3: revival: skip scheduling revival event
+IMPAIR: "west" #3: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"west" #3: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec whack --impair v1_emit_quick_id:3
"west" #4: sent Quick Mode request
IMPAIR: "west" #4: retransmit so timing out SA (may retry)
"west" #4: connection is supposed to remain up; revival attempt 3 scheduled in 10 seconds
-IMPAIR: "west" #4: revival: skip scheduling revival event
+IMPAIR: "west" #4: revival: skip scheduling CONNECTION_REVIVAL event in 10 seconds
"west" #4: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
echo done
IMPAIR: "west-east" #2: kernel: install_ipsec_sa_inbound_policy in install_inbound_ipsec_kernel_policies()
"west-east" #2: state transition failed: failed
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "west-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "west-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
# expect the on-demand kernel policy
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #2: sent Quick Mode request
"west-east" #2: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "west-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.45: No such process (errno 3)
west #
output: "west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
output: | string logger: newref @0x7f18d5449fc8(0->1) (schedule_connection_event() +44 programs/pluto/connection_event.c)
output: | "west-east": addref @0x7f18d5ea1a78(4->5) event CONNECTION_REVIVAL for "west-east": (schedule_connection_event() +49 programs/pluto/connection_event.c)
-IMPAIR: output: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: output: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
output: | spd_owner() looking for SPD owner of 192.0.1.0/24===192.0.2.0/24 with routing >= ROUTED_ONDEMAND[ONDEMAND]
output: | FOR_EACH_SPD_ROUTE[remote_client_range=192.0.2.0/24]... in (routed_negotiation_to_routed_ondemand() +911 programs/pluto/routing.c)
output: | found "west-east" 192.0.1.0/24===192.0.2.0/24
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
# expect the on-demand kernel policy
west #
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
IMPAIR: "west-east" #2: kernel: install_ipsec_sa_inbound_state in setup_half_kernel_state()
"west-east" #2: state transition failed: failed
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "west-east" #2: kernel: xfrm XFRM_MSG_DELPOLICY delete response for flow (in): No such file or directory (errno 2)
"west-east" #2: kernel: replace_ipsec_with_bare_kernel_policy() inbound delete failed
"west-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "west-east" #2: kernel: xfrm XFRM_MSG_DELPOLICY delete response for flow (in): No such file or directory (errno 2)
"west-east" #2: kernel: replace_ipsec_with_bare_kernel_policy() inbound delete failed
ERROR: "west-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #2: sent Quick Mode request
"west-east" #2: STATE_QUICK_I1: 60 second timeout exceeded after 0 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "west-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.45: No such process (errno 3)
west #
output: "west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
output: | string logger: newref @0x7ff4d060efc8(0->1) (schedule_connection_event() +44 programs/pluto/connection_event.c)
output: | "west-east": addref @0x7ff4d1066a78(4->5) event CONNECTION_REVIVAL for "west-east": (schedule_connection_event() +49 programs/pluto/connection_event.c)
-IMPAIR: output: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: output: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
output: | spd_owner() looking for SPD owner of 192.0.1.0/24===192.0.2.0/24 with routing >= ROUTED_ONDEMAND[ONDEMAND]
output: | FOR_EACH_SPD_ROUTE[remote_client_range=192.0.2.0/24]... in (routed_negotiation_to_routed_ondemand() +911 programs/pluto/routing.c)
output: | found "west-east" 192.0.1.0/24===192.0.2.0/24
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
# expect the on-demand kernel policy
west #
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
IMPAIR: "west-east" #2: kernel: install_ipsec_sa_outbound_policy in install_outbound_ipsec_kernel_policies()
"west-east" #2: state transition failed: failed
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
# expect the on-demand kernel policy
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
# expect the on-demand kernel policy
west #
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
# expect the on-demand kernel policy
west #
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
IMPAIR: "west-east" #2: kernel: install_ipsec_sa_outbound_state in setup_half_kernel_state()
"west-east" #2: state transition failed: failed
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-east" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
ERROR: "west-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "west-east" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
# expect the on-demand kernel policy
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"west-east" #1: IKE SA established but initiator rejected Child SA response
"west-east" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"west-east" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-east" #2: revival: skip scheduling revival event
+IMPAIR: "west-east" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
# expect the on-demand kernel policy
west #
down
west #
../../guestbin/wait-for-pluto.sh 'IMPAIR: .* #3: revival'
-IMPAIR: "west-east" #3: revival: skip scheduling revival event
+IMPAIR: "west-east" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec _kernel state
src 192.0.1.254 dst 192.0.2.254
"westnet-eastnet-ikev2" #1: response for Child SA #2 was rejected with NO_PROPOSAL_CHOSEN; initiating delete of Child SA (IKE SA will remain UP)
"westnet-eastnet-ikev2" #2: sent INFORMATIONAL request to delete larval Child SA using IKE SA #1
"westnet-eastnet-ikev2" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling revival event
+IMPAIR: "westnet-eastnet-ikev2" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
ERROR: "westnet-eastnet-ikev2" #2: netlink response for Get SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
ERROR: "westnet-eastnet-ikev2" #2: netlink response for Del SA esp.ESPSPIi@192.1.2.23: No such process (errno 3)
west #
"ikev1-failtest" #1: ignoring unsecured informational payload NO_PROPOSAL_CHOSEN, length=12
"ikev1-failtest" #1: STATE_MAIN_I1: 2 second timeout exceeded after 2 retransmits. No response (or no acceptable response) to our first IKEv1 message
"ikev1-failtest" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev1-failtest" #1: revival: skip scheduling revival event
+IMPAIR: "ikev1-failtest" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev1-failtest" #1: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
ipsec auto --delete ikev1-failtest
"ikev1-aggr-failtest" #2: authentication failed: using RSA with SHA1 for '@east-v1' tried preloaded: *000000000
"ikev1-aggr-failtest" #2: sending notification INVALID_KEY_INFORMATION to 192.1.2.23:500
"ikev1-aggr-failtest" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev1-aggr-failtest" #2: revival: skip scheduling revival event
+IMPAIR: "ikev1-aggr-failtest" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev1-aggr-failtest" #2: deleting ISAKMP SA (AGGR_I1) and NOT sending notification
west #
ipsec auto --delete ikev1-aggr-failtest
"ikev2-failtest" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"ikev2-failtest" #1: encountered fatal error in state IKE_AUTH_I
"ikev2-failtest" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev2-failtest" #2: revival: skip scheduling revival event
+IMPAIR: "ikev2-failtest" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev2-failtest" #1: deleting IKE SA (sent IKE_AUTH request)
west #
ipsec auto --delete ikev2-failtest
"ikev1-ipsec-fail" #2: STATE_QUICK_I1: retransmission; will wait 1 second for response
"ikev1-ipsec-fail" #2: STATE_QUICK_I1: 2 second timeout exceeded after 2 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"ikev1-ipsec-fail" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev1-ipsec-fail" #2: revival: skip scheduling revival event
+IMPAIR: "ikev1-ipsec-fail" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev1-ipsec-fail" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec auto --delete ikev1-ipsec-fail
"ikev1-aggr-ipsec-fail" #4: STATE_QUICK_I1: retransmission; will wait 1 second for response
"ikev1-aggr-ipsec-fail" #4: STATE_QUICK_I1: 2 second timeout exceeded after 2 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"ikev1-aggr-ipsec-fail" #4: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev1-aggr-ipsec-fail" #4: revival: skip scheduling revival event
+IMPAIR: "ikev1-aggr-ipsec-fail" #4: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"ikev1-aggr-ipsec-fail" #4: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec auto --delete ikev1-aggr-ipsec-fail
"ikev2-ipsec-fail" #1: initiator established IKE SA; authenticated peer using preloaded certificate '@east-v2' and 2nnn-bit RSASSA-PSS with SHA2_512 digital signature
"ikev2-ipsec-fail" #2: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"ikev2-ipsec-fail" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "ikev2-ipsec-fail" #2: revival: skip scheduling revival event
+IMPAIR: "ikev2-ipsec-fail" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec auto --delete ikev2-ipsec-fail
"ikev2-ipsec-fail": terminating SAs using this connection
"nss-cert-ocsp" #1: ignoring secured informational payload INVALID_ID_INFORMATION, msgid=MSGID, length=12
IMPAIR: "nss-cert-ocsp" #1: retransmit so timing out SA (may retry)
"nss-cert-ocsp" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-ocsp" #1: revival: skip scheduling revival event
+IMPAIR: "nss-cert-ocsp" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-ocsp" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
echo done
"nss-cert-ocsp" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"nss-cert-ocsp" #1: encountered fatal error in state IKE_AUTH_I
"nss-cert-ocsp" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-ocsp" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert-ocsp" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-ocsp" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"nss-cert-ocsp" #1: ignoring secured informational payload INVALID_ID_INFORMATION, msgid=MSGID, length=12
IMPAIR: "nss-cert-ocsp" #1: retransmit so timing out SA (may retry)
"nss-cert-ocsp" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-ocsp" #1: revival: skip scheduling revival event
+IMPAIR: "nss-cert-ocsp" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-ocsp" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
echo done
"nss-cert-ocsp" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"nss-cert-ocsp" #1: encountered fatal error in state IKE_AUTH_I
"nss-cert-ocsp" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-ocsp" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert-ocsp" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-ocsp" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"nss-cert-ocsp" #1: ignoring secured informational payload INVALID_ID_INFORMATION, msgid=MSGID, length=12
IMPAIR: "nss-cert-ocsp" #1: retransmit so timing out SA (may retry)
"nss-cert-ocsp" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-ocsp" #1: revival: skip scheduling revival event
+IMPAIR: "nss-cert-ocsp" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-ocsp" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
echo done
"west-cuckold" #1: deleting IKE SA (ESTABLISHED_IKE_SA) and sending notification
"west-cuckold" #2: ESP traffic information: in=84B out=84B
"west-cuckoo" #3: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckoo" #3: revival: skip scheduling revival event
+IMPAIR: "west-cuckoo" #3: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckoo" #3: ESP traffic information: in=84B out=84B
west #
ipsec delete west-cuckoo
"west" #1: sent Main Mode request
IMPAIR: "west" #1: retransmit so timing out SA (may retry)
"west" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #1: revival: skip scheduling revival event
+IMPAIR: "west" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting ISAKMP SA (MAIN_I1) and NOT sending notification
west #
ipsec delete west
"west" #1: sent IKE_SA_INIT request to 192.1.2.23:UDP/500
IMPAIR: "west" #1: retransmit so timing out SA (may retry)
"west" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #1: revival: skip scheduling revival event
+IMPAIR: "west" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (sent IKE_SA_INIT request)
west #
ipsec delete west
"west-cuckold" #2: sent Quick Mode request
"west-cuckold" #2: STATE_QUICK_I1: 5 second timeout exceeded after 4 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"west-cuckold" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckold" #2: revival: skip scheduling revival event
+IMPAIR: "west-cuckold" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckold" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec up west-cuckoo-1
"west-cuckold" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"west-cuckold" #2: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"west-cuckold" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckold" #2: revival: skip scheduling revival event
+IMPAIR: "west-cuckold" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec up west-cuckoo-1
"west-cuckoo-1" #3: initiating Child SA using IKE SA #1
"west-cuckold" #2: sent Quick Mode request
"west-cuckold" #2: STATE_QUICK_I1: 5 second timeout exceeded after 4 retransmits. No acceptable response to our first Quick Mode message: perhaps peer likes no proposal
"west-cuckold" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckold" #2: revival: skip scheduling revival event
+IMPAIR: "west-cuckold" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-cuckold" #2: deleting IPsec SA (QUICK_I1) and NOT sending notification
west #
ipsec up west-cuckoo-1
"west-cuckold" #1: initiator established IKE SA; authenticated peer using authby=secret and FQDN '@east'
"west-cuckold" #2: IKE_AUTH response rejected Child SA with TS_UNACCEPTABLE
"west-cuckold" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-cuckold" #2: revival: skip scheduling revival event
+IMPAIR: "west-cuckold" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
west #
ipsec up west-cuckoo-1
"west-cuckoo-1" #3: initiating Child SA using IKE SA #1
"west" #1: ignoring secured informational payload INVALID_ID_INFORMATION, msgid=MSGID, length=12
"west" #1: STATE_MAIN_I3: 60 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"west" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #1: revival: skip scheduling revival event
+IMPAIR: "west" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
echo done
"west" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"west" #1: encountered fatal error in state IKE_AUTH_I
"west" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #2: revival: skip scheduling revival event
+IMPAIR: "west" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"west" #1: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.23:500
"west" #1: STATE_MAIN_I3: 60 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"west" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #1: revival: skip scheduling revival event
+IMPAIR: "west" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
echo done
"west" #1: X509: certificate payload rejected for this connection
"west" #1: encountered fatal error in state IKE_AUTH_I
"west" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west" #2: revival: skip scheduling revival event
+IMPAIR: "west" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"nss-cert" #1: ignoring secured informational payload INVALID_ID_INFORMATION, msgid=MSGID, length=12
"nss-cert" #1: STATE_MAIN_I3: 60 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"nss-cert" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert" #1: revival: skip scheduling revival event
+IMPAIR: "nss-cert" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
echo done
"nss-cert" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"nss-cert" #1: encountered fatal error in state IKE_AUTH_I
"nss-cert" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"nss-cert" #1: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.23:500
"nss-cert" #1: STATE_MAIN_I3: 60 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"nss-cert" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert" #1: revival: skip scheduling revival event
+IMPAIR: "nss-cert" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
echo done
"nss-cert" #1: X509: certificate payload rejected for this connection
"nss-cert" #1: encountered fatal error in state IKE_AUTH_I
"nss-cert" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert" #1: deleting IKE SA (sent IKE_AUTH request)
west #
echo done
"nss-cert-crl" #1: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.23:500
"nss-cert-crl" #1: STATE_MAIN_I3: 15 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"nss-cert-crl" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-crl" #1: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-crl" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
# check there's a pending CRL; fetch it and confirm it has cleared
"nss-cert-crl" #2: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.23:500
"nss-cert-crl" #2: STATE_MAIN_I3: 15 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"nss-cert-crl" #2: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "nss-cert-crl" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #2: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"nss-cert-crl" #2: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
test -r /tmp/pluto.log && grep -e '^[^|].*ERROR' /tmp/pluto.log
"nss-cert-crl" #1: X509: certificate payload rejected for this connection
"nss-cert-crl" #1: encountered fatal error in state IKE_AUTH_I
"nss-cert-crl" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-crl" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-crl" #1: deleting IKE SA (sent IKE_AUTH request)
west #
# check there's a pending CRL; fetch it and confirm it has cleared
"nss-cert-crl" #3: X509: certificate payload rejected for this connection
"nss-cert-crl" #3: encountered fatal error in state IKE_AUTH_I
"nss-cert-crl" #4: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "nss-cert-crl" #4: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #4: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"nss-cert-crl" #3: deleting IKE SA (sent IKE_AUTH request)
west #
test -r /tmp/pluto.log && grep -e '^[^|].*ERROR' /tmp/pluto.log
"nss-cert-crl" #1: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.23:500
"nss-cert-crl" #1: STATE_MAIN_I3: 15 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"nss-cert-crl" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-crl" #1: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-crl" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
# check there's a pending CRL; fetch it and confirm it has cleared
"nss-cert-crl" #2: sending encrypted notification INVALID_ID_INFORMATION to 192.1.2.23:500
"nss-cert-crl" #2: STATE_MAIN_I3: 15 second timeout exceeded after 0 retransmits. Possible authentication failure: no acceptable response to our first encrypted message
"nss-cert-crl" #2: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "nss-cert-crl" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #2: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"nss-cert-crl" #2: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
west #
test -r /tmp/pluto.log && grep -e '^[^|].*ERROR' /tmp/pluto.log
"nss-cert-crl" #1: X509: certificate payload rejected for this connection
"nss-cert-crl" #1: encountered fatal error in state IKE_AUTH_I
"nss-cert-crl" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-crl" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-crl" #1: deleting IKE SA (sent IKE_AUTH request)
west #
# should be no pending CRL fetches; force an update
"nss-cert-crl" #1: X509: certificate payload rejected for this connection
"nss-cert-crl" #1: encountered fatal error in state IKE_AUTH_I
"nss-cert-crl" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "nss-cert-crl" #2: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"nss-cert-crl" #1: deleting IKE SA (sent IKE_AUTH request)
west #
# check there's a pending CRL; fetch it and confirm it has cleared
"nss-cert-crl" #3: X509: certificate payload rejected for this connection
"nss-cert-crl" #3: encountered fatal error in state IKE_AUTH_I
"nss-cert-crl" #4: connection is supposed to remain up; revival attempt 2 scheduled in 5 seconds
-IMPAIR: "nss-cert-crl" #4: revival: skip scheduling revival event
+IMPAIR: "nss-cert-crl" #4: revival: skip scheduling CONNECTION_REVIVAL event in 5 seconds
"nss-cert-crl" #3: deleting IKE SA (sent IKE_AUTH request)
west #
test -r /tmp/pluto.log && grep -e '^[^|].*ERROR' /tmp/pluto.log
"x509" #1: sent Main Mode I3
IMPAIR: "x509" #1: retransmit so timing out SA (may retry)
"x509" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "x509" #1: revival: skip scheduling revival event
+IMPAIR: "x509" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"x509" #1: deleting ISAKMP SA (MAIN_I3) and NOT sending notification
road #
echo done
"west-ku-certSigning" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"west-ku-certSigning" #1: encountered fatal error in state IKE_AUTH_I
"west-ku-certSigning" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-ku-certSigning" #2: revival: skip scheduling revival event
+IMPAIR: "west-ku-certSigning" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-ku-certSigning" #1: deleting IKE SA (sent IKE_AUTH request)
ipsec stop
Redirecting to: [initsystem]
"west-eku-codeSigning" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"west-eku-codeSigning" #1: encountered fatal error in state IKE_AUTH_I
"west-eku-codeSigning" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-eku-codeSigning" #2: revival: skip scheduling revival event
+IMPAIR: "west-eku-codeSigning" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-eku-codeSigning" #1: deleting IKE SA (sent IKE_AUTH request)
ipsec stop
Redirecting to: [initsystem]
"west-bc-missing-chain-end" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"west-bc-missing-chain-end" #1: encountered fatal error in state IKE_AUTH_I
"west-bc-missing-chain-end" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-bc-missing-chain-end" #2: revival: skip scheduling revival event
+IMPAIR: "west-bc-missing-chain-end" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-bc-missing-chain-end" #1: deleting IKE SA (sent IKE_AUTH request)
end #
begin #
"bc-n-ca-west" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"bc-n-ca-west" #1: encountered fatal error in state IKE_AUTH_I
"bc-n-ca-west" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "bc-n-ca-west" #2: revival: skip scheduling revival event
+IMPAIR: "bc-n-ca-west" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"bc-n-ca-west" #1: deleting IKE SA (sent IKE_AUTH request)
end #
begin #
"west-bc-ca-y" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"west-bc-ca-y" #1: encountered fatal error in state IKE_AUTH_I
"west-bc-ca-y" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-bc-ca-y" #2: revival: skip scheduling revival event
+IMPAIR: "west-bc-ca-y" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-bc-ca-y" #1: deleting IKE SA (sent IKE_AUTH request)
ipsec stop
Redirecting to: [initsystem]
"west-bc-ca-y-critical" #1: IKE SA authentication request rejected by peer: AUTHENTICATION_FAILED
"west-bc-ca-y-critical" #1: encountered fatal error in state IKE_AUTH_I
"west-bc-ca-y-critical" #2: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "west-bc-ca-y-critical" #2: revival: skip scheduling revival event
+IMPAIR: "west-bc-ca-y-critical" #2: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
"west-bc-ca-y-critical" #1: deleting IKE SA (sent IKE_AUTH request)
ipsec stop
Redirecting to: [initsystem]
"xauth-road-eastnet" #1: encountered fatal error in state STATE_XAUTH_I1
"xauth-road-eastnet" #1: deleting ISAKMP SA (XAUTH_I1) and sending notification
"xauth-road-eastnet" #1: connection is supposed to remain up; revival attempt 1 scheduled in 0 seconds
-IMPAIR: "xauth-road-eastnet" #1: revival: skip scheduling revival event
+IMPAIR: "xauth-road-eastnet" #1: revival: skip scheduling CONNECTION_REVIVAL event in 0 seconds
road #
# next one should succeed and ping pass throguh
road #