/testing/guestbin/swan-prep --x509
Preparing X.509 files
east #
 ipsec start
Redirecting to: systemctl start ipsec.service
east #
 /testing/pluto/bin/wait-until-pluto-started
east #
 ipsec auto --add westnet-eastnet-ikev2
002 added connection description "westnet-eastnet-ikev2"
east #
 ipsec whack --impair replay-forward
east #
 echo "initdone"
initdone
east #
 grep "retransmits:" /tmp/pluto.log | sed -e 's/current time .*/current time .../'
| #1 STATE_PARENT_R1: retransmits: duplicate IKE_INIT_I message received, retransmiting previous packet
| #1 STATE_PARENT_R1: retransmits: duplicate IKE_INIT_I message received, retransmiting previous packet
| #1 STATE_PARENT_R1: retransmits: duplicate IKE_INIT_I message received, retransmiting previous packet
| #1 STATE_PARENT_R1: retransmits: duplicate IKE_INIT_I message received, retransmiting previous packet
| #1 STATE_PARENT_R1: retransmits: duplicate IKE_INIT_I message received, retransmiting previous packet
| #1 STATE_PARENT_R2: retransmits: retransmitting response for message ID 1 exchange ISAKMP_v2_AUTH fragment 1
| #1 STATE_PARENT_R2: retransmits: ignoring retransmit of message ID 1 exchange ISAKMP_v2_AUTH fragment 2
| #1 STATE_PARENT_R2: retransmits: ignoring retransmit of message ID 1 exchange ISAKMP_v2_AUTH fragment 3
| #1 STATE_PARENT_R2: retransmits: ignoring retransmit of message ID 1 exchange ISAKMP_v2_AUTH fragment 4
| #1 STATE_PARENT_R2: retransmits: ignoring retransmit of message ID 1 exchange ISAKMP_v2_AUTH fragment 5
| #1 STATE_PARENT_R2: retransmits: retransmit response for message ID: 2 exchange ISAKMP_v2_INFORMATIONAL
east #
 ../../pluto/bin/ipsec-look.sh
east NOW
XFRM state:
XFRM policy:
src 192.0.2.0/24 dst 192.0.1.0/24
	dir out priority 1042407 ptype main
	tmpl src 0.0.0.0 dst 0.0.0.0
		proto esp reqid REQID mode transport
XFRM done
IPSEC mangle TABLES
NEW_IPSEC_CONN mangle TABLES
ROUTING TABLES
default via 192.1.2.254 dev eth1 
192.0.1.0/24 via 192.1.2.45 dev eth1 
192.0.2.0/24 dev eth0 proto kernel scope link src 192.0.2.254 
192.1.2.0/24 dev eth1 proto kernel scope link src 192.1.2.23 
192.9.2.0/24 dev eth2 proto kernel scope link src 192.9.2.23 
NSS_CERTIFICATES
Certificate Nickname                                         Trust Attributes
                                                             SSL,S/MIME,JAR/XPI
Libreswan test CA for mainca - Libreswan                     CT,, 
east                                                         u,u,u
hashsha2                                                     P,,  
nic                                                          P,,  
north                                                        P,,  
road                                                         P,,  
west                                                         P,,  
west-ec                                                      P,,  
east #
east #
 ../bin/check-for-core.sh
east #
 if [ -f /sbin/ausearch ]; then ausearch -r -m avc -ts recent ; fi

