📄 helsinki-result.jp
字号:
>spdadd 130.233.9.166 130.233.10.167 any -P out ipsec esp/transport//use;>spdadd 130.233.10.167 130.233.9.166 any -P in ipsec esp/transport//use;>35:45.215745 130.233.10.167:500 -> 130.233.9.166:500: isakmp 1.0 msgid dba05304: phase 2/others ? oakley-quick:> (hash: len=20)> (sa: doi=ipsec situation=identity> (p: #1 protoid=ipsec-esp transform=1 spi=dba05304> (t: #1 id=aes (type=lifetype value=sec)(type=life value=7080)(type=lifetype value=kb)(type=life value=2000)(type=>group desc value=modp768)(type=enc mode value=transport)(type=auth value=hmac-sha1)(type=keylen value=0080))))> (nonce: n len=64)> (ke: key len=96)> (id: idtype=IPv4 protoid=icmp port=0 len=4 130.233.10.167)> (id: idtype=IPv4 protoid=icmp port=0 len=4 130.233.9.166)>2001-08-15 17:35:45: DEBUG: isakmp_quick.c:1951:get_proposal_r(): get a src address from ID payload 130.233.10.167[0] prefixlen=32 ul_proto=1>2001-08-15 17:35:45: DEBUG: isakmp_quick.c:1956:get_proposal_r(): get dst address from ID payload 130.233.9.166[0] prefixlen=32 ul_proto=1>2001-08-15 17:35:45: DEBUG: policy.c:245:cmpspidxwild(): sub:0xbfbfd350: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=icmp dir=in>2001-08-15 17:35:45: DEBUG: policy.c:246:cmpspidxwild(): db: 0x80ca408: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=any dir=in>2001-08-15 17:35:45: DEBUG: policy.c:245:cmpspidxwild(): sub:0xbfbfd350: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=icmp dir=in>2001-08-15 17:35:45: DEBUG: policy.c:246:cmpspidxwild(): db: 0x80ca808: 130.233.9.166/32[0] 130.233.10.167/32[0] proto=any dir=out>2001-08-15 17:35:45: ERROR: isakmp_quick.c:1979:get_proposal_r(): no policy found: 130.233.10.167/32[0] 130.233.9.166/32[0] proto=icmp dir=inZyXEL Tue Aug 14 12:00 ESST 2001 phase1 main mode, pre-shared key, des, sha1, dh1 phase2 esp, des, sha1, tunnel $BLdBj$J$7!#(Bproposal$B$O(B1$B$D$@$1<u$1$D$1$k!#(Brekey$B$O$G$-$J$$!#(BIII Tue Aug 14 14:00 ESST 2001 phase1 main mode, pre-shared key, 3des, md5, dh2 phase2 esp, des, md5, tunnel $BLdBj$J$7!#(Bproposal$B$O(B1$BHVL\$r;H$&!#(Brekey$B$O$G$-$J$$!#(B $BBfOQ$N>e;J$K(BKAME$B$H%F%9%H$7$F$3$$$H8@$o$l$?$i$7$$!#(BWindowsXP Tue Aug 14 20:00 phase1 main mode, pre-shared key, 3des, sha1, modp3072 phase2 esp, 3des, sha1, transport modp3072$B$d$m$&$h$H%J%s%Q$5$l$k!#(B dh$B$N7W;;(B: fbsd43 P100MHz$B$GLs(B7(s) XP P2 200MHz$B$GLs(B9(s) $BL@F|M<J}(B RSA signature mode$B$G:F@o!#(B $B5"$C$A$c$C$?$N$G$G$-$J$$!#(BAshley Tue Aug 14 18:00 invalid-signature$B$HJ86g$r8@$o$l$k!#(B $B8_$$$K(B ssh-ca1$B$+$i=pL>$7$F$b$i$C$?$H8@$C$F$k$,!"(B $B<B$O(Btest-ca1.ssh.com$B$H(Bbakeoff-ca1.ssh.com$B$N(B2$B$D$"$k;v$,H=L@!D(B test-ca1.ssh.com$B$KE}0l$7$F:F@oM=Ls(B Fri Aug 17 10:30 Ashley$B<BAu$K(Bpkcs#1 padding$B$NLdBj$"$j!#%M%4$G$-$:!#(BNetoctave Wed Aug 15 11:00 $B$3$C$A$,(B initiate$B$9$k$H(B no-proposal-chosen$B$,5"$C$F$/$k!#(B $BE($+$i(Bping$B$7$F$b$i$&$H(BIKE$B$N%Q%1%C%H$,=P$J$$!#(B $B>u673NG'$7$F$b$i$C$F8e$+$i:F@o$9$kM=Dj!#(Bisakmpd (jakob@openbsd) Tue Aug 14 IPv4, ESP, transport mode phase 1 3DES + SHA1, group 2, lifetime = 10min phase 2 AES + SHA1, group 2, lifetime = 2min $BLdBj$J$7!#(B Wed Aug 15 21:25:49 JST 2001 IPv6, ESP, tunnel mode phase 1 3DES + SHA1, group 2, lifetime = 10min phase 2 AES + SHA1, group 2, lifetime = 2min $B8~$3$&$O(Bmain mode$B$G(BFQDN$B$r(BID$B$K;H$$$?$,$C$?$,!"$3$&$$$&%(%i!<$GE\$i$l$k!#(B sakane$B$O$3$l$O(Bwg$B$G$N9g0U$H;W$C$F$$$k$,!"MW3NG'!#(B2001-08-15 21:14:41: ERROR: ipsec_doi.c:3063:ipsecdoi_checkid1(): Expecting IP address type in main mode, but FQDN. Fri Aug 17 10:00 rsa signature. $BLdBj$J$7!#(B isakmpd$B$O(B subjectAltName$B$r(B1$B$D$7$+<u$1$D$1$J$$!#(BFitec Wed Aug 15 13:00 RSA signature invalid-authentication $B$GD7$M$i$l$k!#$$$h$$$h$3$C$A$NLdBj$+(B... KeyUsage $B$r(BIKE$B$K$7$H$+$J$$$HE\$i$l$k!#(B $BB>$N<BAu$H$&$^$/$$$+$J$$$N$O!"$3$l$,860x$+!)(B $B$=$&$G$b$J$5$=$&!"(Bopenssl$B$NLdBj$+$b!#(B openssl 0.9.6 $B$K$7$?$i@.8y!#0c$$$,J,$+$i$:!#(BSSH IPv6$B$@$1$d$C$?(B ssh solaris version: ssh$BB&(B: IKE$B$N%Q%1%C%H$,=P$J$$!#(B nd cache$B$NLdBj$+!)(B tcp$B$@$1$N%]%j%7$G$b(BIKE$B$N%Q%1%C%H$,=P$;$J$$!#(B solaris$B$O(Bstatic cache entry$BF~$l$k%3%^%s%I$,$J$$$i$7$$!#(B $B0lC6(Bping6$B$7$F(Bcache$B$r:n$C$?5$$K$J$C$F$b(BNS$B$r=P$=$&$H$9$k!#(B $B860xD4::$9$k$+$i:F@o$7$F$M$H8@$o$l$k!#(B $B:F@o(B. $BLdBj$J$7(B $BBt;3$N(Bphase2 proposal(43440B$B$N(BUDP$B%Q%1%C%H(B)$B$r<u$1$k$H(B racoon $B$^$G%Q%1%C%H$,>e$,$C$FMh$J$$!#(B 500 proposal$B$rEj$2$F$/$k!#(Bproposal#$B$O(B1byte$B$J$N$GCF$/$Y$-!#(B racoon$B$O:G=i$KA4It%Q!<%9$7$F$k$_$?$$!#(B RSA signature mode ssh$BB&$K(Bpublic key$B7W;;$KLdBj$"$C$?!#D>$7$F(BOK ssh$B$O(Bssh-test-ca1$B$,%5%$%s$7$?>ZL@=q$r;H$$!"(B racoon$B$O(Bfujixerox$B$,%5%$%s$7$?>ZL@=q$G$b(BOK AES phase1 $B$,$&$^$/$$$+$J$$!#4V0c$$$J$/(Bracoon$B$NLdBj!#(B($BD>$7$FF0:n3NG':Q(B) phase1 proposal$B$N%Q!<%9$KCn$,$$$k$+$b!#MW3NG'(Bfreeswan IPv4, IPComp + ESP, transport mode phase 1 3DES + SHA1, group 5, lifetime = 10min phase 2 3DES + SHA1 + deflate, group 5, lifetime = 2min IPComp$B$K$OLdBj$J$7!#(B $B@hJ}$,(Binitiate$B$7$F$-$?$H$-$KLdBj$"$j!#(Bphase 2$B$G!"(Bipcomp enc mode$B$,(B $BL5;XDj$N>l9g!"(Bipcomp$B$N>l9g$@$1$O(Btransport$B$H;W$o$J$1$l$P$J$i$J$$!#(B $B$,!"(Bracoon$B$O8=>u$3$l$r(BRFC2407$BE*$K(B(Any$B$H$7$F(B)$B<h$j07$&!#$N$G!"(Bno proposal chosen$B$K$J$k!#(B RFC2407$B$+$i$9$k$H!"(Benc mode unspecified == transport$B$G$b$h$$$h$&$J(B $B5$$,$9$k$,(B... ("host-dependent"$B$C$F=q$$$F$"$k$+$i(B)RFC2407> Encapsulation Mode> RESERVED 0> Tunnel 1> Transport 2>> Values 3-61439 are reserved to IANA. Values 61440-65535 are> for private use.>> If unspecified, the default value shall be assumed to be> unspecified (host-dependent).draft-shacham-ippcp-rfc2393bis-08.txt> Encapsulation Mode>> To propose a non-default Encapsulation Mode (such as Tunnel> Mode), an IPComp proposal MUST include an Encapsulation Mode> attribute. If the Encapsulation Mode is unspecified, the> default value of Transport Mode is assumed.>42:28.211568 130.233.9.175:500 -> 130.233.9.166:500: isakmp 1.0 msgid 6935cbd8: phase 2/others ? oakley-quick:> (hash: len=20)> (sa: doi=ipsec situation=identity> (p: #0 protoid=ipsec-esp transform=2 spi=3a47a3e7> (t: #0 id=3des (type=group desc value=0005)(type=enc mode value=transport)(type=lifetype value=sec)(type=life value=7080)(type=auth value=hmac-md5))> (t: #1 id=3des (type=group desc value=0005)(type=enc mode value=transport)(type=lifetype value=sec)(type=life value=7080)(type=auth value=hmac-sha1)))> (p: #0 protoid=ipcomp transform=1 spi=ac23> (t: #0 id=deflate (type=lifetype value=sec)(type=life value=7080))))> (nonce: n len=16)> (ke: key len=192)>2001-08-15 16:42:28: DEBUG: ipsec_doi.c:1024:get_ph2approvalx(): peer's single bundle:>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto(): (proto_id=ESP spisize=4 spi=3a47a3e7 spi_p=00000000 encmode=Transport reqid=0:0)>2001-08-15 16:42:28: DEBUG: proposal.c:848:printsatrns(): (trns_id=3DES encklen=0 authtype=1)>2001-08-15 16:42:28: DEBUG: proposal.c:848:printsatrns(): (trns_id=3DES encklen=0 authtype=2)>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto(): (proto_id=IPCOMP spisize=2 spi=0000ac23 spi_p=00000000 encmode=Any reqid=0:0)>2001-08-15 16:42:28: DEBUG: proposal.c:855:printsatrns(): (trns_id=DEFLATE)>2001-08-15 16:42:28: DEBUG: ipsec_doi.c:1027:get_ph2approvalx(): my single bundle:>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto(): (proto_id=ESP spisize=4 spi=00000000 spi_p=00000000 encmode=Transport reqid=0:0)>2001-08-15 16:42:28: DEBUG: proposal.c:848:printsatrns(): (trns_id=3DES encklen=0 authtype=2)>2001-08-15 16:42:28: DEBUG: proposal.c:814:printsaproto(): (proto_id=IPCOMP spisize=4 spi=00000000 spi_p=00000000 encmode=Transport reqid=0:0)>2001-08-15 16:42:28: DEBUG: proposal.c:855:printsatrns(): (trns_id=DEFLATE)>2001-08-15 16:42:28: ERROR: proposal.c:497:cmpsatrns(): authtype mismatched: my:1 peer:2>2001-08-15 16:42:28: ERROR: proposal.c:365:cmpsaprop_alloc(): IPComp SPI size promoted from 16bit to 32bit>2001-08-15 16:42:28: ERROR: proposal.c:378:cmpsaprop_alloc(): encmode mismatched: my:2 peer:0 <----- Thu Aug 16 16:49:08 JST 2001 IPv4, IPComp + ESP, transport mode phase 1 3DES + SHA1, group 5, lifetime = 10min phase 2 3DES + SHA1 + deflate, group 5, lifetime = 2min $B:FD)@o!#=$@5$G$-$?$3$H$r3NG'!#(Bnetopia Wed Aug 15 19:00 JST$B:"(B IPv6, ESP, transport mode phase 1 3DES + SHA1, group 2, lifetime = 24h phase 2 3DES + SHA1, group 2, lifetime = 1h KAME$B%Y!<%9<BAu!#(BCPU$B$,$7$g$\$$$i$7$/(BD-H$B$K(B5$BIC$/$i$$$+$+$C$F$I$-$I$-$9$k!#(B bug report$B$J$I$"$C$?$iAw$C$F$b$i$&$h$&$*4j$$$9$k!#(BEricsson Wed Aug 15 20:30 JST$B:"(B IPv6, ESP, transport mode phase 1 3DES + SHA1, group 2, lifetime = 24h phase 2 AES + SHA1, group 2, lifetime = 1h $B@.8y(B IPv6, ESP, transport mode phase 1 3DES + SHA1, group 2, lifetime = 24h phase 2 blowfish + SHA1, group 2, lifetime = 1h $B<:GT!#(Bblowfish$B!"$3$C$A$,$o$N80$N@8@.$,$*$+$7$$(B(= $BD9$$80$N>l9g(B)$B!#(B IPv6, ESP, transport mode phase 1 3DES + SHA1, group 2, lifetime = 24h phase 2 3DES + SHA1, group 2, lifetime = 1h $B<:GT!#(Bericsson$BB&!"(BND$B$,$*$+$7$$!#(BNokia EPOC Wed Aug 15 20:51:25 JST 2001 IPv6, ESP, tunnel mode phase 1 3DES + SHA1, group 2, lifetime = 3600min phase 2 3DES + SHA1 + deflate, group 2, lifetime = 2min IPsec key$B$bF~$k$,!"@hJ}$N%]%j%7LdBj$G(Bping$B$OJV$i$J$$!#(BTrustworks TrustedClient v3.2 Thu Aug 16 20:17:51 JST 2001 IPv6, AH + ESP, transport mode phase 1 3DES + SHA1, group 5, lifetime = 3min phase 2 3DES + SHA1, group 5, lifetime = 2min $B@hJ}$,(Bresponder$B$N$H$-!"808r49$,=*N;$7$?=V4V@hJ}$N(BIKE daemon$B$,(Bpanic$B!#(B $B$^$"808r49<+BN$O$G$-$F$$$k$h$&$@!#(BNortel GatewayController/CallServer 2000 (not released yet) Fri Aug 17 00:16:23 JST 2001 IPv4, ESP, transport mode phase 1 3DES + SHA1, group 5, lifetime = 3min phase 2 AES + SHA1, group 5, lifetime = 2min Nortel$BB&(Binitiator: round=10$B$H$$$&(Battribute$B$r$D$1$F$/$k$N$G(Bno proposal chosen KAME$BB&(Binitiator: id payload$BH4$-(B(ip address$B;H$((B)$B$@$H(BNortel$BB&$O(B $B$X$/$k$N$GBLL\(B IPv4, ESP, transport mode phase 1 3DES + SHA1, group 5, lifetime = 3min phase 2 3DES + SHA1, group 5, lifetime = 2min Nortel$BB&(Binitiator: ok KAME$BB&(Binitiator: id payload$BH4$-$@$H(BNortel$BB&$O$X$/$k$N$GBLL\(B
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -