http://www.tokyovalley.com/yahoo_blog/article/article.php
Linux側ログ
# less /var/log/secure
Aug 15 18:38:48 fedora7logitech pluto[18442]: ike_alg_register_enc(): Activating OAKLEY_AES_CBC: Ok (ret=0)
Aug 15 18:38:48 fedora7logitech pluto[18442]: starting up 1 cryptographic helpers
Aug 15 18:38:48 fedora7logitech pluto[18442]: started helper pid=18444 (fd:6)
Aug 15 18:38:48 fedora7logitech pluto[18442]: Using NETKEY IPsec interface code on 2.6.23.17-88.fc7
Aug 15 18:38:50 fedora7logitech pluto[18442]: Changing to directory '/etc/ipsec.d/cacerts'
Aug 15 18:38:50 fedora7logitech pluto[18442]: Changing to directory '/etc/ipsec.d/aacerts'
Aug 15 18:38:50 fedora7logitech pluto[18442]: Changing to directory '/etc/ipsec.d/ocspcerts'
Aug 15 18:38:50 fedora7logitech pluto[18442]: Changing to directory '/etc/ipsec.d/crls'
Aug 15 18:38:50 fedora7logitech pluto[18442]: Warning: empty directory
Aug 15 18:38:50 fedora7logitech pluto[18442]: added connection description "net-to-net"
Aug 15 18:38:50 fedora7logitech pluto[18442]: listening for IKE messages
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth2/eth2 192.168.2.25:500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth2/eth2 192.168.2.25:4500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth0/eth0 192.168.1.25:500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth0/eth0 192.168.1.25:4500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth0/eth0 192.168.1.38:500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth0/eth0 192.168.1.38:4500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth1/eth1 192.168.0.25:500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface eth1/eth1 192.168.0.25:4500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface lo/lo 127.0.0.1:500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface lo/lo 127.0.0.1:4500
Aug 15 18:38:50 fedora7logitech pluto[18442]: adding interface lo/lo ::1:500
Aug 15 18:38:50 fedora7logitech pluto[18442]: loading secrets from "/etc/ipsec.secrets"
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: initiating Main Mode
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: received Vendor ID payload [draft-ietf-ipsec
-nat-t-ike-03] method set to=108
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: enabling possible NAT-traversal with method
draft-ietf-ipsec-nat-t-ike-02/03
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: transition from state STATE_MAIN_I1 to state
STATE_MAIN_I2
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: STATE_MAIN_I2: sent MI2, expecting MR2
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: received Vendor ID payload [Cisco-Unity]
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: received Vendor ID payload [Dead Peer Detect
ion]
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: ignoring unknown Vendor ID payload [408d0318
3d173dd4e3f79e9ecda70e19]
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: received Vendor ID payload [XAUTH]
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: I did not send a certificate because I do no
t have one.
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: NAT-Traversal: Result using draft-ietf-ipsec
-nat-t-ike-02/03: no NAT detected
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: transition from state STATE_MAIN_I2 to state
STATE_MAIN_I3
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: STATE_MAIN_I3: sent MI3, expecting MR3
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: Main mode peer ID is ID_IPV4_ADDR: '192.168.
0.253'
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: transition from state STATE_MAIN_I3 to state
STATE_MAIN_I4
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #1: STATE_MAIN_I4: ISAKMP SA established {auth=O
AKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192 prf=oakley_sha group=modp1024}
Aug 15 18:38:51 fedora7logitech pluto[18442]: "net-to-net" #2: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS
+UP {using isakmp#1}
Aug 15 18:38:52 fedora7logitech pluto[18442]: "net-to-net" #2: ignoring informational payload, type IPSEC_R
ESPONDER_LIFETIME
Aug 15 18:38:52 fedora7logitech pluto[18442]: "net-to-net" #2: transition from state STATE_QUICK_I1 to stat
e STATE_QUICK_I2
Aug 15 18:38:52 fedora7logitech pluto[18442]: "net-to-net" #2: STATE_QUICK_I2: sent QI2, IPsec SA establish
ed {ESP=>0x337983d4 <0xcadc9537 xfrm=3DES_0-HMAC_SHA1 NATD=none DPD=none}