Re-4: VPN not working ...

Erich Titl <[email protected]>
Newsgroups gmane.network.freeswan.user
Message-ID <[email protected]>
Kai

At 09:01 09.08.2004, [email protected] wrote:
>Hi,
>
>here is my output from ipsec barf.
>
>Greetings,
>   Kai
>
>
>--------- BARF OUTPUT ---------
>
>mngateway
>Mon Aug  9 08:56:31 CEST 2004
>+ _________________________ version
>+ ipsec --version
>Linux FreeS/WAN U2.04/K(no kernel code presently loaded)
>See `ipsec --copyright' for copyright information.
>X.509-1.5.3 distributed by Andreas Steffen <[email protected]>
>+ _________________________ proc/version
>+ cat /proc/version
>Linux version 2.6.5-7.95-default (geeko@buildhost) (gcc version 3.3.3 
>(SuSE Linux)) #1 Thu Jul 1 15:23:45 UTC 2004
>+ _________________________ ipsec_verify
>+ ipsec verify --nocolour
>Checking your system to see if IPsec got installed and started correctly:
>Version check and ipsec on-path                                         [OK]
>Linux FreeS/WAN U2.04/K(no kernel code presently loaded)
>Checking for KLIPS support in 
>kernel                                    [FAILED]
>Checking for RSA private key 
>(/etc/ipsec.secrets)                       [FAILED]

Mhhhh.... not good, you should fix this.

>ipsec showhostkey: no default key in "/etc/ipsec.secrets"
>Checking that pluto is running                                          [OK]
>Two or more interfaces found, checking IP forwarding                    [OK]
>Checking NAT and MASQUERADEing
>
>Opportunistic Encryption DNS checks:

Weird, they seem to be disabled in your conf though.

>Looking for TXT in forward map: 
>mngateway                               [MISSING]
>Does the machine have at least one non-private address?                 [OK]
>Looking for TXT in reverse map: 
>12.2.6.192.in-addr.arpa.                [MISSING]
>Looking for TXT in reverse map: 
>226.191.130.80.in-addr.arpa.            [MISSING]
>+ _________________________ proc/net/ipsec_eroute
>+ sort -sg +3 /proc/net/ipsec_eroute
>sort: open failed: /proc/net/ipsec_eroute: No such file or directory
>+ cat /proc/net/ipsec_eroute
>cat: /proc/net/ipsec_eroute: No such file or directory
>+ _________________________ netstat-rn
>+ netstat -nr
>Kernel IP routing table
>Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
>217.5.98.30     0.0.0.0         255.255.255.255 UH        0 0          0 ppp0
>192.6.2.0       0.0.0.0         255.255.255.0   U         0 0          0 eth0
>169.254.0.0     0.0.0.0         255.255.0.0     U         0 0          0 eth0
>127.0.0.0       0.0.0.0         255.0.0.0       U         0 0          0 lo
>0.0.0.0         217.5.98.30     0.0.0.0         UG        0 0          0 ppp0
>+ _________________________ proc/net/ipsec_spi
>+ cat /proc/net/ipsec_spi
>cat: /proc/net/ipsec_spi: No such file or directory
>+ _________________________ proc/net/ipsec_spigrp
>+ cat /proc/net/ipsec_spigrp
>cat: /proc/net/ipsec_spigrp: No such file or directory
>+ _________________________ proc/net/ipsec_tncfg
>+ cat /proc/net/ipsec_tncfg
>cat: /proc/net/ipsec_tncfg: No such file or directory
>+ _________________________ proc/net/pf_key
>+ cat /proc/net/pf_key
>cat: /proc/net/pf_key: No such file or directory
>+ _________________________ proc/net/pf_key-star
>+ cd /proc/net
>+ egrep '^' 'pf_key_*'
>grep: pf_key_*: No such file or directory
>+ _________________________ proc/sys/net/ipsec-star
>+ cd /proc/sys/net/ipsec
>/usr/lib/ipsec/barf: line 168: cd: /proc/sys/net/ipsec: No such file or 
>directory
>+ _________________________ ipsec/status
>+ ipsec auto --status
>000 interface lo/lo ::1
>000 interface lo/lo 127.0.0.1
>000 interface eth0/eth0 192.6.2.12
>000 interface ppp0/ppp0 80.130.191.226
>000 %myid = (none)
>000 debug none
>000
>000 "L2TP-CERT": 80.130.191.226[C=DE, O=Multinova GmbH, CN=Multinova 
>CA]:17/1701---217.5.98.30...%any[C=DE, O=Multinova GmbH, OU=VPN, 
>CN=VPNCA]:17/1701; unrouted; eroute owner: #0
>000 "L2TP-CERT":   CAs: 'C=DE, O=Multinova GmbH, CN=Multinova CA'...'%any'
>000 "L2TP-CERT":   ike_life: 3600s; ipsec_life: 28800s; rekey_margin: 
>540s; rekey_fuzz: 100%; keyingtries: 3
>000 "L2TP-CERT":   policy: RSASIG+ENCRYPT+TUNNEL+DONTREKEY; prio: 32,32; 
>interface: ppp0;
>000 "L2TP-CERT":   newest ISAKMP SA: #0; newest IPsec SA: #0;
>000
>000
>+ _________________________ ifconfig-a
>+ ifconfig -a
>eth0      Link encap:Ethernet  HWaddr 00:0D:88:7E:BB:5C
>           inet addr:192.6.2.12  Bcast:192.6.2.255  Mask:255.255.255.0
>           inet6 addr: fe80::20d:88ff:fe7e:bb5c/64 Scope:Link
>           UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
>           RX packets:36118 errors:0 dropped:0 overruns:0 frame:0
>           TX packets:37397 errors:0 dropped:0 overruns:0 carrier:0
>           collisions:0 txqueuelen:1000
>           RX bytes:5085416 (4.8 Mb)  TX bytes:18517723 (17.6 Mb)
>           Interrupt:9 Base address:0xd800
>
>eth1      Link encap:Ethernet  HWaddr 00:50:BA:2C:4C:B9
>           inet6 addr: fe80::250:baff:fe2c:4cb9/64 Scope:Link
>           UP BROADCAST NOTRAILERS RUNNING MULTICAST  MTU:1500  Metric:1
>           RX packets:38142 errors:0 dropped:0 overruns:0 frame:1
>           TX packets:36462 errors:0 dropped:0 overruns:0 carrier:0
>           collisions:99 txqueuelen:1000
>           RX bytes:18877041 (18.0 Mb)  TX bytes:5380745 (5.1 Mb)
>           Interrupt:10 Base address:0xd400
>
>lo        Link encap:Local Loopback
>           inet addr:127.0.0.1  Mask:255.0.0.0
>           inet6 addr: ::1/128 Scope:Host
>           UP LOOPBACK RUNNING  MTU:16436  Metric:1
>           RX packets:96 errors:0 dropped:0 overruns:0 frame:0
>           TX packets:96 errors:0 dropped:0 overruns:0 carrier:0
>           collisions:0 txqueuelen:0
>           RX bytes:6192 (6.0 Kb)  TX bytes:6192 (6.0 Kb)
>
>ppp0      Link encap:Point-to-Point Protocol
>           inet addr:80.130.191.226  P-t-P:217.5.98.30  Mask:255.255.255.255
>           UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1492  Metric:1
>           RX packets:37790 errors:0 dropped:0 overruns:0 frame:0
>           TX packets:35945 errors:0 dropped:1 overruns:0 carrier:0
>           collisions:0 txqueuelen:3
>           RX bytes:18024451 (17.1 Mb)  TX bytes:4481451 (4.2 Mb)
>
>sit0      Link encap:IPv6-in-IPv4
>           NOARP  MTU:1480  Metric:1
>           RX packets:0 errors:0 dropped:0 overruns:0 frame:0
>           TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
>           collisions:0 txqueuelen:0
>           RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)
>
>+ _________________________ mii-tool
>+ '[' -x /sbin/mii-tool ']'
>+ /sbin/mii-tool -v
>SIOCGMIIPHY on 'eth0' failed: Operation not supported
>SIOCGMIIPHY on 'eth1' failed: Operation not supported
>no MII interfaces found
>+ _________________________ ipsec/directory
>+ ipsec --directory
>/usr/lib/ipsec
>+ _________________________ hostname/fqdn
>+ hostname --fqdn
>mngateway.local
>+ _________________________ hostname/ipaddress
>+ hostname --ip-address
>192.6.2.12
>+ _________________________ uptime
>+ uptime
>   8:56am  up   2:54,  2 users,  load average: 0.18, 0.77, 1.02
>+ _________________________ ps
>+ ps alxwf
>+ egrep -i 'ppid|pluto|ipsec|klips'
>F   UID   PID  PPID PRI  NI   VSZ  RSS WCHAN  STAT TTY        TIME COMMAND
>4     0  9398  8210  25   0  2576 1224 
>wait4  S+   pts/2      0:00          \_ /bin/sh /usr/lib/ipsec/barf
>4     0  9487  9398  25   0  2172  512 
>-      R+   pts/2      0:00              \_ /bin/sh /usr/bin/egrep -i 
>ppid|pluto|ipsec|klips
>5     0  9211     1  21   0  2576 1180 wait4  S    pts/2      0:00 /bin/sh 
>/usr/lib/ipsec/_plutorun --debug  --uniqueids no 
>--nocrsend  --strictcrlpolicy  --nat_traversal  --keep_alive 
>--force_keepalive  --disable_port_floating  --virtual_private 
>--crlcheckinterval 0 --ocspuri  --dump  --opts  --stderrlog  --wait no 
>--pre  --post  --log daemon.error --pid /var/run/pluto.pid
>5     0  9212  9211  25   0  2576 1196 wait4  S    pts/2      0:00  \_ 
>/bin/sh /usr/lib/ipsec/_plutorun --debug  --uniqueids no 
>--nocrsend  --strictcrlpolicy  --nat_traversal  --keep_alive 
>--force_keepalive  --disable_port_floating  --virtual_private 
>--crlcheckinterval 0 --ocspuri  --dump  --opts  --stderrlog  --wait no 
>--pre  --post  --log daemon.error --pid /var/run/pluto.pid
>4     0  9213  9212  17   0  3608 1376 schedu S    pts/2      0:00  |   \_ 
>/usr/lib/ipsec/pluto --nofork --secretsfile /etc/ipsec.secrets 
>--policygroupsdir /etc/ipsec.d/policies
>4     0  9245  9213  18   0  1304  272 schedu 
>S    pts/2      0:00  |       \_ _pluto_adns
>4     0  9214  9211  17   0  2572 1156 pipe_w S    pts/2      0:00  \_ 
>/bin/sh /usr/lib/ipsec/_plutoload --wait no --post
>4     0  9215     1  25   0  1624  472 pipe_w S    pts/2      0:00 logger 
>-s -p daemon.error -t ipsec__plutorun
>+ _________________________ ipsec/showdefaults
>+ ipsec showdefaults
>routephys=ppp0
>routevirt=ipsec0
>routeaddr=80.130.191.226
>routenexthop=217.5.98.30
>+ _________________________ ipsec/conf
>+ ipsec _keycensor
>+ ipsec _include /etc/ipsec.conf
>
>#< /etc/ipsec.conf 1
># /etc/ipsec.conf - FreeS/WAN IPsec configuration file
># RCSID $Id: ipsec.conf.in,v 1.11 2003/06/13 23:28:41 sam Exp $
>
># This file:  /usr/share/doc/packages/freeswan/ipsec.conf-sample
>#
># Manual:     ipsec.conf.5
>#
># Help:
># http://www.strongsec.com/freeswan/install.htm
>
>version 2.0     # conforms to second version of ipsec.conf specification
>
>
>config setup
>         interfaces="%defaultroute"
>         uniqueids=no
>
>conn %default
>         left=%defaultroute
>         leftcert=mnvpngw-cert.pem
>         auto=add
>         authby=rsasig
>         rekey=no
>         keyingtries=5
>         rightrsasigkey=%cert
>
>
>conn L2TP-CERT
>         authby=rsasig
>         pfs=no
>         leftrsasigkey=%cert
>         leftprotoport=17/1701
>         right=%any
>         rightid="C=DE, O=Multinova GmbH, OU=VPN, CN=VPNCA"
>         rightprotoport=17/1701
>         auto=add
>         keyingtries=3
>
>
>conn block
>         auto=ignore
>
>conn clear
>         auto=ignore
>
>conn private
>         auto=ignore
>
>conn private-or-clear
>         auto=ignore
>
>conn clear-or-private
>         auto=ignore
>
>conn packetdefault
>         auto=ignore
>
>+ _________________________ ipsec/secrets
>+ ipsec _include /etc/ipsec.secrets
>+ ipsec _secretcensor
>+ _________________________ ipsec/listall
>+ ipsec auto --listall
>000
>000 List of Public Keys:
>000
>000 Aug 09 08:54:43 2004, 2048 RSA Key AwEAAcRDN, until May 04 09:34:26 
>2007 ok
>000        ID_DER_ASN1_DN 'C=DE, O=Multinova GmbH, CN=Multinova CA'
>000        Issuer 'C=DE, O=Multinova GmbH, CN=Multinova CA'
>000
>000 List of X.509 End Certificates:
>000
>000 Aug 09 08:54:43 2004, count: 1
>000        subject: 'C=DE, O=Multinova GmbH, CN=Multinova CA'
>000        issuer:  'C=DE, O=Multinova GmbH, CN=Multinova CA'
>000        serial:   01
>000        pubkey:   2048 RSA Key AwEAAcRDN
>000        validity: not before Aug 07 09:34:26 2004 ok
>000                  not after  May 04 09:34:26 2007 ok
>000        subjkey: 
>95:69:34:87:11:8c:13:ca:44:db:3b:1b:4e:e3:fc:1e:0e:2e:61:5c
>000        authkey: 
>0a:f9:ce:f7:f4:fc:19:8a:e3:f9:6e:9e:f0:ec:23:d8:6f:5c:c0:24
>000        aserial:  00
>000
>000 List of X.509 CA Certificates:
>000
>000 Aug 09 08:54:42 2004, count: 1
>000        subject: 'C=DE, O=Multinova GmbH, CN=Multinova CA'
>000        issuer:  'C=DE, O=Multinova GmbH, CN=Multinova CA'
>000        serial:   00
>000        pubkey:   2048 RSA Key AwEAAeYoP
>000        validity: not before Aug 07 09:22:08 2004 ok
>000                  not after  Sep 15 09:22:08 2008 ok
>000        subjkey: 
>0a:f9:ce:f7:f4:fc:19:8a:e3:f9:6e:9e:f0:ec:23:d8:6f:5c:c0:24
>000        authkey: 
>0a:f9:ce:f7:f4:fc:19:8a:e3:f9:6e:9e:f0:ec:23:d8:6f:5c:c0:24
>000        aserial:  00
>+ '[' /etc/ipsec.d/policies ']'
>++ basename /etc/ipsec.d/policies/block
>+ base=block
>+ _________________________ ipsec/policies/block
>+ cat /etc/ipsec.d/policies/block
># This file defines the set of CIDRs (network/mask-length) to which
># communication should never be allowed.
>#
># See /usr/share/doc/packages/freeswan/policygroups.html for details.
>#
># $Id: block.in,v 1.4 2003/02/17 02:22:15 mcr Exp $
>#
>
>++ basename /etc/ipsec.d/policies/clear
>+ base=clear
>+ _________________________ ipsec/policies/clear
>+ cat /etc/ipsec.d/policies/clear
># This file defines the set of CIDRs (network/mask-length) to which
># communication should always be in the clear.
>#
># See /usr/share/doc/packages/freeswan/policygroups.html for details.
>#
># $Id: clear.in,v 1.4 2003/02/17 02:22:15 mcr Exp $
>#
>++ basename /etc/ipsec.d/policies/clear-or-private
>+ base=clear-or-private
>+ _________________________ ipsec/policies/clear-or-private
>+ cat /etc/ipsec.d/policies/clear-or-private
># This file defines the set of CIDRs (network/mask-length) to which
># we will communicate in the clear, or, if the other side initiates IPSEC,
># using encryption.  This behaviour is also called "Opportunistic Responder".
>#
># See /usr/share/doc/packages/freeswan/policygroups.html for details.
>#
># $Id: clear-or-private.in,v 1.4 2003/02/17 02:22:15 mcr Exp $
>#
>++ basename /etc/ipsec.d/policies/private
>+ base=private
>+ _________________________ ipsec/policies/private
>+ cat /etc/ipsec.d/policies/private
># This file defines the set of CIDRs (network/mask-length) to which
># communication should always be private (i.e. encrypted).
># See /usr/share/doc/packages/freeswan/policygroups.html for details.
>#
># $Id: private.in,v 1.4 2003/02/17 02:22:15 mcr Exp $
>#
>++ basename /etc/ipsec.d/policies/private-or-clear
>+ base=private-or-clear
>+ _________________________ ipsec/policies/private-or-clear
>+ cat /etc/ipsec.d/policies/private-or-clear
># This file defines the set of CIDRs (network/mask-length) to which
># communication should be private, if possible, but in the clear otherwise.
>#
># If the target has a TXT (later IPSECKEY) record that specifies
># authentication material, we will require private (i.e. encrypted)
># communications.  If no such record is found, communications will be
># in the clear.
>#
># See /usr/share/doc/packages/freeswan/policygroups.html for details.
>#
># $Id: private-or-clear.in,v 1.5 2003/02/17 02:22:15 mcr Exp $
>#
>
>0.0.0.0/0
>+ _________________________ ipsec/ls-libdir
>+ ls -l /usr/lib/ipsec
>total 1149
>-rwxr-xr-x  1 root root  15206 Apr  7 00:25 _confread
>-rwxr-xr-x  1 root root   6687 Apr  7 00:25 _copyright
>-rwxr-xr-x  1 root root   2379 Apr  7 00:25 _include
>-rwxr-xr-x  1 root root   1475 Apr  7 00:25 _keycensor
>-rwxr-xr-x  1 root root  10908 Apr  7 00:25 _pluto_adns
>-rwxr-xr-x  1 root root   3586 Apr  7 00:25 _plutoload
>-rwxr-xr-x  1 root root   6897 Apr  7 00:25 _plutorun
>-rwxr-xr-x  1 root root  10350 Apr  7 00:25 _realsetup
>-rwxr-xr-x  1 root root   1975 Apr  7 00:25 _secretcensor
>-rwxr-xr-x  1 root root   8069 Apr  7 00:25 _startklips
>-rwxr-xr-x  1 root root   7959 Apr  7 00:25 _updown
>-rwxr-xr-x  1 root root  11992 Apr  7 00:25 _updown_x509
>-rwxr-xr-x  1 root root  16591 Apr  7 00:25 auto
>-rwxr-xr-x  1 root root   8628 Apr  7 00:25 barf
>-rwxr-xr-x  1 root root    816 Apr  7 00:25 calcgoo
>-rw-r--r--  1 root root     75 Apr  7 00:25 distro.txt
>-rwxr-xr-x  1 root root  80853 Apr  7 00:25 eroute
>-rwxr-xr-x  1 root root    960 Apr  7 00:25 ipsec_1_to_2.pl
>-rw-r--r--  1 root root   1942 Apr  7 00:25 ipsec_pr.template
>-rwxr-xr-x  1 root root  59296 Apr  7 00:25 klipsdebug
>-rwxr-xr-x  1 root root   2449 Apr  7 00:25 look
>-rwxr-xr-x  1 root root   7118 Apr  7 00:25 mailkey
>-rwxr-xr-x  1 root root  16188 Apr  7 00:25 manual
>-rwxr-xr-x  1 root root   1921 Apr  7 00:25 newhostkey
>-rwxr-xr-x  1 root root  53459 Apr  7 00:25 pf_key
>-rwxr-xr-x  1 root root 489037 Apr  7 00:25 pluto
>-rwxr-xr-x  1 root root   9532 Apr  7 00:25 ranbits
>-rwxr-xr-x  1 root root  23511 Apr  7 00:25 rsasigkey
>-rwxr-xr-x  1 root root    765 Apr  7 00:25 secrets
>-rwxr-xr-x  1 root root  17566 Apr  7 00:25 send-pr
>lrwxrwxrwx  1 root root     17 Aug  2 10:30 setup -> /etc/init.d/ipsec
>-rwxr-xr-x  1 root root   1048 Apr  7 00:25 showdefaults
>-rwxr-xr-x  1 root root   4321 Apr  7 00:25 showhostkey
>-rwxr-xr-x  1 root root  89321 Apr  7 00:25 spi
>-rwxr-xr-x  1 root root  67842 Apr  7 00:25 spigrp
>-rwxr-xr-x  1 root root  12170 Apr  7 00:25 tncfg
>-rwxr-xr-x  1 root root   9280 Apr  7 00:25 verify
>-rwxr-xr-x  1 root root  40750 Apr  7 00:25 whack
>+ _________________________ ipsec/ls-execdir
>+ ls -l /usr/lib/ipsec
>total 1149
>-rwxr-xr-x  1 root root  15206 Apr  7 00:25 _confread
>-rwxr-xr-x  1 root root   6687 Apr  7 00:25 _copyright
>-rwxr-xr-x  1 root root   2379 Apr  7 00:25 _include
>-rwxr-xr-x  1 root root   1475 Apr  7 00:25 _keycensor
>-rwxr-xr-x  1 root root  10908 Apr  7 00:25 _pluto_adns
>-rwxr-xr-x  1 root root   3586 Apr  7 00:25 _plutoload
>-rwxr-xr-x  1 root root   6897 Apr  7 00:25 _plutorun
>-rwxr-xr-x  1 root root  10350 Apr  7 00:25 _realsetup
>-rwxr-xr-x  1 root root   1975 Apr  7 00:25 _secretcensor
>-rwxr-xr-x  1 root root   8069 Apr  7 00:25 _startklips
>-rwxr-xr-x  1 root root   7959 Apr  7 00:25 _updown
>-rwxr-xr-x  1 root root  11992 Apr  7 00:25 _updown_x509
>-rwxr-xr-x  1 root root  16591 Apr  7 00:25 auto
>-rwxr-xr-x  1 root root   8628 Apr  7 00:25 barf
>-rwxr-xr-x  1 root root    816 Apr  7 00:25 calcgoo
>-rw-r--r--  1 root root     75 Apr  7 00:25 distro.txt
>-rwxr-xr-x  1 root root  80853 Apr  7 00:25 eroute
>-rwxr-xr-x  1 root root    960 Apr  7 00:25 ipsec_1_to_2.pl
>-rw-r--r--  1 root root   1942 Apr  7 00:25 ipsec_pr.template
>-rwxr-xr-x  1 root root  59296 Apr  7 00:25 klipsdebug
>-rwxr-xr-x  1 root root   2449 Apr  7 00:25 look
>-rwxr-xr-x  1 root root   7118 Apr  7 00:25 mailkey
>-rwxr-xr-x  1 root root  16188 Apr  7 00:25 manual
>-rwxr-xr-x  1 root root   1921 Apr  7 00:25 newhostkey
>-rwxr-xr-x  1 root root  53459 Apr  7 00:25 pf_key
>-rwxr-xr-x  1 root root 489037 Apr  7 00:25 pluto
>-rwxr-xr-x  1 root root   9532 Apr  7 00:25 ranbits
>-rwxr-xr-x  1 root root  23511 Apr  7 00:25 rsasigkey
>-rwxr-xr-x  1 root root    765 Apr  7 00:25 secrets
>-rwxr-xr-x  1 root root  17566 Apr  7 00:25 send-pr
>lrwxrwxrwx  1 root root     17 Aug  2 10:30 setup -> /etc/init.d/ipsec
>-rwxr-xr-x  1 root root   1048 Apr  7 00:25 showdefaults
>-rwxr-xr-x  1 root root   4321 Apr  7 00:25 showhostkey
>-rwxr-xr-x  1 root root  89321 Apr  7 00:25 spi
>-rwxr-xr-x  1 root root  67842 Apr  7 00:25 spigrp
>-rwxr-xr-x  1 root root  12170 Apr  7 00:25 tncfg
>-rwxr-xr-x  1 root root   9280 Apr  7 00:25 verify
>-rwxr-xr-x  1 root root  40750 Apr  7 00:25 whack
>+ _________________________ ipsec/updowns
>++ ls /usr/lib/ipsec
>++ egrep updown
>+ cat /usr/lib/ipsec/_updown
>#! /bin/sh
># iproute2 version, default updown script
># Copyright (C) 2002. Michael Richardson
>#
># This program is free software; you can redistribute it and/or modify it
># under the terms of the GNU General Public License as published by the
># Free Software Foundation; either version 2 of the License, or (at your
># option) any later version.  See <http://www.fsf.org/copyleft/gpl.txt>.
>#
># This program is distributed in the hope that it will be useful, but
># WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
># or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
># for more details.
>#
># RCSID $Id: _updown.ip2.in,v 1.2 2003/08/18 16:34:29 mcr Exp $
>
>
>
># CAUTION:  Installing a new version of FreeS/WAN will install a new
># copy of this script, wiping out any custom changes you make.  If
># you need changes, make a copy of this under another name, and customize
># that, and use the (left/right)updown parameters in ipsec.conf to make
># FreeS/WAN use yours instead of this default one.
>
>
># things that this script gets (from ipsec_pluto(8) man page)
>#
>#
>#      PLUTO_VERSION
>#              indicates  what  version of this interface is being
>#              used.  This document describes version  1.1.   This
>#              is upwardly compatible with version 1.0.
>#
>#       PLUTO_VERB
>#              specifies the name of the operation to be performed
>#              (prepare-host,r prepare-client, up-host, up-client,
>#              down-host,  or down-client).  If the address family
>#              for security gateway to security gateway communica­
>#              tions is IPv6, then a suffix of -v6 is added to the
>#              verb.
>#
>#       PLUTO_CONNECTION
>#              is the name of the  connection  for  which  we  are
>#              routing.
>#
>#       PLUTO_NEXT_HOP
>#              is the next hop to which packets bound for the peer
>#              must be sent.
>#
>#       PLUTO_INTERFACE
>#              is the name of the ipsec interface to be used.
>#
>#       PLUTO_ME
>#              is the IP address of our host.
>#
>#       PLUTO_MY_CLIENT
>#              is the IP address / count of our client subnet.  If
>#              the  client  is  just  the  host,  this will be the
>#              host's own IP address / max (where max  is  32  for
>#              IPv4 and 128 for IPv6).
>#
>#       PLUTO_MY_CLIENT_NET
>#              is the IP address of our client net.  If the client
>#              is just the host, this will be the  host's  own  IP
>#              address.
>#
>#       PLUTO_MY_CLIENT_MASK
>#              is  the  mask for our client net.  If the client is
>#              just the host, this will be 255.255.255.255.
>#
>#       PLUTO_PEER
>#              is the IP address of our peer.
>#
>#       PLUTO_PEER_CLIENT
>#              is the IP address / count of the peer's client sub­
>#              net.   If the client is just the peer, this will be
>#              the peer's own IP address / max (where  max  is  32
>#              for IPv4 and 128 for IPv6).
>#
>#       PLUTO_PEER_CLIENT_NET
>#              is the IP address of the peer's client net.  If the
>#              client is just the peer, this will  be  the  peer's
>#              own IP address.
>#
>#       PLUTO_PEER_CLIENT_MASK
>#              is  the  mask  for  the  peer's client net.  If the
>#              client   is   just   the   peer,   this   will   be
>#              255.255.255.255.
>#
># PLUTO_PEER_SOURCEIP
># PLUTO_CONNECTION_TYPE
>#
>
># check interface version
>case "$PLUTO_VERSION" in
>1.[0])  # Older Pluto?!?  Play it safe, script may be using new features.
>         echo "$0: obsolete interface version \`$PLUTO_VERSION'," >&2
>         echo "$0:       called by obsolete Pluto?" >&2
>         exit 2
>         ;;
>1.*)    ;;
>*)      echo "$0: unknown interface version \`$PLUTO_VERSION'" >&2
>         exit 2
>         ;;
>esac
>
># check parameter(s)
>case "$1:$*" in
>':')                    # no parameters
>         ;;
>ipfwadm:ipfwadm)        # due to (left/right)firewall; for default script only
>         ;;
>custom:*)               # custom parameters (see above CAUTION comment)
>         ;;
>*)      echo "$0: unknown parameters \`$*'" >&2
>         exit 2
>         ;;
>esac
>
># utility functions for route manipulation
># Meddling with this stuff should not be necessary and requires great care.
>uproute() {
>         doroute add
>}
>downroute() {
>         doroute del
>}
>doroute() {
>         parms="$PLUTO_PEER_CLIENT"
>         parms2=""
>         if [ -n "$PLUTO_NEXT_HOP" ]
>         then
>             parms2="via $PLUTO_NEXT_HOP"
>         fi
>         parms2="$parms2 dev $PLUTO_INTERFACE"
>
>         if [ -z "$PLUTO_PEER_SOURCEIP" ]
>         then
>             if [ -f /etc/sysconfig/defaultsource ]
>             then
>                 . /etc/sysconfig/defaultsource
>                 if [ -n "$DEFAULTSOURCE" ]
>                 then
>                     PLUTO_PEER_SOURCEIP=$DEFAULTSOURCE
>                 fi
>             fi
>         fi
>
>         if [ -n "$PLUTO_PEER_SOURCEIP" ]
>         then
>             parms2="$parms2 src $DEFAULTSOURCE"
>         fi
>         case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
>         "0.0.0.0/0.0.0.0")
>                 # need to provide route that eclipses default, without
>                 # replacing it.
>                 it="ip route $1 0.0.0.0/1 $parms2 &&"
>                 it="$it ip route $1 128.0.0.0/1 $parms2"
>                 ip route $1 0.0.0.0/1 $parms2 &&
>                     ip route $1 128.0.0.0/1 $parms2
>                 ;;
>         *)      it="ip route $1 $parms $parms2"
>                 ip route $1 $parms $parms2
>                 ;;
>         esac
>         st=$?
>         if test $st -ne 0
>         then
>                 # route has already given its own cryptic message
>                 echo "$0: \`$it' failed" >&2
>                 if test " $1 $st" = " add 7"
>                 then
>                         # another totally undocumented interface -- 7 and
>                         # "SIOCADDRT: Network is unreachable" means that
>                         # the gateway isn't reachable.
>                         echo "$0: (incorrect or missing nexthop 
> setting??)" >&2
>                 fi
>         fi
>         return $st
>}
>
>
>
># the big choice
>case "$PLUTO_VERB:$1" in
>prepare-host:*|prepare-client:*)
>         # delete possibly-existing route (preliminary to adding a route)
>         case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
>         "0.0.0.0/0.0.0.0")
>                 # need to provide route that eclipses default, without
>                 # replacing it.
>                 parms1="0.0.0.0/1"
>                 parms2="128.0.0.0/1"
>                 it="ip route del $parms1 2>&1 ; ip route del $parms2 2>&1"
>                 oops="`ip route del $parms1 2>&1 ; ip route del $parms2 
> 2>&1`"
>                 ;;
>         *)
>                 parms="$PLUTO_PEER_CLIENT"
>                 it="ip route del $parms 2>&1"
>                 oops="`ip route del $parms 2>&1`"
>                 ;;
>         esac
>         status="$?"
>         if test " $oops" = " " -a " $status" != " 0"
>         then
>                 oops="silent error, exit status $status"
>         fi
>         case "$oops" in
>         'RTNETLINK answers: No such process'*)
>                 # This is what route (currently -- not documented!) gives
>                 # for "could not find such a route".
>                 oops=
>                 status=0
>                 ;;
>         esac
>         if test " $oops" != " " -o " $status" != " 0"
>         then
>                 echo "$0: \`$it' failed ($oops)" >&2
>         fi
>         exit $status
>         ;;
>route-host:*|route-client:*)
>         # connection to me or my client subnet being routed
>         uproute
>         ;;
>unroute-host:*|unroute-client:*)
>         # connection to me or my client subnet being unrouted
>         downroute
>         ;;
>up-host:*)
>         # connection to me coming up
>         # If you are doing a custom version, firewall commands go here.
>         ;;
>down-host:*)
>         # connection to me going down
>         # If you are doing a custom version, firewall commands go here.
>         ;;
>up-client:)
>         # connection to my client subnet coming up
>         # If you are doing a custom version, firewall commands go here.
>         ;;
>down-client:)
>         # connection to my client subnet going down
>         # If you are doing a custom version, firewall commands go here.
>         ;;
>up-client:ipfwadm)
>         # connection to client subnet, with (left/right)firewall=yes, 
> coming up
>         # This is used only by the default updown script, not by your custom
>         # ones, so do not mess with it; see CAUTION comment up at top.
>         ipfwadm -F -i accept -b -S 
> $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
>                 -D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
>         ;;
>down-client:ipfwadm)
>         # connection to client subnet, with (left/right)firewall=yes, 
> going down
>         # This is used only by the default updown script, not by your custom
>         # ones, so do not mess with it; see CAUTION comment up at top.
>         ipfwadm -F -d accept -b -S 
> $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
>                 -D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
>         ;;
>*)      echo "$0: unknown verb \`$PLUTO_VERB' or parameter \`$1'" >&2
>         exit 1
>         ;;
>esac
>+ cat /usr/lib/ipsec/_updown_x509
>#! /bin/sh
># iproute2 version, default updown script
># Copyright (C) 2002. Michael Richardson
>#
># This program is free software; you can redistribute it and/or modify it
># under the terms of the GNU General Public License as published by the
># Free Software Foundation; either version 2 of the License, or (at your
># option) any later version.  See <http://www.fsf.org/copyleft/gpl.txt>.
>#
># This program is distributed in the hope that it will be useful, but
># WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
># or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
># for more details.
>#
># RCSID $Id: _updown.ip2.in,v 1.2 2003/08/18 16:34:29 mcr Exp $
>
>
>
># CAUTION:  Installing a new version of FreeS/WAN will install a new
># copy of this script, wiping out any custom changes you make.  If
># you need changes, make a copy of this under another name, and customize
># that, and use the (left/right)updown parameters in ipsec.conf to make
># FreeS/WAN use yours instead of this default one.
>
>
># things that this script gets (from ipsec_pluto(8) man page)
>#
>#
>#      PLUTO_VERSION
>#              indicates  what  version of this interface is being
>#              used.  This document describes version  1.1.   This
>#              is upwardly compatible with version 1.0.
>#
>#       PLUTO_VERB
>#              specifies the name of the operation to be performed
>#              (prepare-host,r prepare-client, up-host, up-client,
>#              down-host,  or down-client).  If the address family
>#              for security gateway to security gateway communica­
>#              tions is IPv6, then a suffix of -v6 is added to the
>#              verb.
>#
>#       PLUTO_CONNECTION
>#              is the name of the  connection  for  which  we  are
>#              routing.
>#
>#       PLUTO_NEXT_HOP
>#              is the next hop to which packets bound for the peer
>#              must be sent.
>#
>#       PLUTO_INTERFACE
>#              is the name of the ipsec interface to be used.
>#
>#       PLUTO_ME
>#              is the IP address of our host.
>#
>#       PLUTO_MY_ID
>#              is the ID of our host.
>#
>#       PLUTO_MY_CLIENT
>#              is the IP address / count of our client subnet.  If
>#              the  client  is  just  the  host,  this will be the
>#              host's own IP address / max (where max  is  32  for
>#              IPv4 and 128 for IPv6).
>#
>#       PLUTO_MY_CLIENT_NET
>#              is the IP address of our client net.  If the client
>#              is just the host, this will be the  host's  own  IP
>#              address.
>#
>#       PLUTO_MY_CLIENT_MASK
>#              is  the  mask for our client net.  If the client is
>#              just the host, this will be 255.255.255.255.
>#
>#       PLUTO_MY_PROTOCOL
>#              is the IP protocol that will be transported.
>#
>#       PLUTO_MY_PORT
>#              is  the  UDP/TCP  port  to  which  the IPsec SA  is
>#              restricted on our side.
>#
>#       PLUTO_PEER
>#              is the IP address of our peer.
>#
>#       PLUTO_PEER_ID
>#              is the ID of our peer.
>#
>#       PLUTO_PEER_CA
>#              is the CA which issued the cert of our peer.
>#
>#       PLUTO_PEER_CLIENT
>#              is the IP address / count of the peer's client sub­
>#              net.   If the client is just the peer, this will be
>#              the peer's own IP address / max (where  max  is  32
>#              for IPv4 and 128 for IPv6).
>#
>#       PLUTO_PEER_CLIENT_NET
>#              is the IP address of the peer's client net.  If the
>#              client is just the peer, this will  be  the  peer's
>#              own IP address.
>#
>#       PLUTO_PEER_CLIENT_MASK
>#              is  the  mask  for  the  peer's client net.  If the
>#              client   is   just   the   peer,   this   will   be
>#              255.255.255.255.
>#
>#       PLUTO_PEER_PROTOCOL
>#              is the IP protocol that will be transported.
>#
>#       PLUTO_PEER_PORT
>#              is  the  UDP/TCP  port  to  which  the IPsec SA  is
>#              restricted on the peer side.
>#
>
># PLUTO_PEER_SOURCEIP
># PLUTO_CONNECTION_TYPE
>#
>
># logging of VPN connections
>#
># tag put in front of each log entry:
>TAG=vpn
>#
># syslog facility and priority used:
>FAC_PRIO=local0.notice
>#
># to create a special vpn logging file, put the following line into
># the syslog configuration file /etc/syslog.conf:
>#
># local0.notice                   -/var/log/vpn
>#
>
># check interface version
>case "$PLUTO_VERSION" in
>1.[0])  # Older Pluto?!?  Play it safe, script may be using new features.
>         echo "$0: obsolete interface version \`$PLUTO_VERSION'," >&2
>         echo "$0:       called by obsolete Pluto?" >&2
>         exit 2
>         ;;
>1.*)    ;;
>*)      echo "$0: unknown interface version \`$PLUTO_VERSION'" >&2
>         exit 2
>         ;;
>esac
>
># check parameter(s)
>case "$1:$*" in
>':')                    # no parameters
>         ;;
>ipfwadm:ipfwadm)        # due to (left/right)firewall; for default script only
>         ;;
>custom:*)               # custom parameters (see above CAUTION comment)
>         ;;
>*)      echo "$0: unknown parameters \`$*'" >&2
>         exit 2
>         ;;
>esac
>
># utility functions for route manipulation
># Meddling with this stuff should not be necessary and requires great care.
>uproute() {
>         doroute add
>}
>downroute() {
>         doroute del
>}
>doroute() {
>         parms="$PLUTO_PEER_CLIENT"
>         parms2=""
>         if [ -n "$PLUTO_NEXT_HOP" ]
>         then
>             parms2="via $PLUTO_NEXT_HOP"
>         fi
>         parms2="$parms2 dev $PLUTO_INTERFACE"
>
>         if [ -z "$PLUTO_PEER_SOURCEIP" ]
>         then
>             if [ -f /etc/sysconfig/defaultsource ]
>             then
>                 . /etc/sysconfig/defaultsource
>                 if [ -n "$DEFAULTSOURCE" ]
>                 then
>                     PLUTO_PEER_SOURCEIP=$DEFAULTSOURCE
>                 fi
>             fi
>         fi
>
>         if [ -n "$PLUTO_PEER_SOURCEIP" ]
>         then
>             parms2="$parms2 src $DEFAULTSOURCE"
>         fi
>         case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
>         "0.0.0.0/0.0.0.0")
>                 # need to provide route that eclipses default, without
>                 # replacing it.
>                 it="ip route $1 0.0.0.0/1 $parms2 &&"
>                 it="$it ip route $1 128.0.0.0/1 $parms2"
>                 ip route $1 0.0.0.0/1 $parms2 &&
>                     ip route $1 128.0.0.0/1 $parms2
>                 ;;
>         *)      it="ip route $1 $parms $parms2"
>                 ip route $1 $parms $parms2
>                 ;;
>         esac
>         st=$?
>         if test $st -ne 0
>         then
>                 # route has already given its own cryptic message
>                 echo "$0: \`$it' failed" >&2
>                 if test " $1 $st" = " add 7"
>                 then
>                         # another totally undocumented interface -- 7 and
>                         # "SIOCADDRT: Network is unreachable" means that
>                         # the gateway isn't reachable.
>                         echo "$0: (incorrect or missing nexthop 
> setting??)" >&2
>                 fi
>         fi
>         return $st
>}
>
># are there port numbers?
>if [ "$PLUTO_MY_PORT" != 0 ]
>then
>         S_MY_PORT="--sport $PLUTO_MY_PORT"
>         D_MY_PORT="--dport $PLUTO_MY_PORT"
>fi
>if [ "$PLUTO_PEER_PORT" != 0 ]
>then
>         S_PEER_PORT="--sport $PLUTO_PEER_PORT"
>         D_PEER_PORT="--dport $PLUTO_PEER_PORT"
>fi
>
># the big choice
>case "$PLUTO_VERB:$1" in
>prepare-host:*|prepare-client:*)
>         # delete possibly-existing route (preliminary to adding a route)
>         case "$PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK" in
>         "0.0.0.0/0.0.0.0")
>                 # need to provide route that eclipses default, without
>                 # replacing it.
>                 parms1="0.0.0.0/1"
>                 parms2="128.0.0.0/1"
>                 it="ip route del $parms1 2>&1 ; ip route del $parms2 2>&1"
>                 oops="`ip route del $parms1 2>&1 ; ip route del $parms2 
> 2>&1`"
>                 ;;
>         *)
>                 parms="$PLUTO_PEER_CLIENT"
>                 it="ip route del $parms 2>&1"
>                 oops="`ip route del $parms 2>&1`"
>                 ;;
>         esac
>         status="$?"
>         if test " $oops" = " " -a " $status" != " 0"
>         then
>                 oops="silent error, exit status $status"
>         fi
>         case "$oops" in
>         'RTNETLINK answers: No such process'*)
>                 # This is what route (currently -- not documented!) gives
>                 # for "could not find such a route".
>                 oops=
>                 status=0
>                 ;;
>         esac
>         if test " $oops" != " " -o " $status" != " 0"
>         then
>                 echo "$0: \`$it' failed ($oops)" >&2
>         fi
>         exit $status
>         ;;
>route-host:*|route-client:*)
>         # connection to me or my client subnet being routed
>         uproute
>         ;;
>unroute-host:*|unroute-client:*)
>         # connection to me or my client subnet being unrouted
>         downroute
>         ;;
>up-host:*)
>         # connection to me coming up
>         # If you are doing a custom version, firewall commands go here.
>         iptables -I INPUT 1 -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
>             -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
>             -d $PLUTO_ME $D_MY_PORT -j ACCEPT
>         iptables -I OUTPUT 1 -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
>             -s $PLUTO_ME $S_MY_PORT \
>             -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK 
> $D_PEER_PORT -j ACCEPT
>         #
>         if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
>         then
>           logger -t $TAG -p $FAC_PRIO \
>             "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME"
>         else
>           logger -t $TAG -p $FAC_PRIO \
>             "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER 
> -- $PLUTO_ME"
>         fi
>         ;;
>down-host:*)
>         # connection to me going down
>         # If you are doing a custom version, firewall commands go here.
>         # connection to me going down
>         # If you are doing a custom version, firewall commands go here.
>         iptables -D INPUT -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
>             -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
>             -d $PLUTO_ME $D_MY_PORT -j ACCEPT
>         iptables -D OUTPUT -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
>             -s $PLUTO_ME $S_MY_PORT \
>             -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK 
> $D_PEER_PORT -j ACCEPT
>         #
>         if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
>         then
>           logger -t $TAG -p $FAC_PRIO -- \
>             "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME"
>         else
>           logger -t $TAG -p $FAC_PRIO -- \
>           "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER 
> -- $PLUTO_ME"
>         fi
>         ;;
>up-client:)
>         # connection to my client subnet coming up
>         # If you are doing a custom version, firewall commands go here.
>         iptables -I FORWARD 1 -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
>             -s $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $S_MY_PORT \
>             -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK 
> $D_PEER_PORT -j ACCEPT
>         iptables -I FORWARD 1 -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
>             -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
>             -d $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $D_MY_PORT -j 
> ACCEPT
>         #
>         if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
>         then
>           logger -t $TAG -p $FAC_PRIO \
>             "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME == 
> $PLUTO_MY_CLIENT"
>         else
>           logger -t $TAG -p $FAC_PRIO \
>             "+ `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER 
> -- $PLUTO_ME == $PLUTO_MY_CLIENT"
>         fi
>         ;;
>down-client:)
>         # connection to my client subnet going down
>         # If you are doing a custom version, firewall commands go here.
>         iptables -D FORWARD -o $PLUTO_INTERFACE -p $PLUTO_PEER_PROTOCOL \
>             -s $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $S_MY_PORT \
>             -d $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK 
> $D_PEER_PORT -j ACCEPT
>         iptables -D FORWARD -i $PLUTO_INTERFACE -p $PLUTO_MY_PROTOCOL \
>             -s $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK $S_PEER_PORT \
>             -d $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK $D_MY_PORT -j 
> ACCEPT
>         #
>         if [ "$PLUTO_PEER_CLIENT" == "$PLUTO_PEER/32" ]
>         then
>           logger -t $TAG -p $FAC_PRIO -- \
>             "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER -- $PLUTO_ME == 
> $PLUTO_MY_CLIENT"
>         else
>           logger -t $TAG -p $FAC_PRIO -- \
>             "- `echo -e $PLUTO_PEER_ID` $PLUTO_PEER_CLIENT == $PLUTO_PEER 
> -- $PLUTO_ME == $PLUTO_MY_CLIENT"
>         fi
>         ;;
>up-client:ipfwadm)
>         # connection to client subnet, with (left/right)firewall=yes, 
> coming up
>         # This is used only by the default updown script, not by your custom
>         # ones, so do not mess with it; see CAUTION comment up at top.
>         ipfwadm -F -i accept -b -S 
> $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
>                 -D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
>         ;;
>down-client:ipfwadm)
>         # connection to client subnet, with (left/right)firewall=yes, 
> going down
>         # This is used only by the default updown script, not by your custom
>         # ones, so do not mess with it; see CAUTION comment up at top.
>         ipfwadm -F -d accept -b -S 
> $PLUTO_MY_CLIENT_NET/$PLUTO_MY_CLIENT_MASK \
>                 -D $PLUTO_PEER_CLIENT_NET/$PLUTO_PEER_CLIENT_MASK
>         ;;
>*)      echo "$0: unknown verb \`$PLUTO_VERB' or parameter \`$1'" >&2
>         exit 1
>         ;;
>esac
>+ _________________________ proc/net/dev
>+ cat /proc/net/dev
>Inter-|   Receive                                                |  Transmit
>  face |bytes    packets errs drop fifo frame compressed 
> multicast|bytes    packets errs drop fifo colls carrier compressed
>     lo:    6192      96    0    0    0     0          0         0 
> 6192      96    0    0    0     0       0          0
>   sit0:       0       0    0    0    0     0          0         0 
> 0       0    0    0    0     0       0          0
>   eth0: 5085416   36118    0    0    0     0          0         0 
> 18517723   37397    0    0    0     0       0          0
>   eth1:18877041   38142    0    0    0     1          0         0 
> 5380745   36462    0    0    0    99       0          0
>   ppp0:18024451   37790    0    0    0     0          0         0 
> 4481451   35945    0    1    0     0       0          0
>+ _________________________ proc/net/route
>+ cat /proc/net/route
>Iface   Destination     Gateway         Flags   RefCnt  Use     Metric 
>Mask            MTU     Window  IRTT 
>
>ppp0    1E6205D9        00000000        0005    0       0       0 
>FFFFFFFF        0       0       0 
>
>eth0    000206C0        00000000        0001    0       0       0 
>00FFFFFF        0       0       0 
>
>eth0    0000FEA9        00000000        0001    0       0       0 
>0000FFFF        0       0       0 
>
>lo      0000007F        00000000        0001    0       0       0 
>000000FF        0       0       0 
>
>ppp0    00000000        1E6205D9        0003    0       0       0 
>00000000        0       0       0 
>
>+ _________________________ proc/sys/net/ipv4/ip_forward
>+ cat /proc/sys/net/ipv4/ip_forward
>1
>+ _________________________ proc/sys/net/ipv4/conf/star-rp_filter
>+ cd /proc/sys/net/ipv4/conf
>+ egrep '^' all/rp_filter default/rp_filter eth0/rp_filter lo/rp_filter 
>ppp0/rp_filter
>all/rp_filter:1
>default/rp_filter:1
>eth0/rp_filter:1
>lo/rp_filter:1
>ppp0/rp_filter:1
>+ _________________________ uname-a
>+ uname -a
>Linux mngateway 2.6.5-7.95-default #1 Thu Jul 1 15:23:45 UTC 2004 i686 
>athlon i386 GNU/Linux
>+ _________________________ redhat-release
>+ test -r /etc/redhat-release
>+ _________________________ proc/net/ipsec_version
>+ cat /proc/net/ipsec_version
>cat: /proc/net/ipsec_version: No such file or directory
>+ _________________________ iptables/list
>+ iptables -L -v -n
>Chain INPUT (policy DROP 0 packets, 0 bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>    92  5980 
> ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0
>     0     0 
> DROP       all  --  ppp0   *       0.0.0.0/0            255.255.255.255
>     0     0 
> input_int  all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    MARK match 0x1701d
>   657 40844 
> input_ext  all  --  ppp0   *       0.0.0.0/0            0.0.0.0/0
>    64 17402 
> input_int  all  --  eth0   *       0.0.0.0/0            0.0.0.0/0
>     0     0 
> LOG        all  --  eth0   *       0.0.0.0/0            80.130.191.226 
>    LOG flags 6 level 4 prefix `SFW2-IN-ACC_DENIED_INT '
>     0     0 
> DROP       all  --  eth0   *       0.0.0.0/0            80.130.191.226
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-IN-ILL-TARGET '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>
>Chain FORWARD (policy DROP 0 packets, 0 bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>  8862  524K 
> TCPMSS     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp flags:0x06/0x02 TCPMSS clamp to PMTU
>     0     0 
> ACCEPT     all  --  eth0   eth0    0.0.0.0/0            0.0.0.0/0
>     0     0 
> ACCEPT     all  --  ppp0   ppp0    0.0.0.0/0            0.0.0.0/0
>37130   18M 
>forward_ext  all  --  ppp0   *       0.0.0.0/0            0.0.0.0/0
>35791 4471K 
>forward_int  all  --  eth0   *       0.0.0.0/0            0.0.0.0/0
>     1    60 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-FWD-ILL-ROUTING '
>     1    60 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>     0     0 
> ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-FORWARD-ERROR '
>
>Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>    92  5980 
> ACCEPT     all  --  *      lo      0.0.0.0/0            0.0.0.0/0
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11 
> LOG flags 6 level 4 prefix `SFW2-OUT-TRACERT-ATTEMPT '
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11
>     5   959 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 code 3
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 code 4
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 code 9
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 
> code 10
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 
> code 13
>     0     0 DROP       icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3
>   169 13456 
> ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-OUTPUT-ERROR '
>
>Chain forward_dmz (0 references)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            192.6.2.12 
>    LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-CIRCUMV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            192.6.2.12
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            80.130.191.226 
>    LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-CIRCUMV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            80.130.191.226
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED 
> icmp type 3
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 0
>     0     0 
> ACCEPT     all  --  *      ppp0    0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED
>     0     0 
> ACCEPT     all  --  ppp0   *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 
> LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT '
>     0     0 
> LOG        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT '
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state INVALID LOG flags 6 level 4 prefix `SFW2-FWDdmz-DROP-DEFLT-INV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>
>Chain forward_ext (1 references)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            192.6.2.12 
>    LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-CIRCUMV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            192.6.2.12
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED 
> icmp type 3
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 0
>     0     0 
> ACCEPT     all  --  *      ppp0    0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED
>37130   18M 
>ACCEPT     all  --  ppp0   *       0.0.0.0/0            0.0.0.0/0 
>  state RELATED,ESTABLISHED
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 
> LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT '
>     0     0 
> LOG        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT '
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state INVALID LOG flags 6 level 4 prefix `SFW2-FWDext-DROP-DEFLT-INV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>
>Chain forward_int (1 references)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            80.130.191.226 
>    LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-CIRCUMV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            80.130.191.226
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED 
> icmp type 3
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 0
>35790 4471K 
>ACCEPT     all  --  *      ppp0    0.0.0.0/0            0.0.0.0/0 
>  state NEW,RELATED,ESTABLISHED
>     0     0 
> ACCEPT     all  --  ppp0   *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 
> LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT '
>     0     0 
> LOG        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT '
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state INVALID LOG flags 6 level 4 prefix `SFW2-FWDint-DROP-DEFLT-INV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>
>Chain input_dmz (0 references)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 0
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 3
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 11
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 12
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 14
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 18
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 2 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-ICMP-CRIT '
>     0     0 DROP       icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0
>     0     0 
> reject_func  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>      tcp dpt:113 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:22 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INdmz-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:22 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:53 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INdmz-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:53 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:111 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INdmz-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:111 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:631 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INdmz-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:631 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:10000 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INdmz-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:10000 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED tcp flags:0x16/0x02 LOG flags 6 level 4 
> prefix `SFW2-INdmz-ACC-HiTCP '
>     0     0 
> ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:22 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:53 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:53 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:68 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:111 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:111 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:631 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:631 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:1026 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:10000 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:10000 state NEW
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW udp dpts:1024:65535
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT '
>     0     0 
> LOG        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT '
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state INVALID LOG flags 6 level 4 prefix `SFW2-INdmz-DROP-DEFLT-INV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>
>Chain input_ext (1 references)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-INext-ACC-SOURCEQUENCH '
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4
>     4   208 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 0
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 3
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 11
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 12
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 14
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 18
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 2 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-ICMP-CRIT '
>     0     0 DROP       icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:50 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-ACC-TCP '
>     0     0 
> ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp dpt:50
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:500 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-ACC-TCP '
>     0     0 
> ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp dpt:500
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:53 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-ACC-TCP '
>     0     0 
> ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp dpt:53
>     6   288 
> reject_func  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>      tcp dpt:113 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:22 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:22 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:111 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:111 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:631 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:631 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:10000 flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-DROP '
>     0     0 
> DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp dpt:10000 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED tcp flags:0x16/0x02 LOG flags 6 level 4 
> prefix `SFW2-INext-ACC-HiTCP '
>    84  8464 
> ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:500
>    32  3666 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:22 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:53 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:68 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:111 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:111 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:631 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:631 state NEW
>     1   836 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:1026 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:10000 state NEW
>     0     0 
> DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:10000 state NEW
>     4   964 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW udp dpts:1024:65535
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state ESTABLISHED udp dpts:61000:65095
>   509 25300 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT '
>     9   702 
> LOG        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT '
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state INVALID LOG flags 6 level 4 prefix `SFW2-INext-DROP-DEFLT-INV '
>   526 26418 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>
>Chain input_int (2 references)
>  pkts bytes target     prot opt 
> in     out     source               destination
>    64 17402 
> ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 0
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 3
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 11
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 12
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 14
>     0     0 ACCEPT     icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           state 
> RELATED,ESTABLISHED icmp type 18
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-ICMP-CRIT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 2 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-ICMP-CRIT '
>     0     0 DROP       icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0
>     0     0 
> ACCEPT     esp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED
>     0     0 
> reject_func  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>      tcp dpt:113 flags:0x16/0x02
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED tcp flags:0x16/0x02 LOG flags 6 level 4 
> prefix `SFW2-INint-ACC-HiTCP '
>     0     0 
> ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:1024
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:1025
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state RELATED,ESTABLISHED
>     0     0 
> ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW udp dpts:1024:65535
>     0     0 
> LOG        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    tcp flags:0x16/0x02 LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 4 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 13 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT '
>     0     0 LOG        icmp 
> --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 17 
> LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT '
>     0     0 
> LOG        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT '
>     0     0 
> LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state INVALID LOG flags 6 level 4 prefix `SFW2-INint-DROP-DEFLT-INV '
>     0     0 
> DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
>
>Chain reject_func (3 references)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     6   288 
> REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    reject-with tcp-reset
>     0     0 
> REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    reject-with icmp-port-unreachable
>     0     0 
> REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    reject-with icmp-proto-unreachable
>+ _________________________ ipchains/list
>+ ipchains -L -v -n
>/usr/lib/ipsec/barf: line 238: ipchains: command not found
>+ _________________________ ipfwadm/forward
>+ ipfwadm -F -l -n -e
>/usr/lib/ipsec/barf: line 240: ipfwadm: command not found
>+ _________________________ ipfwadm/input
>+ ipfwadm -I -l -n -e
>/usr/lib/ipsec/barf: line 242: ipfwadm: command not found
>+ _________________________ ipfwadm/output
>+ ipfwadm -O -l -n -e
>/usr/lib/ipsec/barf: line 244: ipfwadm: command not found
>+ _________________________ iptables/nat
>+ iptables -t nat -L -v -n
>Chain PREROUTING (policy ACCEPT 5062 packets, 323K bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>
>Chain POSTROUTING (policy ACCEPT 12 packets, 684 bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>  4525  289K 
> MASQUERADE  all  --  *      ppp0    0.0.0.0/0            0.0.0.0/0
>
>Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>+ _________________________ ipchains/masq
>+ ipchains -M -L -v -n
>/usr/lib/ipsec/barf: line 248: ipchains: command not found
>+ _________________________ ipfwadm/masq
>+ ipfwadm -M -l -n -e
>/usr/lib/ipsec/barf: line 250: ipfwadm: command not found
>+ _________________________ iptables/mangle
>+ iptables -t mangle -L -v -n
>Chain PREROUTING (policy ACCEPT 73743 packets, 23M bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp spt:20 TOS set 0x08
>     0     0 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp dpt:20 TOS set 0x08
>27114   16M 
>TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>  state NEW,RELATED,ESTABLISHED tcp spt:80 TOS set 0x08
>26284 3798K 
>TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>  state NEW,RELATED,ESTABLISHED tcp dpt:80 TOS set 0x08
>     0     0 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp spt:53 TOS set 0x10
>   578 36906 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:53 TOS set 0x10
>     0     0 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:161 TOS set 0x04
>     0     0 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:162 TOS set 0x04
>     0     0 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:514 TOS set 0x04
>
>Chain INPUT (policy ACCEPT 818 packets, 64667 bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 
> MARK       esp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    MARK set 0x1701d
>
>Chain FORWARD (policy ACCEPT 72925 packets, 22M bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>
>Chain OUTPUT (policy ACCEPT 270 packets, 20607 bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>     0     0 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp spt:20 TOS set 0x08
>     0     0 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp dpt:20 TOS set 0x08
>     0     0 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp spt:80 TOS set 0x08
>   102  7108 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp dpt:80 TOS set 0x08
>     0     0 
> TOS        tcp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED tcp spt:53 TOS set 0x10
>    33  2092 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:53 TOS set 0x10
>     0     0 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:161 TOS set 0x04
>     0     0 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    state NEW,RELATED,ESTABLISHED udp dpt:162 TOS set 0x04
>     0     0 
> TOS        udp  --  *      *       0.0.0.0/0            0.0.0.0/0 
>    udp dpt:514 TOS set 0x04
>
>Chain POSTROUTING (policy ACCEPT 73192 packets, 22M bytes)
>  pkts bytes target     prot opt 
> in     out     source               destination
>+ _________________________ proc/modules
>+ cat /proc/modules
>pppoe 13760 2 - Live 0xd2947000
>pppox 3720 1 pppoe, Live 0xd280e000
>usbserial 29040 0 - Live 0xd2e9c000
>parport_pc 35520 1 - Live 0xd2e92000
>lp 11044 0 - Live 0xd2e3f000
>parport 37832 2 parport_pc,lp, Live 0xd2e87000
>edd 9368 0 - Live 0xd2e3b000
>joydev 10304 0 - Live 0xd2d08000
>sg 35616 0 - Live 0xd2e53000
>st 39068 0 - Live 0xd2e48000
>sd_mod 20224 0 - Live 0xd2e1f000
>sr_mod 16292 0 - Live 0xd2e1a000
>scsi_mod 108748 4 sg,st,sd_mod,sr_mod, Live 0xd2e5e000
>ide_cd 36740 0 - Live 0xd2e31000
>cdrom 36764 2 sr_mod,ide_cd, Live 0xd2e27000
>nvram 8456 0 - Live 0xd2dc8000
>deflate 3968 0 - Live 0xd2c37000
>zlib_deflate 22808 1 deflate, Live 0xd2e06000
>twofish 42624 0 - Live 0xd2e0e000
>serpent 17408 0 - Live 0xd2df9000
>aes 30528 0 - Live 0xd2df0000
>blowfish 10496 0 - Live 0xd2da8000
>sha256 10240 0 - Live 0xd2d9b000
>sha1 8960 0 - Live 0xd2d6c000
>crypto_null 2560 0 - Live 0xd2926000
>xfrm_user 13828 0 - Live 0xd2d53000
>ipcomp 7424 0 - Live 0xd2d0c000
>esp4 10368 0 - Live 0xd2d01000
>ah4 7808 0 - Live 0xd2d05000
>af_key 31376 0 - Live 0xd2de7000
>snd_seq_oss 31232 0 - Live 0xd2dde000
>snd_pcm_oss 57512 0 - Live 0xd2dce000
>snd_mixer_oss 18944 1 snd_pcm_oss, Live 0xd2da2000
>snd_seq_midi 9120 0 - Live 0xd2d68000
>snd_seq_midi_event 7680 2 snd_seq_oss,snd_seq_midi, Live 0xd2cfc000
>snd_seq 54928 7 snd_seq_oss,snd_seq_midi,snd_seq_midi_event, Live 0xd2dad000
>speedstep_lib 3712 0 - Live 0xd2c35000
>snd_ens1371 23140 8 - Live 0xd2d79000
>snd_rawmidi 25508 2 snd_seq_midi,snd_ens1371, Live 0xd2d71000
>snd_seq_device 8456 4 snd_seq_oss,snd_seq_midi,snd_seq,snd_rawmidi, Live 
>0xd2d64000
>snd_pcm 97032 2 snd_pcm_oss,snd_ens1371, Live 0xd2d82000
>snd_page_alloc 11528 1 snd_pcm, Live 0xd2d58000
>snd_timer 25860 2 snd_seq,snd_pcm, Live 0xd2d5c000
>snd_ac97_codec 62468 1 snd_ens1371, Live 0xd2d31000
>freq_table 4612 0 - Live 0xd2d1c000
>snd 61444 30 
>snd_seq_oss,snd_pcm_oss,snd_mixer_oss,snd_seq_midi,snd_seq_midi_event,snd_seq,snd_ens1371,snd_rawmidi,snd_seq_device,snd_pcm,snd_timer,snd_ac97_codec, 
>Live 0xd2d42000
>soundcore 9056 1 snd, Live 0xd2d2a000
>gameport 4736 1 snd_ens1371, Live 0xd2d19000
>ipt_MASQUERADE 3840 1 - Live 0xd2d17000
>ppp_generic 29332 6 pppoe,pppox, Live 0xd2d21000
>slhc 7552 1 ppp_generic, Live 0xd2cf9000
>af_packet 20872 4 - Live 0xd2d10000
>ohci_hcd 19332 0 - Live 0xd2cca000
>amd_k7_agp 7820 1 - Live 0xd2928000
>agpgart 30888 1 amd_k7_agp, Live 0xd2cdb000
>evdev 9856 0 - Live 0xd2ca5000
>via_rhine 20104 0 - Live 0xd2c9a000
>mii 5248 1 via_rhine, Live 0xd2c90000
>usbcore 103516 4 usbserial,ohci_hcd, Live 0xd2caf000
>ipt_TCPMSS 4480 1 - Live 0xd2c89000
>ipt_TOS 2688 18 - Live 0xd2c3e000
>ipt_state 2176 95 - Live 0xd2c39000
>ipt_LOG 5760 89 - Live 0xd2c8d000
>ipt_MARK 2304 1 - Live 0xd2c84000
>ipt_mark 1920 1 - Live 0xd2c40000
>ip6t_LOG 5632 2 - Live 0xd2c81000
>ip6t_REJECT 7296 3 - Live 0xd2c42000
>ip6table_mangle 2816 0 - Live 0xd282e000
>ipt_REJECT 6656 3 - Live 0xd2c3b000
>iptable_mangle 3072 1 - Live 0xd283c000
>iptable_filter 2944 1 - Live 0xd2830000
>ip_nat_ftp 4848 0 - Live 0xd2c30000
>iptable_nat 22060 3 ipt_MASQUERADE,ip_nat_ftp, Live 0xd2c29000
>ip_conntrack_ftp 72112 1 ip_nat_ftp, Live 0xd2c16000
>ip_conntrack 31280 5 
>ipt_MASQUERADE,ipt_state,ip_nat_ftp,iptable_nat,ip_conntrack_ftp, Live 
>0xd2c0d000
>ip_tables 17280 11 
>ipt_MASQUERADE,ipt_TCPMSS,ipt_TOS,ipt_state,ipt_LOG,ipt_MARK,ipt_mark,ipt_REJECT,iptable_mangle,iptable_filter,iptable_nat, 
>Live 0xd2920000
>ip6table_filter 2816 1 - Live 0xd2835000
>ip6_tables 18576 4 ip6t_LOG,ip6t_REJECT,ip6table_mangle,ip6table_filter, 
>Live 0xd284c000
>ipv6 237440 24 ip6t_REJECT, Live 0xd2c46000
>subfs 7424 3 - Live 0xd2832000
>dm_mod 50300 0 - Live 0xd283e000
>reiserfs 241360 1 - Live 0xd2853000
>+ _________________________ proc/meminfo
>+ cat /proc/meminfo
>MemTotal:       256656 kB
>MemFree:          7176 kB
>Buffers:         28732 kB
>Cached:          65280 kB
>SwapCached:          0 kB
>Active:         196704 kB
>Inactive:        21480 kB
>HighTotal:           0 kB
>HighFree:            0 kB
>LowTotal:       256656 kB
>LowFree:          7176 kB
>SwapTotal:      512024 kB
>SwapFree:       512012 kB
>Dirty:             276 kB
>Writeback:           0 kB
>Mapped:         159584 kB
>Slab:            23248 kB
>Committed_AS:   242048 kB
>PageTables:       2192 kB
>VmallocTotal:   770040 kB
>VmallocUsed:     36864 kB
>VmallocChunk:   730468 kB
>HugePages_Total:     0
>HugePages_Free:      0
>Hugepagesize:     4096 kB
>+ _________________________ dev/ipsec-ls
>+ ls -l '/dev/ipsec*'
>ls: /dev/ipsec*: No such file or directory
>+ _________________________ proc/net/ipsec-ls
>+ ls -l '/proc/net/ipsec_*'
>ls: /proc/net/ipsec_*: No such file or directory
>+ _________________________ usr/src/linux/.config
>+ test -f /usr/src/linux/.config
>+ _________________________ etc/syslog.conf
>+ cat /etc/syslog.conf
># /etc/syslog.conf - Configuration file for syslogd(8)
>#
># For info about the format of this file, see "man syslog.conf".
>#
>
>#
>#
># print most on tty10 and on the xconsole pipe
>#
>kern.warning;*.err;authpriv.none        /dev/tty10
>kern.warning;*.err;authpriv.none        |/dev/xconsole
>*.emerg                         *
>
># enable this, if you want that root is informed
># immediately, e.g. of logins
>#*.alert                                root
>
>
>#
># all email-messages in one file
>#
>mail.*                          -/var/log/mail
>mail.info                       -/var/log/mail.info
>mail.warning                    -/var/log/mail.warn
>mail.err                        /var/log/mail.err
>
>#
># all news-messages
>#
># these files are rotated and examined by "news.daily"
>news.crit                       -/var/log/news/news.crit
>news.err                        -/var/log/news/news.err
>news.notice                     -/var/log/news/news.notice
># enable this, if you want to keep all news messages
># in one file
>#news.*                         -/var/log/news.all
>
>#
># Warnings in one file
>#
>*.=warning;*.=err               -/var/log/warn
>*.crit                          /var/log/warn
>
>#
># save the rest in one file
>#
>*.*;mail.none;news.none         -/var/log/messages
>
>#
># enable this, if you want to keep all messages
># in one file
>#*.*                            -/var/log/allmessages
>
>#
># Some foreign boot scripts require local7
>#
>local0,local1.*                 -/var/log/localmessages
>local2,local3.*                 -/var/log/localmessages
>local4,local5.*                 -/var/log/localmessages
>local6,local7.*                 -/var/log/localmessages
>
>authpriv.* /var/log/security
>authpriv.none /var/log/messages
>
>+ _________________________ etc/resolv.conf
>+ cat /etc/resolv.conf
>### BEGIN INFO
>#
># Modified_by:  smpppd-ifcfg
># Backup:       /etc/resolv.conf.saved.by.smpppd-ifcfg
># Process:      smpppd-ifcfg
># Process_id:   4157
># Script:       /usr/sbin/smpppd-ifcfg
># Saveto:
># Info:         This is a temporary resolv.conf created by service
>#               smpppd-ifcfg.  The previous file has been saved and will be
>#               restored later.
>#
>#               If you don't like your resolv.conf to be changed, you
>#               can set MODIFY_{RESOLV,NAMED}_CONF_DYNAMICALLY=no. This
>#               variables are placed in /etc/sysconfig/network/config.
>#
>#               You can also configure service smpppd-ifcfg not to
>#               modify it.
>#
>#               If you do not want the smpppd to change your nameserver
>#               settings
>#               set MODIFYDNS=no in the config file for this provider in
>#               /etc/sysconfig/network/providers/.
>#
>### END INFO
>nameserver 217.237.149.161
>nameserver 194.25.2.129
>+ _________________________ lib/modules-ls
>+ ls -ltr /lib/modules
>total 0
>drwxr-xr-x  3 root root 104 Jul  1 19:18 scripts
>drwxr-xr-x  2 root root  48 Jul  1 19:18 2.6.5-override-default
>drwxr-xr-x  3 root root  88 Jul 26 20:14 precompiled
>drwxr-xr-x  4 root root 448 Jul 26 20:24 2.6.5-7.95-default
>+ _________________________ proc/ksyms-netif_rx
>+ egrep netif_rx /proc/ksyms
>grep: /proc/ksyms: No such file or directory
>+ _________________________ lib/modules-netif_rx
>+ modulegoo kernel/net/ipv4/ipip.o netif_rx
>+ set +x
>2.6.5-7.95-default:
>2.6.5-override-default:
>precompiled:
>scripts:
>+ _________________________ kern.debug
>+ test -f /var/log/kern.debug
>+ _________________________ klog
>+ sed -n '8587,$p' /var/log/messages
>+ egrep -i 'ipsec|klips|pluto'
>+ cat
>Aug  9 08:54:42 mngateway ipsec_setup: Starting FreeS/WAN IPsec 2.04...
>Aug  9 08:54:42 mngateway ipsec_setup: KLIPS ipsec0 on ppp0 
>80.130.191.226/255.255.255.255 pointopoint 217.5.98.30
>Aug  9 08:54:42 mngateway ipsec__plutorun: Starting Pluto subsystem...
>Aug  9 08:54:42 mngateway ipsec_setup: ...FreeS/WAN IPsec started
>Aug  9 08:54:42 mngateway pluto[9213]: Starting Pluto (FreeS/WAN Version 
>2.04 X.509-1.5.3 LIBCURL PLUTO_USES_KEYRR)
>Aug  9 08:54:42 mngateway pluto[9213]:   including NAT-Traversal patch 
>(Version 0.6) [disabled]
>Aug  9 08:54:42 mngateway pluto[9213]: Using Linux 2.6 IPsec interface code
>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/cacerts'
>Aug  9 08:54:42 mngateway pluto[9213]:   loaded CA cert file 
>'MultinovaCA-cert.pem' (1294 bytes)
>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/aacerts'
>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/ocspcerts'
>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/crls'
>Aug  9 08:54:43 mngateway pluto[9213]:   loaded host cert file 
>'/etc/ipsec.d/certs/mnvpngw-cert.pem' (4507 bytes)
>Aug  9 08:54:43 mngateway pluto[9213]: added connection description 
>"L2TP-CERT"
>Aug  9 08:54:43 mngateway pluto[9213]: listening for IKE messages
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface ppp0/ppp0 
>80.130.191.226
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface eth0/eth0 192.6.2.12
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface lo/lo 127.0.0.1
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface lo/lo ::1
>Aug  9 08:54:43 mngateway pluto[9213]: loading secrets from 
>"/etc/ipsec.secrets"
>Aug  9 08:55:24 mngateway pluto[9213]: loading secrets from 
>"/etc/ipsec.secrets"
>+ _________________________ plog
>+ sed -n '8589,$p' /var/log/messages
>+ egrep -i pluto
>+ cat
>Aug  9 08:54:42 mngateway ipsec__plutorun: Starting Pluto subsystem...
>Aug  9 08:54:42 mngateway pluto[9213]: Starting Pluto (FreeS/WAN Version 
>2.04 X.509-1.5.3 LIBCURL PLUTO_USES_KEYRR)
>Aug  9 08:54:42 mngateway pluto[9213]:   including NAT-Traversal patch 
>(Version 0.6) [disabled]
>Aug  9 08:54:42 mngateway pluto[9213]: Using Linux 2.6 IPsec interface code
>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/cacerts'
>Aug  9 08:54:42 mngateway pluto[9213]:   loaded CA cert file 
>'MultinovaCA-cert.pem' (1294 bytes)

OK

>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/aacerts'
>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/ocspcerts'
>Aug  9 08:54:42 mngateway pluto[9213]: Changing to directory 
>'/etc/ipsec.d/crls'
>Aug  9 08:54:43 mngateway pluto[9213]:   loaded host cert file 
>'/etc/ipsec.d/certs/mnvpngw-cert.pem' (4507 bytes)

OK

>Aug  9 08:54:43 mngateway pluto[9213]: added connection description 
>"L2TP-CERT"
>Aug  9 08:54:43 mngateway pluto[9213]: listening for IKE messages
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface ppp0/ppp0 
>80.130.191.226
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface eth0/eth0 192.6.2.12
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface lo/lo 127.0.0.1
>Aug  9 08:54:43 mngateway pluto[9213]: adding interface lo/lo ::1
>Aug  9 08:54:43 mngateway pluto[9213]: loading secrets from 
>"/etc/ipsec.secrets"
>Aug  9 08:55:24 mngateway pluto[9213]: loading secrets from 
>"/etc/ipsec.secrets"

Why is this twice?

>+ _________________________ date
>+ date
>Mon Aug  9 08:56:33 CEST 2004


Here there seems to be no connection attempt at all and I cannot see a 
private key to be loaded. Did you access the gateway at all?

I have no experience with 2.6 so maybe someone else can shed more light on 
this.

cheers
Erich

THINK
Püntenstrasse 39
8143 Stallikon
mailto:[email protected]
PGP Fingerprint: BC9A 25BC 3954 3BC8 C024 8D8A B7D4 FF9D 05B8 0A16
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.