Oct 27 10:11:02 inet pluto[16342]: packet from 192.168.1.3:500: ignoring Vendor ID payload [MS NT5 ISAKMPOAKLEY 00000006] Oct 27 10:11:02 inet pluto[16342]: packet from 192.168.1.3:500: received Vendor ID payload [RFC 3947] method set to=109 Oct 27 10:11:02 inet pluto[16342]: packet from 192.168.1.3:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but already using method 109 Oct 27 10:11:02 inet pluto[16342]: packet from 192.168.1.3:500: ignoring Vendor ID payload [FRAGMENTATION] Oct 27 10:11:02 inet pluto[16342]: packet from 192.168.1.3:500: ignoring Vendor ID payload [MS-Negotiation Discovery Capable] Oct 27 10:11:02 inet pluto[16342]: packet from 192.168.1.3:500: ignoring Vendor ID payload [Vid-Initial-Contact] Oct 27 10:11:02 inet pluto[16342]: packet from 192.168.1.3:500: ignoring Vendor ID payload [IKE CGA version 1] Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: responding to Main Mode from unknown peer 192.168.1.3 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: OAKLEY_GROUP 20 not supported. Attribute OAKLEY_GROUP_DESCRIPTION Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: OAKLEY_GROUP 19 not supported. Attribute OAKLEY_GROUP_DESCRIPTION Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: STATE_MAIN_R1: sent MR1, expecting MI2 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: NAT-Traversal: Result using RFC 3947 (NAT-Traversal): peer is NATed Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: STATE_MAIN_R2: sent MR2, expecting MI3 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: Main mode peer ID is ID_DER_ASN1_DN: 'C=BR, ST=Sao Paulo, L=Piracicaba, O=Teste Co, CN=mr.testdomain.com.br' Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: I am sending my cert Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: new NAT mapping for #6, was 192.168.1.3:500, now 192.168.1.3:4500 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=OAKLEY_RSA_SIG cipher=oakley_3des_cbc_192 prf=oakley_sha group=modp2048} Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: the peer proposed: 192.168.1.67/32:17/1701 -> 172.31.72.99/32:17/1701 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: NAT-Traversal: received 2 NAT-OA. using first, ignoring others Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[4] 192.168.1.3 #7: responding to Quick Mode proposal {msgid:01000000} Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[4] 192.168.1.3 #7: us: 192.168.1.67<192.168.1.67>[+S=C]:17/1701 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[4] 192.168.1.3 #7: them: 192.168.1.3[C=BR, ST=Sao Paulo, L=Piracicaba, O=Teste Co, CN=mr.testdomain.com.br,+S=C]:17/1701===172.31.72.99/32 Oct 27 10:11:02 inet pluto[16342]: | NAT-OA: 32 tunnel: 0 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[4] 192.168.1.3 #7: transition from state STATE_QUICK_R0 to state STATE_QUICK_R1 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[4] 192.168.1.3 #7: STATE_QUICK_R1: sent QR1, inbound IPsec SA installed, expecting QI2 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[4] 192.168.1.3 #7: transition from state STATE_QUICK_R1 to state STATE_QUICK_R2 Oct 27 10:11:02 inet pluto[16342]: "MR-Co"[4] 192.168.1.3 #7: STATE_QUICK_R2: IPsec SA established tunnel mode {ESP=>0x38addd62 <0xc5b65e26 xfrm=AES_128-HMAC_SHA1 NATOA=172.31.72.99 NATD=192.168.1.3:4500 DPD=none} Oct 27 10:12:33 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: the peer proposed: 192.168.1.67/32:17/1701 -> 172.31.72.99/32:17/1701 Oct 27 10:12:34 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: NAT-Traversal: received 2 NAT-OA. using first, ignoring others Oct 27 10:12:34 inet pluto[16342]: "MR-Co"[5] 192.168.1.3 #8: responding to Quick Mode proposal {msgid:02000000} Oct 27 10:12:34 inet pluto[16342]: "MR-Co"[5] 192.168.1.3 #8: us: 192.168.1.67<192.168.1.67>[+S=C]:17/1701 Oct 27 10:12:34 inet pluto[16342]: "MR-Co"[5] 192.168.1.3 #8: them: 192.168.1.3[C=BR, ST=Sao Paulo, L=Piracicaba, O=Teste Co, CN=mr.testdomain.com.br,+S=C]:17/1701===172.31.72.99/32 Oct 27 10:12:34 inet pluto[16342]: | NAT-OA: 32 tunnel: 0 Oct 27 10:12:34 inet pluto[16342]: "MR-Co"[5] 192.168.1.3 #8: cannot install eroute -- it is in use for "MR-Co"[4] 192.168.1.3 #7 Oct 27 10:12:35 inet pluto[16342]: "MR-Co"[5] 192.168.1.3 #8: discarding duplicate packet; already STATE_QUICK_R0 Oct 27 10:12:38 inet pluto[16342]: "MR-Co"[5] 192.168.1.3 #8: discarding duplicate packet; already STATE_QUICK_R0 Oct 27 10:12:39 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: received Delete SA(0x38addd62) payload: deleting IPSEC State #7 Oct 27 10:12:40 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: deleting connection "MR-Co" instance with peer 192.168.1.3 {isakmp=#0/ipsec=#0} Oct 27 10:12:40 inet pluto[16342]: "MR-Co"[2] 192.168.1.3 #6: received and ignored informational message Oct 27 10:12:43 inet pluto[16342]: "MR-Co"[5] 192.168.1.3 #8: discarding duplicate packet; already STATE_QUICK_R0