12.07.2015 Views

download

download

download

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

[ 143 ]Chapter 8At this point, there is no SA established between two hosts, as there has been notraffic between the hosts, so far. This can be verified using the setkey –D commandas follows:# setkey -DNo SAD entries.Once you ping the other side of the tunnel, the IKE daemons should exchangeencryption keys and establish SA:# ping -oq 10.10.6.1PING 10.10.6.1 (10.10.6.1): 56 data bytes--- 10.10.6.1 ping statistics ---1 packets transmitted, 1 packets received, 0.0% packet lossround-trip min/avg/max/stddev = 87.537/87.537/87.537/0.000 msNow that the host is reachable, it means the SA is established and the keysare installed.# setkey -D192.168.0.5 192.168.0.6esp mode=transport spi=85769720(0x051cbdf8)reqid=0(0x00000000)E: 3des-cbc 26715dcd c77affd3 39165b39 073637a1 ee8b979deebd8368A: hmac-sha1 6eb62659 5058e91e e36b19ab abec245c 76bd67bdseq=0x00000007 replay=4 flags=0x00000000 state=maturecreated: Jun 23 23:50:09 2007 current: Jun 23 23:51:49 2007diff: 100(s) hard: 43200(s) soft: 34560(s)last: Jun 23 23:51:10 2007 hard: 0(s) soft: 0(s)current: 952(bytes) hard: 0(bytes) soft: 0(bytes)allocated: 7 hard: 0 soft: 0sadb_seq=1 pid=1554 refcnt=2192.168.0.6 192.168.0.5esp mode=transport spi=61669162(0x03acff2a)reqid=0(0x00000000)E: 3des-cbc 99792546 3c0e0a2c 9cde2a3b be503817 4efc7422573d7014A: hmac-sha1 f3da6e46 10bec5b7 0e21f167 2387136e 656da322seq=0x00000006 replay=4 flags=0x00000000 state=maturecreated: Jun 23 23:50:09 2007 current: Jun 23 23:51:49 2007diff: 100(s) hard: 43200(s) soft: 34560(s)last: Jun 23 23:51:10 2007 hard: 0(s) soft: 0(s)current: 624(bytes) hard: 0(bytes) soft: 0(bytes)allocated: 6 hard: 0 soft: 0sadb_seq=0 pid=1554 refcnt=1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!