diff options
Diffstat (limited to 'regress/sbin/ipsecctl/ike13.ok')
-rw-r--r-- | regress/sbin/ipsecctl/ike13.ok | 57 |
1 files changed, 51 insertions, 6 deletions
diff --git a/regress/sbin/ipsecctl/ike13.ok b/regress/sbin/ipsecctl/ike13.ok index 29d0cb1baea..3af68e7a7a9 100644 --- a/regress/sbin/ipsecctl/ike13.ok +++ b/regress/sbin/ipsecctl/ike13.ok @@ -4,14 +4,29 @@ C set [peer-1.1.1.1]:Phase=1 force C set [peer-1.1.1.1]:Address=1.1.1.1 force C set [peer-1.1.1.1]:Configuration=phase1-peer-1.1.1.1 force C set [phase1-peer-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force -C add [phase1-peer-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force +C add [phase1-peer-1.1.1.1]:Transforms=phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force C set [from-2.2.2.0/24-to-1.1.1.1]:Phase=2 force C set [from-2.2.2.0/24-to-1.1.1.1]:ISAKMP-peer=peer-1.1.1.1 force C set [from-2.2.2.0/24-to-1.1.1.1]:Configuration=phase2-from-2.2.2.0/24-to-1.1.1.1 force C set [from-2.2.2.0/24-to-1.1.1.1]:Local-ID=from-2.2.2.0/24 force C set [from-2.2.2.0/24-to-1.1.1.1]:Remote-ID=to-1.1.1.1 force C set [phase2-from-2.2.2.0/24-to-1.1.1.1]:EXCHANGE_TYPE=QUICK_MODE force -C set [phase2-from-2.2.2.0/24-to-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [phase2-from-2.2.2.0/24-to-1.1.1.1]:Suites=phase2-suite-from-2.2.2.0/24-to-1.1.1.1 force +C set [phase2-suite-from-2.2.2.0/24-to-1.1.1.1]:Protocols=phase2-protocol-from-2.2.2.0/24-to-1.1.1.1 force +C set [phase2-protocol-from-2.2.2.0/24-to-1.1.1.1]:PROTOCOL_ID=IPSEC_ESP force +C set [phase2-protocol-from-2.2.2.0/24-to-1.1.1.1]:Transforms=phase2-transform-from-2.2.2.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force +C set [phase2-transform-from-2.2.2.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force +C set [phase2-transform-from-2.2.2.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force +C set [phase2-transform-from-2.2.2.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force +C set [phase2-transform-from-2.2.2.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force +C set [phase2-transform-from-2.2.2.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase2-transform-from-2.2.2.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force C set [from-2.2.2.0/24]:ID-type=IPV4_ADDR_SUBNET force C set [from-2.2.2.0/24]:Network=2.2.2.0 force C set [from-2.2.2.0/24]:Netmask=255.255.255.0 force @@ -23,14 +38,29 @@ C set [peer-1.1.1.1]:Phase=1 force C set [peer-1.1.1.1]:Address=1.1.1.1 force C set [peer-1.1.1.1]:Configuration=phase1-peer-1.1.1.1 force C set [phase1-peer-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force -C add [phase1-peer-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force +C add [phase1-peer-1.1.1.1]:Transforms=phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force C set [from-3.3.3.0/24-to-1.1.1.1]:Phase=2 force C set [from-3.3.3.0/24-to-1.1.1.1]:ISAKMP-peer=peer-1.1.1.1 force C set [from-3.3.3.0/24-to-1.1.1.1]:Configuration=phase2-from-3.3.3.0/24-to-1.1.1.1 force C set [from-3.3.3.0/24-to-1.1.1.1]:Local-ID=from-3.3.3.0/24 force C set [from-3.3.3.0/24-to-1.1.1.1]:Remote-ID=to-1.1.1.1 force C set [phase2-from-3.3.3.0/24-to-1.1.1.1]:EXCHANGE_TYPE=QUICK_MODE force -C set [phase2-from-3.3.3.0/24-to-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [phase2-from-3.3.3.0/24-to-1.1.1.1]:Suites=phase2-suite-from-3.3.3.0/24-to-1.1.1.1 force +C set [phase2-suite-from-3.3.3.0/24-to-1.1.1.1]:Protocols=phase2-protocol-from-3.3.3.0/24-to-1.1.1.1 force +C set [phase2-protocol-from-3.3.3.0/24-to-1.1.1.1]:PROTOCOL_ID=IPSEC_ESP force +C set [phase2-protocol-from-3.3.3.0/24-to-1.1.1.1]:Transforms=phase2-transform-from-3.3.3.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force +C set [phase2-transform-from-3.3.3.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force +C set [phase2-transform-from-3.3.3.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force +C set [phase2-transform-from-3.3.3.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force +C set [phase2-transform-from-3.3.3.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force +C set [phase2-transform-from-3.3.3.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase2-transform-from-3.3.3.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force C set [from-3.3.3.0/24]:ID-type=IPV4_ADDR_SUBNET force C set [from-3.3.3.0/24]:Network=3.3.3.0 force C set [from-3.3.3.0/24]:Netmask=255.255.255.0 force @@ -42,14 +72,29 @@ C set [peer-1.1.1.1]:Phase=1 force C set [peer-1.1.1.1]:Address=1.1.1.1 force C set [peer-1.1.1.1]:Configuration=phase1-peer-1.1.1.1 force C set [phase1-peer-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force -C add [phase1-peer-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force +C add [phase1-peer-1.1.1.1]:Transforms=phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase1-transform-peer-1.1.1.1-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force C set [from-4.4.4.0/24-to-1.1.1.1]:Phase=2 force C set [from-4.4.4.0/24-to-1.1.1.1]:ISAKMP-peer=peer-1.1.1.1 force C set [from-4.4.4.0/24-to-1.1.1.1]:Configuration=phase2-from-4.4.4.0/24-to-1.1.1.1 force C set [from-4.4.4.0/24-to-1.1.1.1]:Local-ID=from-4.4.4.0/24 force C set [from-4.4.4.0/24-to-1.1.1.1]:Remote-ID=to-1.1.1.1 force C set [phase2-from-4.4.4.0/24-to-1.1.1.1]:EXCHANGE_TYPE=QUICK_MODE force -C set [phase2-from-4.4.4.0/24-to-1.1.1.1]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [phase2-from-4.4.4.0/24-to-1.1.1.1]:Suites=phase2-suite-from-4.4.4.0/24-to-1.1.1.1 force +C set [phase2-suite-from-4.4.4.0/24-to-1.1.1.1]:Protocols=phase2-protocol-from-4.4.4.0/24-to-1.1.1.1 force +C set [phase2-protocol-from-4.4.4.0/24-to-1.1.1.1]:PROTOCOL_ID=IPSEC_ESP force +C set [phase2-protocol-from-4.4.4.0/24-to-1.1.1.1]:Transforms=phase2-transform-from-4.4.4.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force +C set [phase2-transform-from-4.4.4.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force +C set [phase2-transform-from-4.4.4.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force +C set [phase2-transform-from-4.4.4.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force +C set [phase2-transform-from-4.4.4.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force +C set [phase2-transform-from-4.4.4.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force +C set [phase2-transform-from-4.4.4.0/24-to-1.1.1.1-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force C set [from-4.4.4.0/24]:ID-type=IPV4_ADDR_SUBNET force C set [from-4.4.4.0/24]:Network=4.4.4.0 force C set [from-4.4.4.0/24]:Netmask=255.255.255.0 force |