Unique

Tests for the unique connection option, which controls what happens when a peer (identified by remote IKE identity) establishes a new SA while an existing one is already active. Although these tests use site-to-site peer configurations, the unique option behaves identically for DMVPN profiles. DUT0 acts as responder. DUT1 and DUT2 share the same IKE identity (roadwarrior) to trigger the uniqueness check on DUT0. Tests are split into two groups: proactive tests use unique never on initiators, so they do NOT send INITIAL_CONTACT (isolating the responder’s proactive uniqueness check), and INITIAL_CONTACT tests use the default unique (no) on initiators, so they DO send INITIAL_CONTACT (testing the responder’s reaction to peer-initiated cleanup).

Test Never Without Initial Contact

Description

With unique = never and no INITIAL_CONTACT, no uniqueness checks are performed. Both SAs coexist without restriction.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX19W1ScZzRZkTDm4xvh8ijCAY63J1+HTQ0g=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/HVv284Um+CWQCjfbJW0BmCBv/p6+YIHM=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.578 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.578/0.578/0.578/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.616 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.616/0.616/0.616/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique never

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique never

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 74e937d148b68d02_i 6d1bdb5013e2f72f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 16091s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3343s, expires in 3960s
in  cc767e52,      0 bytes,     0 packets
out c0da2829,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/XA+U4dMfo682lu2ICYdJ/WutH/qQtM8Y=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique never

Step 11: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=0.238 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.238/0.238/0.238/0.000 ms

Step 12: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.2\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, 9b45b054c50f62f4_i 03e3672ec7c271dd_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 5s ago, rekeying in 24512s
peer-PEER-tunnel-1: #5, reqid 2, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 5s ago, rekeying in 3325s, expires in 3955s
in  c59b33d1,      0 bytes,     0 packets
out cfc3c490,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 74e937d148b68d02_i 6d1bdb5013e2f72f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 8s ago, rekeying in 16083s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 8s ago, rekeying in 3335s, expires in 3952s
in  cc767e52,      0 bytes,     0 packets
out c0da2829,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 13: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, 9b45b054c50f62f4_i 03e3672ec7c271dd_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 5s ago, rekeying in 24512s
peer-PEER-tunnel-1: #5, reqid 2, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 5s ago, rekeying in 3325s, expires in 3955s
in  c59b33d1,      0 bytes,     0 packets
out cfc3c490,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 74e937d148b68d02_i 6d1bdb5013e2f72f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 8s ago, rekeying in 16083s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 8s ago, rekeying in 3335s, expires in 3952s
in  cc767e52,      0 bytes,     0 packets
out c0da2829,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Test No Without Initial Contact

Description

With unique = no and no INITIAL_CONTACT, no proactive duplicate check is performed. Both SAs coexist.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX19XFi1wVjFzDNAO5AyedHbVBFBQ4lY1gsI=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/KZ0hINBfBEBZjoyouWo7njx04KEyH6Kg=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.607 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.607/0.607/0.607/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.270 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.270/0.270/0.270/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique no

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique never

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 01ee03778d6a827f_i 5b613c096e04ea10_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 18989s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3318s, expires in 3960s
in  c18d2c6d,      0 bytes,     0 packets
out c0ea4ea7,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/SALKf8bAPWY+Xg4fwBKX937hFs4gw02M=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique never

Step 11: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=0.316 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.316/0.316/0.316/0.000 ms

Step 12: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.2\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, 3b35bf47040d1ab8_i 96ee3aca2188995f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 15939s
peer-PEER-tunnel-1: #5, reqid 2, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3337s, expires in 3954s
in  c5eca4b3,      0 bytes,     0 packets
out cda1b73a,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 01ee03778d6a827f_i 5b613c096e04ea10_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 9s ago, rekeying in 18980s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 9s ago, rekeying in 3309s, expires in 3951s
in  c18d2c6d,      0 bytes,     0 packets
out c0ea4ea7,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 13: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, 3b35bf47040d1ab8_i 96ee3aca2188995f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 15939s
peer-PEER-tunnel-1: #5, reqid 2, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3337s, expires in 3954s
in  c5eca4b3,      0 bytes,     0 packets
out cda1b73a,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 01ee03778d6a827f_i 5b613c096e04ea10_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 9s ago, rekeying in 18980s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 9s ago, rekeying in 3309s, expires in 3951s
in  c18d2c6d,      0 bytes,     0 packets
out c0ea4ea7,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Test Replace Without Initial Contact

Description

With unique = replace and no INITIAL_CONTACT, the responder proactively detects the duplicate and accepts the new SA. DUT1 may auto-reconnect, so we only verify that DUT2’s SA is accepted (unlike keep which rejects it).

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/Cv01wBOIIAlW+CGhPwlBk3XNTWFFkmH0=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/bjIJ6nwJwEWslc15sCSWE7NrekKCTdwg=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.610 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.610/0.610/0.610/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.286 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.286/0.286/0.286/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique replace

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique never

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 49553956a6750404_i d448fca977bf8623_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 13476s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3288s, expires in 3960s
in  c046b30f,      0 bytes,     0 packets
out ca312b52,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/adENdsHWNInzNEvNpLWrRu86NTCHOCp0=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique never

Step 11: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=0.280 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.280/0.280/0.280/0.000 ms

Step 12: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
(unnamed): #702, CONNECTING, IKEv2, 2bc7bd1f0598efe7_i d5a9e30ea8d6df7f_r*
local  '%any' @ 80.0.0.1[500]
remote '%any' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
passive: IKE_INIT IKE_CERT_PRE IKE_AUTH IKE_CERT_POST IKE_CONFIG IKE_MOBIKE IKE_ESTABLISH IKE_AUTH_LIFETIME CHILD_CREATE
vpn-peer-PEER: #701, ESTABLISHED, IKEv2, fdb11eb449ec2641_i 8a76f6e6f9ffb7a4_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 19106s
peer-PEER-tunnel-1: #702, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3375s, expires in 3960s
in  ca2ea67b,      0 bytes,     0 packets
out ceeda16c,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Test Keep Without Initial Contact

Description

With unique = keep and no INITIAL_CONTACT, the responder proactively detects the duplicate and rejects the new connection from a different IP, keeping the existing SA. If the peer reconnects from the same IP, the new connection is allowed (treated as reauthentication).

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX19nyq1ZU+0/GPA1zBoBAllvXfVgDTBlvsw=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/IKphH02NzSfFSSOP3arWLB+5bwzBleGE=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.506 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.506/0.506/0.506/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.505 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.505/0.505/0.505/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique keep

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique never

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 2a654943060366d9_i 2a5e228ce26e299f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 14884s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3489s, expires in 3960s
in  cefcdb27,      0 bytes,     0 packets
out cfb5ac47,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/J4RoxdhxLFRbvmqgba6gyZ7ksnGS/uu0=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique never

Step 11: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=0.267 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.267/0.267/0.267/0.000 ms

Step 12: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.2\[500\].*INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 2a654943060366d9_i 2a5e228ce26e299f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 8s ago, rekeying in 14876s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 8s ago, rekeying in 3481s, expires in 3952s
in  cefcdb27,      0 bytes,     0 packets
out cfb5ac47,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 13: Expect a failure in the following command: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 2a654943060366d9_i 2a5e228ce26e299f_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 8s ago, rekeying in 14876s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 8s ago, rekeying in 3481s, expires in 3952s
in  cefcdb27,      0 bytes,     0 packets
out cfb5ac47,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Test Never Ignores Initial Contact

Description

With unique = never, INITIAL_CONTACT notifications from the peer are ignored. Both SAs coexist even when the new peer sends INITIAL_CONTACT.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX18BuxDkPh+UewcV+kGnX1zsqVyGHyWF4sw=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX19XZd2s7DE/hgY5+vdmSxgXS6A13bwA1pY=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.459 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.459/0.459/0.459/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.320 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.320/0.320/0.320/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique never

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique no

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, e80a2c41731ee49a_i d9d7c99c5849fea3_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 18300s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3327s, expires in 3960s
in  cc7f82a2,      0 bytes,     0 packets
out c1729b27,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX19otmm4V+hIR9uuypMEiT0kAxlTEunb+rk=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique no

Step 11: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=0.252 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.252/0.252/0.252/0.000 ms

Step 12: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.2\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, 7905561f0041380d_i 541c28012f74cf3d_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 5s ago, rekeying in 23721s
peer-PEER-tunnel-1: #5, reqid 2, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 5s ago, rekeying in 3498s, expires in 3955s
in  ce52ab5e,      0 bytes,     0 packets
out cc9d933c,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, e80a2c41731ee49a_i d9d7c99c5849fea3_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 8s ago, rekeying in 18292s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 8s ago, rekeying in 3319s, expires in 3952s
in  cc7f82a2,      0 bytes,     0 packets
out c1729b27,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 13: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, 7905561f0041380d_i 541c28012f74cf3d_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 5s ago, rekeying in 23721s
peer-PEER-tunnel-1: #5, reqid 2, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 5s ago, rekeying in 3498s, expires in 3955s
in  ce52ab5e,      0 bytes,     0 packets
out cc9d933c,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, e80a2c41731ee49a_i d9d7c99c5849fea3_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 8s ago, rekeying in 18292s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 8s ago, rekeying in 3319s, expires in 3952s
in  cc7f82a2,      0 bytes,     0 packets
out c1729b27,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Test No Reacts To Initial Contact

Description

With unique = no, the responder does not proactively check for duplicates but does delete existing SAs when the new peer sends INITIAL_CONTACT.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/YI6B4ot0wkpaXyBvLNx8xv5QLP//sk+M=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX18zlhkXZn6yn1LMfKHpn9QlaThuoDtFlBg=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.469 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.469/0.469/0.469/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.359 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.359/0.359/0.359/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique no

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique no

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 5c9e115b1bbaa3f0_i b85d053e977588c8_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 14022s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3282s, expires in 3960s
in  c9bfabde,      0 bytes,     0 packets
out cc25ed58,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Modify the following configuration lines in DUT1 :

set interfaces ethernet eth0 disable

Step 11: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX18ns/nyvUD6JshdnhpjbWUZED/4xnm+YTc=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique no

Step 12: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=0.294 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.294/0.294/0.294/0.000 ms

Step 13: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, ea7179b8af655e21_i 2f3cd1ee7e24b4fe_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 22942s
peer-PEER-tunnel-1: #5, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3316s, expires in 3954s
in  c520d188,      0 bytes,     0 packets
out c5f5f18c,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24

Step 14: Expect a failure in the following command: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.2\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, ea7179b8af655e21_i 2f3cd1ee7e24b4fe_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 22942s
peer-PEER-tunnel-1: #5, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3316s, expires in 3954s
in  c520d188,      0 bytes,     0 packets
out c5f5f18c,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24

Test Replace Reacts To Initial Contact

Description

With unique = replace, the responder also reacts to INITIAL_CONTACT from the new peer, destroying existing SAs for the same identity.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX18o7KB6u6xgtKCl/8EfnO7xwZPxfLRKl3U=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX19zci4O341Ixw3UX6gnqveXnUrRx0TgUzk=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.470 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.470/0.470/0.470/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.270 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.270/0.270/0.270/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique replace

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique no

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, c77072ffba69f0e6_i 7100e401f04f0b76_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 15591s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3270s, expires in 3960s
in  c710c461,      0 bytes,     0 packets
out c73ea294,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Modify the following configuration lines in DUT1 :

set interfaces ethernet eth0 disable

Step 11: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX18h9kI87uW1rYWhOcgAmhuB6NSVePfVpdQ=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique no

Step 12: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=6.27 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 6.268/6.268/6.268/0.000 ms

Step 13: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, a6e06699d94904cb_i 5e0b7f2e361f978b_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 24123s
peer-PEER-tunnel-1: #5, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3514s, expires in 3954s
in  c36422de,      0 bytes,     0 packets
out c5b40cfb,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24

Step 14: Expect a failure in the following command: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.2\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, a6e06699d94904cb_i 5e0b7f2e361f978b_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 24123s
peer-PEER-tunnel-1: #5, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3514s, expires in 3954s
in  c36422de,      0 bytes,     0 packets
out c5b40cfb,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24

Test Keep With Initial Contact

Description

With unique = keep, if the new peer sends INITIAL_CONTACT, the existing SA is destroyed regardless of the keep policy. INITIAL_CONTACT is processed before evaluating the unique policy.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces dummy dum0 address 10.1.0.1/24
set interfaces ethernet eth0 address 80.0.0.1/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX18+YzgVVl2Mr79hv3omRQx3vg1dXGcHzZo=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type respond
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.1
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.2
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.3.0.0/24

Step 2: Set the following configuration in DUT1 :

set interfaces dummy dum0 address 10.3.0.1/24
set interfaces ethernet eth0 address 80.0.0.2/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1873Y7bYPq4QwYqypqgyPcpveZgUaL6e34=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.2
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.3.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24

Step 3: Ping the IP address 80.0.0.1 from DUT1:

admin@DUT1$ ping 80.0.0.1 count 1 size 56 timeout 1
Show output
PING 80.0.0.1 (80.0.0.1) 56(84) bytes of data.
64 bytes from 80.0.0.1: icmp_seq=1 ttl=64 time=0.285 ms

--- 80.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.285/0.285/0.285/0.000 ms

Step 4: Ping the IP address 80.0.0.2 from DUT0:

admin@DUT0$ ping 80.0.0.2 count 1 size 56 timeout 1
Show output
PING 80.0.0.2 (80.0.0.2) 56(84) bytes of data.
64 bytes from 80.0.0.2: icmp_seq=1 ttl=64 time=0.267 ms

--- 80.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.267/0.267/0.267/0.000 ms

Step 5: Modify the following configuration lines in DUT0 :

delete vpn ipsec site-to-site peer PEER remote-address
set vpn ipsec auth-profile AUTH-SA local id server
set vpn ipsec auth-profile AUTH-SA remote id roadwarrior
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 0.0.0.0/0
set vpn ipsec site-to-site peer PEER unique keep

Step 6: Modify the following configuration lines in DUT1 :

set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec site-to-site peer PEER unique no

Step 7: Run the command vpn ipsec clear sa on DUT1 and expect the following output:

Show output
Closed tunnels: 1

Step 8: Run the command vpn ipsec initiate peer PEER tunnel 1 on DUT1 and expect the following output:

Show output
Initiated tunnels: 1

Step 9: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

peer-PEER-tunnel-\d+.+INSTALLED
Show output
vpn-peer-PEER: #3, ESTABLISHED, IKEv2, 632f68b050d808c1_i 26288ebd5744bda6_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.2[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 0s ago, rekeying in 17259s
peer-PEER-tunnel-1: #4, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 0s ago, rekeying in 3244s, expires in 3960s
in  ce84c3bb,      0 bytes,     0 packets
out c0a546e4,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.3.0.0/24

Step 10: Modify the following configuration lines in DUT1 :

set interfaces ethernet eth0 disable

Step 11: Set the following configuration in DUT2 :

set interfaces dummy dum0 address 10.2.0.1/24
set interfaces ethernet eth0 address 80.0.0.3/24
set protocols static route 0.0.0.0/0 interface dum0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set vpn ipsec auth-profile AUTH-SA global-secrets ike-psk %any encrypted-secret U2FsdGVkX1/CUhpYwwfLM4GyuP1yIAgkSm2Tsm0sQ1U=
set vpn ipsec auth-profile AUTH-SA local auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA local id roadwarrior
set vpn ipsec auth-profile AUTH-SA remote auth ike-psk id %any
set vpn ipsec auth-profile AUTH-SA remote id server
set vpn ipsec esp-group CHILD-SA mode tunnel
set vpn ipsec esp-group CHILD-SA proposal 1 encryption aes256gcm128
set vpn ipsec esp-group CHILD-SA proposal 1 pfs dh-group19
set vpn ipsec ike-group IKE-SA key-exchange ikev2
set vpn ipsec ike-group IKE-SA proposal 1 dh-group 19
set vpn ipsec ike-group IKE-SA proposal 1 encryption aes256gcm128
set vpn ipsec ike-group IKE-SA proposal 1 hash sha256
set vpn ipsec site-to-site peer PEER auth-profile AUTH-SA
set vpn ipsec site-to-site peer PEER connection-type initiate
set vpn ipsec site-to-site peer PEER default-esp-group CHILD-SA
set vpn ipsec site-to-site peer PEER ike-group IKE-SA
set vpn ipsec site-to-site peer PEER local-address 80.0.0.3
set vpn ipsec site-to-site peer PEER remote-address 80.0.0.1
set vpn ipsec site-to-site peer PEER tunnel 1 local prefix 10.2.0.0/24
set vpn ipsec site-to-site peer PEER tunnel 1 local-interface dum0
set vpn ipsec site-to-site peer PEER tunnel 1 remote prefix 10.1.0.0/24
set vpn ipsec site-to-site peer PEER unique no

Step 12: Ping the IP address 80.0.0.3 from DUT0:

admin@DUT0$ ping 80.0.0.3 count 1 size 56 timeout 1
Show output
PING 80.0.0.3 (80.0.0.3) 56(84) bytes of data.
64 bytes from 80.0.0.3: icmp_seq=1 ttl=64 time=0.261 ms

--- 80.0.0.3 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.261/0.261/0.261/0.000 ms

Step 13: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.3\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, fb305a1876b3cf1d_i 1a6fab1ba2a4eebf_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 14507s
peer-PEER-tunnel-1: #5, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3525s, expires in 3954s
in  ccc2985b,      0 bytes,     0 packets
out c8b0d214,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24

Step 14: Expect a failure in the following command: Run the command vpn ipsec show sa on DUT0 and check whether the output matches the following regular expressions:

(?s)80.0.0\.2\[500\].*INSTALLED
Show output
vpn-peer-PEER: #4, ESTABLISHED, IKEv2, fb305a1876b3cf1d_i 1a6fab1ba2a4eebf_r*
local  'server' @ 80.0.0.1[500]
remote 'roadwarrior' @ 80.0.0.3[500]
AES_GCM_16-256/PRF_HMAC_SHA2_256/ECP_256
established 6s ago, rekeying in 14507s
peer-PEER-tunnel-1: #5, reqid 1, INSTALLED, TUNNEL, ESP:AES_GCM_16-256
installed 6s ago, rekeying in 3525s, expires in 3954s
in  ccc2985b,      0 bytes,     0 packets
out c8b0d214,      0 bytes,     0 packets
local  10.1.0.0/24
remote 10.2.0.0/24