/testing/guestbin/swan-prep
west #
 ipsec start
Redirecting to: [initsystem]
west #
 ../../guestbin/wait-until-pluto-started
west #
 ipsec add addconn--ikev1
"addconn--ikev1": added unoriented IKEv1 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec add addconn--ikev1--fragmentation-force
"addconn--ikev1--fragmentation-force": added unoriented IKEv1 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec add addconn--ikev2
"addconn--ikev2": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec add addconn--ikev2--fragmentation-no
"addconn--ikev2--fragmentation-no": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec add addconn--ikev2--fragmentation-yes
"addconn--ikev2--fragmentation-yes": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec add addconn--ikev2--fragmentation-force
"addconn--ikev2--fragmentation-force": warning: IKEv1 only fragmentation=force ignored; using fragmentation=yes
"addconn--ikev2--fragmentation-force": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev1                      --host 1.2.3.4                       --no-esn --pfs --tunnel --encrypt --ikev1 --ipv4 --to --host 5.6.7.8
"whack--ikev1": added unoriented IKEv1 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev1--fragmentation-force --host 1.2.3.4 --fragmentation force --no-esn --pfs --tunnel --encrypt --ikev1 --ipv4 --to --host 5.6.7.8
"whack--ikev1--fragmentation-force": added unoriented IKEv1 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev2                      --host 1.2.3.4                       --no-esn --pfs --tunnel --encrypt --ikev2 --ipv4 --to --host 5.6.7.8
"whack--ikev2": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev2--ikefrag-allow       --host 1.2.3.4 --ikefrag-allow       --no-esn --pfs --tunnel --encrypt --ikev2 --ipv4 --to --host 5.6.7.8
"whack--ikev2--ikefrag-allow": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev2--ikefrag-force       --host 1.2.3.4 --ikefrag-force       --no-esn --pfs --tunnel --encrypt --ikev2 --ipv4 --to --host 5.6.7.8
"whack--ikev2--ikefrag-force": warning: IKEv1 only fragmentation=force ignored; using fragmentation=yes
"whack--ikev2--ikefrag-force": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev2--fragmentation-no    --host 1.2.3.4 --fragmentation no    --no-esn --pfs --tunnel --encrypt --ikev2 --ipv4 --to --host 5.6.7.8
"whack--ikev2--fragmentation-no": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev2--fragmentation-yes   --host 1.2.3.4 --fragmentation yes   --no-esn --pfs --tunnel --encrypt --ikev2 --ipv4 --to --host 5.6.7.8
"whack--ikev2--fragmentation-yes": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec whack --name whack--ikev2--fragmentation-force --host 1.2.3.4 --fragmentation force --no-esn --pfs --tunnel --encrypt --ikev2 --ipv4 --to --host 5.6.7.8
"whack--ikev2--fragmentation-force": warning: IKEv1 only fragmentation=force ignored; using fragmentation=yes
"whack--ikev2--fragmentation-force": added unoriented IKEv2 connection (neither left=1.2.3.4 nor right=5.6.7.8 match an interface)
west #
 ipsec connectionstatus | sed -n -e 's/\(.* policy:\) .*\(IKEv[12]\).*/\1 \2/p'
"addconn--ikev1":   policy: IKEv1
"addconn--ikev1--fragmentation-force":   policy: IKEv1
"addconn--ikev2":   policy: IKEv2
"addconn--ikev2--fragmentation-force":   policy: IKEv2
"addconn--ikev2--fragmentation-no":   policy: IKEv2
"addconn--ikev2--fragmentation-yes":   policy: IKEv2
"whack--ikev1":   policy: IKEv1
"whack--ikev1--fragmentation-force":   policy: IKEv1
"whack--ikev2":   policy: IKEv2
"whack--ikev2--fragmentation-force":   policy: IKEv2
"whack--ikev2--fragmentation-no":   policy: IKEv2
"whack--ikev2--fragmentation-yes":   policy: IKEv2
"whack--ikev2--ikefrag-allow":   policy: IKEv2
"whack--ikev2--ikefrag-force":   policy: IKEv2
west #
 ipsec connectionstatus | sed -n -e 's/\(.* policy:\) .*IKE_FRAG_ALLOW.*/\1 IKE_FRAG_ALLOW/p'
"addconn--ikev1":   policy: IKE_FRAG_ALLOW
"addconn--ikev1--fragmentation-force":   policy: IKE_FRAG_ALLOW
"addconn--ikev2":   policy: IKE_FRAG_ALLOW
"addconn--ikev2--fragmentation-force":   policy: IKE_FRAG_ALLOW
"addconn--ikev2--fragmentation-yes":   policy: IKE_FRAG_ALLOW
"whack--ikev1":   policy: IKE_FRAG_ALLOW
"whack--ikev1--fragmentation-force":   policy: IKE_FRAG_ALLOW
"whack--ikev2":   policy: IKE_FRAG_ALLOW
"whack--ikev2--fragmentation-force":   policy: IKE_FRAG_ALLOW
"whack--ikev2--fragmentation-yes":   policy: IKE_FRAG_ALLOW
"whack--ikev2--ikefrag-allow":   policy: IKE_FRAG_ALLOW
"whack--ikev2--ikefrag-force":   policy: IKE_FRAG_ALLOW
west #
 ipsec connectionstatus | sed -n -e 's/\(.* policy:\) .*IKE_FRAG_FORCE.*/\1 IKE_FRAG_FORCE/p'
"addconn--ikev1--fragmentation-force":   policy: IKE_FRAG_FORCE
"whack--ikev1--fragmentation-force":   policy: IKE_FRAG_FORCE
west #
 
