testing: Fixed ikev2/alg-chacha20poly1305 scenario

This commit is contained in:
Andreas Steffen 2018-04-19 16:33:04 +02:00
parent a747ad738c
commit 51d5b35f51
2 changed files with 5 additions and 5 deletions

View File

@ -1,5 +1,5 @@
Roadwarrior <b>carol</b> proposes to gateway <b>moon</b> the cipher suite
<b>CHACHA20_POLY1305_256</b> both for IKE and ESP by defining
<b>CHACHA20_POLY1305</b> both for IKE and ESP by defining
<b>ike=chacha20poly1305-prfsha256-ntru256</b> and
<b>esp=chacha20poly1305-ntru256</b> in ipsec.conf, respectively.
A ping from <b>carol</b> to <b>alice</b> successfully checks the established tunnel.

View File

@ -3,10 +3,10 @@ carol::ipsec status 2> /dev/null::home.*ESTABLISHED.*carol@strongswan.org.*moon.
moon:: ipsec status 2> /dev/null::rw.*INSTALLED, TUNNEL::YES
carol::ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
carol::ping -c 1 -s 120 -p deadbeef PH_IP_ALICE::128 bytes from PH_IP_ALICE: icmp_.eq=1::YES
moon:: ipsec statusall 2> /dev/null::IKE proposal: CHACHA20_POLY1305_256::YES
carol::ipsec statusall 2> /dev/null::IKE proposal: CHACHA20_POLY1305_256::YES
moon:: ipsec statusall 2> /dev/null::CHACHA20_POLY1305_256,::YES
carol::ipsec statusall 2> /dev/null::CHACHA20_POLY1305_256,::YES
moon:: ipsec statusall 2> /dev/null::IKE proposal: CHACHA20_POLY1305::YES
carol::ipsec statusall 2> /dev/null::IKE proposal: CHACHA20_POLY1305::YES
moon:: ipsec statusall 2> /dev/null::CHACHA20_POLY1305,::YES
carol::ipsec statusall 2> /dev/null::CHACHA20_POLY1305,::YES
moon:: ip xfrm state::aead rfc7539esp(chacha20,poly1305)::YES
carol::ip xfrm state::aead rfc7539esp(chacha20,poly1305)::YES
moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP.*length 184::YES