#
# LEAK_DETECTIVE_LOG is set for automated runs, however, this is not passed
# to a process started via systemctl. This wrapper is used to set the variable
-# for the strongswan-swanctl.service unit.
+# for the strongswan.service unit.
ORIG=/bin/systemctl
-CONF=/lib/systemd/system/strongswan-swanctl.service
+CONF=/lib/systemd/system/strongswan.service
-if [[ "$2" != "strongswan-swanctl" ]]; then
+if [[ "$2" != "strongswan" ]]; then
$ORIG "$@"
fi
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection net
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection net
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::rm /etc/swanctl/pkcs8/*
sun::rm /etc/swanctl/rsa/sunKey.pem
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::rm /etc/swanctl/pkcs12/moonCert.p12
sun::cd /etc/swanctl; rm rsa/sunKey.pem x509/sunCert.pem x509ca/strongswanCert.pem
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
\ No newline at end of file
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
\ No newline at end of file
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
\ No newline at end of file
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
\ No newline at end of file
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
\ No newline at end of file
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection net
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection net
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip6tables-restore < /etc/ip6tables.flush
sun::iptables-restore < /etc/iptables.drop
moon::ip6tables-restore < /etc/ip6tables.rules
sun::ip6tables-restore < /etc/ip6tables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
sun::expect-connection host-host
moon::expect-connection host-host
moon::swanctl --initiate --child host-host 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip6tables-restore < /etc/ip6tables.flush
sun::iptables-restore < /etc/iptables.drop
moon::ip6tables-restore < /etc/ip6tables.rules
sun::ip6tables-restore < /etc/ip6tables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection host-host
sun::expect-connection host-host
moon::swanctl --initiate --child host-host 2> /dev/null
\ No newline at end of file
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
alice::"ip route del fec2:\:/16 via fec1:\:1"
moon::"ip route del fec2:\:/16 via fec0:\:2"
sun::"ip route del fec1:\:/16 via fec0:\:1"
moon::"ip route add fec2:\:/16 via fec0:\:2"
sun::"ip route add fec1:\:/16 via fec0:\:1"
bob::"ip route add fec1:\:/16 via fec2:\:1"
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
alice::"ip route del fec2:\:/16 via fec1:\:1"
moon::"ip route del fec2:\:/16 via fec0:\:2"
sun::"ip route del fec1:\:/16 via fec0:\:1"
moon::"ip route add fec2:\:/16 via fec0:\:2"
sun::"ip route add fec1:\:/16 via fec0:\:1"
bob::"ip route add fec1:\:/16 via fec2:\:1"
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip6tables-restore < /etc/ip6tables.flush
sun::iptables-restore < /etc/iptables.drop
moon::ip6tables-restore < /etc/ip6tables.rules
sun::ip6tables-restore < /etc/ip6tables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip6tables-restore < /etc/ip6tables.flush
sun::iptables-restore < /etc/iptables.drop
moon::ip6tables-restore < /etc/ip6tables.rules
sun::ip6tables-restore < /etc/ip6tables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
alice::"ip route del fec2:\:/16 via fec1:\:1"
moon::"ip route del fec2:\:/16 via fec0:\:2"
sun::"ip route del fec1:\:/16 via fec0:\:1"
moon::"ip route add fec2:\:/16 via fec0:\:2"
sun::"ip route add fec1:\:/16 via fec0:\:1"
bob::"ip route add fec1:\:/16 via fec2:\:1"
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
alice::"ip route del fec2:\:/16 via fec1:\:1"
moon::"ip route del fec2:\:/16 via fec0:\:2"
sun::"ip route del fec1:\:/16 via fec0:\:1"
moon::"ip route add fec2:\:/16 via fec0:\:2"
sun::"ip route add fec1:\:/16 via fec0:\:1"
bob::"ip route add fec1:\:/16 via fec2:\:1"
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
alice::"ip route del fec2:\:/16 via fec1:\:1"
moon::"ip route del fec2:\:/16 via fec0:\:2"
sun::"ip route del fec1:\:/16 via fec0:\:1"
moon::"ip route add fec2:\:/16 via fec0:\:2"
sun::"ip route add fec1:\:/16 via fec0:\:1"
bob::"ip route add fec1:\:/16 via fec2:\:1"
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::ip6tables-restore < /etc/ip6tables.flush
moon::ip6tables -I OUTPUT 1 -o eth1 -p icmpv6 --icmpv6-type 2 -j ACCEPT
alice::"ip route add fec0:\:/16 via fec1:\:1"
carol::"ip route add fec1:\:/16 via fec0:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
alice::"ip route add fec0:\:/16 via fec1:\:1"
carol::"ip route add fec1:\:/16 via fec0:\:1"
dave::"ip route add fec1:\:/16 via fec0:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
dave::expect-connection home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
alice::"ip route add fec0:\:/16 via fec1:\:1"
carol::"ip route add fec1:\:/16 via fec0:\:1"
dave::"ip route add fec1:\:/16 via fec0:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
dave::expect-connection home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
carol::ip6tables-restore < /etc/ip6tables.rules
dave::ip6tables-restore < /etc/ip6tables.rules
alice::"ip route add fec3:\:/16 via fec1:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
dave::expect-connection home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
carol::ip6tables-restore < /etc/ip6tables.rules
dave::ip6tables-restore < /etc/ip6tables.rules
alice::"ip route add fec3:\:/16 via fec1:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
dave::expect-connection home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
carol::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
dave::expect-connection home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
carol::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
dave::expect-connection home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
alice::"ip route add fec0:\:/16 via fec1:\:1"
carol::"ip route add fec1:\:/16 via fec0:\:1"
dave::"ip route add fec1:\:/16 via fec0:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
dave::expect-connection home
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip6tables-restore < /etc/ip6tables.flush
sun::iptables-restore < /etc/iptables.drop
moon::ip6tables-restore < /etc/ip6tables.rules
sun::ip6tables-restore < /etc/ip6tables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection host-host
sun::expect-connection host-host
moon::swanctl --initiate --child host-host 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip6tables-restore < /etc/ip6tables.flush
sun::iptables-restore < /etc/iptables.drop
moon::ip6tables-restore < /etc/ip6tables.rules
sun::ip6tables-restore < /etc/ip6tables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection host-host
sun::expect-connection host-host
moon::swanctl --initiate --child host-host
moon::swanctl --terminate --ike host-host 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::sysctl --pattern net.ipv4.conf.all.rp_filter --system
sun::sysctl -w net.ipv4.conf.all.rp_filter=2
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
sun::expect-connection host-host
moon::expect-connection host-host
moon::swanctl --initiate --child host-host 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
alice::"ip route del fec2:\:/16 via fec1:\:1"
moon::"ip route del fec2:\:/16 via fec0:\:2"
sun::"ip route del fec1:\:/16 via fec0:\:1"
moon::"ip route add fec2:\:/16 via fec0:\:2"
sun::"ip route add fec1:\:/16 via fec0:\:1"
bob::"ip route add fec1:\:/16 via fec2:\:1"
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection net
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::rm /etc/swanctl/ecdsa/carolKey.pem
dave::rm /etc/swanctl/ecdsa/daveKey.pem
moon::rm /etc/swanctl/ecdsa/moonKey.pem
carol::rm /etc/swanctl/rsa/carolKey.pem
dave::rm /etc/swanctl/rsa/daveKey.pem
moon::rm /etc/swanctl/rsa/moonKey.pem
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection net
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::rm /etc/swanctl/x509/moonCert.der
sun::rm /etc/swanctl/x509/sunCert.der
moon::rm /etc/swanctl/x509/moonCert.pem
sun::rm /etc/swanctl/x509/sunCert.pem
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::rm /etc/swanctl/ecdsa/carolKey.pem
dave::rm /etc/swanctl/ecdsa/daveKey.pem
moon::rm /etc/swanctl/ecdsa/moonKey.pem
carol::rm /etc/swanctl/rsa/carolKey.pem
dave::rm /etc/swanctl/rsa/daveKey.pem
moon::rm /etc/swanctl/rsa/moonKey.pem
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::rm /etc/swanctl/pkcs8/carolKey.pem
dave::rm /etc/swanctl/pkcs8/daveKey.pem
moon::rm /etc/swanctl/ecdsa/moonKey.pem
carol::rm /etc/swanctl/rsa/carolKey.pem
dave::rm /etc/swanctl/rsa/daveKey.pem
moon::rm /etc/swanctl/rsa/moonKey.pem
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::rm /etc/swanctl/pkcs12/moonCert.p12
sun::cd /etc/swanctl; rm rsa/sunKey.pem x509/sunCert.pem x509ca/strongswanCert.pem
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
mmoon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
moon::swanctl --terminate --ike gw-gw
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip tunnel del gre-moon
sun::ip route add 10.1.0.0/16 dev gre-sun
sun::iptables -A FORWARD -i gre-sun -j ACCEPT
sun::iptables -A FORWARD -o gre-sun -j ACCEPT
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child gre
moon::swanctl --terminate --ike gw-gw
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip tunnel del vti-moon
sun::ip route add 10.1.0.0/16 dev vti-sun
sun::iptables -A FORWARD -i vti-sun -j ACCEPT
sun::iptables -A FORWARD -o vti-sun -j ACCEPT
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net
moon::swanctl --terminate --ike gw-gw
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip -s link show xfrm-moon-out
moon::ip route add 10.2.0.0/16 dev xfrm-moon-out
moon::iptables -A FORWARD -o xfrm-moon-out -j ACCEPT
moon::iptables -A FORWARD -i xfrm-moon-in -j ACCEPT
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child alice-net
moon::swanctl --terminate --ike gw-gw
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip -s link show xfrm-moon
moon::ip route add 10.2.0.0/16 dev xfrm-moon
moon::iptables -A FORWARD -i xfrm-moon -j ACCEPT
moon::iptables -A FORWARD -o xfrm-moon -j ACCEPT
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net
moon::swanctl --terminate --ike gw-gw
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::ip -s link show xfrm-moon-out
moon::ip route add 10.2.0.0/16 dev xfrm-moon-out
moon::iptables -A FORWARD -o xfrm-moon-out -j ACCEPT
moon::iptables -A FORWARD -i xfrm-moon-in -j ACCEPT
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::"ip route add fec3:\:/16 dev vti0"
moon::ip6tables -A FORWARD -i vti0 -j ACCEPT
moon::ip6tables -A FORWARD -o vti0 -j ACCEPT
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::ip route add 10.3.0.0/28 dev vti0
moon::iptables -A FORWARD -i vti0 -j ACCEPT
moon::iptables -A FORWARD -o vti0 -j ACCEPT
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::ip route add 10.3.0.0/28 dev xfrm-moon
moon::iptables -A FORWARD -i xfrm-moon -j ACCEPT
moon::iptables -A FORWARD -o xfrm-moon -j ACCEPT
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
dave::expect-connection home
dave::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
dave::expect-connection home
dave::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
sun::expect-connection net-net
moon::swanctl --initiate --child net-net 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection net-net
alice::ping -c 1 -W 1 10.2.0.10
bob::ping -c 1 -W 1 10.1.0.20
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-sun::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
sun::expect-connection net-net
-moon::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
moon::sleep 4
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap-aka
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
alice::"ip route add fec0:\:/16 via fec1:\:1"
carol::"ip route add fec1:\:/16 via fec0:\:1"
dave::"ip route add fec1:\:/16 via fec0:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-alice::systemctl stop strongswan-swanctl
-venus::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+alice::systemctl stop strongswan
+venus::systemctl stop strongswan
+sun::systemctl stop strongswan
sun::iptables-restore < /etc/iptables.flush
moon::iptables -t nat -F
sun::iptables-restore < /etc/iptables.rules
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p udp -j SNAT --to-source PH_IP_MOON:1024-1100
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p tcp -j SNAT --to-source PH_IP_MOON:2000-2100
-sun::systemctl start strongswan-swanctl
-alice::systemctl start strongswan-swanctl
-venus::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
+alice::systemctl start strongswan
+venus::systemctl start strongswan
sun::expect-connection nat-t
alice::expect-connection nat-t
alice::swanctl --initiate --child nat-t 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
moon::cat /etc/swanctl/swanctl_base.conf
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-carol
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::rm /etc/swanctl/x509crl/*
carol::rm /etc/swanctl/x509crl/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
venus::cat /var/lib/dhcp/dhcpd.leases
venus::service isc-dhcp-server stop 2> /dev/null
venus::rm /var/lib/dhcp/dhcpd.leases*; touch /var/lib/dhcp/dhcpd.leases
dave::iptables-restore < /etc/iptables.rules
venus::cat /etc/dhcp/dhcpd.conf
venus::service isc-dhcp-server start 2> /dev/null
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home 2> /dev/null
dave::swanctl --terminate --ike home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home 2> /dev/null
dave::swanctl --terminate --ike home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
alice::"ip route add fec0:\:/16 via fec1:\:1"
carol::"ip route add fec1:\:/16 via fec0:\:1"
dave::"ip route add fec1:\:/16 via fec0:\:1"
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
moon::swanctl --terminate --ike host-host 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection host-host
sun::expect-connection host-hhost
moon::swanctl --initiate --child host-host 2> /dev/null
moon::swanctl --terminate --ike host-host 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection host-host
sun::expect-connection host-hhost
moon::swanctl --initiate --child host-host 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-alice::systemctl stop strongswan-swanctl
-venus::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+alice::systemctl stop strongswan
+venus::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.rules
alice::iptables-restore < /etc/iptables.rules
venus::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
-alice::systemctl start strongswan-swanctl
-venus::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
+alice::systemctl start strongswan
+venus::systemctl start strongswan
moon::expect-connection int
moon::expect-connection ext
carol::expect-connection home
carol::swanctl --terminate --ike home
alice::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-alice::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+alice::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
alice::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
alice::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-alice::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+alice::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
winnetou::ip route del 10.1.0.0/16 via 192.168.0.1
carol::ip route del 10.1.0.0/16 via 192.168.0.1
dave::ip route del 10.1.0.0/16 via 192.168.0.1
winnetou::ip route add 10.1.0.0/16 via 192.168.0.1
carol::ip route add 10.1.0.0/16 via 192.168.0.1
dave::ip route add 10.1.0.0/16 via 192.168.0.1
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
carol::cat /etc/ipsec.d/triplets.dat
dave::cat /etc/ipsec.d/triplets.dat
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home 2> /dev/null
dave::swanctl --terminate --ike home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection research
carol::expect-connection alice
carol::swanctl --initiate --child alice 2> /dev/null
-sun::systemctl stop strongswan-swanctl
-alice::systemctl stop strongswan-swanctl
-venus::systemctl stop strongswan-swanctl
+sun::systemctl stop strongswan
+alice::systemctl stop strongswan
+venus::systemctl stop strongswan
alice::iptables-restore < /etc/iptables.flush
venus::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::cd /etc/swanctl; rm x509ca/* x509/* rsa/*
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p udp -j SNAT --to-source PH_IP_MOON:1024-1100
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p tcp -j SNAT --to-source PH_IP_MOON:2000-2100
-sun::systemctl start strongswan-swanctl
-alice::systemctl start strongswan-swanctl
-venus::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
+alice::systemctl start strongswan
+venus::systemctl start strongswan
sun::expect-connection nat-t
alice::expect-connection nat-t
alice::swanctl --initiate --child nat-t
-sun::systemctl stop strongswan-swanctl
-alice::systemctl stop strongswan-swanctl
-venus::systemctl stop strongswan-swanctl
+sun::systemctl stop strongswan
+alice::systemctl stop strongswan
+venus::systemctl stop strongswan
alice::iptables-restore < /etc/iptables.flush
venus::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.rules
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p udp -j SNAT --to-source PH_IP_MOON:1024-1100
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p tcp -j SNAT --to-source PH_IP_MOON:2000-2100
-sun::systemctl start strongswan-swanctl
-alice::systemctl start strongswan-swanctl
-venus::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
+alice::systemctl start strongswan
+venus::systemctl start strongswan
sun::expect-connection nat-t
alice::expect-connection nat-t
alice::swanctl --initiate --child nat-t
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::rm /etc/swanctl/pkcs8/*
sun::rm /etc/swanctl/rsa/sunKey.pem
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
sun::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
+carol::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
+carol::systemctl start strongswan
carol::expect-connection gw-moon
carol::expect-connection gw-sun
moon::expect-connection gw-gw
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::echo 1 > /proc/sys/net/ipv4/igmp_max_memberships
sun::echo 1 > /proc/sys/net/ipv4/igmp_max_memberships
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.rules
moon::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
sun::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::rm /etc/swanctl/pubkey/*
moon::iptables-restore < /etc/iptables.rules
sun::cd /etc/swanctl; rm x509/* x509ca/*
moon::cd /etc/swanctl; rm x509/* x509ca/*
-sun::systemctl start strongswan-swanctl
-moon::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
+moon::systemctl start strongswan
sun::expect-connection gw-gw
moon::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.rules
moon::iptables-restore < /etc/iptables.rules
-sun::systemctl start strongswan-swanctl
-moon::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
+moon::systemctl start strongswan
sun::expect-connection gw-gw
moon::expect-connection gw-gw
alice::ping -c 3 -W 1 -i 0.2 PH_IP_BOB
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
moon::expect-connection gw-gw
sun::expect-connection gw-gw
moon::swanctl --initiate --child net-net 2> /dev/null
moon::swanctl --terminate --ike gw-gw 2> /dev/null
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.rules
moon::iptables-restore < /etc/iptables.rules
-sun::systemctl start strongswan-swanctl
-moon::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
+moon::systemctl start strongswan
moon::sleep 0.5
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home
carol::swanctl --terminate --ike home 2> /dev/null
dave::swanctl --terminate --ike home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
moon::cd /etc/swanctl; rm -r rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection research
carol::expect-connection home
carol::swanctl --initiate --child alice 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection icmp
moon::expect-connection ssh
carol::expect-connection icmp
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection icmp-req
moon::expect-connection icmp-rep
moon::expect-connection ftp-ssh
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::rm /etc/swanctl/pubkey/*
carol::rm /etc/swanctl/pubkey/*
dave::rm /etc/swanctl/pubkey/*
moon::cd /etc/swanctl; rm x509/* x509ca/*
carol::cd /etc/swanctl; rm x509/* x509ca/*
dave::cd /etc/swanctl; rm x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::cd /etc/ipsec.d; cat tables.sql data.sql > ipsec.sql; cat ipsec.sql | sqlite3 ipsec.db
moon::cd /etc/ipsec.d; cat tables.sql data.sql > ipsec.sql; cat ipsec.sql | sqlite3 ipsec.db
carol::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
dave::swanctl --terminate --ike home
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
dave::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
dave::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
dave::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::cd /etc/swanctl; rm rsa/* x509/*
dave::cd /etc/swanctl; rm rsa/* x509/*
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::cd /etc/swanctl; rm rsa/* x509/*
carol::cat /etc/ipsec.d/triplets.dat
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::cat /etc/ipsec.d/triplets.dat
dave::cat /etc/ipsec.d/triplets.dat
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::cat /etc/ipsec.d/triplets.dat
dave::cat /etc/ipsec.d/triplets.dat
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.rules
carol::cd /etc/swanctl; rm rsa/* x509/*
dave::cd /etc/swanctl; rm rsa/* x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
alice::killall freeradius
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::cd /etc/swanctl; rm rsa/* x509/*
dave::cd /etc/swanctl; rm rsa/* x509/*
alice::freeradius
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-eap
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
carol::rm /etc/swanctl/pkcs8/*
dave::rm /etc/swanctl/pkcs8/*
moon::rm /etc/swanctl/pkcs8/*
moon::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/rsa/*
dave::rm /etc/swanctl/rsa/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection net-1
moon::expect-connection net-2
carol::expect-connection home
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/moonCert.pem x509ca/strongswanCert.pem
carol::cd /etc/swanctl; rm rsa/* x509/carolCert.pem x509ca/strongswanCert.pem
dave::cd /etc/swanctl; rm rsa/* x509/daveCert.pem x509ca/strongswanCert.pem
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/moonCert.pem x509ca/strongswanCert.pem
carol::cd /etc/swanctl; rm rsa/* x509/carolCert.pem x509ca/strongswanCert.pem
dave::cd /etc/swanctl; rm rsa/* x509/daveCert.pem x509ca/strongswanCert.pem
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
carol::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
carol::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection net-1
moon::expect-connection net-2
carol::expect-connection home
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
carol::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
carol::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
dave::cd /etc/swanctl; rm rsa/* x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::rm /etc/swanctl/pubkey/*
carol::rm /etc/swanctl/pubkey/*
dave::rm /etc/swanctl/pubkey/*
moon::cd /etc/swanctl; rm x509/* x509ca/*
carol::cd /etc/swanctl; rm x509/* x509ca/*
dave::cd /etc/swanctl; rm x509/* x509ca/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::rm /etc/swanctl/pubkey/*
carol::rm /etc/swanctl/pubkey/*
dave::rm /etc/swanctl/pubkey/*
carol::cd /etc/swanctl; rm x509/* x509ca/*
dave::cd /etc/swanctl; rm x509/* x509ca/*
moon::cat /etc/swanctl/swanctl_base.conf
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-carol
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-alice::systemctl stop strongswan-swanctl
-venus::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+alice::systemctl stop strongswan
+venus::systemctl stop strongswan
+sun::systemctl stop strongswan
sun::iptables-restore < /etc/iptables.flush
moon::iptables -t nat -F
sun::iptables-restore < /etc/iptables.rules
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p udp -j SNAT --to-source PH_IP_MOON:1024-1100
moon::iptables -t nat -A POSTROUTING -o eth0 -s 10.1.0.0/16 -p tcp -j SNAT --to-source PH_IP_MOON:2000-2100
-sun::systemctl start strongswan-swanctl
-alice::systemctl start strongswan-swanctl
-venus::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
+alice::systemctl start strongswan
+venus::systemctl start strongswan
sun::expect-connection nat-t
alice::expect-connection nat-t
venus::expect-connection nat-t
carol::swanctl --terminate --ike home
dave::swanctl --terminate --ike home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
carol::iptables-restore < /etc/iptables.rules
dave::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw
carol::expect-connection home
carol::swanctl --initiate --child home 2> /dev/null
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
dave::ip route del 10.1.0.0/16 via 192.168.0.1
winnetou::ip route del 10.1.0.0/16 via 192.168.0.1
carol::rm /etc/pts/collector.sql
-alice::systemctl stop strongswan-swanctl
+alice::systemctl stop strongswan
alice::systemctl stop apache2
alice::rm /etc/swanctl/rsa/aaaKey.pem
alice::rm /etc/swanctl/x509/aaaCert.pem
alice::rm /etc/swanctl/x509/aliceCert.pem
alice::rm /etc/swanctl/rsa/aliceKey.pem
alice::systemctl start apache2
-alice::systemctl start strongswan-swanctl
+alice::systemctl start strongswan
alice::swanctl --load-creds
winnetou::ip route add 10.1.0.0/16 via 192.168.0.1
dave::ip route add 10.1.0.0/16 via 192.168.0.1
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
-carol::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
carol::cat /etc/tnc_config
carol::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
-alice::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
+alice::systemctl stop strongswan
alice::rm /etc/swanctl/rsa/aaaKey.pem
alice::rm /etc/swanctl/x509/aaaCert.pem
winnetou::ip route del 10.1.0.0/16 via 192.168.0.1
dave::echo aabbccddeeff11223344556677889900 > /var/lib/dbus/machine-id
alice::rm /etc/swanctl/rsa/aliceKey.pem
alice::rm /etc/swanctl/x509/aliceCert.pem
-alice::systemctl start strongswan-swanctl
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+alice::systemctl start strongswan
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
sun::expect-connection mutual
moon::expect-connection mutual
moon::swanctl --initiate --child mutual
-moon::systemctl stop strongswan-swanctl
-sun::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+sun::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
sun::iptables-restore < /etc/iptables.flush
moon::iptables-restore < /etc/iptables.rules
sun::iptables-restore < /etc/iptables.rules
-moon::systemctl start strongswan-swanctl
-sun::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+sun::systemctl start strongswan
sun::expect-connection mutual
moon::expect-connection mutual
moon::swanctl --initiate --child mutual
-sun::systemctl stop strongswan-swanctl
+sun::systemctl stop strongswan
-sun::systemctl start strongswan-swanctl
+sun::systemctl start strongswan
moon::cat /etc/pts/options
moon::sleep 1
moon::/usr/local/bin/pt-tls-client --optionsfrom /etc/pts/options
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
dave::expect-connection home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
-moon::systemctl stop strongswan-swanctl
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-alice::systemctl stop strongswan-swanctl
+moon::systemctl stop strongswan
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+alice::systemctl stop strongswan
alice::systemctl stop apache2
alice::rm /etc/swanctl/x509/aaaCert.pem
alice::rm /etc/swanctl/rsa/aaaKey.pem
alice::chgrp -R www-data /etc/db.d/config.db; chmod -R g+w /etc/db.d/config.db
alice::/usr/local/bin/init_tnc
alice::systemctl start apache2
-alice::systemctl start strongswan-swanctl
-moon::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+alice::systemctl start strongswan
+moon::systemctl start strongswan
+dave::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
dave::expect-connection home
carol::ip route del 10.1.0.0/16 via 192.168.0.1
dave::ip route del 10.1.0.0/16 via 192.168.0.1
winnetou::ip route del 10.1.0.0/16 via 192.168.0.1
-alice::systemctl stop strongswan-swanctl
+alice::systemctl stop strongswan
alice::systemctl stop apache2
alice::rm /etc/swanctl/rsa/aaaKey.pem
alice::rm /etc/swanctl/x509/aaaCert.pem
alice::rm /etc/swanctl/x509/aliceCert.pem
alice::rm /etc/swanctl/rsa/aliceKey.pem
alice::systemctl start apache2
-alice::systemctl start strongswan-swanctl
+alice::systemctl start strongswan
alice::swanctl --load-creds
winnetou::ip route add 10.1.0.0/16 via 192.168.0.1
dave::ip route add 10.1.0.0/16 via 192.168.0.1
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+dave::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
dave::expect-connection home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+dave::systemctl start strongswan
+carol::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
dave::expect-connection home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
moon::cat /etc/tnc_config
carol::cat /etc/tnc_config
dave::cat /etc/tnc_config
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home
-carol::systemctl stop strongswan-swanctl
-dave::systemctl stop strongswan-swanctl
-moon::systemctl stop strongswan-swanctl
+carol::systemctl stop strongswan
+dave::systemctl stop strongswan
+moon::systemctl stop strongswan
moon::iptables-restore < /etc/iptables.flush
carol::iptables-restore < /etc/iptables.flush
dave::iptables-restore < /etc/iptables.flush
dave::rm /etc/swanctl/rsa/*
carol::rm /etc/swanctl/x509/*
dave::rm /etc/swanctl/x509/*
-moon::systemctl start strongswan-swanctl
-carol::systemctl start strongswan-swanctl
-dave::systemctl start strongswan-swanctl
+moon::systemctl start strongswan
+carol::systemctl start strongswan
+dave::systemctl start strongswan
moon::expect-connection rw-allow
moon::expect-connection rw-isolate
carol::expect-connection home