Frame 1 (162 bytes on wire, 162 bytes captured) Arrival Time: Sep 20, 2007 15:29:02.460415000 Time delta from previous packet: 0.000000000 seconds Time since reference or first frame: 0.000000000 seconds Frame Number: 1 Packet Length: 162 bytes Capture Length: 162 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab), Dst: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Destination: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Source: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.115 (165.227.249.115), Dst: 165.227.249.131 (165.227.249.131) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 148 Identification: 0x038f (911) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf80b [correct] Good: True Bad : False Source: 165.227.249.115 (165.227.249.115) Destination: 165.227.249.131 (165.227.249.131) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 128 Checksum: 0x9528 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xDC10ABE6F2CD7D3C Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 120 Security Association payload Next payload: Vendor ID (13) Length: 52 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 40 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 32 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (3600) Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-00 Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 0000 00 1b 2f 37 c7 b9 00 0c 29 ab 06 ab 08 00 45 00 ../7....).....E. 0010 00 94 03 8f 00 00 80 11 f8 0b a5 e3 f9 73 a5 e3 .............s.. 0020 f9 83 01 f4 01 f4 00 80 95 28 dc 10 ab e6 f2 cd .........(...... 0030 7d 3c 00 00 00 00 00 00 00 00 01 10 02 00 00 00 }<.............. 0040 00 00 00 00 00 78 0d 00 00 34 00 00 00 01 00 00 .....x...4...... 0050 00 01 00 00 00 28 01 01 00 01 00 00 00 20 01 01 .....(....... .. 0060 00 00 80 01 00 05 80 02 00 02 80 04 00 02 80 03 ................ 0070 00 01 80 0b 00 01 80 0c 0e 10 0d 00 00 14 44 85 ..............D. 0080 15 2d 18 b6 bb cd 0b e8 a8 46 95 79 dd cc 00 00 .-.......F.y.... 0090 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 ec 42 ......>.in.c...B 00a0 7b 1f {. Frame 2 (142 bytes on wire, 142 bytes captured) Arrival Time: Sep 20, 2007 15:29:02.605710000 Time delta from previous packet: 0.145295000 seconds Time since reference or first frame: 0.145295000 seconds Frame Number: 2 Packet Length: 142 bytes Capture Length: 142 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9), Dst: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Destination: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Source: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.131 (165.227.249.131), Dst: 165.227.249.115 (165.227.249.115) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 128 Identification: 0x0000 (0) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfbae [correct] Good: True Bad : False Source: 165.227.249.131 (165.227.249.131) Destination: 165.227.249.115 (165.227.249.115) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 108 Checksum: 0xded3 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xDC10ABE6F2CD7D3C Responder cookie: 0x73E90170D5BA1D19 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 100 Security Association payload Next payload: Vendor ID (13) Length: 52 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 40 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 32 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (3600) Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: RFC 3706 Detecting Dead IKE Peers (DPD) 0000 00 0c 29 ab 06 ab 00 1b 2f 37 c7 b9 08 00 45 00 ..)...../7....E. 0010 00 80 00 00 40 00 40 11 fb ae a5 e3 f9 83 a5 e3 ....@.@......... 0020 f9 73 01 f4 01 f4 00 6c de d3 dc 10 ab e6 f2 cd .s.....l........ 0030 7d 3c 73 e9 01 70 d5 ba 1d 19 01 10 02 00 00 00 }. 0080 00 f6 98 b4 89 08 f4 69 a4 17 ac 71 e5 67 d4 16 .......i...q.g.. 0090 b2 55 5d 64 1d 6f 0a 34 1e e4 f1 ed ad c2 aa 90 .U]d.o.4........ 00a0 13 42 a4 5d b6 55 d4 8b 80 e3 cd e7 dd 10 c8 db .B.].U.......... 00b0 eb 02 b9 55 b7 8f 30 1e b0 59 cb ef 24 b8 20 9e ...U..0..Y..$. . 00c0 90 37 5d 0b a2 88 69 c5 f8 58 0d 00 00 18 a6 24 .7]...i..X.....$ 00d0 4c 7b 94 a0 9d 7b 0e 37 88 21 3f 8a 1f 9f f4 2d L{...{.7.!?....- 00e0 0f 29 0d 00 00 30 47 bb e7 c9 93 f1 fc 13 b4 e6 .)...0G......... 00f0 d0 db 56 5c 68 e5 01 02 01 01 02 01 01 03 11 31 ..V\h..........1 0100 30 2e 31 2e 31 20 28 42 75 69 6c 64 20 31 30 29 0.1.1 (Build 10) 0110 00 00 0d 00 00 0c da 8e 93 78 80 01 00 00 00 00 .........x...... 0120 00 0c 09 00 26 89 df d6 b7 12 ....&..... Frame 4 (222 bytes on wire, 222 bytes captured) Arrival Time: Sep 20, 2007 15:29:04.437272000 Time delta from previous packet: 0.372454000 seconds Time since reference or first frame: 1.976857000 seconds Frame Number: 4 Packet Length: 222 bytes Capture Length: 222 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9), Dst: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Destination: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Source: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.131 (165.227.249.131), Dst: 165.227.249.115 (165.227.249.115) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 208 Identification: 0x0000 (0) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb5e [correct] Good: True Bad : False Source: 165.227.249.131 (165.227.249.131) Destination: 165.227.249.115 (165.227.249.115) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 188 Checksum: 0x294e [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xDC10ABE6F2CD7D3C Responder cookie: 0x73E90170D5BA1D19 Next payload: Key Exchange (4) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 180 Key Exchange payload Next payload: Nonce (10) Length: 132 Key Exchange Data Nonce payload Next payload: NONE (0) Length: 20 Nonce Data 0000 00 0c 29 ab 06 ab 00 1b 2f 37 c7 b9 08 00 45 00 ..)...../7....E. 0010 00 d0 00 00 40 00 40 11 fb 5e a5 e3 f9 83 a5 e3 ....@.@..^...... 0020 f9 73 01 f4 01 f4 00 bc 29 4e dc 10 ab e6 f2 cd .s......)N...... 0030 7d 3c 73 e9 01 70 d5 ba 1d 19 04 10 02 00 00 00 }.....\..v 0070 35 6f b2 69 b2 d4 69 98 83 02 69 aa 13 d3 2b 85 5o.i..i...i...+. 0080 5c 36 24 4a 2d cd \6$J-. Frame 6 (110 bytes on wire, 110 bytes captured) Arrival Time: Sep 20, 2007 15:29:05.832615000 Time delta from previous packet: 0.115920000 seconds Time since reference or first frame: 3.372200000 seconds Frame Number: 6 Packet Length: 110 bytes Capture Length: 110 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9), Dst: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Destination: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Source: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.131 (165.227.249.131), Dst: 165.227.249.115 (165.227.249.115) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 96 Identification: 0x0000 (0) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfbce [correct] Good: True Bad : False Source: 165.227.249.131 (165.227.249.131) Destination: 165.227.249.115 (165.227.249.115) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 76 Checksum: 0x1a70 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xDC10ABE6F2CD7D3C Responder cookie: 0x73E90170D5BA1D19 Next payload: Identification (5) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 68 Encrypted payload (40 bytes) 0000 00 0c 29 ab 06 ab 00 1b 2f 37 c7 b9 08 00 45 00 ..)...../7....E. 0010 00 60 00 00 40 00 40 11 fb ce a5 e3 f9 83 a5 e3 .`..@.@......... 0020 f9 73 01 f4 01 f4 00 4c 1a 70 dc 10 ab e6 f2 cd .s.....L.p...... 0030 7d 3c 73 e9 01 70 d5 ba 1d 19 05 10 02 01 00 00 }uJ..{.8 0060 f7 86 02 52 98 58 63 45 ca 4f 6e c1 e6 bf 67 37 ...R.XcE.On...g7 0070 0e 86 5d 07 d3 7e 01 7d a2 d7 5c 58 fd 85 89 5a ..]..~.}..\X...Z 0080 66 c3 a9 ab 37 0c 2a 92 fd cd d1 3d 89 fd 01 e0 f...7.*....=.... 0090 36 c4 03 c7 70 8c 71 50 28 00 d9 07 20 24 5d da 6...p.qP(... $]. 00a0 e9 ac 15 29 78 3b bb ca 12 cc 8a b3 d1 d3 30 03 ...)x;........0. 00b0 fc 67 47 cb 4e 22 89 9e 49 be 7f ce c4 0b af f3 .gG.N"..I....... 00c0 e7 d8 1a 99 f6 5c 36 39 00 e4 37 94 57 ba d1 6d .....\69..7.W..m 00d0 02 03 7a 6f 51 d2 d4 89 c7 07 2e ec 98 f8 35 71 ..zoQ.........5q 00e0 ea d0 82 50 19 4c 77 5a 6d 3c f0 ed c3 58 3e b6 ...P.LwZm<...X>. 00f0 61 e6 5a 88 61 10 ce 20 a4 a5 1a d3 98 e7 51 51 a.Z.a.. ......QQ 0100 28 bc 51 22 19 1b b5 e4 1b c2 d3 07 a2 75 02 a5 (.Q".........u.. 0110 3c 9c 5b 8a 38 a2 90 6c 2a 63 bb d3 c9 0c 31 66 <.[.8..l*c....1f 0120 dd af 14 85 25 77 6f 4b 79 78 54 ee 6e 4e ee 23 ....%woKyxT.nN.# 0130 54 76 8d a6 ee 24 be 37 b6 60 7e c9 ca 55 fe da Tv...$.7.`~..U.. 0140 18 a8 94 88 62 d7 ff e1 6f d2 5f dd 37 f6 ....b...o._.7. Frame 8 (326 bytes on wire, 326 bytes captured) Arrival Time: Sep 20, 2007 15:29:08.292916000 Time delta from previous packet: 0.343800000 seconds Time since reference or first frame: 5.832501000 seconds Frame Number: 8 Packet Length: 326 bytes Capture Length: 326 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9), Dst: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Destination: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Source: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.131 (165.227.249.131), Dst: 165.227.249.115 (165.227.249.115) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 312 Identification: 0x0000 (0) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfaf6 [correct] Good: True Bad : False Source: 165.227.249.131 (165.227.249.131) Destination: 165.227.249.115 (165.227.249.115) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 292 Checksum: 0x08dd [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xDC10ABE6F2CD7D3C Responder cookie: 0x73E90170D5BA1D19 Next payload: Hash (8) Version: 1.0 Exchange type: Quick Mode (32) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0xA4217EF2 Length: 284 Encrypted payload (256 bytes) 0000 00 0c 29 ab 06 ab 00 1b 2f 37 c7 b9 08 00 45 00 ..)...../7....E. 0010 01 38 00 00 40 00 40 11 fa f6 a5 e3 f9 83 a5 e3 .8..@.@......... 0020 f9 73 01 f4 01 f4 01 24 08 dd dc 10 ab e6 f2 cd .s.....$........ 0030 7d 3c 73 e9 01 70 d5 ba 1d 19 08 10 20 01 a4 21 }.. 0050 52 e7 47 2f 54 83 c0 f9 69 11 48 9b 17 a0 66 0d R.G/T...i.H...f. 0060 40 40 27 13 5c ae 38 52 9f f6 eb 73 72 b7 cf 3d @@'.\.8R...sr..= 0070 cd 6d 58 75 df 3f 80 5a 86 84 65 88 6b 42 10 03 .mXu.?.Z..e.kB.. 0080 b3 bd 05 9f f3 a7 64 03 c6 64 65 cb a9 3a 72 0b ......d..de..:r. 0090 80 18 23 ff c5 d4 75 64 a2 1a e9 a4 62 35 13 12 ..#...ud....b5.. 00a0 82 ca 65 2c 30 21 66 91 c4 44 61 23 47 e3 3d 76 ..e,0!f..Da#G.=v 00b0 e6 e1 0f 1f b3 b5 a5 5a fb de a6 3d 89 2c 2b c6 .......Z...=.,+. 00c0 d4 0c 09 16 95 67 b2 d6 c3 87 f8 d3 c9 a7 b9 44 .....g.........D 00d0 e1 41 67 af 73 a7 41 32 e4 50 fc 39 f6 12 7e f7 .Ag.s.A2.P.9..~. 00e0 f3 b6 d2 32 43 ac 8a 72 13 88 a6 de ad 12 55 d3 ...2C..r......U. 00f0 a5 54 60 88 b3 71 32 a6 b6 f2 55 76 5b 3d f6 8f .T`..q2...Uv[=.. 0100 84 55 14 67 00 ef 4e e6 ec 15 2d b0 6b bc 0d 3c .U.g..N...-.k..< 0110 e3 1c 41 0e 76 79 05 98 fc ef a5 86 29 89 2d 2b ..A.vy......).-+ 0120 06 7b da f8 52 fa c2 5e b1 1a fd b5 27 15 1f 4d .{..R..^....'..M 0130 80 c1 17 05 b4 9b 44 6e 83 30 67 a6 e2 36 4c ec ......Dn.0g..6L. 0140 d1 74 bd 60 47 93 .t.`G. Frame 9 (94 bytes on wire, 94 bytes captured) Arrival Time: Sep 20, 2007 15:29:08.292918000 Time delta from previous packet: 0.000002000 seconds Time since reference or first frame: 5.832503000 seconds Frame Number: 9 Packet Length: 94 bytes Capture Length: 94 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab), Dst: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Destination: 00:1b:2f:37:c7:b9 (00:1b:2f:37:c7:b9) Source: 00:0c:29:ab:06:ab (00:0c:29:ab:06:ab) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.115 (165.227.249.115), Dst: 165.227.249.131 (165.227.249.131) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 80 Identification: 0x0395 (917) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf849 [correct] Good: True Bad : False Source: 165.227.249.115 (165.227.249.115) Destination: 165.227.249.131 (165.227.249.131) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 60 Checksum: 0xfcec [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xDC10ABE6F2CD7D3C Responder cookie: 0x73E90170D5BA1D19 Next payload: Hash (8) Version: 1.0 Exchange type: Quick Mode (32) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0xA4217EF2 Length: 52 Encrypted payload (24 bytes) 0000 00 1b 2f 37 c7 b9 00 0c 29 ab 06 ab 08 00 45 00 ../7....).....E. 0010 00 50 03 95 00 00 80 11 f8 49 a5 e3 f9 73 a5 e3 .P.......I...s.. 0020 f9 83 01 f4 01 f4 00 3c fc ec dc 10 ab e6 f2 cd .......<........ 0030 7d 3c 73 e9 01 70 d5 ba 1d 19 08 10 20 01 a4 21 }-(}B 0070 ed 57 2c 1e 89 03 0c a5 73 b0 9c bb 47 a1 .W,.....s...G.