Frame 1 (174 bytes on wire, 174 bytes captured) Arrival Time: Sep 5, 2005 11:13:54.452511000 Time delta from previous packet: 0.000000000 seconds Time since reference or first frame: 0.000000000 seconds Frame Number: 1 Packet Length: 174 bytes Capture Length: 174 bytes Ethernet II, Src: 00:0c:29:89:f2:82, Dst: 00:13:46:3d:7d:5e Destination: 00:13:46:3d:7d:5e (00:13:46:3d:7d:5e) Source: 00:0c:29:89:f2:82 (00:0c:29:89:f2:82) Type: IP (0x0800) Frame check sequence: 0x2dd2b949 (correct) Internet Protocol, Src Addr: 165.227.249.122 (165.227.249.122), Dst Addr: 165.227.249.108 (165.227.249.108) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 156 Identification: 0x000c (12) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb96 (correct) Source: 165.227.249.122 (165.227.249.122) Destination: 165.227.249.108 (165.227.249.108) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 136 Checksum: 0xa86f (correct) Internet Security Association and Key Management Protocol Initiator cookie: 0x48068B97C5D819DE Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = No encryption .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 128 Security Association payload Next payload: Vendor ID (13) Length: 56 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 44 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 36 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Authentication-Method (3): PSK (1) Group-Description (4): Alternate 1024-bit MODP group (2) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: NONE (0) Length: 44 Vendor ID: Check Point Check Point Product: VPN-1 Version: NG with Application Intelligence R55 0000 00 13 46 3d 7d 5e 00 0c 29 89 f2 82 08 00 45 00 ..F=}^..).....E. 0010 00 9c 00 0c 40 00 40 11 fb 96 a5 e3 f9 7a a5 e3 ....@.@......z.. 0020 f9 6c 01 f4 01 f4 00 88 a8 6f 48 06 8b 97 c5 d8 .l.......oH..... 0030 19 de 00 00 00 00 00 00 00 00 01 10 02 00 00 00 ................ 0040 00 00 00 00 00 80 0d 00 00 38 00 00 00 01 00 00 .........8...... 0050 00 01 00 00 00 2c 01 01 00 01 00 00 00 24 01 01 .....,.......$.. 0060 00 00 80 01 00 05 80 02 00 02 80 03 00 01 80 04 ................ 0070 00 02 80 0b 00 01 00 0c 00 04 00 00 70 80 00 00 ............p... 0080 00 2c f4 ed 19 e0 c1 14 eb 51 6f aa ac 0e e3 7d .,.......Qo....} 0090 af 28 07 b4 38 1f 00 00 00 01 00 00 13 8d 42 c2 .(..8.........B. 00a0 44 cf 00 00 00 00 18 00 00 00 2d d2 b9 49 D.........-..I Frame 2 (270 bytes on wire, 270 bytes captured) Arrival Time: Sep 5, 2005 11:13:54.462368000 Time delta from previous packet: 0.009857000 seconds Time since reference or first frame: 0.009857000 seconds Frame Number: 2 Packet Length: 270 bytes Capture Length: 270 bytes Ethernet II, Src: 00:13:46:3d:7d:5e, Dst: 00:0c:29:89:f2:82 Destination: 00:0c:29:89:f2:82 (00:0c:29:89:f2:82) Source: 00:13:46:3d:7d:5e (00:13:46:3d:7d:5e) Type: IP (0x0800) Frame check sequence: 0x445765ff (correct) Internet Protocol, Src Addr: 165.227.249.108 (165.227.249.108), Dst Addr: 165.227.249.122 (165.227.249.122) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 252 Identification: 0x39a6 (14758) Flags: 0x00 .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 255 Protocol: UDP (0x11) Header checksum: 0x429c (correct) Source: 165.227.249.108 (165.227.249.108) Destination: 165.227.249.122 (165.227.249.122) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 232 Checksum: 0xf87f (correct) Internet Security Association and Key Management Protocol Initiator cookie: 0x48068B97C5D819DE Responder cookie: 0x88A56F5554F1F012 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = No encryption .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 224 Security Association payload Next payload: Vendor ID (13) Length: 56 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 44 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 36 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Authentication-Method (3): PSK (1) Group-Description (4): Alternate 1024-bit MODP group (2) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-dpd-00.txt Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-stenberg-ipsec-nat-traversal-01 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-stenberg-ipsec-nat-traversal-02 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-00 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-03 0000 00 0c 29 89 f2 82 00 13 46 3d 7d 5e 08 00 45 00 ..).....F=}^..E. 0010 00 fc 39 a6 00 00 ff 11 42 9c a5 e3 f9 6c a5 e3 ..9.....B....l.. 0020 f9 7a 01 f4 01 f4 00 e8 f8 7f 48 06 8b 97 c5 d8 .z........H..... 0030 19 de 88 a5 6f 55 54 f1 f0 12 01 10 02 00 00 00 ....oUT......... 0040 00 00 00 00 00 e0 0d 00 00 38 00 00 00 01 00 00 .........8...... 0050 00 01 00 00 00 2c 01 01 00 01 00 00 00 24 01 01 .....,.......$.. 0060 00 00 80 01 00 05 80 02 00 02 80 03 00 01 80 04 ................ 0070 00 02 80 0b 00 01 00 0c 00 04 00 00 70 80 0d 00 ............p... 0080 00 14 af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 ......h...k...wW 0090 01 00 0d 00 00 14 27 ba b5 dc 01 ea 07 60 ea 4e ......'......`.N 00a0 31 90 ac 27 c0 d0 0d 00 00 14 61 05 c4 22 e7 68 1..'......a..".h 00b0 47 e4 3f 96 84 80 12 92 ae cd 0d 00 00 14 44 85 G.?...........D. 00c0 15 2d 18 b6 bb cd 0b e8 a8 46 95 79 dd cc 0d 00 .-.......F.y.... 00d0 00 14 cd 60 46 43 35 df 21 f8 7c fd b2 fc 68 b6 ...`FC5.!.|...h. 00e0 a4 48 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 .H........>.in.c 00f0 81 b5 ec 42 7b 1f 00 00 00 14 7d 94 19 a6 53 10 ...B{.....}...S. 0100 ca 6f 2c 17 9d 92 15 52 9d 56 44 57 65 ff .o,....R.VDWe. Frame 3 (230 bytes on wire, 230 bytes captured) Arrival Time: Sep 5, 2005 11:13:54.475028000 Time delta from previous packet: 0.012660000 seconds Time since reference or first frame: 0.022517000 seconds Frame Number: 3 Packet Length: 230 bytes Capture Length: 230 bytes Ethernet II, Src: 00:0c:29:89:f2:82, Dst: 00:13:46:3d:7d:5e Destination: 00:13:46:3d:7d:5e (00:13:46:3d:7d:5e) Source: 00:0c:29:89:f2:82 (00:0c:29:89:f2:82) Type: IP (0x0800) Frame check sequence: 0xf67881cc (correct) Internet Protocol, Src Addr: 165.227.249.122 (165.227.249.122), Dst Addr: 165.227.249.108 (165.227.249.108) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 212 Identification: 0x000d (13) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb5d (correct) Source: 165.227.249.122 (165.227.249.122) Destination: 165.227.249.108 (165.227.249.108) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 192 Checksum: 0xaff0 (correct) Internet Security Association and Key Management Protocol Initiator cookie: 0x48068B97C5D819DE Responder cookie: 0x88A56F5554F1F012 Next payload: Key Exchange (4) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = No encryption .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 184 Key Exchange payload Next payload: Nonce (10) Length: 132 Key Exchange Data Nonce payload Next payload: NONE (0) Length: 24 Nonce Data 0000 00 13 46 3d 7d 5e 00 0c 29 89 f2 82 08 00 45 00 ..F=}^..).....E. 0010 00 d4 00 0d 40 00 40 11 fb 5d a5 e3 f9 7a a5 e3 ....@.@..]...z.. 0020 f9 6c 01 f4 01 f4 00 c0 af f0 48 06 8b 97 c5 d8 .l........H..... 0030 19 de 88 a5 6f 55 54 f1 f0 12 04 10 02 00 00 00 ....oUT......... 0040 00 00 00 00 00 b8 0a 00 00 84 b6 38 cd 42 80 2c ...........8.B., 0050 0b 84 b1 bf 97 9f 37 3b 6c 5c f1 ff 2a 40 9d c2 ......7;l\..*@.. 0060 1c 78 8a 4a ea 01 1e 2b a3 10 9a 61 4d 9d 57 fd .x.J...+...aM.W. 0070 3c 04 c6 65 f4 51 8b 3d f7 53 c1 90 10 dc 61 34 <..e.Q.=.S....a4 0080 31 48 79 38 31 57 d4 9c 16 78 7a 13 68 ed 45 43 1Hy81W...xz.h.EC 0090 1e eb a5 b4 7d 7d b9 1c ac cb 4a 5f f8 bb ec b5 ....}}....J_.... 00a0 3d a9 a1 ce 8e 16 5d 53 70 f3 0d 7f f3 86 fc 11 =.....]Sp....... 00b0 c4 34 32 7e dc 19 35 07 85 62 c1 81 69 48 ac 54 .42~..5..b..iH.T 00c0 19 0e c9 a0 bf 4a 65 75 e0 9f 00 00 00 18 f6 6a .....Jeu.......j 00d0 c5 56 e0 05 bb f8 10 74 ce db 13 ed 1e 93 53 6e .V.....t......Sn 00e0 0b c6 f6 78 81 cc ...x.. Frame 4 (226 bytes on wire, 226 bytes captured) Arrival Time: Sep 5, 2005 11:13:54.801764000 Time delta from previous packet: 0.326736000 seconds Time since reference or first frame: 0.349253000 seconds Frame Number: 4 Packet Length: 226 bytes Capture Length: 226 bytes Ethernet II, Src: 00:13:46:3d:7d:5e, Dst: 00:0c:29:89:f2:82 Destination: 00:0c:29:89:f2:82 (00:0c:29:89:f2:82) Source: 00:13:46:3d:7d:5e (00:13:46:3d:7d:5e) Type: IP (0x0800) Frame check sequence: 0x2f31fc2e (correct) Internet Protocol, Src Addr: 165.227.249.108 (165.227.249.108), Dst Addr: 165.227.249.122 (165.227.249.122) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 208 Identification: 0x389e (14494) Flags: 0x00 .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 255 Protocol: UDP (0x11) Header checksum: 0x43d0 (correct) Source: 165.227.249.108 (165.227.249.108) Destination: 165.227.249.122 (165.227.249.122) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 188 Checksum: 0xd577 (correct) Internet Security Association and Key Management Protocol Initiator cookie: 0x48068B97C5D819DE Responder cookie: 0x88A56F5554F1F012 Next payload: Key Exchange (4) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = No encryption .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 180 Key Exchange payload Next payload: Nonce (10) Length: 132 Key Exchange Data Nonce payload Next payload: NONE (0) Length: 20 Nonce Data 0000 00 0c 29 89 f2 82 00 13 46 3d 7d 5e 08 00 45 00 ..).....F=}^..E. 0010 00 d0 38 9e 00 00 ff 11 43 d0 a5 e3 f9 6c a5 e3 ..8.....C....l.. 0020 f9 7a 01 f4 01 f4 00 bc d5 77 48 06 8b 97 c5 d8 .z.......wH..... 0030 19 de 88 a5 6f 55 54 f1 f0 12 04 10 02 00 00 00 ....oUT......... 0040 00 00 00 00 00 b4 0a 00 00 84 f0 75 c9 de bb b4 ...........u.... 0050 5e e7 c8 4b 86 4e 5f 2c ed 97 f7 69 cc f0 39 13 ^..K.N_,...i..9. 0060 2e bb f1 75 cc 62 72 dd b1 47 78 1e 17 28 b8 43 ...u.br..Gx..(.C 0070 a5 42 3c 75 f4 a8 96 08 f5 ca c4 17 97 59 cf d8 .B.s.. 0030 14 a8 1f 28 a2 44 55 b9 9c 27 4c 64 58 47 6a ad ...(.DU..'LdXGj. 0040 f0 b2 02 a6 4e bf 7c 58 0b c8 7e 5f c3 71 02 23 ....N.|X..~_.q.# 0050 4e e7 ed 7b e8 75 a5 93 c8 10 ec 40 9a ee 4c 13 N..{.u.....@..L. 0060 93 78 60 f4 3f 19 ab f4 29 c7 f8 b7 fa cc 69 06 .x`.?...).....i. 0070 bb 5b 44 07 99 4c b3 20 10 f6 24 96 dc 71 01 0e .[D..L. ..$..q.. 0080 e2 55 .U Frame 13 (130 bytes on wire, 130 bytes captured) Arrival Time: Sep 5, 2005 11:13:59.356343000 Time delta from previous packet: 3.995722000 seconds Time since reference or first frame: 4.903832000 seconds Frame Number: 13 Packet Length: 130 bytes Capture Length: 130 bytes Ethernet II, Src: 00:0c:29:89:f2:82, Dst: 00:13:46:3d:7d:5e Destination: 00:13:46:3d:7d:5e (00:13:46:3d:7d:5e) Source: 00:0c:29:89:f2:82 (00:0c:29:89:f2:82) Type: IP (0x0800) Frame check sequence: 0x85c93b34 (correct) Internet Protocol, Src Addr: 165.227.249.122 (165.227.249.122), Dst Addr: 165.227.249.108 (165.227.249.108) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 112 Identification: 0x0008 (8) Flags: 0x00 .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 255 Protocol: ESP (0x32) Header checksum: 0x7ca5 (correct) Source: 165.227.249.122 (165.227.249.122) Destination: 165.227.249.108 (165.227.249.108) Encapsulating Security Payload SPI: 0x99f7fe77 Sequence: 2 Data (84 bytes) 0000 00 13 46 3d 7d 5e 00 0c 29 89 f2 82 08 00 45 00 ..F=}^..).....E. 0010 00 70 00 08 00 00 ff 32 7c a5 a5 e3 f9 7a a5 e3 .p.....2|....z.. 0020 f9 6c 99 f7 fe 77 00 00 00 02 f9 f9 13 d9 7e d4 .l...w........~. 0030 c4 1e 96 a0 4c 86 4f 88 27 a5 cd db cb 10 81 11 ....L.O.'....... 0040 47 e4 e5 89 17 5c 43 da 58 50 41 54 9a d1 57 b1 G....\C.XPAT..W. 0050 10 b8 68 9e 03 92 9f b1 62 14 a1 c7 5c d6 3c b0 ..h.....b...\.<. 0060 dc b6 59 73 7f 53 51 4b e5 27 ed 7b c1 1a ac 79 ..Ys.SQK.'.{...y 0070 ef 46 d8 ca 0d 4f 5c 5d 81 fa 49 f4 db b0 85 c9 .F...O\]..I..... 0080 3b 34 ;4