Frame 1 (226 bytes on wire, 226 bytes captured) Arrival Time: Aug 15, 2006 11:04:45.151333000 Time delta from previous packet: 0.000000000 seconds Time since reference or first frame: 0.000000000 seconds Frame Number: 1 Packet Length: 226 bytes Capture Length: 226 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Destination: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Frame check sequence: 0xb31be570 [correct] Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.141 (165.227.249.141) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 208 Identification: 0x01ac (428) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf985 [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.141 (165.227.249.141) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 188 Checksum: 0x6420 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x1F48E8BC61430918 Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 180 Security Association payload Next payload: Vendor ID (13) Length: 52 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 40 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 32 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: unknown vendor ID: 0x4A131C81070358455C5728F20E95452F Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-03 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-00 Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: RFC 3706 Detecting Dead IKE Peers (DPD) 0000 00 50 bf 94 c7 01 00 0c 29 96 e1 fa 08 00 45 00 .P......).....E. 0010 00 d0 01 ac 00 00 80 11 f9 85 a5 e3 f9 96 a5 e3 ................ 0020 f9 8d 01 f4 01 f4 00 bc 64 20 1f 48 e8 bc 61 43 ........d .H..aC 0030 09 18 00 00 00 00 00 00 00 00 01 10 02 00 00 00 ................ 0040 00 00 00 00 00 b4 0d 00 00 34 00 00 00 01 00 00 .........4...... 0050 00 01 00 00 00 28 01 01 00 01 00 00 00 20 01 01 .....(....... .. 0060 00 00 80 01 00 05 80 02 00 02 80 04 00 02 80 03 ................ 0070 00 01 80 0b 00 01 80 0c 70 80 0d 00 00 14 4a 13 ........p.....J. 0080 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 ....XE\W(...E/.. 0090 00 14 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 ..}...S..o,....R 00a0 9d 56 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 .V........>.in.c 00b0 81 b5 ec 42 7b 1f 0d 00 00 14 44 85 15 2d 18 b6 ...B{.....D..-.. 00c0 bb cd 0b e8 a8 46 95 79 dd cc 00 00 00 14 af ca .....F.y........ 00d0 d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 b3 1b ..h...k...wW.... 00e0 e5 70 .p Frame 2 (266 bytes on wire, 266 bytes captured) Arrival Time: Aug 15, 2006 11:04:45.193228000 Time delta from previous packet: 0.041895000 seconds Time since reference or first frame: 0.041895000 seconds Frame Number: 2 Packet Length: 266 bytes Capture Length: 266 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Type: IP (0x0800) Frame check sequence: 0x95e2f3bb [correct] Internet Protocol, Src: 165.227.249.141 (165.227.249.141), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 248 Identification: 0x0004 (4) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb05 [correct] Good: True Bad : False Source: 165.227.249.141 (165.227.249.141) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 228 Checksum: 0x974d [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x1F48E8BC61430918 Responder cookie: 0x78166C9630BE28C6 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 220 Security Association payload Next payload: Vendor ID (13) Length: 52 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 40 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 32 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: unknown vendor ID: 0x8F9CC94E01248ECDF147594C284B213B Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-stenberg-ipsec-nat-traversal-01 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-stenberg-ipsec-nat-traversal-02 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-00 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-03 0000 00 0c 29 96 e1 fa 00 50 bf 94 c7 01 08 00 45 00 ..)....P......E. 0010 00 f8 00 04 40 00 40 11 fb 05 a5 e3 f9 8d a5 e3 ....@.@......... 0020 f9 96 01 f4 01 f4 00 e4 97 4d 1f 48 e8 bc 61 43 .........M.H..aC 0030 09 18 78 16 6c 96 30 be 28 c6 01 10 02 00 00 00 ..x.l.0.(....... 0040 00 00 00 00 00 dc 0d 00 00 34 00 00 00 01 00 00 .........4...... 0050 00 01 00 00 00 28 01 01 00 01 00 00 00 20 01 01 .....(....... .. 0060 00 00 80 01 00 05 80 02 00 02 80 04 00 02 80 03 ................ 0070 00 01 80 0b 00 01 80 0c 70 80 0d 00 00 14 8f 9c ........p....... 0080 c9 4e 01 24 8e cd f1 47 59 4c 28 4b 21 3b 0d 00 .N.$...GYL(K!;.. 0090 00 14 27 ba b5 dc 01 ea 07 60 ea 4e 31 90 ac 27 ..'......`.N1..' 00a0 c0 d0 0d 00 00 14 61 05 c4 22 e7 68 47 e4 3f 96 ......a..".hG.?. 00b0 84 80 12 92 ae cd 0d 00 00 14 44 85 15 2d 18 b6 ..........D..-.. 00c0 bb cd 0b e8 a8 46 95 79 dd cc 0d 00 00 14 cd 60 .....F.y.......` 00d0 46 43 35 df 21 f8 7c fd b2 fc 68 b6 a4 48 0d 00 FC5.!.|...h..H.. 00e0 00 14 90 cb 80 91 3e bb 69 6e 08 63 81 b5 ec 42 ......>.in.c...B 00f0 7b 1f 00 00 00 14 7d 94 19 a6 53 10 ca 6f 2c 17 {.....}...S..o,. 0100 9d 92 15 52 9d 56 95 e2 f3 bb ...R.V.... Frame 3 (274 bytes on wire, 274 bytes captured) Arrival Time: Aug 15, 2006 11:04:45.299755000 Time delta from previous packet: 0.106527000 seconds Time since reference or first frame: 0.148422000 seconds Frame Number: 3 Packet Length: 274 bytes Capture Length: 274 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Destination: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Frame check sequence: 0x45d18b88 [correct] Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.141 (165.227.249.141) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 256 Identification: 0x01ad (429) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf954 [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.141 (165.227.249.141) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 236 Checksum: 0x5e4b [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x1F48E8BC61430918 Responder cookie: 0x78166C9630BE28C6 Next payload: Key Exchange (4) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 228 Key Exchange payload Next payload: Nonce (10) Length: 132 Key Exchange Data Nonce payload Next payload: NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) (130) Length: 20 Nonce Data NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) payload Next payload: NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) (130) Length: 24 Hash of address and port: FA5058F34F9CFFC00C7737D9D98006C0D87CFA3E NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) payload Next payload: NONE (0) Length: 24 Hash of address and port: 485C417F7639895D65D31E89D58F8A65250C790A 0000 00 50 bf 94 c7 01 00 0c 29 96 e1 fa 08 00 45 00 .P......).....E. 0010 01 00 01 ad 00 00 80 11 f9 54 a5 e3 f9 96 a5 e3 .........T...... 0020 f9 8d 01 f4 01 f4 00 ec 5e 4b 1f 48 e8 bc 61 43 ........^K.H..aC 0030 09 18 78 16 6c 96 30 be 28 c6 04 10 02 00 00 00 ..x.l.0.(....... 0040 00 00 00 00 00 e4 0a 00 00 84 a7 9c 8f f7 2d 52 ..............-R 0050 b1 8f 57 c1 03 f2 4d bb d2 9d 92 5e 8e 9a ca ff ..W...M....^.... 0060 62 43 93 c7 de 5c f0 5e 02 ec 0f d2 38 92 fd 3f bC...\.^....8..? 0070 18 f3 8c ba 9b b0 7c 79 95 c7 b2 7b 81 f6 80 91 ......|y...{.... 0080 4c 2e 87 c8 61 41 e0 8b 94 a0 b3 e3 4e 6e 05 26 L...aA......Nn.& 0090 44 1f b0 a7 01 76 2b c4 d9 4d 98 4e 41 7e 32 56 D....v+..M.NA~2V 00a0 aa ed 3e fc 36 3f ad 33 cd 26 29 1a ba f9 58 8b ..>.6?.3.&)...X. 00b0 77 2a d3 8e ce 1a b3 89 3d 58 11 0a 60 a6 bc 06 w*......=X..`... 00c0 79 46 57 6a 07 03 96 73 ff 69 82 00 00 14 9e 59 yFWj...s.i.....Y 00d0 a9 72 4a c7 f9 e7 48 56 96 47 d0 67 eb 77 82 00 .rJ...HV.G.g.w.. 00e0 00 18 fa 50 58 f3 4f 9c ff c0 0c 77 37 d9 d9 80 ...PX.O....w7... 00f0 06 c0 d8 7c fa 3e 00 00 00 18 48 5c 41 7f 76 39 ...|.>....H\A.v9 0100 89 5d 65 d3 1e 89 d5 8f 8a 65 25 0c 79 0a 45 d1 .]e......e%.y.E. 0110 8b 88 .. Frame 4 (274 bytes on wire, 274 bytes captured) Arrival Time: Aug 15, 2006 11:04:45.313305000 Time delta from previous packet: 0.013550000 seconds Time since reference or first frame: 0.161972000 seconds Frame Number: 4 Packet Length: 274 bytes Capture Length: 274 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Type: IP (0x0800) Frame check sequence: 0x51415691 [correct] Internet Protocol, Src: 165.227.249.141 (165.227.249.141), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 256 Identification: 0x0005 (5) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfafc [correct] Good: True Bad : False Source: 165.227.249.141 (165.227.249.141) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 236 Checksum: 0x32c6 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x1F48E8BC61430918 Responder cookie: 0x78166C9630BE28C6 Next payload: Key Exchange (4) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 228 Key Exchange payload Next payload: Nonce (10) Length: 132 Key Exchange Data Nonce payload Next payload: NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) (130) Length: 20 Nonce Data NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) payload Next payload: NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) (130) Length: 24 Hash of address and port: 485C417F7639895D65D31E89D58F8A65250C790A NAT-D (draft-ietf-ipsec-nat-t-ike-01 to 03) payload Next payload: NONE (0) Length: 24 Hash of address and port: FA5058F34F9CFFC00C7737D9D98006C0D87CFA3E 0000 00 0c 29 96 e1 fa 00 50 bf 94 c7 01 08 00 45 00 ..)....P......E. 0010 01 00 00 05 40 00 40 11 fa fc a5 e3 f9 8d a5 e3 ....@.@......... 0020 f9 96 01 f4 01 f4 00 ec 32 c6 1f 48 e8 bc 61 43 ........2..H..aC 0030 09 18 78 16 6c 96 30 be 28 c6 04 10 02 00 00 00 ..x.l.0.(....... 0040 00 00 00 00 00 e4 0a 00 00 84 ba 93 54 61 3c f7 ............Ta<. 0050 df 48 a9 94 e1 b5 5f b4 a1 51 12 6c 3b bf 6f d5 .H...._..Q.l;.o. 0060 38 14 08 3d 7a 8a 3a 40 70 7e d7 ef d1 70 0a 87 8..=z.:@p~...p.. 0070 0c 57 9e 9e 46 c3 c7 0f ac 94 28 f7 ae 68 43 3e .W..F.....(..hC> 0080 6c 2e 32 c3 a2 cb 46 33 c9 e5 12 57 23 5a 18 c5 l.2...F3...W#Z.. 0090 cb cf cf 2d a7 bf 1a 4c 91 27 2c 0e df 96 d8 ab ...-...L.',..... 00a0 54 7b 28 e8 79 a6 99 35 47 c3 ea 44 99 c2 e7 dd T{(.y..5G..D.... 00b0 c3 8f 50 44 27 01 09 89 f6 9d 5b 22 83 8b 65 41 ..PD'.....["..eA 00c0 45 81 16 6b 4e 23 ed df 7a ea 82 00 00 14 b0 da E..kN#..z....... 00d0 6f 40 72 84 d4 1c 35 25 a4 36 b4 0c d0 be 82 00 o@r...5%.6...... 00e0 00 18 48 5c 41 7f 76 39 89 5d 65 d3 1e 89 d5 8f ..H\A.v9.]e..... 00f0 8a 65 25 0c 79 0a 00 00 00 18 fa 50 58 f3 4f 9c .e%.y......PX.O. 0100 ff c0 0c 77 37 d9 d9 80 06 c0 d8 7c fa 3e 51 41 ...w7......|.>QA 0110 56 91 V. Frame 5 (146 bytes on wire, 146 bytes captured) Arrival Time: Aug 15, 2006 11:04:45.464497000 Time delta from previous packet: 0.151192000 seconds Time since reference or first frame: 0.313164000 seconds Frame Number: 5 Packet Length: 146 bytes Capture Length: 146 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Destination: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Frame check sequence: 0x1f448fab [correct] Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.141 (165.227.249.141) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 128 Identification: 0x01ae (430) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf9d3 [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.141 (165.227.249.141) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 108 Checksum: 0xd117 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x1F48E8BC61430918 Responder cookie: 0x78166C9630BE28C6 Next payload: Identification (5) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 100 Encrypted payload (72 bytes) 0000 00 50 bf 94 c7 01 00 0c 29 96 e1 fa 08 00 45 00 .P......).....E. 0010 00 80 01 ae 00 00 80 11 f9 d3 a5 e3 f9 96 a5 e3 ................ 0020 f9 8d 01 f4 01 f4 00 6c d1 17 1f 48 e8 bc 61 43 .......l...H..aC 0030 09 18 78 16 6c 96 30 be 28 c6 05 10 02 01 00 00 ..x.l.0.(....... 0040 00 00 00 00 00 64 f8 68 2b f7 0a 79 0e 2c ee a7 .....d.h+..y.,.. 0050 ee 55 47 7b 6e c9 29 16 c9 d5 23 92 cf a9 40 89 .UG{n.)...#...@. 0060 6c 0d 2f a9 f6 85 6f 98 1e 25 f5 44 11 0b a2 29 l./...o..%.D...) 0070 b1 69 c3 a5 fa 1e 9a 52 d1 af da 55 d6 e1 9b 37 .i.....R...U...7 0080 37 89 4b 7f a0 06 51 78 f5 49 6d 16 75 2f 1f 44 7.K...Qx.Im.u/.D 0090 8f ab .. Frame 6 (114 bytes on wire, 114 bytes captured) Arrival Time: Aug 15, 2006 11:04:45.465018000 Time delta from previous packet: 0.000521000 seconds Time since reference or first frame: 0.313685000 seconds Frame Number: 6 Packet Length: 114 bytes Capture Length: 114 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Type: IP (0x0800) Frame check sequence: 0x34c1e020 [correct] Internet Protocol, Src: 165.227.249.141 (165.227.249.141), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 96 Identification: 0x0006 (6) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb9b [correct] Good: True Bad : False Source: 165.227.249.141 (165.227.249.141) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 76 Checksum: 0x56b8 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x1F48E8BC61430918 Responder cookie: 0x78166C9630BE28C6 Next payload: Identification (5) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 68 Encrypted payload (40 bytes) 0000 00 0c 29 96 e1 fa 00 50 bf 94 c7 01 08 00 45 00 ..)....P......E. 0010 00 60 00 06 40 00 40 11 fb 9b a5 e3 f9 8d a5 e3 .`..@.@......... 0020 f9 96 01 f4 01 f4 00 4c 56 b8 1f 48 e8 bc 61 43 .......LV..H..aC 0030 09 18 78 16 6c 96 30 be 28 c6 05 10 02 01 00 00 ..x.l.0.(....... 0040 00 00 00 00 00 44 66 f7 d7 69 bf 93 23 94 14 82 .....Df..i..#... 0050 32 1e 61 e0 39 89 84 fe f5 8a 9d c4 2c 27 e4 95 2.a.9.......,'.. 0060 9a f8 d7 82 d7 57 2c b7 65 f1 62 dd 41 ec 34 c1 .....W,.e.b.A.4. 0070 e0 20 . Frame 7 (338 bytes on wire, 338 bytes captured) Arrival Time: Aug 15, 2006 11:04:45.575830000 Time delta from previous packet: 0.110812000 seconds Time since reference or first frame: 0.424497000 seconds Frame Number: 7 Packet Length: 338 bytes Capture Length: 338 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Destination: 00:50:bf:94:c7:01 (00:50:bf:94:c7:01) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Frame check sequence: 0x2db5df03 [correct] Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.141 (165.227.249.141) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 320 Identification: 0x01af (431) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf912 [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.141 (165.227.249.141) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 300 Checksum: 0x8536 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x1F48E8BC61430918 Responder cookie: 0x78166C9630BE28C6 Next payload: Hash (8) Version: 1.0 Exchange type: Quick Mode (32) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0xB8F5710F Length: 292 Encrypted payload (264 bytes) 0000 00 50 bf 94 c7 01 00 0c 29 96 e1 fa 08 00 45 00 .P......).....E. 0010 01 40 01 af 00 00 80 11 f9 12 a5 e3 f9 96 a5 e3 .@.............. 0020 f9 8d 01 f4 01 f4 01 2c 85 36 1f 48 e8 bc 61 43 .......,.6.H..aC 0030 09 18 78 16 6c 96 30 be 28 c6 08 10 20 01 b8 f5 ..x.l.0.(... ... 0040 71 0f 00 00 01 24 5f eb 65 d9 49 cf 3c 70 1f ec q....$_.e.I.