Frame 1 (222 bytes on wire, 222 bytes captured) Arrival Time: Oct 24, 2006 12:14:42.619314000 Time delta from previous packet: 0.000000000 seconds Time since reference or first frame: 0.000000000 seconds Frame Number: 1 Packet Length: 222 bytes Capture Length: 222 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Destination: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.145 (165.227.249.145) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 208 Identification: 0x0250 (592) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf8dd [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.145 (165.227.249.145) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 188 Checksum: 0xc296 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x3CC45B7B7A0101A5 Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 180 Security Association payload Next payload: Vendor ID (13) Length: 52 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 40 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 32 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: unknown vendor ID: 0x4A131C81070358455C5728F20E95452F Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-03 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-00 Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: RFC 3706 Detecting Dead IKE Peers (DPD) 0000 00 d0 c9 9c 38 64 00 0c 29 96 e1 fa 08 00 45 00 ....8d..).....E. 0010 00 d0 02 50 00 00 80 11 f8 dd a5 e3 f9 96 a5 e3 ...P............ 0020 f9 91 01 f4 01 f4 00 bc c2 96 3c c4 5b 7b 7a 01 ..........<.[{z. 0030 01 a5 00 00 00 00 00 00 00 00 01 10 02 00 00 00 ................ 0040 00 00 00 00 00 b4 0d 00 00 34 00 00 00 01 00 00 .........4...... 0050 00 01 00 00 00 28 01 01 00 01 00 00 00 20 01 01 .....(....... .. 0060 00 00 80 01 00 05 80 02 00 02 80 04 00 02 80 03 ................ 0070 00 01 80 0b 00 01 80 0c 70 80 0d 00 00 14 4a 13 ........p.....J. 0080 1c 81 07 03 58 45 5c 57 28 f2 0e 95 45 2f 0d 00 ....XE\W(...E/.. 0090 00 14 7d 94 19 a6 53 10 ca 6f 2c 17 9d 92 15 52 ..}...S..o,....R 00a0 9d 56 0d 00 00 14 90 cb 80 91 3e bb 69 6e 08 63 .V........>.in.c 00b0 81 b5 ec 42 7b 1f 0d 00 00 14 44 85 15 2d 18 b6 ...B{.....D..-.. 00c0 bb cd 0b e8 a8 46 95 79 dd cc 00 00 00 14 af ca .....F.y........ 00d0 d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 ..h...k...wW.. Frame 2 (142 bytes on wire, 142 bytes captured) Arrival Time: Oct 24, 2006 12:14:42.619607000 Time delta from previous packet: 0.000293000 seconds Time since reference or first frame: 0.000293000 seconds Frame Number: 2 Packet Length: 142 bytes Capture Length: 142 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.145 (165.227.249.145), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 128 Identification: 0x0000 (0) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb7d [correct] Good: True Bad : False Source: 165.227.249.145 (165.227.249.145) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 108 Checksum: 0xf39a [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x3CC45B7B7A0101A5 Responder cookie: 0x09584FA01F7F5C69 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 100 Security Association payload Next payload: Vendor ID (13) Length: 52 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 40 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 32 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): 3DES-CBC (5) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: RFC 3706 Detecting Dead IKE Peers (DPD) 0000 00 0c 29 96 e1 fa 00 d0 c9 9c 38 64 08 00 45 00 ..).......8d..E. 0010 00 80 00 00 40 00 40 11 fb 7d a5 e3 f9 91 a5 e3 ....@.@..}...... 0020 f9 96 01 f4 01 f4 00 6c f3 9a 3c c4 5b 7b 7a 01 .......l..<.[{z. 0030 01 a5 09 58 4f a0 1f 7f 5c 69 01 10 02 00 00 00 ...XO...\i...... 0040 00 00 00 00 00 64 0d 00 00 34 00 00 00 01 00 00 .....d...4...... 0050 00 01 00 00 00 28 01 01 00 01 00 00 00 20 01 01 .....(....... .. 0060 00 00 80 01 00 05 80 02 00 02 80 04 00 02 80 03 ................ 0070 00 01 80 0b 00 01 80 0c 70 80 00 00 00 14 af ca ........p....... 0080 d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 01 00 ..h...k...wW.. Frame 3 (222 bytes on wire, 222 bytes captured) Arrival Time: Oct 24, 2006 12:14:42.662757000 Time delta from previous packet: 0.043150000 seconds Time since reference or first frame: 0.043443000 seconds Frame Number: 3 Packet Length: 222 bytes Capture Length: 222 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Destination: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.145 (165.227.249.145) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 208 Identification: 0x0251 (593) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf8dc [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.145 (165.227.249.145) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 188 Checksum: 0x5716 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x3CC45B7B7A0101A5 Responder cookie: 0x09584FA01F7F5C69 Next payload: Key Exchange (4) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 180 Key Exchange payload Next payload: Nonce (10) Length: 132 Key Exchange Data Nonce payload Next payload: NONE (0) Length: 20 Nonce Data 0000 00 d0 c9 9c 38 64 00 0c 29 96 e1 fa 08 00 45 00 ....8d..).....E. 0010 00 d0 02 51 00 00 80 11 f8 dc a5 e3 f9 96 a5 e3 ...Q............ 0020 f9 91 01 f4 01 f4 00 bc 57 16 3c c4 5b 7b 7a 01 ........W.<.[{z. 0030 01 a5 09 58 4f a0 1f 7f 5c 69 04 10 02 00 00 00 ...XO...\i...... 0040 00 00 00 00 00 b4 0a 00 00 84 12 05 b5 60 03 65 .............`.e 0050 21 6e 33 a1 d6 43 cc 96 28 6a 64 41 c4 a1 7f 00 !n3..C..(jdA.... 0060 94 a9 ec e0 3c 45 f4 16 51 49 c0 b3 b8 00 74 69 ....C.f 0100 35 20 27 57 cc 9e b0 1d 0f e6 82 d9 9e 3d 63 12 5 'W.........=c. 0110 36 ba 55 23 dc 76 13 45 eb ed cd d4 e2 e9 82 77 6.U#.v.E.......w 0120 ef 74 c0 19 cd c4 17 23 c5 8e c8 f9 4d 9f ea 94 .t.....#....M... 0130 85 eb 57 a3 c9 0c b0 66 57 4a 7a 9a 83 c6 4c 3e ..W....fWJz...L> 0140 87 10 2a 13 bc 05 31 3a cd 53 66 1c 9f 21 ..*...1:.Sf..! Frame 9 (102 bytes on wire, 102 bytes captured) Arrival Time: Oct 24, 2006 12:14:42.849990000 Time delta from previous packet: 0.103583000 seconds Time since reference or first frame: 0.230676000 seconds Frame Number: 9 Packet Length: 102 bytes Capture Length: 102 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Destination: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.145 (165.227.249.145) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 88 Identification: 0x0254 (596) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xf951 [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.145 (165.227.249.145) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 68 Checksum: 0xf1e5 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x3CC45B7B7A0101A5 Responder cookie: 0x09584FA01F7F5C69 Next payload: Hash (8) Version: 1.0 Exchange type: Quick Mode (32) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x44DB712B Length: 60 Encrypted payload (32 bytes) 0000 00 d0 c9 9c 38 64 00 0c 29 96 e1 fa 08 00 45 00 ....8d..).....E. 0010 00 58 02 54 00 00 80 11 f9 51 a5 e3 f9 96 a5 e3 .X.T.....Q...... 0020 f9 91 01 f4 01 f4 00 44 f1 e5 3c c4 5b 7b 7a 01 .......D..<.[{z. 0030 01 a5 09 58 4f a0 1f 7f 5c 69 08 10 20 01 44 db ...XO...\i.. .D. 0040 71 2b 00 00 00 3c 90 69 5f c3 d3 f8 23 db 1d b8 q+...<.i_...#... 0050 5f ab 2e c3 de 82 1a aa be 3a ae 1d 0e da 5f 1f _........:...._. 0060 98 22 7f 25 84 9f .".%.. Frame 10 (134 bytes on wire, 134 bytes captured) Arrival Time: Oct 24, 2006 12:14:45.656772000 Time delta from previous packet: 2.806782000 seconds Time since reference or first frame: 3.037458000 seconds Frame Number: 10 Packet Length: 134 bytes Capture Length: 134 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.145 (165.227.249.145), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 120 Identification: 0x0004 (4) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb81 [correct] Good: True Bad : False Source: 165.227.249.145 (165.227.249.145) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 100 Checksum: 0x6c60 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x3CC45B7B7A0101A5 Responder cookie: 0x09584FA01F7F5C69 Next payload: Hash (8) Version: 1.0 Exchange type: Informational (5) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0xB54B88B5 Length: 92 Encrypted payload (64 bytes) 0000 00 0c 29 96 e1 fa 00 d0 c9 9c 38 64 08 00 45 00 ..).......8d..E. 0010 00 78 00 04 40 00 40 11 fb 81 a5 e3 f9 91 a5 e3 .x..@.@......... 0020 f9 96 01 f4 01 f4 00 64 6c 60 3c c4 5b 7b 7a 01 .......dl`<.[{z. 0030 01 a5 09 58 4f a0 1f 7f 5c 69 08 10 05 01 b5 4b ...XO...\i.....K 0040 88 b5 00 00 00 5c e5 63 93 91 ff 39 dd 7a 12 df .....\.c...9.z.. 0050 60 34 40 96 14 f0 5e b5 51 06 87 96 07 a8 59 82 `4@...^.Q.....Y. 0060 86 e7 69 9b f2 3c 76 00 e9 58 40 1c 9e de 98 37 ..i..............N.* 0160 f3 f1 45 0b 7c 20 36 3d 95 b6 12 6c ad b2 1d e8 ..E.| 6=...l.... 0170 dd b0 ba 07 1e 06 0b 7c db c6 6c dd 8b 6e 43 05 .......|..l..nC. 0180 40 a0 72 71 3a 46 09 8c f9 fe d2 46 38 2d @.rq:F.....F8- Frame 14 (134 bytes on wire, 134 bytes captured) Arrival Time: Oct 24, 2006 12:14:51.658225000 Time delta from previous packet: 1.341504000 seconds Time since reference or first frame: 9.038911000 seconds Frame Number: 14 Packet Length: 134 bytes Capture Length: 134 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:d0:c9:9c:38:64 (00:d0:c9:9c:38:64) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.145 (165.227.249.145), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 120 Identification: 0x0006 (6) Flags: 0x04 (Don't Fragment) 0... = Reserved bit: Not set .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xfb7f [correct] Good: True Bad : False Source: 165.227.249.145 (165.227.249.145) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 100 Checksum: 0x07a8 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x3CC45B7B7A0101A5 Responder cookie: 0x09584FA01F7F5C69 Next payload: Hash (8) Version: 1.0 Exchange type: Informational (5) Flags .... ...1 = Encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0xFE2F97F7 Length: 92 Encrypted payload (64 bytes) 0000 00 0c 29 96 e1 fa 00 d0 c9 9c 38 64 08 00 45 00 ..).......8d..E. 0010 00 78 00 06 40 00 40 11 fb 7f a5 e3 f9 91 a5 e3 .x..@.@......... 0020 f9 96 01 f4 01 f4 00 64 07 a8 3c c4 5b 7b 7a 01 .......d..<.[{z. 0030 01 a5 09 58 4f a0 1f 7f 5c 69 08 10 05 01 fe 2f ...XO...\i...../ 0040 97 f7 00 00 00 5c 98 41 96 35 cf 3f 7f 86 41 b7 .....\.A.5.?..A. 0050 f2 a2 52 04 78 b8 f1 6b c4 53 f6 8d 87 08 3c 42 ..R.x..k.S....