Frame 1 (130 bytes on wire, 130 bytes captured) Arrival Time: Jan 26, 2008 15:38:54.330244000 Time delta from previous packet: 0.000000000 seconds Time since reference or first frame: 0.000000000 seconds Frame Number: 1 Packet Length: 130 bytes Capture Length: 130 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.152 (165.227.249.152), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 116 Identification: 0x89aa (35242) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xb1d8 [correct] Good: True Bad : False Source: 165.227.249.152 (165.227.249.152) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 96 Checksum: 0x7881 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x12173550B1B6D36B Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 88 Security Association payload Next payload: NONE (0) Length: 60 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 48 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 40 Transform number: 1 Transform ID: KEY_IKE (1) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Encryption-Algorithm (1): AES-CBC (7) Key-Length (14): Key-Length (128) Hash-Algorithm (2): SHA (2) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) 0000 00 0c 29 96 e1 fa 00 90 7f 3e ca 91 08 00 45 00 ..)......>....E. 0010 00 74 89 aa 00 00 40 11 b1 d8 a5 e3 f9 98 a5 e3 .t....@......... 0020 f9 96 01 f4 01 f4 00 60 78 81 12 17 35 50 b1 b6 .......`x...5P.. 0030 d3 6b 00 00 00 00 00 00 00 00 01 10 02 00 00 00 .k.............. 0040 00 00 00 00 00 58 00 00 00 3c 00 00 00 01 00 00 .....X...<...... 0050 00 01 00 00 00 30 01 01 00 01 00 00 00 28 01 01 .....0.......(.. 0060 00 00 80 04 00 02 80 03 00 01 80 01 00 07 80 0e ................ 0070 00 80 80 02 00 02 80 0b 00 01 00 0c 00 04 00 00 ................ 0080 70 80 p. Frame 2 (130 bytes on wire, 130 bytes captured) Arrival Time: Jan 26, 2008 15:38:56.413206000 Time delta from previous packet: 2.082962000 seconds Time since reference or first frame: 2.082962000 seconds Frame Number: 2 Packet Length: 130 bytes Capture Length: 130 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.152 (165.227.249.152), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 116 Identification: 0x89ab (35243) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xb1d7 [correct] Good: True Bad : False Source: 165.227.249.152 (165.227.249.152) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 96 Checksum: 0x7881 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x12173550B1B6D36B Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 88 Security Association payload Next payload: NONE (0) Length: 60 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 48 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 40 Transform number: 1 Transform ID: KEY_IKE (1) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Encryption-Algorithm (1): AES-CBC (7) Key-Length (14): Key-Length (128) Hash-Algorithm (2): SHA (2) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) 0000 00 0c 29 96 e1 fa 00 90 7f 3e ca 91 08 00 45 00 ..)......>....E. 0010 00 74 89 ab 00 00 40 11 b1 d7 a5 e3 f9 98 a5 e3 .t....@......... 0020 f9 96 01 f4 01 f4 00 60 78 81 12 17 35 50 b1 b6 .......`x...5P.. 0030 d3 6b 00 00 00 00 00 00 00 00 01 10 02 00 00 00 .k.............. 0040 00 00 00 00 00 58 00 00 00 3c 00 00 00 01 00 00 .....X...<...... 0050 00 01 00 00 00 30 01 01 00 01 00 00 00 28 01 01 .....0.......(.. 0060 00 00 80 04 00 02 80 03 00 01 80 01 00 07 80 0e ................ 0070 00 80 80 02 00 02 80 0b 00 01 00 0c 00 04 00 00 ................ 0080 70 80 p. Frame 3 (130 bytes on wire, 130 bytes captured) Arrival Time: Jan 26, 2008 15:38:59.420336000 Time delta from previous packet: 3.007130000 seconds Time since reference or first frame: 5.090092000 seconds Frame Number: 3 Packet Length: 130 bytes Capture Length: 130 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.152 (165.227.249.152), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 116 Identification: 0x89ac (35244) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xb1d6 [correct] Good: True Bad : False Source: 165.227.249.152 (165.227.249.152) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 96 Checksum: 0x7881 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x12173550B1B6D36B Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 88 Security Association payload Next payload: NONE (0) Length: 60 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 48 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 40 Transform number: 1 Transform ID: KEY_IKE (1) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Encryption-Algorithm (1): AES-CBC (7) Key-Length (14): Key-Length (128) Hash-Algorithm (2): SHA (2) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) 0000 00 0c 29 96 e1 fa 00 90 7f 3e ca 91 08 00 45 00 ..)......>....E. 0010 00 74 89 ac 00 00 40 11 b1 d6 a5 e3 f9 98 a5 e3 .t....@......... 0020 f9 96 01 f4 01 f4 00 60 78 81 12 17 35 50 b1 b6 .......`x...5P.. 0030 d3 6b 00 00 00 00 00 00 00 00 01 10 02 00 00 00 .k.............. 0040 00 00 00 00 00 58 00 00 00 3c 00 00 00 01 00 00 .....X...<...... 0050 00 01 00 00 00 30 01 01 00 01 00 00 00 28 01 01 .....0.......(.. 0060 00 00 80 04 00 02 80 03 00 01 80 01 00 07 80 0e ................ 0070 00 80 80 02 00 02 80 0b 00 01 00 0c 00 04 00 00 ................ 0080 70 80 p. Frame 4 (130 bytes on wire, 130 bytes captured) Arrival Time: Jan 26, 2008 15:39:02.428910000 Time delta from previous packet: 3.008574000 seconds Time since reference or first frame: 8.098666000 seconds Frame Number: 4 Packet Length: 130 bytes Capture Length: 130 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.152 (165.227.249.152), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 116 Identification: 0x89ad (35245) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xb1d5 [correct] Good: True Bad : False Source: 165.227.249.152 (165.227.249.152) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 96 Checksum: 0x7881 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0x12173550B1B6D36B Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 88 Security Association payload Next payload: NONE (0) Length: 60 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 48 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 40 Transform number: 1 Transform ID: KEY_IKE (1) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Encryption-Algorithm (1): AES-CBC (7) Key-Length (14): Key-Length (128) Hash-Algorithm (2): SHA (2) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) 0000 00 0c 29 96 e1 fa 00 90 7f 3e ca 91 08 00 45 00 ..)......>....E. 0010 00 74 89 ad 00 00 40 11 b1 d5 a5 e3 f9 98 a5 e3 .t....@......... 0020 f9 96 01 f4 01 f4 00 60 78 81 12 17 35 50 b1 b6 .......`x...5P.. 0030 d3 6b 00 00 00 00 00 00 00 00 01 10 02 00 00 00 .k.............. 0040 00 00 00 00 00 58 00 00 00 3c 00 00 00 01 00 00 .....X...<...... 0050 00 01 00 00 00 30 01 01 00 01 00 00 00 28 01 01 .....0.......(.. 0060 00 00 80 04 00 02 80 03 00 01 80 01 00 07 80 0e ................ 0070 00 80 80 02 00 02 80 0b 00 01 00 0c 00 04 00 00 ................ 0080 70 80 p. Frame 5 (226 bytes on wire, 226 bytes captured) Arrival Time: Jan 26, 2008 15:39:07.974540000 Time delta from previous packet: 5.545630000 seconds Time since reference or first frame: 13.644296000 seconds Frame Number: 5 Packet Length: 226 bytes Capture Length: 226 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Destination: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.152 (165.227.249.152) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 212 Identification: 0x41cc (16844) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xb956 [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.152 (165.227.249.152) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 192 Checksum: 0x8cf4 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xF0E5993A624CDC6B Responder cookie: 0x0000000000000000 Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 184 Security Association payload Next payload: Vendor ID (13) Length: 56 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 44 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 36 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): AES-CBC (7) Key-Length (14): Key-Length (128) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: unknown vendor ID: 0x4A131C81070358455C5728F20E95452F Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-03 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-02 Vendor ID payload Next payload: Vendor ID (13) Length: 20 Vendor ID: draft-ietf-ipsec-nat-t-ike-00 Vendor ID payload Next payload: NONE (0) Length: 20 Vendor ID: RFC 3706 Detecting Dead IKE Peers (DPD) 0000 00 90 7f 3e ca 91 00 0c 29 96 e1 fa 08 00 45 00 ...>....).....E. 0010 00 d4 41 cc 00 00 80 11 b9 56 a5 e3 f9 96 a5 e3 ..A......V...... 0020 f9 98 01 f4 01 f4 00 c0 8c f4 f0 e5 99 3a 62 4c .............:bL 0030 dc 6b 00 00 00 00 00 00 00 00 01 10 02 00 00 00 .k.............. 0040 00 00 00 00 00 b8 0d 00 00 38 00 00 00 01 00 00 .........8...... 0050 00 01 00 00 00 2c 01 01 00 01 00 00 00 24 01 01 .....,.......$.. 0060 00 00 80 01 00 07 80 0e 00 80 80 02 00 02 80 04 ................ 0070 00 02 80 03 00 01 80 0b 00 01 80 0c 70 80 0d 00 ............p... 0080 00 14 4a 13 1c 81 07 03 58 45 5c 57 28 f2 0e 95 ..J.....XE\W(... 0090 45 2f 0d 00 00 14 7d 94 19 a6 53 10 ca 6f 2c 17 E/....}...S..o,. 00a0 9d 92 15 52 9d 56 0d 00 00 14 90 cb 80 91 3e bb ...R.V........>. 00b0 69 6e 08 63 81 b5 ec 42 7b 1f 0d 00 00 14 44 85 in.c...B{.....D. 00c0 15 2d 18 b6 bb cd 0b e8 a8 46 95 79 dd cc 00 00 .-.......F.y.... 00d0 00 14 af ca d7 13 68 a1 f1 c9 6b 86 96 fc 77 57 ......h...k...wW 00e0 01 00 .. Frame 6 (138 bytes on wire, 138 bytes captured) Arrival Time: Jan 26, 2008 15:39:07.974542000 Time delta from previous packet: 0.000002000 seconds Time since reference or first frame: 13.644298000 seconds Frame Number: 6 Packet Length: 138 bytes Capture Length: 138 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91), Dst: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Destination: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Source: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.152 (165.227.249.152), Dst: 165.227.249.150 (165.227.249.150) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 124 Identification: 0x89ae (35246) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: UDP (0x11) Header checksum: 0xb1cc [correct] Good: True Bad : False Source: 165.227.249.152 (165.227.249.152) Destination: 165.227.249.150 (165.227.249.150) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 104 Checksum: 0x6137 [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xF0E5993A624CDC6B Responder cookie: 0x3EB6B825581D787A Next payload: Security Association (1) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 96 Security Association payload Next payload: Vendor ID (13) Length: 56 Domain of interpretation: IPSEC (1) Situation: IDENTITY (1) Proposal payload # 1 Next payload: NONE (0) Length: 44 Proposal number: 1 Protocol ID: ISAKMP (1) SPI size: 0 Number of transforms: 1 Transform payload # 1 Next payload: NONE (0) Length: 36 Transform number: 1 Transform ID: KEY_IKE (1) Encryption-Algorithm (1): AES-CBC (7) Key-Length (14): Key-Length (128) Hash-Algorithm (2): SHA (2) Group-Description (4): Alternate 1024-bit MODP group (2) Authentication-Method (3): PSK (1) Life-Type (11): Seconds (1) Life-Duration (12): Duration-Value (28800) Vendor ID payload Next payload: NONE (0) Length: 12 Vendor ID: draft-beaulieu-ike-xauth-02.txt 0000 00 0c 29 96 e1 fa 00 90 7f 3e ca 91 08 00 45 00 ..)......>....E. 0010 00 7c 89 ae 00 00 40 11 b1 cc a5 e3 f9 98 a5 e3 .|....@......... 0020 f9 96 01 f4 01 f4 00 68 61 37 f0 e5 99 3a 62 4c .......ha7...:bL 0030 dc 6b 3e b6 b8 25 58 1d 78 7a 01 10 02 00 00 00 .k>..%X.xz...... 0040 00 00 00 00 00 60 0d 00 00 38 00 00 00 01 00 00 .....`...8...... 0050 00 01 00 00 00 2c 01 01 00 01 00 00 00 24 01 01 .....,.......$.. 0060 00 00 80 01 00 07 80 0e 00 80 80 02 00 02 80 04 ................ 0070 00 02 80 03 00 01 80 0b 00 01 80 0c 70 80 00 00 ............p... 0080 00 0c 09 00 26 89 df d6 b7 12 ....&..... Frame 7 (222 bytes on wire, 222 bytes captured) Arrival Time: Jan 26, 2008 15:39:07.974544000 Time delta from previous packet: 0.000002000 seconds Time since reference or first frame: 13.644300000 seconds Frame Number: 7 Packet Length: 222 bytes Capture Length: 222 bytes Protocols in frame: eth:ip:udp:isakmp Ethernet II, Src: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa), Dst: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Destination: 00:90:7f:3e:ca:91 (00:90:7f:3e:ca:91) Source: 00:0c:29:96:e1:fa (00:0c:29:96:e1:fa) Type: IP (0x0800) Internet Protocol, Src: 165.227.249.150 (165.227.249.150), Dst: 165.227.249.152 (165.227.249.152) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 208 Identification: 0x41cd (16845) Flags: 0x00 0... = Reserved bit: Not set .0.. = Don't fragment: Not set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 128 Protocol: UDP (0x11) Header checksum: 0xb959 [correct] Good: True Bad : False Source: 165.227.249.150 (165.227.249.150) Destination: 165.227.249.152 (165.227.249.152) User Datagram Protocol, Src Port: 500 (500), Dst Port: 500 (500) Source port: 500 (500) Destination port: 500 (500) Length: 188 Checksum: 0x06eb [correct] Internet Security Association and Key Management Protocol Initiator cookie: 0xF0E5993A624CDC6B Responder cookie: 0x3EB6B825581D787A Next payload: Key Exchange (4) Version: 1.0 Exchange type: Identity Protection (Main Mode) (2) Flags .... ...0 = Not encrypted .... ..0. = No commit .... .0.. = No authentication Message ID: 0x00000000 Length: 180 Key Exchange payload Next payload: Nonce (10) Length: 132 Key Exchange Data Nonce payload Next payload: NONE (0) Length: 20 Nonce Data 0000 00 90 7f 3e ca 91 00 0c 29 96 e1 fa 08 00 45 00 ...>....).....E. 0010 00 d0 41 cd 00 00 80 11 b9 59 a5 e3 f9 96 a5 e3 ..A......Y...... 0020 f9 98 01 f4 01 f4 00 bc 06 eb f0 e5 99 3a 62 4c .............:bL 0030 dc 6b 3e b6 b8 25 58 1d 78 7a 04 10 02 00 00 00 .k>..%X.xz...... 0040 00 00 00 00 00 b4 0a 00 00 84 0e 5e 2a fb 64 b8 ...........^*.d. 0050 9b 48 c6 c3 78 cd b5 4e 94 23 54 8b c3 f4 27 39 .H..x..N.#T...'9 0060 0a 75 18 dd 85 43 5a 29 cf d8 52 5e c0 1b 19 e1 .u...CZ)..R^.... 0070 10 05 f0 4f 2f d4 82 ed fb 72 0b 4b 54 a5 9d e4 ...O/....r.KT... 0080 63 08 41 5c 12 fa 82 72 8f c6 0e 85 12 22 2b 96 c.A\...r....."+. 0090 80 08 1c 10 ac 2f c7 6c be fb c2 07 e9 89 8b 1a ...../.l........ 00a0 fd 1e 27 02 22 ae 72 0e 73 90 4a 9e 8c b4 88 7b ..'.".r.s.J....{ 00b0 ae 2f ca 9e 9d 23 ea fe 93 6e bf 89 20 eb 7e a7 ./...#...n.. .~. 00c0 44 88 fd a7 c7 27 36 c8 25 36 00 00 00 14 cf 40 D....'6.%6.....@ 00d0 fe e6 d4 d3 30 19 a9 c2 47 3c 70 94 30 b2 ....0...G