Post-IPsec-process packet dump: Frame 1 (80 bytes on wire, 80 bytes captured) Arrival Time: Sep 30, 2003 13:32:36.454969000 Time delta from previous packet: 0.000000000 seconds Time relative to first packet: 0.000000000 seconds Frame Number: 1 Packet Length: 80 bytes Capture Length: 80 bytes Enc IPv4, SPI 0xbe2000b9, authentic, confidential Address Family: IPv4 (2) SPI: 0xbe2000b9 Flags: 0x00000c00 Internet Protocol, Src Addr: 64.94.50.108 (64.94.50.108), Dst Addr: 63.202.92.134 (63.202.92.134) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 68 Identification: 0x0024 (36) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 215 Protocol: IPIP (0x04) Header checksum: 0x9477 (correct) Source: 64.94.50.108 (64.94.50.108) Destination: 63.202.92.134 (63.202.92.134) Internet Protocol, Src Addr: 172.30.22.1 (172.30.22.1), Dst Addr: 10.8.8.3 (10.8.8.3) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 48 Identification: 0x0135 (309) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 127 Protocol: TCP (0x06) Header checksum: 0x2669 (correct) Source: 172.30.22.1 (172.30.22.1) Destination: 10.8.8.3 (10.8.8.3) Transmission Control Protocol, Src Port: 1053 (1053), Dst Port: 80 (80), Seq: 3431051181, Ack: 0, Len: 0 Source port: 1053 (1053) Destination port: 80 (80) Sequence number: 3431051181 Header length: 28 bytes Flags: 0x0002 (SYN) 0... .... = Congestion Window Reduced (CWR): Not set .0.. .... = ECN-Echo: Not set ..0. .... = Urgent: Not set ...0 .... = Acknowledgment: Not set .... 0... = Push: Not set .... .0.. = Reset: Not set .... ..1. = Syn: Set .... ...0 = Fin: Not set Window size: 16384 Checksum: 0xee8e (correct) Options: (8 bytes) Maximum segment size: 1406 bytes NOP NOP SACK permitted 0000 02 00 00 00 be 20 00 b9 00 0c 00 00 45 00 00 44 ..... ......E..D 0010 00 24 40 00 d7 04 94 77 40 5e 32 6c 3f ca 5c 86 .$@....w@^2l?.\. 0020 45 00 00 30 01 35 40 00 7f 06 26 69 ac 1e 16 01 E..0.5@...&i.... 0030 0a 08 08 03 04 1d 00 50 cc 81 af ad 00 00 00 00 .......P........ 0040 70 02 40 00 ee 8e 00 00 02 04 05 7e 01 01 04 02 p.@........~.... Frame 2 (76 bytes on wire, 76 bytes captured) Arrival Time: Sep 30, 2003 13:32:36.456287000 Time delta from previous packet: 0.001318000 seconds Time relative to first packet: 0.001318000 seconds Frame Number: 2 Packet Length: 76 bytes Capture Length: 76 bytes Enc IPv4, SPI 0x2e4a4b9b, authentic, confidential Address Family: IPv4 (2) SPI: 0x2e4a4b9b Flags: 0x00000c00 Internet Protocol, Src Addr: 63.202.92.134 (63.202.92.134), Dst Addr: 64.94.50.108 (64.94.50.108) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 64 Identification: 0xf71e (63262) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: IPIP (0x04) Header checksum: 0x0000 (incorrect, should be 0x3481) Source: 63.202.92.134 (63.202.92.134) Destination: 64.94.50.108 (64.94.50.108) Internet Protocol, Src Addr: 10.8.8.3 (10.8.8.3), Dst Addr: 172.30.22.1 (172.30.22.1) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 44 Identification: 0x2bcc (11212) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 63 Protocol: TCP (0x06) Header checksum: 0x3bd6 (correct) Source: 10.8.8.3 (10.8.8.3) Destination: 172.30.22.1 (172.30.22.1) Transmission Control Protocol, Src Port: 80 (80), Dst Port: 1053 (1053), Seq: 1373703718, Ack: 3431051182, Len: 0 Source port: 80 (80) Destination port: 1053 (1053) Sequence number: 1373703718 Acknowledgement number: 3431051182 Header length: 24 bytes Flags: 0x0012 (SYN, ACK) 0... .... = Congestion Window Reduced (CWR): Not set .0.. .... = ECN-Echo: Not set ..0. .... = Urgent: Not set ...1 .... = Acknowledgment: Set .... 0... = Push: Not set .... .0.. = Reset: Not set .... ..1. = Syn: Set .... ...0 = Fin: Not set Window size: 57344 Checksum: 0x0347 (correct) Options: (4 bytes) Maximum segment size: 1460 bytes 0000 02 00 00 00 2e 4a 4b 9b 00 0c 00 00 45 00 00 40 .....JK.....E..@ 0010 f7 1e 40 00 40 04 00 00 3f ca 5c 86 40 5e 32 6c ..@.@...?.\.@^2l 0020 45 00 00 2c 2b cc 40 00 3f 06 3b d6 0a 08 08 03 E..,+.@.?.;..... 0030 ac 1e 16 01 00 50 04 1d 51 e1 0e 26 cc 81 af ae .....P..Q..&.... 0040 60 12 e0 00 03 47 00 00 02 04 05 b4 `....G...... Frame 3 (72 bytes on wire, 72 bytes captured) Arrival Time: Sep 30, 2003 13:32:36.566913000 Time delta from previous packet: 0.110626000 seconds Time relative to first packet: 0.111944000 seconds Frame Number: 3 Packet Length: 72 bytes Capture Length: 72 bytes Enc IPv4, SPI 0xbe2000b9, authentic, confidential Address Family: IPv4 (2) SPI: 0xbe2000b9 Flags: 0x00000c00 Internet Protocol, Src Addr: 64.94.50.108 (64.94.50.108), Dst Addr: 63.202.92.134 (63.202.92.134) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 60 Identification: 0x0025 (37) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 215 Protocol: IPIP (0x04) Header checksum: 0x947e (correct) Source: 64.94.50.108 (64.94.50.108) Destination: 63.202.92.134 (63.202.92.134) Internet Protocol, Src Addr: 172.30.22.1 (172.30.22.1), Dst Addr: 10.8.8.3 (10.8.8.3) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 40 Identification: 0x0137 (311) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 126 Protocol: TCP (0x06) Header checksum: 0x276f (correct) Source: 172.30.22.1 (172.30.22.1) Destination: 10.8.8.3 (10.8.8.3) Transmission Control Protocol, Src Port: 1053 (1053), Dst Port: 80 (80), Seq: 3431051182, Ack: 1373703719, Len: 0 Source port: 1053 (1053) Destination port: 80 (80) Sequence number: 3431051182 Acknowledgement number: 1373703719 Header length: 20 bytes Flags: 0x0010 (ACK) 0... .... = Congestion Window Reduced (CWR): Not set .0.. .... = ECN-Echo: Not set ..0. .... = Urgent: Not set ...1 .... = Acknowledgment: Set .... 0... = Push: Not set .... .0.. = Reset: Not set .... ..0. = Syn: Not set .... ...0 = Fin: Not set Window size: 16872 Checksum: 0xb91c (correct) 0000 02 00 00 00 be 20 00 b9 00 0c 00 00 45 00 00 3c ..... ......E..< 0010 00 25 40 00 d7 04 94 7e 40 5e 32 6c 3f ca 5c 86 .%@....~@^2l?.\. 0020 45 00 00 28 01 37 40 00 7e 06 27 6f ac 1e 16 01 E..(.7@.~.'o.... 0030 0a 08 08 03 04 1d 00 50 cc 81 af ae 51 e1 0e 27 .......P....Q..' 0040 50 10 41 e8 b9 1c 00 00 P.A..... Frame 4 (425 bytes on wire, 425 bytes captured) Arrival Time: Sep 30, 2003 13:32:36.572679000 Time delta from previous packet: 0.005766000 seconds Time relative to first packet: 0.117710000 seconds Frame Number: 4 Packet Length: 425 bytes Capture Length: 425 bytes Enc IPv4, SPI 0xbe2000b9, authentic, confidential Address Family: IPv4 (2) SPI: 0xbe2000b9 Flags: 0x00000c00 Internet Protocol, Src Addr: 64.94.50.108 (64.94.50.108), Dst Addr: 63.202.92.134 (63.202.92.134) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 413 Identification: 0x0026 (38) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 215 Protocol: IPIP (0x04) Header checksum: 0x931c (correct) Source: 64.94.50.108 (64.94.50.108) Destination: 63.202.92.134 (63.202.92.134) Internet Protocol, Src Addr: 172.30.22.1 (172.30.22.1), Dst Addr: 10.8.8.3 (10.8.8.3) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 393 Identification: 0x0138 (312) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 126 Protocol: TCP (0x06) Header checksum: 0x260d (correct) Source: 172.30.22.1 (172.30.22.1) Destination: 10.8.8.3 (10.8.8.3) Transmission Control Protocol, Src Port: 1053 (1053), Dst Port: 80 (80), Seq: 3431051182, Ack: 1373703719, Len: 353 Source port: 1053 (1053) Destination port: 80 (80) Sequence number: 3431051182 Next sequence number: 3431051535 Acknowledgement number: 1373703719 Header length: 20 bytes Flags: 0x0018 (PSH, ACK) 0... .... = Congestion Window Reduced (CWR): Not set .0.. .... = ECN-Echo: Not set ..0. .... = Urgent: Not set ...1 .... = Acknowledgment: Set .... 1... = Push: Set .... .0.. = Reset: Not set .... ..0. = Syn: Not set .... ...0 = Fin: Not set Window size: 16872 Checksum: 0xa8ef (correct) Hypertext Transfer Protocol GET / HTTP/1.1\r\n Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*\r\n Accept-Language: en-us\r\n Accept-Encoding: gzip, deflate\r\n User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)\r\n Host: 10.8.8.3\r\n Connection: Keep-Alive\r\n \r\n 0000 02 00 00 00 be 20 00 b9 00 0c 00 00 45 00 01 9d ..... ......E... 0010 00 26 40 00 d7 04 93 1c 40 5e 32 6c 3f ca 5c 86 .&@.....@^2l?.\. 0020 45 00 01 89 01 38 40 00 7e 06 26 0d ac 1e 16 01 E....8@.~.&..... 0030 0a 08 08 03 04 1d 00 50 cc 81 af ae 51 e1 0e 27 .......P....Q..' 0040 50 18 41 e8 a8 ef 00 00 47 45 54 20 2f 20 48 54 P.A.....GET / HT 0050 54 50 2f 31 2e 31 0d 0a 41 63 63 65 70 74 3a 20 TP/1.1..Accept: 0060 69 6d 61 67 65 2f 67 69 66 2c 20 69 6d 61 67 65 image/gif, image 0070 2f 78 2d 78 62 69 74 6d 61 70 2c 20 69 6d 61 67 /x-xbitmap, imag 0080 65 2f 6a 70 65 67 2c 20 69 6d 61 67 65 2f 70 6a e/jpeg, image/pj 0090 70 65 67 2c 20 61 70 70 6c 69 63 61 74 69 6f 6e peg, application 00a0 2f 76 6e 64 2e 6d 73 2d 65 78 63 65 6c 2c 20 61 /vnd.ms-excel, a 00b0 70 70 6c 69 63 61 74 69 6f 6e 2f 76 6e 64 2e 6d pplication/vnd.m 00c0 73 2d 70 6f 77 65 72 70 6f 69 6e 74 2c 20 61 70 s-powerpoint, ap 00d0 70 6c 69 63 61 74 69 6f 6e 2f 6d 73 77 6f 72 64 plication/msword 00e0 2c 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 78 2d , application/x- 00f0 73 68 6f 63 6b 77 61 76 65 2d 66 6c 61 73 68 2c shockwave-flash, 0100 20 2a 2f 2a 0d 0a 41 63 63 65 70 74 2d 4c 61 6e */*..Accept-Lan 0110 67 75 61 67 65 3a 20 65 6e 2d 75 73 0d 0a 41 63 guage: en-us..Ac 0120 63 65 70 74 2d 45 6e 63 6f 64 69 6e 67 3a 20 67 cept-Encoding: g 0130 7a 69 70 2c 20 64 65 66 6c 61 74 65 0d 0a 55 73 zip, deflate..Us 0140 65 72 2d 41 67 65 6e 74 3a 20 4d 6f 7a 69 6c 6c er-Agent: Mozill 0150 61 2f 34 2e 30 20 28 63 6f 6d 70 61 74 69 62 6c a/4.0 (compatibl 0160 65 3b 20 4d 53 49 45 20 35 2e 30 31 3b 20 57 69 e; MSIE 5.01; Wi 0170 6e 64 6f 77 73 20 4e 54 20 35 2e 30 29 0d 0a 48 ndows NT 5.0)..H 0180 6f 73 74 3a 20 31 30 2e 38 2e 38 2e 33 0d 0a 43 ost: 10.8.8.3..C 0190 6f 6e 6e 65 63 74 69 6f 6e 3a 20 4b 65 65 70 2d onnection: Keep- 01a0 41 6c 69 76 65 0d 0a 0d 0a Alive.... Frame 5 (903 bytes on wire, 903 bytes captured) Arrival Time: Sep 30, 2003 13:32:36.594641000 Time delta from previous packet: 0.021962000 seconds Time relative to first packet: 0.139672000 seconds Frame Number: 5 Packet Length: 903 bytes Capture Length: 903 bytes Enc IPv4, SPI 0x2e4a4b9b, authentic, confidential Address Family: IPv4 (2) SPI: 0x2e4a4b9b Flags: 0x00000c00 Internet Protocol, Src Addr: 63.202.92.134 (63.202.92.134), Dst Addr: 64.94.50.108 (64.94.50.108) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 891 Identification: 0xa020 (40992) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 64 Protocol: IPIP (0x04) Header checksum: 0x0000 (incorrect, should be 0x8844) Source: 63.202.92.134 (63.202.92.134) Destination: 64.94.50.108 (64.94.50.108) Internet Protocol, Src Addr: 10.8.8.3 (10.8.8.3), Dst Addr: 172.30.22.1 (172.30.22.1) Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) 0000 00.. = Differentiated Services Codepoint: Default (0x00) .... ..0. = ECN-Capable Transport (ECT): 0 .... ...0 = ECN-CE: 0 Total Length: 871 Identification: 0x2bcd (11213) Flags: 0x04 .1.. = Don't fragment: Set ..0. = More fragments: Not set Fragment offset: 0 Time to live: 63 Protocol: TCP (0x06) Header checksum: 0x389a (correct) Source: 10.8.8.3 (10.8.8.3) Destination: 172.30.22.1 (172.30.22.1) Transmission Control Protocol, Src Port: 80 (80), Dst Port: 1053 (1053), Seq: 1373703719, Ack: 3431051535, Len: 831 Source port: 80 (80) Destination port: 1053 (1053) Sequence number: 1373703719 Next sequence number: 1373704550 Acknowledgement number: 3431051535 Header length: 20 bytes Flags: 0x0018 (PSH, ACK) 0... .... = Congestion Window Reduced (CWR): Not set .0.. .... = ECN-Echo: Not set ..0. .... = Urgent: Not set ...1 .... = Acknowledgment: Set .... 1... = Push: Set .... .0.. = Reset: Not set .... ..0. = Syn: Not set .... ...0 = Fin: Not set Window size: 57646 Checksum: 0x44a4 (correct) Hypertext Transfer Protocol HTTP/1.1 200 OK\r\n Date: Tue, 30 Sep 2003 19:50:34 GMT\r\n Server: Apache/2.0.44 (Unix)\r\n Keep-Alive: timeout=15, max=100\r\n Connection: Keep-Alive\r\n Transfer-Encoding: chunked\r\n Content-Type: text/html\r\n \r\n Data (635 bytes) 0000 02 00 00 00 2e 4a 4b 9b 00 0c 00 00 45 00 03 7b .....JK.....E..{ 0010 a0 20 40 00 40 04 00 00 3f ca 5c 86 40 5e 32 6c . @.@...?.\.@^2l 0020 45 00 03 67 2b cd 40 00 3f 06 38 9a 0a 08 08 03 E..g+.@.?.8..... 0030 ac 1e 16 01 00 50 04 1d 51 e1 0e 27 cc 81 b1 0f .....P..Q..'.... 0040 50 18 e1 2e 44 a4 00 00 48 54 54 50 2f 31 2e 31 P...D...HTTP/1.1 0050 20 32 30 30 20 4f 4b 0d 0a 44 61 74 65 3a 20 54 200 OK..Date: T 0060 75 65 2c 20 33 30 20 53 65 70 20 32 30 30 33 20 ue, 30 Sep 2003 0070 31 39 3a 35 30 3a 33 34 20 47 4d 54 0d 0a 53 65 19:50:34 GMT..Se 0080 72 76 65 72 3a 20 41 70 61 63 68 65 2f 32 2e 30 rver: Apache/2.0 0090 2e 34 34 20 28 55 6e 69 78 29 0d 0a 4b 65 65 70 .44 (Unix)..Keep 00a0 2d 41 6c 69 76 65 3a 20 74 69 6d 65 6f 75 74 3d -Alive: timeout= 00b0 31 35 2c 20 6d 61 78 3d 31 30 30 0d 0a 43 6f 6e 15, max=100..Con 00c0 6e 65 63 74 69 6f 6e 3a 20 4b 65 65 70 2d 41 6c nection: Keep-Al 00d0 69 76 65 0d 0a 54 72 61 6e 73 66 65 72 2d 45 6e ive..Transfer-En 00e0 63 6f 64 69 6e 67 3a 20 63 68 75 6e 6b 65 64 0d coding: chunked. 00f0 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 74 .Content-Type: t 0100 65 78 74 2f 68 74 6d 6c 0d 0a 0d 0a 32 37 34 0d ext/html....274. 0110 0a 3c 68 74 6d 6c 3e 0a 3c 62 6f 64 79 3e 0a 3c ..
.< 0120 70 3e 0a 43 6f 6e 67 72 61 74 75 6c 61 74 69 6f p>.Congratulatio 0130 6e 73 2e 20 59 6f 75 20 67 6f 74 20 68 65 72 65 ns. You got here 0140 20 76 69 61 20 31 30 2e 38 2e 38 2e 33 21 20 54 via 10.8.8.3! T 0150 68 69 73 20 6d 65 61 6e 73 20 74 68 61 74 0a 79 his means that.y 0160 6f 75 20 77 65 6e 74 20 74 68 72 6f 75 67 68 20 ou went through 0170 74 68 65 20 74 65 73 74 2d 6f 70 65 6e 62 73 64 the test-openbsd 0180 20 49 50 73 65 63 20 67 61 74 65 77 61 79 2e 0a IPsec gateway.. 0190 3c 70 3e 0a 49 66 20 79 6f 75 20 68 61 76 65 20.If you have 01a0 6a 75 73 74 20 63 6f 6d 70 6c 65 74 65 64 20 79 just completed y 01b0 6f 75 72 20 74 65 73 74 20 66 6f 72 20 61 20 6c our test for a l 01c0 6f 67 6f 2c 20 70 6c 65 61 73 65 0a 73 65 6e 64 ogo, please.send 01d0 20 74 68 65 20 66 6f 6c 6c 6f 77 69 6e 67 20 69 the following i 01e0 6e 66 6f 72 6d 61 74 69 6f 6e 20 74 6f 0a 3c 61 nformation to.paul.hoffma 0220 6e 40 76 70 6e 63 2e 6f 72 67 3c 2f 61 3e 3a 0a n@vpnc.org:. 0230 3c 75 6c 3e 0a 3c 6c 69 3e 59 6f 75 72 20 63 6f