#config vpn ipsec phase1-interface# Phase 2
edit "swan_p1"
set interface "v986"
set ike-version 2
set peertype any
set proposal aes128-sha1
set dhgrp 14
set remote-gw 172.31.203.130
set psksecret ENC xxxxxxx
next
end
#config vpn ipsec phase2-interface# Static route
edit "swan_p2"
set phase1name "swan_p1"
set proposal aes128-sha1
set pfs disable
set src-subnet 10.10.0.0 255.255.240.0
set dst-subnet 10.118.0.0 255.255.0.0
next
end
#config router static# IPSEC routes on the FIM
edit 2
set dst 10.118.0.0 255.255.0.0
set device "swan_p1"
next
#FG74E43E16****** [FIM01] (global) # diagnose test application fctrlproxyd 2
fcp route dump : last_update_time 992760
Slot:3
routecache entry: (1)
checksum:3B B2 EC 83 87 C9 04 11 4B E1 44 2F D3 5C F5 85
vd 4 seq:2 p1:swan_p1 p2: subnet:10.118.0.0 mask:255.255.0.0 enable:1
=========================================
Slot:4
routecache entry: (1)
checksum:3B B2 EC 83 87 C9 04 11 4B E1 44 2F D3 5C F5 85
vd 4 seq:2 p1:swan_p1 p2: subnet:10.118.0.0 mask:255.255.0.0 enable:1
#fctrlproxyd debugs upon route addition/removal
FG74E43E16****** [FIM01] (ipsec_s) # diag debug app fctrlproxyd -1
FG74E43E16****** [FIM01] (ipsec_s) # diag deb en
# static route pointing to vpn interface added
[fcp_proto_fim_recv:720] Recv pkt FCP_PUSH_ROUTE_INFO from slot 4
[routecache_slot_add_rt:231] Add p1:swan_p1 p2: rt:10.118.0.0/255.255.0.0 on slot4 <----- Added to slot4
[fcp_proto_send_route_cs_req:307] Send pkt FCP_GET_ROUTE_CHECK_SUM to slot 3
[fcp_proto_send_route_cs_req:307] Send pkt FCP_GET_ROUTE_CHECK_SUM to slot 4
[fcp_proto_fim_recv:725] Recv pkt FCP_GET_ROUTE_CHECK_SUM_RET from slot 3
[fcp_proto_fim_recv:725] Recv pkt FCP_GET_ROUTE_CHECK_SUM_RET from slot 4
fcp_proto_proc_local_port_info 917: received port info from 2 entry_nr 17
[fcp_proto_send_route_cs_req:307] Send pkt FCP_GET_ROUTE_CHECK_SUM to slot 3
[fcp_proto_send_route_cs_req:307] Send pkt FCP_GET_ROUTE_CHECK_SUM to slot 4
[fcp_proto_fim_recv:725] Recv pkt FCP_GET_ROUTE_CHECK_SUM_RET from slot 3
[fcp_proto_fim_recv:725] Recv pkt FCP_GET_ROUTE_CHECK_SUM_RET from slot 4
send local port info entry_nr 38
fcp_proto_send_local_port_info 886: send packet len 1343 ret 1343
send local port info entry_nr 38
fcp_proto_send_local_port_info 886: send packet len 1343 ret 1343
send local port info entry_nr 38
fcp_proto_send_local_port_info 886: send packet len 1343 ret 1343
# static route pointing to vpn interface removed
[fcp_proto_fim_recv:720] Recv pkt FCP_PUSH_ROUTE_INFO from slot 4
[routecache_slot_del_rt:204] Delete p1:swan_p1 p2: rt:10.118.0.0/255.255.0.0 seq 2 vd 4 on slot4 <----- Removed from slot4
fcp_proto_proc_local_port_info 917: received port info from 2 entry_nr 17
[fcp_proto_send_route_cs_req:307] Send pkt FCP_GET_ROUTE_CHECK_SUM to slot 3
[fcp_proto_send_route_cs_req:307] Send pkt FCP_GET_ROUTE_CHECK_SUM to slot 4
[fcp_proto_fim_recv:725] Recv pkt FCP_GET_ROUTE_CHECK_SUM_RET from slot 3
[fcp_proto_fim_recv:725] Recv pkt FCP_GET_ROUTE_CHECK_SUM_RET from slot 4