Hi emnoc,
The command (diag vpn tunnel show) is not working,
here is the diag vpn tunnel list instead.
name=Jason ver=1 serial=2 0.0.0.0:0->175.*.*.*:0 lgwy=dyn tun=tunnel mode=auto bound_if=5
proxyid_num=1 child_num=0 refcnt=7 ilast=344 olast=344
stat: rxp=0 txp=0 rxb=0 txb=0
dpd: mode=active on=0 idle=5000ms retry=3 count=0 seqno=36393
natt: mode=none draft=0 interval=0 remote_port=0
proxyid=TestJason proto=0 sa=1 ref=2 auto_negotiate=0 serial=12
src: 0:192.168.10.0/255.255.255.0:0
dst: 0:192.168.0.0/255.255.255.0:0
SA: ref=3 options=0000000d type=00 soft=0 mtu=1280 expire=6815 replaywin=0 seqno=1
life: type=01 bytes=0/0 timeout=7150/7200
dec: spi=e30e81f4 esp=3des key=24 2f2005f432d5808a7a769ef4ab75357f6b129e3f086dcef3
ah=sha1 key=20 eee8b5f7917d1e6093782d5fa55479b8917f73d3
enc: spi=88081883 esp=3des key=24 e862a4412b8fe4f9e08b6bb01c362f129ffd8b3c71910a70
ah=sha1 key=20 df3c7aaa9cfecb0b8ef13f43b53fb83020facbdd
npu_flag=00 npu_rgwy=175.*.*.* npu_lgwy=0.0.0.0 npu_selid=c, dec:pkts/bytes=0/0, enc:pkts/bytes=0/0
Wireshark (tethereal)
tethereal -i eth1 -R esp.spi
0.000000 175.*.*.* -> 116.48.*.* ESP ESP (SPI=0xe30e81f4)
1.000096 175.*.*.* -> 116.48.*.* ESP ESP (SPI=0xe30e81f4)
1.999981 175.*.*.* -> 116.48.*.* ESP ESP (SPI=0xe30e81f4)
2.999971 175.*.*.* -> 116.48.*.* ESP ESP (SPI=0xe30e81f4)
3.999999 175.*.*.* -> 116.48.*.* ESP ESP (SPI=0xe30e81f4)
in /var/log/secure
Jul 17 23:03:33 localhost pluto[31358]: " twghnet" #5: transition from state STATE_MAIN_I3 to state STATE_MAIN_I4
Jul 17 23:03:33 localhost pluto[31358]: " twghnet" #5: STATE_MAIN_I4: ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192 prf=oakley_sha group=modp1536}
Jul 18 00:41:42 localhost pluto[31358]: " twghnet" #5: DPD: received old or duplicate R_U_THERE
Jul 18 00:41:47 localhost pluto[31358]: " twghnet" #5: DPD: received old or duplicate R_U_THERE
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #5: received Delete SA payload: deleting ISAKMP State #5
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: responding to Main Mode
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: transition from state STATE_MAIN_R0 to state STATE_MAIN_R1
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: STATE_MAIN_R1: sent MR1, expecting MI2
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: transition from state STATE_MAIN_R1 to state STATE_MAIN_R2
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: STATE_MAIN_R2: sent MR2, expecting MI3
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: ignoring informational payload, type IPSEC_INITIAL_CONTACT msgid=00000000
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: Main mode peer ID is ID_IPV4_ADDR: ' 116.*.*.*'
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: transition from state STATE_MAIN_R2 to state STATE_MAIN_R3
Jul 18 00:41:52 localhost pluto[31358]: " twghnet" #6: STATE_MAIN_R3: sent MR3, ISAKMP SA established {auth=OAKLEY_PRESHARED_KEY cipher=oakley_3des_cbc_192 prf=oakley_sha group=modp1536}
Jul 18 01:16:10 localhost pluto[31358]: " twghnet" #6: ignoring informational payload, type INVALID_SPI msgid=00000000
Jul 18 01:16:10 localhost pluto[31358]: " twghnet" #6: received and ignored informational message
Jul 18 01:16:13 localhost pluto[31358]: " twghnet" #6: ignoring informational payload, type INVALID_SPI msgid=00000000
Jul 18 01:16:13 localhost pluto[31358]: " twghnet" #6: received and ignored informational message
For Fortigate Setting
Thanks very much for your help!
B. Regards,
Jason