Yogesh Purohit
2018-11-08 05:17:18 UTC
Hi All,
I was trying to decrypt IKEv1 packets using wireshark 2.6.
For decryption of Ikev1 one needs Initiator cookie and encryption key. I
have enabled log level for ike = 4 in strongswan.conf.
I can see complete dump in log files, where I could find encryption key.
But I was unable to find initiator cookie without which I am unable to
decrypt the packet.
I am using strongswan version 5.5.2.
Please let me know if I have missed something or I am looking at wrong
place for ICOOKIE. In previous versions of strongswan where pluto was used,
a separate line used to be printed in logs such as:
*ICOOKIE: c6 d1 45 92 85 15 0c 7e*
Thanks & Regards,
Yogesh Purohit
I was trying to decrypt IKEv1 packets using wireshark 2.6.
For decryption of Ikev1 one needs Initiator cookie and encryption key. I
have enabled log level for ike = 4 in strongswan.conf.
I can see complete dump in log files, where I could find encryption key.
But I was unable to find initiator cookie without which I am unable to
decrypt the packet.
I am using strongswan version 5.5.2.
Please let me know if I have missed something or I am looking at wrong
place for ICOOKIE. In previous versions of strongswan where pluto was used,
a separate line used to be printed in logs such as:
*ICOOKIE: c6 d1 45 92 85 15 0c 7e*
Thanks & Regards,
Yogesh Purohit