Try following<br><br> type=passthrough<br> left=<a href="http://127.0.0.1">127.0.0.1</a><br> leftsubnet=<a href="http://1.100.0.9/32">1.100.0.9/32</a>[icmp/]<br> right=<a href="http://127.0.0.1">127.0.0.1</a><br> rightsubnet=<a href="http://1.100.0.5/32">1.100.0.5/32</a>[icmp/]<br> auto=route<br><br><br><br>---- agarwalpiyush@gmail.com skrev ----<br><br><div dir="ltr">Reading another thread, I changed "right" of "skip" connection on both client and server to be "<a href="tel:127.0.0.1">127.0.0.1</a>" and that fixed up a few things:<div>1) The IPsec installed is type transport (as desired)</div><div>2) I do see shunted policies list ICMP PASS</div><div><br></div><div><b>However, I still have my pings from client to server encrypted :(</b><br></div><div><div><br></div><div><b>Client:</b></div><div><div># ipsec statusall</div><div>Status of IKE charon daemon (strongSwan <a href="tel:5.1.2">5.1.2</a>, Linux <a href="tel:4.4.0-75">4.4.0-75</a>-generic, x86_64):</div><div> uptime: 10 minutes, since May 23 12:02:<a href="tel:46 2017">46 2017</a></div><div> malloc: sbrk <a href="tel:2564096">2564096</a>, mmap 0, used <a href="tel:393728">393728</a>, free <a href="tel:2170368">2170368</a></div><div> worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 3</div><div> loaded plugins: charon test-vectors aes rc2 sha1 sha2 md4 md5 rdrand random nonce x509 revocation constraints pkcs1 pkcs7 pkcs8 pkcs12 pem openssl xcbc cmac hmac ctr ccm gcm attr kernel-netlink resolve socket-default stroke updown eap-identity addrblock</div><div>Listening IP addresses:</div><div> <a href="tel:1.100.0.9">1.100.0.9</a></div><div>Connections:</div><div> skip: %any...<a href="http://127.0.0.1">127.0.0.1</a> IKEv2</div><div> skip: local: [C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>] uses public key authentication</div><div> skip: cert: "C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>"</div><div> skip: remote: [C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>] uses public key authentication</div><div> skip: cert: "C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>"</div><div> skip: child: <a href="tel:0.0.0.0">0.0.0.0</a>/0[icmp] === <a href="tel:0.0.0.0">0.0.0.0</a>/0[icmp] PASS</div><div> <a href="http://1.100.0.5">1.100.0.5</a>: <a href="tel:1.100.0.9...1.100.0.5">1.100.0.9...1.100.0.5</a> IKEv2, dpddelay=60s</div><div> <a href="http://1.100.0.5">1.100.0.5</a>: local: [C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>] uses public key authentication</div><div> <a href="http://1.100.0.5">1.100.0.5</a>: cert: "C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>"</div><div> <a href="http://1.100.0.5">1.100.0.5</a>: remote: [C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>] uses public key authentication</div><div> <a href="http://1.100.0.5">1.100.0.5</a>: cert: "C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>"</div><div> <a href="http://1.100.0.5">1.100.0.5</a>: child: dynamic === dynamic <b>TRANSPORT</b>, dpdaction=restart</div><div><b>Shunted Connections:</b></div><div><b> skip: <a href="tel:0.0.0.0">0.0.0.0</a>/0[icmp] === <a href="tel:0.0.0.0">0.0.0.0</a>/0[icmp] PASS</b></div><div>Security Associations (1 up, 0 connecting):</div><div> <a href="tel:1.100.0.5">1.100.0.5</a>[1]: ESTABLISHED 10 minutes ago, <a href="tel:1.100.0.9">1.100.0.9</a>[C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>]...<a href="http://1.100.0.5">1.100.0.5</a>[C=US, ST=CA, L=Mountain View, O=TEST, OU=AgentC, CN=<a href="http://test.com">test.com</a>]</div><div> <a href="tel:1.100.0.5">1.100.0.5</a>[1]: IKEv2 SPIs: be5caa6cea2281c2_i* 79bb5ad924d8d919_r, rekeying in 44 minutes</div><div> <a href="tel:1.100.0.5">1.100.0.5</a>[1]: IKE proposal: AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_2048</div><div> <a href="tel:1.100.0.5">1.100.0.5</a>{1}: INSTALLED, <b>TRANSPORT</b>, ESP SPIs: c989f733_i c3f6a42e_o</div><div> <a href="tel:1.100.0.5">1.100.0.5</a>{1}: AES_CBC_128/HMAC_SHA1_96, <a href="tel:520206">520206</a> bytes_i (2551 pkts, 1s ago), <a href="tel:1691623">1691623</a> bytes_o (2986 pkts, 10s ago), rekeying in 5 minutes</div><div> <a href="tel:1.100.0.5">1.100.0.5</a>{1}: <b><a href="tel:1.100.0.9">1.100.0.9</a>/32 === <a href="tel:1.100.0.5">1.100.0.5</a>/32</b> </div><div><br></div><div><br></div><div><b>Client setkey -DP output:</b></div><div><div><a href="tel:1.100.0.5">1.100.0.5</a>[any] <a href="tel:1.100.0.9">1.100.0.9</a>[any] 255</div><div> in prio high + <a href="tel:1073740029">1073740029</a> ipsec</div><div> esp/transport//unique:1</div><div> created: May 23 12:18:<a href="tel:12 2017">12 2017</a> lastused: May 23 12:18:<a href="tel:52 2017">52 2017</a></div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=2248 seq=1 pid=176401</div><div> refcnt=11</div><div><a href="tel:1.100.0.9">1.100.0.9</a>[any] <a href="tel:1.100.0.5">1.100.0.5</a>[any] 255</div><div> out prio high + <a href="tel:1073740029">1073740029</a> ipsec</div><div> esp/transport//unique:1</div><div> created: May 23 12:18:<a href="tel:12 2017">12 2017</a> lastused: May 23 12:18:<a href="tel:47 2017">47 2017</a></div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=2241 seq=2 pid=176401</div><div> refcnt=11</div><div><a href="tel:0.0.0.0">0.0.0.0</a>/0 0.0.0.0/0 icmp</div><div> fwd prio high + <a href="tel:1073739774">1073739774</a> none</div><div> created: May 23 12:02:<a href="tel:46 2017">46 2017</a> lastused: </div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=2130 seq=3 pid=176401</div><div> refcnt=1</div><div><a href="tel:0.0.0.0">0.0.0.0</a>/0 0.0.0.0/0 icmp</div><div> in prio high + <a href="tel:1073739774">1073739774</a> none</div><div> created: May 23 12:02:<a href="tel:46 2017">46 2017</a> lastused: May 23 12:02:<a href="tel:50 2017">50 2017</a></div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=2120 seq=4 pid=176401</div><div> refcnt=1</div><div><a href="tel:0.0.0.0">0.0.0.0</a>/0 0.0.0.0/0 icmp</div><div> out prio high + <a href="tel:1073739774">1073739774</a> none</div><div> created: May 23 12:02:<a href="tel:46 2017">46 2017</a> lastused: </div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=2113 seq=5 pid=176401</div><div> refcnt=1</div></div><div><br></div><br>On Tuesday, May 23, 2017 at 11:29:04 AM UTC-7, <a href="mailto:agarwa...@gmail.com">agarwa...@gmail.com</a> wrote:<blockquote class="gmail_quote" style="margin: 0;margin-left: 0.8ex;border-left: 1px #ccc solid;padding-left: 1ex;"><div dir="ltr">Hi Noel,<div>Many thanks for the pointer. Looks like I am missing something more or perhaps making a mistake. </div><div><br></div><div>Client [<a href="http://1.100.0.9">1.100.0.9</a>] -- Server [<a href="http://1.100.0.5">1.100.0.5</a>] <br></div><div><br></div><div>Goal: All non-ICMP traffic to be over IPsec tunnel between these two machines.</div><div><br></div><div>Strongswan <a href="tel:5.1.2">5.1.2</a></div><div><br></div><div>The client and server are using self-signed certificates and have each other's certs in /etc/ipsec.d/certs/</div><div><br></div><div><b>Client <a href="http://ipsec.conf">ipsec.conf</a>:</b></div><div><div><br></div></div><div><div>config setup</div><div> charondebug = "dmn 0,mgr 1, ike 2, job 2, cfg 2, knl 1, net 1, tls 1, lib 0, enc 0, tnc 0"</div><div> uniqueids=no</div><div><br></div><div>conn %default</div><div> ikelifetime=60m</div><div> keylife=20m</div><div> rekeymargin=3m</div><div> keyingtries=1</div><div> keyexchange=ikev2</div><div> authby=rsasig</div><div><br></div><div>conn skip</div><div> type=<b><font color="#ff0000">passthrough</font></b></div><div> left=<a href="http://1.100.0.9">1.100.0.9</a></div><div> leftsubnet=<a href="http://0.0.0.0/0%5Bicmp/%5D" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;">0.0.0.0/0[icmp/]</a></div><div> leftcert=client_<a href="http://cert.pem">cert.pem</a></div><div> leftsendcert=always</div><div> rightcert=server_<a href="http://cert.pem">cert.pem</a></div><div> right=<a href="http://1.100.0.5">1.100.0.5</a></div><div> rightsubnet=<a href="http://0.0.0.0/0%5Bicmp/%5D" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;">0.0.0.0/0[icmp/]</a></div><div> auto=route</div><div><br></div><div>conn <a href="tel:1.100.0.5">1.100.0.5</a></div><div> type=<font color="#ff0000"><b>transport</b></font></div><div> left=<a href="http://1.100.0.9">1.100.0.9</a></div><div> leftcert=client_<a href="http://cert.pem">cert.pem</a></div><div> leftsendcert=always</div><div> rightcert=server_<a href="http://cert.pem">cert.pem</a></div><div> right=<a href="http://1.100.0.5">1.100.0.5</a></div><div> reauth=no</div><div> auto=start</div></div><div><br></div><div><b>Server <a href="http://ipsec.conf">ipsec.conf</a>:</b></div><div><br></div><div><div>config setup</div><div> charondebug = "dmn 0,mgr 1, ike 2, job 2, cfg 2, knl 1, net 1, tls 1, lib 0, enc 0, tnc 0"</div><div> uniqueids=no</div><div><br></div><div>conn %default</div><div> ikelifetime=60m</div><div> keylife=20m</div><div> rekeymargin=3m</div><div> keyingtries=1</div><div> keyexchange=ikev2</div><div> authby=rsasig</div><div><br></div><div>conn skip</div><div> type=<b><font color="#ff0000">passthrough</font></b></div><div> left=<a href="http://1.100.0.5">1.100.0.5</a></div><div> leftsubnet=<a href="http://0.0.0.0/0%5Bicmp/%5D" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;">0.0.0.0/0[icmp/]</a></div><div> leftcert=server_<a href="http://cert.pem">cert.pem</a></div><div> leftsendcert=always</div><div> rightcert=client_<a href="http://cert.pem">cert.pem</a></div><div> right=<a href="http://1.100.0.9">1.100.0.9</a></div><div> rightsubnet=<a href="http://0.0.0.0/0%5Bicmp/%5D" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0%255Bicmp%2F%255D\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHZ0VHOsME_CjtHtA78qw8AubjTqQ';return true;">0.0.0.0/0[icmp/]</a></div><div> auto=route</div><div><br></div><div>conn <a href="tel:1.100.0.9">1.100.0.9</a></div><div> type=<b><font color="#ff0000">transport</font></b></div><div> left=<a href="http://1.100.0.5">1.100.0.5</a></div><div> leftcert=server_<a href="http://cert.pem">cert.pem</a></div><div> leftsendcert=always</div><div> rightcert=client_<a href="http://cert.pem">cert.pem</a></div><div> right=<a href="http://1.100.0.9">1.100.0.9</a></div><div> reauth=no</div><div> auto=add</div></div><div><br></div><div><div>=============</div><div>Output of setkey -DP on client:</div><div><div>root@agarwalpiyush0:/usr/<wbr>local/google/home/<wbr>agarwalpiyush/work/agent-v# ./sbin/nfv_cli dm_carl0 setkey -DP</div><div><a href="tel:1.100.0.5 1.100.0.9">1.100.0.5 1.100.0.9</a> icmp</div><div> fwd prio high + <a href="tel:1073740030">1073740030</a> ipsec</div><div> esp/tunnel/<a href="http://1.100.0.5">1.100.0.5</a>-1.100.0.<wbr>9/unique:1</div><div> created: May 23 11:21:<a href="tel:42 2017">42 2017</a> lastused: </div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=1834 seq=1 pid=103981</div><div> refcnt=1</div><div><a href="tel:1.100.0.5 1.100.0.9">1.100.0.5 1.100.0.9</a> icmp</div><div> in prio high + <a href="tel:1073740030">1073740030</a> ipsec</div><div> esp/tunnel/<a href="http://1.100.0.5">1.100.0.5</a>-1.100.0.<wbr>9/unique:1</div><div> created: May 23 11:21:<a href="tel:42 2017">42 2017</a> lastused: </div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=1824 seq=2 pid=103981</div><div> refcnt=1</div><div><a href="tel:1.100.0.9 1.100.0.5">1.100.0.9 1.100.0.5</a> icmp</div><div> out prio high + <a href="tel:1073740030">1073740030</a> ipsec</div><div> esp/tunnel/<a href="http://1.100.0.9">1.100.0.9</a>-1.100.0.<wbr>5/unique:1</div><div> created: May 23 11:21:<a href="tel:42 2017">42 2017</a> lastused: </div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=1817 seq=3 pid=103981</div><div> refcnt=1</div><div><a href="http://0.0.0.0/0" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;">0.0.0.0/0</a> <a href="http://0.0.0.0/0" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;">0.0.0.0/0</a> icmp</div><div> fwd prio high + <a href="tel:1073739774">1073739774</a> none</div><div> created: May 23 11:21:<a href="tel:31 2017">31 2017</a> lastused: </div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=1698 seq=4 pid=103981</div><div> refcnt=1</div><div><a href="http://0.0.0.0/0" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;">0.0.0.0/0</a> <a href="http://0.0.0.0/0" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;">0.0.0.0/0</a> icmp</div><div> in prio high + <a href="tel:1073739774">1073739774</a> none</div><div> created: May 23 11:21:<a href="tel:31 2017">31 2017</a> lastused: May 23 11:21:<a href="tel:35 2017">35 2017</a></div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=1688 seq=5 pid=103981</div><div> refcnt=2</div><div><a href="http://0.0.0.0/0" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;">0.0.0.0/0</a> <a href="http://0.0.0.0/0" target="_blank" rel="nofollow" onmousedown="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;" onclick="this.href='http://www.google.com/url?q\x3dhttp%3A%2F%2F0.0.0.0%2F0\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNETOu60a3HCyMN138-VZlWuvaAA1A';return true;">0.0.0.0/0</a> icmp</div><div> out prio high + <a href="tel:1073739774">1073739774</a> none</div><div> created: May 23 11:21:<a href="tel:31 2017">31 2017</a> lastused: </div><div> lifetime: 0(s) validtime: 0(s)</div><div> spid=1681 seq=6 pid=103981</div><div> refcnt=1</div></div><div><br></div><div><div><br></div></div><div>Questions:</div><div>1) I'd like a transport type IPsec session for all non-ICMP traffic between client and server. As soon as I specify "passthrough" policy, my IPsec session changes to type "tunnel" from output of ipsec status. Clearly I am not specifying passthrough policy correctly.</div><div><br></div><div>1) Do I need to specify left/right for my "skip" passthrough conn? If I do NOT specify left and right for skip connection, I see the IPsec type remains transport (which is good and what I want), I do see shunted policies in "ipsec status" but I still see ping packets are encrypted.</div><div><br></div><div>Thank you for any help!</div><div>Piyush</div><div><br></div>On Monday, May 22, 2017 at 12:19:17 PM UTC-7, Noel Kuntze wrote:<blockquote class="gmail_quote" style="margin:0;margin-left:0.8ex;border-left:1px #ccc solid;padding-left:1ex"><div>Add a passthrough policy for the protocol.<br><br><div class="gmail_quote">Am 22. Mai 2017 19:09:03 MESZ schrieb Piyush Agarwal <<a rel="nofollow">agarwa...@gmail.com</a>>:<blockquote class="gmail_quote" style="margin:0pt 0pt 0pt 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir="ltr">Hi,<div>Reading through the left|rightsubnet, it seems like there is no way to *exclude* a protocol from getting encrypted? </div><div><br></div><div>I have a host to host tunnel and I want to encrypt everything between these except ICMP since I'd like to do out-of-tunnel ping/traceroute.</div><div><br></div><div>Prior to using strongswan, I was using racoon where I could use setkey to manually update the SPD to exclude icmp alone.</div><div><br></div><div>Please advise if there is any way to achieve this with strongswan.</div><div><br></div><div>Thanks.<br clear="all"><div><br></div>-- <br><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">Piyush Agarwal</span><br></div><div><span style="color:rgb(17,17,17)"><font face="arial, helvetica, sans-serif" size="2">Life can only be understood backwards; but it must be lived forwards.</font></span><br></div></div></div></div></div></div></div></div></div></div></div></div></div>
</div></div>
</blockquote></div><br>
-- <br>
Sent from mobile</div></blockquote></div></div></blockquote></div></div></div>