2 * Copyright (c) 2020 Cisco and/or its affiliates.
3 * Licensed under the Apache License, Version 2.0 (the "License");
4 * you may not use this file except in compliance with the License.
5 * You may obtain a copy of the License at:
7 * http://www.apache.org/licenses/LICENSE-2.0
9 * Unless required by applicable law or agreed to in writing, software
10 * distributed under the License is distributed on an "AS IS" BASIS,
11 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12 * See the License for the specific language governing permissions and
13 * limitations under the License.
16 #ifndef __CNAT_SESSION_H__
17 #define __CNAT_SESSION_H__
19 #include <vnet/udp/udp_packet.h>
21 #include <cnat/cnat_types.h>
22 #include <cnat/cnat_client.h>
23 #include <cnat/cnat_bihash.h>
26 * A session represents the memory of a translation.
27 * In the tx direction (from behind to in front of the NAT), the
28 * session is preserved so subsequent packets follow the same path
29 * even if the translation has been updated. In the tx direction
30 * the session represents the swap from the VIP to the server address
31 * In the RX direction the swap is from the server address/port to VIP.
33 * A session exists only as key and value in the bihash, there is no
34 * pool for this object. If there were a pool, one would need to be
35 * concerned about what worker is using it.
37 typedef struct cnat_session_t_
40 * this key sits in the same memory location a 'key' in the bihash kvp
45 * IP 4/6 address in the rx/tx direction
47 ip46_address_t cs_ip[VLIB_N_DIR];
52 u16 cs_port[VLIB_N_DIR];
55 * The IP protocol TCP or UDP only supported
57 ip_protocol_t cs_proto;
60 * The address family describing the IP addresses
65 * input / output / fib session
72 * this value sits in the same memory location a 'value' in the bihash kvp
77 * The IP address to translate to.
79 ip46_address_t cs_ip[VLIB_N_DIR];
82 * the port to translate to.
84 u16 cs_port[VLIB_N_DIR];
87 * The load balance object to use to forward
92 * Persist translation->ct_lb.dpoi_next_node
97 * Timestamp index this session was last used
110 typedef enum cnat_session_flag_t_
113 * Indicates a return path session that was source NATed
116 CNAT_SESSION_FLAG_HAS_SNAT = (1 << 0),
118 * This session source port was allocated, free it on cleanup
120 CNAT_SESSION_FLAG_ALLOC_PORT = (1 << 1),
122 * This session doesn't have a client, do not attempt to free it
124 CNAT_SESSION_FLAG_NO_CLIENT = (1 << 2),
126 /* Do not actually translate the packet but still forward it
127 * Used for Maglev, with an encap */
128 CNAT_SESSION_FLAG_NO_NAT = (1 << 3),
130 /* Debug flag marking return sessions */
131 CNAT_SESSION_IS_RETURN = (1 << 4),
132 } cnat_session_flag_t;
134 typedef enum cnat_session_location_t_
136 CNAT_LOCATION_INPUT = 0,
137 CNAT_LOCATION_OUTPUT = 1,
138 CNAT_LOCATION_FIB = 0xff,
139 } cnat_session_location_t;
141 extern u8 *format_cnat_session (u8 * s, va_list * args);
144 * Ensure the session object correctly overlays the bihash key/value pair
146 STATIC_ASSERT (STRUCT_OFFSET_OF (cnat_session_t, key) ==
147 STRUCT_OFFSET_OF (cnat_bihash_kv_t, key),
149 STATIC_ASSERT (STRUCT_OFFSET_OF (cnat_session_t, value) ==
150 STRUCT_OFFSET_OF (cnat_bihash_kv_t, value),
152 STATIC_ASSERT (sizeof (cnat_session_t) == sizeof (cnat_bihash_kv_t),
158 extern cnat_bihash_t cnat_session_db;
161 * Callback function invoked during a walk of all translations
163 typedef walk_rc_t (*cnat_session_walk_cb_t) (const cnat_session_t *
167 * Walk/visit each of the cnat session
169 extern void cnat_session_walk (cnat_session_walk_cb_t cb, void *ctx);
172 * Scan the session DB for expired sessions
174 extern u64 cnat_session_scan (vlib_main_t * vm, f64 start_time, int i);
177 * Purge all the sessions
179 extern int cnat_session_purge (void);
182 * Free a session & update refcounts
184 extern void cnat_session_free (cnat_session_t * session);
187 * Port cleanup callback
189 extern void (*cnat_free_port_cb) (u16 port, ip_protocol_t iproto);
192 * fd.io coding-style-patch-verification: ON
195 * eval: (c-set-style "gnu")