vlib: exec cli line-by-line processing and script updates
[vpp.git] / src / scripts / vnet / ipsec_spd_vrf
1
2 create packet-generator interface pg0
3 set int mac addr pg0 4.5.6
4
5 create sub-interfaces pg0 1
6 create sub-interfaces pg0 2
7 create sub-interfaces pg0 3
8
9 ip table add 1
10 ip table add 2
11 ip table add 3
12
13 set int ip table pg0.1 1
14 set int ip table pg0.2 2
15 set int ip table pg0.3 3
16
17 set int ip address pg0.1 192.168.0.1/24
18 set int ip address pg0.2 192.168.0.1/24
19 set int ip address pg0.3 192.168.0.1/24
20
21 set int state pg0 up
22 set int state pg0.1 up
23 set int state pg0.2 up
24 set int state pg0.3 up
25
26 ipsec sa add 2 spi 2 crypto-key 6541686776336961656264656f6f6579 crypto-alg aes-cbc-128 tunnel-src 192.168.0.1 tunnel-dst 192.168.0.2 tx-table-id 2
27 ipsec sa add 3 spi 3 crypto-key 6541686776336961656264656f6f6579 crypto-alg aes-cbc-128 tunnel-src 192.168.0.1 tunnel-dst 192.168.0.2 tx-table-id 3
28
29 ipsec spd add 1
30 set interface ipsec spd pg0.1 1
31 ipsec policy add spd 1 priority 100 outbound action bypass protocol 50
32 ipsec policy add spd 1 priority 10 outbound action protect sa 2 local-ip-range 10.5.0.0 - 10.5.0.255 remote-ip-range 10.6.0.0 - 10.6.0.16
33 ipsec policy add spd 1 priority 10 outbound action protect sa 3 local-ip-range 10.5.0.0 - 10.5.0.255 remote-ip-range 10.6.0.17 - 10.6.0.32
34
35 ip route table 1 add 10.6.0.0/16 via 192.168.0.2 pg0.1
36 set ip neighbor pg0.1 192.168.0.2 00:11:22:33:44:55
37 set ip neighbor pg0.2 192.168.0.2 00:11:22:33:44:55
38 set ip neighbor pg0.3 192.168.0.2 00:11:22:33:44:55
39
40 trace add pg-input 100
41
42 packet-generator new {                                          \
43   name ipsec2                                                   \
44   limit 1                                                       \
45   rate 1e4                                                      \
46   node ethernet-input                                           \
47   interface pg0                                                 \
48   size 100-100                                                  \
49   data {                                                        \
50    IP4: 1.2.3 -> 4.5.6 vlan 1                                   \
51    UDP: 10.5.0.1 -> 10.6.0.1                                    \
52    UDP: 4321 -> 1234                                            \
53     length 72                                                   \
54     incrementing 100                                            \
55   }                                                             \
56 }
57
58 packet-generator new {                                          \
59   name ipsec3                                                   \
60   limit 1                                                       \
61   rate 1e4                                                      \
62   node ethernet-input                                           \
63   interface pg0                                                 \
64   size 100-100                                                  \
65   data {                                                        \
66    IP4: 1.2.3 -> 4.5.6 vlan 1                                   \
67    UDP: 10.5.0.1 -> 10.6.0.22                                   \
68    UDP: 4321 -> 1234                                            \
69     length 72                                                   \
70     incrementing 100                                            \
71   }                                                             \
72 }