4 from socket import AF_INET, AF_INET6, inet_pton
6 from framework import VppTestCase, VppTestRunner
7 from vpp_neighbor import VppNeighbor, find_nbr
8 from vpp_ip_route import VppIpRoute, VppRoutePath, find_route, \
11 from scapy.packet import Raw
12 from scapy.layers.l2 import Ether, ARP, Dot1Q
13 from scapy.layers.inet import IP, UDP
14 from scapy.contrib.mpls import MPLS
15 from scapy.layers.inet6 import IPv6
17 # not exported by scapy, so redefined here
18 arp_opts = {"who-has": 1, "is-at": 2}
21 class ARPTestCase(VppTestCase):
25 super(ARPTestCase, self).setUp()
27 # create 3 pg interfaces
28 self.create_pg_interfaces(range(4))
30 # pg0 configured with ip4 and 6 addresses used for input
31 # pg1 configured with ip4 and 6 addresses used for output
32 # pg2 is unnumbered to pg0
33 for i in self.pg_interfaces:
38 self.pg0.resolve_arp()
43 # pg3 in a different VRF
44 self.tbl = VppIpTable(self, 1)
45 self.tbl.add_vpp_config()
47 self.pg3.set_table_ip4(1)
51 self.pg0.unconfig_ip4()
52 self.pg0.unconfig_ip6()
54 self.pg1.unconfig_ip4()
55 self.pg1.unconfig_ip6()
57 self.pg3.unconfig_ip4()
58 self.pg3.set_table_ip4(0)
60 for i in self.pg_interfaces:
63 super(ARPTestCase, self).tearDown()
65 def verify_arp_req(self, rx, smac, sip, dip):
67 self.assertEqual(ether.dst, "ff:ff:ff:ff:ff:ff")
68 self.assertEqual(ether.src, smac)
71 self.assertEqual(arp.hwtype, 1)
72 self.assertEqual(arp.ptype, 0x800)
73 self.assertEqual(arp.hwlen, 6)
74 self.assertEqual(arp.plen, 4)
75 self.assertEqual(arp.op, arp_opts["who-has"])
76 self.assertEqual(arp.hwsrc, smac)
77 self.assertEqual(arp.hwdst, "00:00:00:00:00:00")
78 self.assertEqual(arp.psrc, sip)
79 self.assertEqual(arp.pdst, dip)
81 def verify_arp_resp(self, rx, smac, dmac, sip, dip):
83 self.assertEqual(ether.dst, dmac)
84 self.assertEqual(ether.src, smac)
87 self.assertEqual(arp.hwtype, 1)
88 self.assertEqual(arp.ptype, 0x800)
89 self.assertEqual(arp.hwlen, 6)
90 self.assertEqual(arp.plen, 4)
91 self.assertEqual(arp.op, arp_opts["is-at"])
92 self.assertEqual(arp.hwsrc, smac)
93 self.assertEqual(arp.hwdst, dmac)
94 self.assertEqual(arp.psrc, sip)
95 self.assertEqual(arp.pdst, dip)
97 def verify_arp_vrrp_resp(self, rx, smac, dmac, sip, dip):
99 self.assertEqual(ether.dst, dmac)
100 self.assertEqual(ether.src, smac)
103 self.assertEqual(arp.hwtype, 1)
104 self.assertEqual(arp.ptype, 0x800)
105 self.assertEqual(arp.hwlen, 6)
106 self.assertEqual(arp.plen, 4)
107 self.assertEqual(arp.op, arp_opts["is-at"])
108 self.assertNotEqual(arp.hwsrc, smac)
109 self.assertTrue("00:00:5e:00:01" in arp.hwsrc or
110 "00:00:5E:00:01" in arp.hwsrc)
111 self.assertEqual(arp.hwdst, dmac)
112 self.assertEqual(arp.psrc, sip)
113 self.assertEqual(arp.pdst, dip)
115 def verify_ip(self, rx, smac, dmac, sip, dip):
117 self.assertEqual(ether.dst, dmac)
118 self.assertEqual(ether.src, smac)
121 self.assertEqual(ip.src, sip)
122 self.assertEqual(ip.dst, dip)
124 def verify_ip_o_mpls(self, rx, smac, dmac, label, sip, dip):
126 self.assertEqual(ether.dst, dmac)
127 self.assertEqual(ether.src, smac)
130 self.assertTrue(mpls.label, label)
133 self.assertEqual(ip.src, sip)
134 self.assertEqual(ip.dst, dip)
140 # Generate some hosts on the LAN
142 self.pg1.generate_remote_hosts(11)
145 # Send IP traffic to one of these unresolved hosts.
146 # expect the generation of an ARP request
148 p = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
149 IP(src=self.pg0.remote_ip4, dst=self.pg1._remote_hosts[1].ip4) /
150 UDP(sport=1234, dport=1234) /
153 self.pg0.add_stream(p)
154 self.pg_enable_capture(self.pg_interfaces)
157 rx = self.pg1.get_capture(1)
159 self.verify_arp_req(rx[0],
162 self.pg1._remote_hosts[1].ip4)
165 # And a dynamic ARP entry for host 1
167 dyn_arp = VppNeighbor(self,
168 self.pg1.sw_if_index,
169 self.pg1.remote_hosts[1].mac,
170 self.pg1.remote_hosts[1].ip4)
171 dyn_arp.add_vpp_config()
174 # now we expect IP traffic forwarded
176 dyn_p = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
177 IP(src=self.pg0.remote_ip4,
178 dst=self.pg1._remote_hosts[1].ip4) /
179 UDP(sport=1234, dport=1234) /
182 self.pg0.add_stream(dyn_p)
183 self.pg_enable_capture(self.pg_interfaces)
186 rx = self.pg1.get_capture(1)
188 self.verify_ip(rx[0],
190 self.pg1.remote_hosts[1].mac,
192 self.pg1._remote_hosts[1].ip4)
195 # And a Static ARP entry for host 2
197 static_arp = VppNeighbor(self,
198 self.pg1.sw_if_index,
199 self.pg1.remote_hosts[2].mac,
200 self.pg1.remote_hosts[2].ip4,
202 static_arp.add_vpp_config()
204 static_p = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
205 IP(src=self.pg0.remote_ip4,
206 dst=self.pg1._remote_hosts[2].ip4) /
207 UDP(sport=1234, dport=1234) /
210 self.pg0.add_stream(static_p)
211 self.pg_enable_capture(self.pg_interfaces)
214 rx = self.pg1.get_capture(1)
216 self.verify_ip(rx[0],
218 self.pg1.remote_hosts[2].mac,
220 self.pg1._remote_hosts[2].ip4)
223 # flap the link. dynamic ARPs get flush, statics don't
225 self.pg1.admin_down()
228 self.pg0.add_stream(static_p)
229 self.pg_enable_capture(self.pg_interfaces)
231 rx = self.pg1.get_capture(1)
233 self.verify_ip(rx[0],
235 self.pg1.remote_hosts[2].mac,
237 self.pg1._remote_hosts[2].ip4)
239 self.pg0.add_stream(dyn_p)
240 self.pg_enable_capture(self.pg_interfaces)
243 rx = self.pg1.get_capture(1)
244 self.verify_arp_req(rx[0],
247 self.pg1._remote_hosts[1].ip4)
250 # Send an ARP request from one of the so-far unlearned remote hosts
252 p = (Ether(dst="ff:ff:ff:ff:ff:ff",
253 src=self.pg1._remote_hosts[3].mac) /
255 hwsrc=self.pg1._remote_hosts[3].mac,
256 pdst=self.pg1.local_ip4,
257 psrc=self.pg1._remote_hosts[3].ip4))
259 self.pg1.add_stream(p)
260 self.pg_enable_capture(self.pg_interfaces)
263 rx = self.pg1.get_capture(1)
264 self.verify_arp_resp(rx[0],
266 self.pg1._remote_hosts[3].mac,
268 self.pg1._remote_hosts[3].ip4)
271 # VPP should have learned the mapping for the remote host
273 self.assertTrue(find_nbr(self,
274 self.pg1.sw_if_index,
275 self.pg1._remote_hosts[3].ip4))
277 # Fire in an ARP request before the interface becomes IP enabled
279 self.pg2.generate_remote_hosts(4)
281 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg2.remote_mac) /
283 hwsrc=self.pg2.remote_mac,
284 pdst=self.pg1.local_ip4,
285 psrc=self.pg2.remote_hosts[3].ip4))
286 pt = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg2.remote_mac) /
289 hwsrc=self.pg2.remote_mac,
290 pdst=self.pg1.local_ip4,
291 psrc=self.pg2.remote_hosts[3].ip4))
292 self.send_and_assert_no_replies(self.pg2, p,
293 "interface not IP enabled")
296 # Make pg2 un-numbered to pg1
298 self.pg2.set_unnumbered(self.pg1.sw_if_index)
300 unnum = self.vapi.ip_unnumbered_dump()
301 self.assertEqual(unnum[0].ip_sw_if_index, self.pg1.sw_if_index)
302 self.assertEqual(unnum[0].sw_if_index, self.pg2.sw_if_index)
305 # We should respond to ARP requests for the unnumbered to address
306 # once an attached route to the source is known
308 self.send_and_assert_no_replies(
310 "ARP req for unnumbered address - no source")
312 attached_host = VppIpRoute(self, self.pg2.remote_hosts[3].ip4, 32,
313 [VppRoutePath("0.0.0.0",
314 self.pg2.sw_if_index)])
315 attached_host.add_vpp_config()
317 self.pg2.add_stream(p)
318 self.pg_enable_capture(self.pg_interfaces)
321 rx = self.pg2.get_capture(1)
322 self.verify_arp_resp(rx[0],
326 self.pg2.remote_hosts[3].ip4)
328 self.pg2.add_stream(pt)
329 self.pg_enable_capture(self.pg_interfaces)
332 rx = self.pg2.get_capture(1)
333 self.verify_arp_resp(rx[0],
337 self.pg2.remote_hosts[3].ip4)
340 # A neighbor entry that has no associated FIB-entry
342 arp_no_fib = VppNeighbor(self,
343 self.pg1.sw_if_index,
344 self.pg1.remote_hosts[4].mac,
345 self.pg1.remote_hosts[4].ip4,
347 arp_no_fib.add_vpp_config()
350 # check we have the neighbor, but no route
352 self.assertTrue(find_nbr(self,
353 self.pg1.sw_if_index,
354 self.pg1._remote_hosts[4].ip4))
355 self.assertFalse(find_route(self,
356 self.pg1._remote_hosts[4].ip4,
359 # pg2 is unnumbered to pg1, so we can form adjacencies out of pg2
360 # from within pg1's subnet
362 arp_unnum = VppNeighbor(self,
363 self.pg2.sw_if_index,
364 self.pg1.remote_hosts[5].mac,
365 self.pg1.remote_hosts[5].ip4)
366 arp_unnum.add_vpp_config()
368 p = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
369 IP(src=self.pg0.remote_ip4,
370 dst=self.pg1._remote_hosts[5].ip4) /
371 UDP(sport=1234, dport=1234) /
374 self.pg0.add_stream(p)
375 self.pg_enable_capture(self.pg_interfaces)
378 rx = self.pg2.get_capture(1)
380 self.verify_ip(rx[0],
382 self.pg1.remote_hosts[5].mac,
384 self.pg1._remote_hosts[5].ip4)
387 # ARP requests from hosts in pg1's subnet sent on pg2 are replied to
388 # with the unnumbered interface's address as the source
390 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg2.remote_mac) /
392 hwsrc=self.pg2.remote_mac,
393 pdst=self.pg1.local_ip4,
394 psrc=self.pg1.remote_hosts[6].ip4))
396 self.pg2.add_stream(p)
397 self.pg_enable_capture(self.pg_interfaces)
400 rx = self.pg2.get_capture(1)
401 self.verify_arp_resp(rx[0],
405 self.pg1.remote_hosts[6].ip4)
408 # An attached host route out of pg2 for an undiscovered hosts generates
409 # an ARP request with the unnumbered address as the source
411 att_unnum = VppIpRoute(self, self.pg1.remote_hosts[7].ip4, 32,
412 [VppRoutePath("0.0.0.0",
413 self.pg2.sw_if_index)])
414 att_unnum.add_vpp_config()
416 p = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
417 IP(src=self.pg0.remote_ip4,
418 dst=self.pg1._remote_hosts[7].ip4) /
419 UDP(sport=1234, dport=1234) /
422 self.pg0.add_stream(p)
423 self.pg_enable_capture(self.pg_interfaces)
426 rx = self.pg2.get_capture(1)
428 self.verify_arp_req(rx[0],
431 self.pg1._remote_hosts[7].ip4)
433 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg2.remote_mac) /
435 hwsrc=self.pg2.remote_mac,
436 pdst=self.pg1.local_ip4,
437 psrc=self.pg1.remote_hosts[7].ip4))
439 self.pg2.add_stream(p)
440 self.pg_enable_capture(self.pg_interfaces)
443 rx = self.pg2.get_capture(1)
444 self.verify_arp_resp(rx[0],
448 self.pg1.remote_hosts[7].ip4)
451 # An attached host route as yet unresolved out of pg2 for an
452 # undiscovered host, an ARP requests begets a response.
454 att_unnum1 = VppIpRoute(self, self.pg1.remote_hosts[8].ip4, 32,
455 [VppRoutePath("0.0.0.0",
456 self.pg2.sw_if_index)])
457 att_unnum1.add_vpp_config()
459 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg2.remote_mac) /
461 hwsrc=self.pg2.remote_mac,
462 pdst=self.pg1.local_ip4,
463 psrc=self.pg1.remote_hosts[8].ip4))
465 self.pg2.add_stream(p)
466 self.pg_enable_capture(self.pg_interfaces)
469 rx = self.pg2.get_capture(1)
470 self.verify_arp_resp(rx[0],
474 self.pg1.remote_hosts[8].ip4)
477 # Send an ARP request from one of the so-far unlearned remote hosts
480 p = (Ether(dst="ff:ff:ff:ff:ff:ff",
481 src=self.pg1._remote_hosts[9].mac) /
484 hwsrc=self.pg1._remote_hosts[9].mac,
485 pdst=self.pg1.local_ip4,
486 psrc=self.pg1._remote_hosts[9].ip4))
488 self.pg1.add_stream(p)
489 self.pg_enable_capture(self.pg_interfaces)
492 rx = self.pg1.get_capture(1)
493 self.verify_arp_resp(rx[0],
495 self.pg1._remote_hosts[9].mac,
497 self.pg1._remote_hosts[9].ip4)
500 # Add a hierachy of routes for a host in the sub-net.
501 # Should still get an ARP resp since the cover is attached
503 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg1.remote_mac) /
505 hwsrc=self.pg1.remote_mac,
506 pdst=self.pg1.local_ip4,
507 psrc=self.pg1.remote_hosts[10].ip4))
509 r1 = VppIpRoute(self, self.pg1.remote_hosts[10].ip4, 30,
510 [VppRoutePath(self.pg1.remote_hosts[10].ip4,
511 self.pg1.sw_if_index)])
514 self.pg1.add_stream(p)
515 self.pg_enable_capture(self.pg_interfaces)
517 rx = self.pg1.get_capture(1)
518 self.verify_arp_resp(rx[0],
522 self.pg1.remote_hosts[10].ip4)
524 r2 = VppIpRoute(self, self.pg1.remote_hosts[10].ip4, 32,
525 [VppRoutePath(self.pg1.remote_hosts[10].ip4,
526 self.pg1.sw_if_index)])
529 self.pg1.add_stream(p)
530 self.pg_enable_capture(self.pg_interfaces)
532 rx = self.pg1.get_capture(1)
533 self.verify_arp_resp(rx[0],
537 self.pg1.remote_hosts[10].ip4)
540 # add an ARP entry that's not on the sub-net and so whose
541 # adj-fib fails the refinement check. then send an ARP request
544 a1 = VppNeighbor(self,
545 self.pg0.sw_if_index,
550 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
552 hwsrc=self.pg0.remote_mac,
553 psrc="100.100.100.50",
554 pdst=self.pg0.remote_ip4))
555 self.send_and_assert_no_replies(self.pg0, p,
556 "ARP req for from failed adj-fib")
560 # 1 - don't respond to ARP request for address not within the
561 # interface's sub-net
562 # 1b - nor within the unnumbered subnet
563 # 1c - nor within the subnet of a different interface
565 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
567 hwsrc=self.pg0.remote_mac,
569 psrc=self.pg0.remote_ip4))
570 self.send_and_assert_no_replies(self.pg0, p,
571 "ARP req for non-local destination")
572 self.assertFalse(find_nbr(self,
573 self.pg0.sw_if_index,
576 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg2.remote_mac) /
578 hwsrc=self.pg2.remote_mac,
580 psrc=self.pg1.remote_hosts[7].ip4))
581 self.send_and_assert_no_replies(
583 "ARP req for non-local destination - unnum")
585 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
587 hwsrc=self.pg0.remote_mac,
588 pdst=self.pg1.local_ip4,
589 psrc=self.pg1.remote_ip4))
590 self.send_and_assert_no_replies(self.pg0, p,
591 "ARP req diff sub-net")
592 self.assertFalse(find_nbr(self,
593 self.pg0.sw_if_index,
594 self.pg1.remote_ip4))
597 # 2 - don't respond to ARP request from an address not within the
598 # interface's sub-net
599 # 2b - to a prxied address
600 # 2c - not within a differents interface's sub-net
601 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
603 hwsrc=self.pg0.remote_mac,
605 pdst=self.pg0.local_ip4))
606 self.send_and_assert_no_replies(self.pg0, p,
607 "ARP req for non-local source")
608 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg2.remote_mac) /
610 hwsrc=self.pg2.remote_mac,
612 pdst=self.pg0.local_ip4))
613 self.send_and_assert_no_replies(
615 "ARP req for non-local source - unnum")
616 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
618 hwsrc=self.pg0.remote_mac,
619 psrc=self.pg1.remote_ip4,
620 pdst=self.pg0.local_ip4))
621 self.send_and_assert_no_replies(self.pg0, p,
622 "ARP req for non-local source 2c")
625 # 3 - don't respond to ARP request from an address that belongs to
628 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
630 hwsrc=self.pg0.remote_mac,
631 psrc=self.pg0.local_ip4,
632 pdst=self.pg0.local_ip4))
633 self.send_and_assert_no_replies(self.pg0, p,
634 "ARP req for non-local source")
637 # 4 - don't respond to ARP requests that has mac source different
638 # from ARP request HW source
640 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
642 hwsrc="00:00:00:DE:AD:BE",
643 psrc=self.pg0.remote_ip4,
644 pdst=self.pg0.local_ip4))
645 self.send_and_assert_no_replies(self.pg0, p,
646 "ARP req for non-local source")
649 # 5 - don't respond to ARP requests for address within the
650 # interface's sub-net but not the interface's address
652 self.pg0.generate_remote_hosts(2)
653 p = (Ether(dst="ff:ff:ff:ff:ff:ff", src=self.pg0.remote_mac) /
655 hwsrc=self.pg0.remote_mac,
656 psrc=self.pg0.remote_hosts[0].ip4,
657 pdst=self.pg0.remote_hosts[1].ip4))
658 self.send_and_assert_no_replies(self.pg0, p,
659 "ARP req for non-local destination")
664 dyn_arp.remove_vpp_config()
665 static_arp.remove_vpp_config()
666 self.pg2.unset_unnumbered(self.pg1.sw_if_index)
668 # need this to flush the adj-fibs
669 self.pg2.unset_unnumbered(self.pg1.sw_if_index)
670 self.pg2.admin_down()
671 self.pg1.admin_down()
673 def test_proxy_mirror_arp(self):
674 """ Interface Mirror Proxy ARP """
677 # When VPP has an interface whose address is also applied to a TAP
678 # interface on the host, then VPP's TAP interface will be unnumbered
679 # to the 'real' interface and do proxy ARP from the host.
680 # the curious aspect of this setup is that ARP requests from the host
681 # will come from the VPP's own address.
683 self.pg0.generate_remote_hosts(2)
685 arp_req_from_me = (Ether(src=self.pg2.remote_mac,
686 dst="ff:ff:ff:ff:ff:ff") /
688 hwsrc=self.pg2.remote_mac,
689 pdst=self.pg0.remote_hosts[1].ip4,
690 psrc=self.pg0.local_ip4))
693 # Configure Proxy ARP for the subnet on PG0addresses on pg0
695 self.vapi.proxy_arp_add_del(self.pg0._local_ip4n_subnet,
696 self.pg0._local_ip4n_bcast)
698 # Make pg2 un-numbered to pg0
700 self.pg2.set_unnumbered(self.pg0.sw_if_index)
703 # Enable pg2 for proxy ARP
705 self.pg2.set_proxy_arp()
708 # Send the ARP request with an originating address that
709 # is VPP's own address
711 self.pg2.add_stream(arp_req_from_me)
712 self.pg_enable_capture(self.pg_interfaces)
715 rx = self.pg2.get_capture(1)
716 self.verify_arp_resp(rx[0],
719 self.pg0.remote_hosts[1].ip4,
723 # validate we have not learned an ARP entry as a result of this
725 self.assertFalse(find_nbr(self,
726 self.pg2.sw_if_index,
732 self.pg2.set_proxy_arp(0)
733 self.vapi.proxy_arp_add_del(self.pg0._local_ip4n_subnet,
734 self.pg0._local_ip4n_bcast,
737 def test_proxy_arp(self):
740 self.pg1.generate_remote_hosts(2)
743 # Proxy ARP rewquest packets for each interface
745 arp_req_pg0 = (Ether(src=self.pg0.remote_mac,
746 dst="ff:ff:ff:ff:ff:ff") /
748 hwsrc=self.pg0.remote_mac,
750 psrc=self.pg0.remote_ip4))
751 arp_req_pg0_tagged = (Ether(src=self.pg0.remote_mac,
752 dst="ff:ff:ff:ff:ff:ff") /
755 hwsrc=self.pg0.remote_mac,
757 psrc=self.pg0.remote_ip4))
758 arp_req_pg1 = (Ether(src=self.pg1.remote_mac,
759 dst="ff:ff:ff:ff:ff:ff") /
761 hwsrc=self.pg1.remote_mac,
763 psrc=self.pg1.remote_ip4))
764 arp_req_pg2 = (Ether(src=self.pg2.remote_mac,
765 dst="ff:ff:ff:ff:ff:ff") /
767 hwsrc=self.pg2.remote_mac,
769 psrc=self.pg1.remote_hosts[1].ip4))
770 arp_req_pg3 = (Ether(src=self.pg3.remote_mac,
771 dst="ff:ff:ff:ff:ff:ff") /
773 hwsrc=self.pg3.remote_mac,
775 psrc=self.pg3.remote_ip4))
778 # Configure Proxy ARP for 10.10.10.0 -> 10.10.10.124
780 self.vapi.proxy_arp_add_del(inet_pton(AF_INET, "10.10.10.2"),
781 inet_pton(AF_INET, "10.10.10.124"))
784 # No responses are sent when the interfaces are not enabled for proxy
787 self.send_and_assert_no_replies(self.pg0, arp_req_pg0,
788 "ARP req from unconfigured interface")
789 self.send_and_assert_no_replies(self.pg2, arp_req_pg2,
790 "ARP req from unconfigured interface")
793 # Make pg2 un-numbered to pg1
796 self.pg2.set_unnumbered(self.pg1.sw_if_index)
798 self.send_and_assert_no_replies(self.pg2, arp_req_pg2,
799 "ARP req from unnumbered interface")
802 # Enable each interface to reply to proxy ARPs
804 for i in self.pg_interfaces:
808 # Now each of the interfaces should reply to a request to a proxied
811 self.pg0.add_stream(arp_req_pg0)
812 self.pg_enable_capture(self.pg_interfaces)
815 rx = self.pg0.get_capture(1)
816 self.verify_arp_resp(rx[0],
822 self.pg0.add_stream(arp_req_pg0_tagged)
823 self.pg_enable_capture(self.pg_interfaces)
826 rx = self.pg0.get_capture(1)
827 self.verify_arp_resp(rx[0],
833 self.pg1.add_stream(arp_req_pg1)
834 self.pg_enable_capture(self.pg_interfaces)
837 rx = self.pg1.get_capture(1)
838 self.verify_arp_resp(rx[0],
844 self.pg2.add_stream(arp_req_pg2)
845 self.pg_enable_capture(self.pg_interfaces)
848 rx = self.pg2.get_capture(1)
849 self.verify_arp_resp(rx[0],
853 self.pg1.remote_hosts[1].ip4)
856 # A request for an address out of the configured range
858 arp_req_pg1_hi = (Ether(src=self.pg1.remote_mac,
859 dst="ff:ff:ff:ff:ff:ff") /
861 hwsrc=self.pg1.remote_mac,
863 psrc=self.pg1.remote_ip4))
864 self.send_and_assert_no_replies(self.pg1, arp_req_pg1_hi,
865 "ARP req out of range HI")
866 arp_req_pg1_low = (Ether(src=self.pg1.remote_mac,
867 dst="ff:ff:ff:ff:ff:ff") /
869 hwsrc=self.pg1.remote_mac,
871 psrc=self.pg1.remote_ip4))
872 self.send_and_assert_no_replies(self.pg1, arp_req_pg1_low,
873 "ARP req out of range Low")
876 # Request for an address in the proxy range but from an interface
879 self.send_and_assert_no_replies(self.pg3, arp_req_pg3,
880 "ARP req from different VRF")
883 # Disable Each interface for proxy ARP
884 # - expect none to respond
886 for i in self.pg_interfaces:
889 self.send_and_assert_no_replies(self.pg0, arp_req_pg0,
890 "ARP req from disable")
891 self.send_and_assert_no_replies(self.pg1, arp_req_pg1,
892 "ARP req from disable")
893 self.send_and_assert_no_replies(self.pg2, arp_req_pg2,
894 "ARP req from disable")
897 # clean up on interface 2
899 self.pg2.unset_unnumbered(self.pg1.sw_if_index)
905 # Interface 2 does not yet have ip4 config
907 self.pg2.config_ip4()
908 self.pg2.generate_remote_hosts(2)
911 # Add a reoute with out going label via an ARP unresolved next-hop
913 ip_10_0_0_1 = VppIpRoute(self, "10.0.0.1", 32,
914 [VppRoutePath(self.pg2.remote_hosts[1].ip4,
915 self.pg2.sw_if_index,
917 ip_10_0_0_1.add_vpp_config()
920 # packets should generate an ARP request
922 p = (Ether(src=self.pg0.remote_mac,
923 dst=self.pg0.local_mac) /
924 IP(src=self.pg0.remote_ip4, dst="10.0.0.1") /
925 UDP(sport=1234, dport=1234) /
928 self.pg0.add_stream(p)
929 self.pg_enable_capture(self.pg_interfaces)
932 rx = self.pg2.get_capture(1)
933 self.verify_arp_req(rx[0],
936 self.pg2._remote_hosts[1].ip4)
939 # now resolve the neighbours
941 self.pg2.configure_ipv4_neighbors()
944 # Now packet should be properly MPLS encapped.
945 # This verifies that MPLS link-type adjacencies are completed
946 # when the ARP entry resolves
948 self.pg0.add_stream(p)
949 self.pg_enable_capture(self.pg_interfaces)
952 rx = self.pg2.get_capture(1)
953 self.verify_ip_o_mpls(rx[0],
955 self.pg2.remote_hosts[1].mac,
959 self.pg2.unconfig_ip4()
961 def test_arp_vrrp(self):
962 """ ARP reply with VRRP virtual src hw addr """
965 # IP packet destined for pg1 remote host arrives on pg0 resulting
966 # in an ARP request for the address of the remote host on pg1
968 p0 = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
969 IP(src=self.pg0.remote_ip4, dst=self.pg1.remote_ip4) /
970 UDP(sport=1234, dport=1234) /
973 self.pg0.add_stream(p0)
974 self.pg_enable_capture(self.pg_interfaces)
977 rx1 = self.pg1.get_capture(1)
979 self.verify_arp_req(rx1[0],
985 # ARP reply for address of pg1 remote host arrives on pg1 with
986 # the hw src addr set to a value in the VRRP IPv4 range of
989 p1 = (Ether(dst=self.pg1.local_mac, src=self.pg1.remote_mac) /
990 ARP(op="is-at", hwdst=self.pg1.local_mac,
991 hwsrc="00:00:5e:00:01:09", pdst=self.pg1.local_ip4,
992 psrc=self.pg1.remote_ip4))
994 self.pg1.add_stream(p1)
995 self.pg_enable_capture(self.pg_interfaces)
999 # IP packet destined for pg1 remote host arrives on pg0 again.
1000 # VPP should have an ARP entry for that address now and the packet
1001 # should be sent out pg1.
1003 self.pg0.add_stream(p0)
1004 self.pg_enable_capture(self.pg_interfaces)
1007 rx1 = self.pg1.get_capture(1)
1009 self.verify_ip(rx1[0],
1011 "00:00:5e:00:01:09",
1012 self.pg0.remote_ip4,
1013 self.pg1.remote_ip4)
1015 self.pg1.admin_down()
1018 def test_arp_duplicates(self):
1019 """ ARP Duplicates"""
1022 # Generate some hosts on the LAN
1024 self.pg1.generate_remote_hosts(3)
1027 # Add host 1 on pg1 and pg2
1029 arp_pg1 = VppNeighbor(self,
1030 self.pg1.sw_if_index,
1031 self.pg1.remote_hosts[1].mac,
1032 self.pg1.remote_hosts[1].ip4)
1033 arp_pg1.add_vpp_config()
1034 arp_pg2 = VppNeighbor(self,
1035 self.pg2.sw_if_index,
1036 self.pg2.remote_mac,
1037 self.pg1.remote_hosts[1].ip4)
1038 arp_pg2.add_vpp_config()
1041 # IP packet destined for pg1 remote host arrives on pg1 again.
1043 p = (Ether(dst=self.pg0.local_mac,
1044 src=self.pg0.remote_mac) /
1045 IP(src=self.pg0.remote_ip4,
1046 dst=self.pg1.remote_hosts[1].ip4) /
1047 UDP(sport=1234, dport=1234) /
1050 self.pg0.add_stream(p)
1051 self.pg_enable_capture(self.pg_interfaces)
1054 rx1 = self.pg1.get_capture(1)
1056 self.verify_ip(rx1[0],
1058 self.pg1.remote_hosts[1].mac,
1059 self.pg0.remote_ip4,
1060 self.pg1.remote_hosts[1].ip4)
1063 # remove the duplicate on pg1
1064 # packet stream shoud generate ARPs out of pg1
1066 arp_pg1.remove_vpp_config()
1068 self.pg0.add_stream(p)
1069 self.pg_enable_capture(self.pg_interfaces)
1072 rx1 = self.pg1.get_capture(1)
1074 self.verify_arp_req(rx1[0],
1077 self.pg1.remote_hosts[1].ip4)
1082 arp_pg1.add_vpp_config()
1084 self.pg0.add_stream(p)
1085 self.pg_enable_capture(self.pg_interfaces)
1088 rx1 = self.pg1.get_capture(1)
1090 self.verify_ip(rx1[0],
1092 self.pg1.remote_hosts[1].mac,
1093 self.pg0.remote_ip4,
1094 self.pg1.remote_hosts[1].ip4)
1096 def test_arp_static(self):
1098 self.pg2.generate_remote_hosts(3)
1101 # Add a static ARP entry
1103 static_arp = VppNeighbor(self,
1104 self.pg2.sw_if_index,
1105 self.pg2.remote_hosts[1].mac,
1106 self.pg2.remote_hosts[1].ip4,
1108 static_arp.add_vpp_config()
1111 # Add the connected prefix to the interface
1113 self.pg2.config_ip4()
1116 # We should now find the adj-fib
1118 self.assertTrue(find_nbr(self,
1119 self.pg2.sw_if_index,
1120 self.pg2.remote_hosts[1].ip4,
1122 self.assertTrue(find_route(self,
1123 self.pg2.remote_hosts[1].ip4,
1127 # remove the connected
1129 self.pg2.unconfig_ip4()
1132 # put the interface into table 1
1134 self.pg2.set_table_ip4(1)
1137 # configure the same connected and expect to find the
1138 # adj fib in the new table
1140 self.pg2.config_ip4()
1141 self.assertTrue(find_route(self,
1142 self.pg2.remote_hosts[1].ip4,
1149 self.pg2.unconfig_ip4()
1150 self.pg2.set_table_ip4(0)
1152 def test_arp_incomplete(self):
1153 """ ARP Incomplete"""
1154 self.pg1.generate_remote_hosts(3)
1156 p0 = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
1157 IP(src=self.pg0.remote_ip4,
1158 dst=self.pg1.remote_hosts[1].ip4) /
1159 UDP(sport=1234, dport=1234) /
1161 p1 = (Ether(dst=self.pg0.local_mac, src=self.pg0.remote_mac) /
1162 IP(src=self.pg0.remote_ip4,
1163 dst=self.pg1.remote_hosts[2].ip4) /
1164 UDP(sport=1234, dport=1234) /
1168 # a packet to an unresolved destination generates an ARP request
1170 rx = self.send_and_expect(self.pg0, [p0], self.pg1)
1171 self.verify_arp_req(rx[0],
1174 self.pg1._remote_hosts[1].ip4)
1177 # add a neighbour for remote host 1
1179 static_arp = VppNeighbor(self,
1180 self.pg1.sw_if_index,
1181 self.pg1.remote_hosts[1].mac,
1182 self.pg1.remote_hosts[1].ip4,
1184 static_arp.add_vpp_config()
1187 # change the interface's MAC
1189 mac = [chr(0x00), chr(0x00), chr(0x00),
1190 chr(0x33), chr(0x33), chr(0x33)]
1191 mac_string = ''.join(mac)
1193 self.vapi.sw_interface_set_mac_address(self.pg1.sw_if_index,
1197 # now ARP requests come from the new source mac
1199 rx = self.send_and_expect(self.pg0, [p1], self.pg1)
1200 self.verify_arp_req(rx[0],
1201 "00:00:00:33:33:33",
1203 self.pg1._remote_hosts[2].ip4)
1206 # packets to the resolved host also have the new source mac
1208 rx = self.send_and_expect(self.pg0, [p0], self.pg1)
1209 self.verify_ip(rx[0],
1210 "00:00:00:33:33:33",
1211 self.pg1.remote_hosts[1].mac,
1212 self.pg0.remote_ip4,
1213 self.pg1.remote_hosts[1].ip4)
1216 # set the mac address on the inteface that does not have a
1217 # configured subnet and thus no glean
1219 self.vapi.sw_interface_set_mac_address(self.pg2.sw_if_index,
1222 def test_garp(self):
1226 # Generate some hosts on the LAN
1228 self.pg1.generate_remote_hosts(4)
1233 arp = VppNeighbor(self,
1234 self.pg1.sw_if_index,
1235 self.pg1.remote_hosts[1].mac,
1236 self.pg1.remote_hosts[1].ip4)
1237 arp.add_vpp_config()
1239 self.assertTrue(find_nbr(self,
1240 self.pg1.sw_if_index,
1241 self.pg1.remote_hosts[1].ip4,
1242 mac=self.pg1.remote_hosts[1].mac))
1245 # Send a GARP (request) to swap the host 1's address to that of host 2
1247 p1 = (Ether(dst="ff:ff:ff:ff:ff:ff",
1248 src=self.pg1.remote_hosts[2].mac) /
1250 hwdst=self.pg1.local_mac,
1251 hwsrc=self.pg1.remote_hosts[2].mac,
1252 pdst=self.pg1.remote_hosts[1].ip4,
1253 psrc=self.pg1.remote_hosts[1].ip4))
1255 self.pg1.add_stream(p1)
1256 self.pg_enable_capture(self.pg_interfaces)
1259 self.assertTrue(find_nbr(self,
1260 self.pg1.sw_if_index,
1261 self.pg1.remote_hosts[1].ip4,
1262 mac=self.pg1.remote_hosts[2].mac))
1265 # Send a GARP (reply) to swap the host 1's address to that of host 3
1267 p1 = (Ether(dst="ff:ff:ff:ff:ff:ff",
1268 src=self.pg1.remote_hosts[3].mac) /
1270 hwdst=self.pg1.local_mac,
1271 hwsrc=self.pg1.remote_hosts[3].mac,
1272 pdst=self.pg1.remote_hosts[1].ip4,
1273 psrc=self.pg1.remote_hosts[1].ip4))
1275 self.pg1.add_stream(p1)
1276 self.pg_enable_capture(self.pg_interfaces)
1279 self.assertTrue(find_nbr(self,
1280 self.pg1.sw_if_index,
1281 self.pg1.remote_hosts[1].ip4,
1282 mac=self.pg1.remote_hosts[3].mac))
1285 # GARPs (requets nor replies) for host we don't know yet
1286 # don't result in new neighbour entries
1288 p1 = (Ether(dst="ff:ff:ff:ff:ff:ff",
1289 src=self.pg1.remote_hosts[3].mac) /
1291 hwdst=self.pg1.local_mac,
1292 hwsrc=self.pg1.remote_hosts[3].mac,
1293 pdst=self.pg1.remote_hosts[2].ip4,
1294 psrc=self.pg1.remote_hosts[2].ip4))
1296 self.pg1.add_stream(p1)
1297 self.pg_enable_capture(self.pg_interfaces)
1300 self.assertFalse(find_nbr(self,
1301 self.pg1.sw_if_index,
1302 self.pg1.remote_hosts[2].ip4))
1304 p1 = (Ether(dst="ff:ff:ff:ff:ff:ff",
1305 src=self.pg1.remote_hosts[3].mac) /
1307 hwdst=self.pg1.local_mac,
1308 hwsrc=self.pg1.remote_hosts[3].mac,
1309 pdst=self.pg1.remote_hosts[2].ip4,
1310 psrc=self.pg1.remote_hosts[2].ip4))
1312 self.pg1.add_stream(p1)
1313 self.pg_enable_capture(self.pg_interfaces)
1316 self.assertFalse(find_nbr(self,
1317 self.pg1.sw_if_index,
1318 self.pg1.remote_hosts[2].ip4))
1320 def test_arp_incomplete(self):
1321 """ Incomplete Entries """
1324 # ensure that we throttle the ARP requests
1326 self.pg0.generate_remote_hosts(2)
1328 ip_10_0_0_1 = VppIpRoute(self, "10.0.0.1", 32,
1329 [VppRoutePath(self.pg0.remote_hosts[1].ip4,
1330 self.pg0.sw_if_index,
1332 ip_10_0_0_1.add_vpp_config()
1334 p1 = (Ether(dst=self.pg1.local_mac,
1335 src=self.pg1.remote_mac) /
1336 IP(src=self.pg1.remote_ip4,
1338 UDP(sport=1234, dport=1234) /
1341 self.pg1.add_stream(p1 * 257)
1342 self.pg_enable_capture(self.pg_interfaces)
1344 rx = self.pg0._get_capture(1)
1347 # how many we get is going to be dependent on the time for packet
1348 # processing but it should be small
1350 self.assertTrue(len(rx) < 64)
1353 class NeighborStatsTestCase(VppTestCase):
1354 """ ARP Test Case """
1357 super(NeighborStatsTestCase, self).setUp()
1359 self.create_pg_interfaces(range(2))
1361 # pg0 configured with ip4 and 6 addresses used for input
1362 # pg1 configured with ip4 and 6 addresses used for output
1363 # pg2 is unnumbered to pg0
1364 for i in self.pg_interfaces:
1372 super(NeighborStatsTestCase, self).tearDown()
1374 for i in self.pg_interfaces:
1379 def test_arp_stats(self):
1380 """ ARP Counters """
1382 self.vapi.cli("adj counters enable")
1383 self.pg1.generate_remote_hosts(2)
1385 arp1 = VppNeighbor(self,
1386 self.pg1.sw_if_index,
1387 self.pg1.remote_hosts[0].mac,
1388 self.pg1.remote_hosts[0].ip4)
1389 arp1.add_vpp_config()
1390 arp2 = VppNeighbor(self,
1391 self.pg1.sw_if_index,
1392 self.pg1.remote_hosts[1].mac,
1393 self.pg1.remote_hosts[1].ip4)
1394 arp2.add_vpp_config()
1396 p1 = (Ether(dst=self.pg0.local_mac,
1397 src=self.pg0.remote_mac) /
1398 IP(src=self.pg0.remote_ip4,
1399 dst=self.pg1.remote_hosts[0].ip4) /
1400 UDP(sport=1234, dport=1234) /
1402 p2 = (Ether(dst=self.pg0.local_mac,
1403 src=self.pg0.remote_mac) /
1404 IP(src=self.pg0.remote_ip4,
1405 dst=self.pg1.remote_hosts[1].ip4) /
1406 UDP(sport=1234, dport=1234) /
1409 rx = self.send_and_expect(self.pg0, p1 * 65, self.pg1)
1410 rx = self.send_and_expect(self.pg0, p2 * 65, self.pg1)
1412 self.assertEqual(65, arp1.get_stats()['packets'])
1413 self.assertEqual(65, arp2.get_stats()['packets'])
1415 rx = self.send_and_expect(self.pg0, p1 * 65, self.pg1)
1416 self.assertEqual(130, arp1.get_stats()['packets'])
1418 def test_nd_stats(self):
1421 self.vapi.cli("adj counters enable")
1422 self.pg0.generate_remote_hosts(3)
1424 nd1 = VppNeighbor(self,
1425 self.pg0.sw_if_index,
1426 self.pg0.remote_hosts[1].mac,
1427 self.pg0.remote_hosts[1].ip6,
1429 nd1.add_vpp_config()
1430 nd2 = VppNeighbor(self,
1431 self.pg0.sw_if_index,
1432 self.pg0.remote_hosts[2].mac,
1433 self.pg0.remote_hosts[2].ip6,
1435 nd2.add_vpp_config()
1437 p1 = (Ether(dst=self.pg1.local_mac,
1438 src=self.pg1.remote_mac) /
1439 IPv6(src=self.pg1.remote_ip6,
1440 dst=self.pg0.remote_hosts[1].ip6) /
1441 UDP(sport=1234, dport=1234) /
1443 p2 = (Ether(dst=self.pg1.local_mac,
1444 src=self.pg1.remote_mac) /
1445 IPv6(src=self.pg1.remote_ip6,
1446 dst=self.pg0.remote_hosts[2].ip6) /
1447 UDP(sport=1234, dport=1234) /
1450 rx = self.send_and_expect(self.pg1, p1 * 16, self.pg0)
1451 rx = self.send_and_expect(self.pg1, p2 * 16, self.pg0)
1453 self.assertEqual(16, nd1.get_stats()['packets'])
1454 self.assertEqual(16, nd2.get_stats()['packets'])
1456 rx = self.send_and_expect(self.pg1, p1 * 65, self.pg0)
1457 self.assertEqual(81, nd1.get_stats()['packets'])
1460 if __name__ == '__main__':
1461 unittest.main(testRunner=VppTestRunner)