class TestIpsec4TunIfEsp1(TemplateIpsec4TunIfEsp, IpsecTun4Tests):
""" Ipsec ESP - TUN tests """
- tun4_encrypt_node_name = "esp4-encrypt"
+ tun4_encrypt_node_name = "esp4-encrypt-tun"
tun4_decrypt_node_name = "esp4-decrypt"
def test_tun_basic64(self):
""" ipsec 6o4 tunnel basic test """
+ self.tun4_encrypt_node_name = "esp6-encrypt-tun"
+
self.verify_tun_64(self.params[socket.AF_INET], count=1)
def test_tun_burst64(self):
""" ipsec 6o4 tunnel basic test """
+ self.tun4_encrypt_node_name = "esp6-encrypt-tun"
+
self.verify_tun_64(self.params[socket.AF_INET], count=257)
def test_tun_basic_frag44(self):
""" ipsec 4o4 tunnel frag basic test """
+ self.tun4_encrypt_node_name = "esp4-encrypt-tun"
+
p = self.ipv4_params
self.vapi.sw_interface_set_mtu(p.tun_if.sw_if_index,
class TestIpsec6TunIfEsp1(TemplateIpsec6TunIfEsp, IpsecTun6Tests):
""" Ipsec ESP - TUN tests """
- tun6_encrypt_node_name = "esp6-encrypt"
+ tun6_encrypt_node_name = "esp6-encrypt-tun"
tun6_decrypt_node_name = "esp6-decrypt"
def test_tun_basic46(self):
""" ipsec 4o6 tunnel basic test """
+ self.tun6_encrypt_node_name = "esp4-encrypt-tun"
self.verify_tun_46(self.params[socket.AF_INET6], count=1)
def test_tun_burst46(self):
""" ipsec 4o6 tunnel burst test """
+ self.tun6_encrypt_node_name = "esp4-encrypt-tun"
self.verify_tun_46(self.params[socket.AF_INET6], count=257)
""" IPsec IPv4 Multi Tunnel interface """
encryption_type = ESP
- tun4_encrypt_node_name = "esp4-encrypt"
+ tun4_encrypt_node_name = "esp4-encrypt-tun"
tun4_decrypt_node_name = "esp4-decrypt"
def setUp(self):
""" IPsec IPv4 Tunnel interface all Algos """
encryption_type = ESP
- tun4_encrypt_node_name = "esp4-encrypt"
+ tun4_encrypt_node_name = "esp4-encrypt-tun"
tun4_decrypt_node_name = "esp4-decrypt"
def config_network(self, p):
def tearDown(self):
super(TestIpsec4TunIfEspAll, self).tearDown()
+ def rekey(self, p):
+ #
+ # change the key and the SPI
+ #
+ p.crypt_key = 'X' + p.crypt_key[1:]
+ p.scapy_tun_spi += 1
+ p.scapy_tun_sa_id += 1
+ p.vpp_tun_spi += 1
+ p.vpp_tun_sa_id += 1
+ p.tun_if.local_spi = p.vpp_tun_spi
+ p.tun_if.remote_spi = p.scapy_tun_spi
+
+ config_tun_params(p, self.encryption_type, self.tun_if)
+
+ p.tun_sa_in = VppIpsecSA(self,
+ p.scapy_tun_sa_id,
+ p.scapy_tun_spi,
+ p.auth_algo_vpp_id,
+ p.auth_key,
+ p.crypt_algo_vpp_id,
+ p.crypt_key,
+ self.vpp_esp_protocol,
+ self.tun_if.local_addr[p.addr_type],
+ self.tun_if.remote_addr[p.addr_type],
+ flags=p.flags,
+ salt=p.salt)
+ p.tun_sa_out = VppIpsecSA(self,
+ p.vpp_tun_sa_id,
+ p.vpp_tun_spi,
+ p.auth_algo_vpp_id,
+ p.auth_key,
+ p.crypt_algo_vpp_id,
+ p.crypt_key,
+ self.vpp_esp_protocol,
+ self.tun_if.remote_addr[p.addr_type],
+ self.tun_if.local_addr[p.addr_type],
+ flags=p.flags,
+ salt=p.salt)
+ p.tun_sa_in.add_vpp_config()
+ p.tun_sa_out.add_vpp_config()
+
+ self.vapi.ipsec_tunnel_if_set_sa(sw_if_index=p.tun_if.sw_if_index,
+ sa_id=p.tun_sa_in.id,
+ is_outbound=1)
+ self.vapi.ipsec_tunnel_if_set_sa(sw_if_index=p.tun_if.sw_if_index,
+ sa_id=p.tun_sa_out.id,
+ is_outbound=0)
+ self.logger.info(self.vapi.cli("sh ipsec sa"))
+
def test_tun_44(self):
"""IPSEC tunnel all algos """
c = p.tun_if.get_tx_stats()
self.assertEqual(c['packets'], 127)
+ #
+ # rekey the tunnel
+ #
+ self.rekey(p)
+ self.verify_tun_44(p, count=127)
+
self.unconfig_network(p)
+ p.tun_sa_out.remove_vpp_config()
+ p.tun_sa_in.remove_vpp_config()
class TestIpsec6MultiTunIfEsp(TemplateIpsec, IpsecTun6):
""" IPsec IPv6 Multi Tunnel interface """
encryption_type = ESP
- tun6_encrypt_node_name = "esp6-encrypt"
+ tun6_encrypt_node_name = "esp6-encrypt-tun"
tun6_decrypt_node_name = "esp6-decrypt"
def setUp(self):