blob: 9927cc7bcc3d21f8340938588b873c4d78694b20 [file] [log] [blame]
Klement Sekera31da2e32018-06-24 22:49:55 +02001import unittest
Klement Sekera611864f2018-09-26 11:19:00 +02002import socket
Neale Ranns80f6fd52019-04-16 02:41:34 +00003import struct
Klement Sekera31da2e32018-06-24 22:49:55 +02004
Neale Ranns53f526b2019-02-25 14:32:02 +00005from scapy.layers.inet import IP, ICMP, TCP, UDP
Damjan Mariona829b132019-04-24 23:39:16 +02006from scapy.layers.ipsec import SecurityAssociation, ESP
snaramre5d4b8912019-12-13 23:39:35 +00007from scapy.layers.l2 import Ether
Paul Vinciguerra582eac52020-04-03 12:18:40 -04008from scapy.packet import raw, Raw
Neale Ranns02950402019-12-20 00:54:57 +00009from scapy.layers.inet6 import IPv6, ICMPv6EchoRequest, IPv6ExtHdrHopByHop, \
10 IPv6ExtHdrFragment, IPv6ExtHdrDestOpt
11
Klement Sekera31da2e32018-06-24 22:49:55 +020012
13from framework import VppTestCase, VppTestRunner
Neale Ranns14046982019-07-29 14:49:52 +000014from util import ppp, reassemble4, fragment_rfc791, fragment_rfc8200
Neale Ranns17dcec02019-01-09 21:22:20 -080015from vpp_papi import VppEnum
Klement Sekera31da2e32018-06-24 22:49:55 +020016
Govindarajan Mohandoss6d7dfcb2021-03-19 19:20:49 +000017from vpp_ipsec import VppIpsecSpd, VppIpsecSpdEntry, \
18 VppIpsecSpdItfBinding
19from ipaddress import ip_address
20from re import search
21from os import popen
22
Klement Sekera31da2e32018-06-24 22:49:55 +020023
Paul Vinciguerrae061dad2020-12-04 14:57:51 -050024class IPsecIPv4Params:
Neale Ranns17dcec02019-01-09 21:22:20 -080025
Klement Sekera611864f2018-09-26 11:19:00 +020026 addr_type = socket.AF_INET
27 addr_any = "0.0.0.0"
28 addr_bcast = "255.255.255.255"
29 addr_len = 32
30 is_ipv6 = 0
Klement Sekera611864f2018-09-26 11:19:00 +020031
Neale Ranns17dcec02019-01-09 21:22:20 -080032 def __init__(self):
33 self.remote_tun_if_host = '1.1.1.1'
Neale Ranns987aea82019-03-27 13:40:35 +000034 self.remote_tun_if_host6 = '1111::1'
Klement Sekera611864f2018-09-26 11:19:00 +020035
Neale Ranns28287212019-12-16 00:53:11 +000036 self.scapy_tun_sa_id = 100
Neale Rannsa9e27742020-12-23 16:22:28 +000037 self.scapy_tun_spi = 1000
Neale Ranns28287212019-12-16 00:53:11 +000038 self.vpp_tun_sa_id = 200
Neale Rannsa9e27742020-12-23 16:22:28 +000039 self.vpp_tun_spi = 2000
Klement Sekera611864f2018-09-26 11:19:00 +020040
Neale Ranns28287212019-12-16 00:53:11 +000041 self.scapy_tra_sa_id = 300
Neale Rannsa9e27742020-12-23 16:22:28 +000042 self.scapy_tra_spi = 3000
Neale Ranns28287212019-12-16 00:53:11 +000043 self.vpp_tra_sa_id = 400
Neale Rannsa9e27742020-12-23 16:22:28 +000044 self.vpp_tra_spi = 4000
Klement Sekera611864f2018-09-26 11:19:00 +020045
Neale Ranns9ec846c2021-02-09 14:04:02 +000046 self.outer_hop_limit = 64
47 self.inner_hop_limit = 255
48 self.outer_flow_label = 0
49 self.inner_flow_label = 0x12345
50
Neale Ranns17dcec02019-01-09 21:22:20 -080051 self.auth_algo_vpp_id = (VppEnum.vl_api_ipsec_integ_alg_t.
52 IPSEC_API_INTEG_ALG_SHA1_96)
53 self.auth_algo = 'HMAC-SHA1-96' # scapy name
Ole Troan64e978b2019-10-17 21:40:36 +020054 self.auth_key = b'C91KUR9GYMm5GfkEvNjX'
Neale Ranns17dcec02019-01-09 21:22:20 -080055
56 self.crypt_algo_vpp_id = (VppEnum.vl_api_ipsec_crypto_alg_t.
57 IPSEC_API_CRYPTO_ALG_AES_CBC_128)
58 self.crypt_algo = 'AES-CBC' # scapy name
Ole Troan64e978b2019-10-17 21:40:36 +020059 self.crypt_key = b'JPjyOWBeVEQiMe7h'
Neale Ranns80f6fd52019-04-16 02:41:34 +000060 self.salt = 0
Neale Ranns53f526b2019-02-25 14:32:02 +000061 self.flags = 0
62 self.nat_header = None
Neale Ranns041add72020-01-02 04:06:10 +000063 self.tun_flags = (VppEnum.vl_api_tunnel_encap_decap_flags_t.
64 TUNNEL_API_ENCAP_DECAP_FLAG_NONE)
65 self.dscp = 0
Neale Ranns8c609af2021-02-25 10:05:32 +000066 self.async_mode = False
Klement Sekera611864f2018-09-26 11:19:00 +020067
68
Paul Vinciguerrae061dad2020-12-04 14:57:51 -050069class IPsecIPv6Params:
Neale Ranns17dcec02019-01-09 21:22:20 -080070
Klement Sekera611864f2018-09-26 11:19:00 +020071 addr_type = socket.AF_INET6
72 addr_any = "0::0"
73 addr_bcast = "ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff"
74 addr_len = 128
75 is_ipv6 = 1
Klement Sekera611864f2018-09-26 11:19:00 +020076
Neale Ranns17dcec02019-01-09 21:22:20 -080077 def __init__(self):
78 self.remote_tun_if_host = '1111:1111:1111:1111:1111:1111:1111:1111'
Neale Ranns987aea82019-03-27 13:40:35 +000079 self.remote_tun_if_host4 = '1.1.1.1'
Klement Sekera611864f2018-09-26 11:19:00 +020080
Neale Ranns28287212019-12-16 00:53:11 +000081 self.scapy_tun_sa_id = 500
Neale Ranns17dcec02019-01-09 21:22:20 -080082 self.scapy_tun_spi = 3001
Neale Ranns28287212019-12-16 00:53:11 +000083 self.vpp_tun_sa_id = 600
Neale Ranns17dcec02019-01-09 21:22:20 -080084 self.vpp_tun_spi = 3000
Klement Sekera611864f2018-09-26 11:19:00 +020085
Neale Ranns28287212019-12-16 00:53:11 +000086 self.scapy_tra_sa_id = 700
Neale Ranns17dcec02019-01-09 21:22:20 -080087 self.scapy_tra_spi = 4001
Neale Ranns28287212019-12-16 00:53:11 +000088 self.vpp_tra_sa_id = 800
Neale Ranns17dcec02019-01-09 21:22:20 -080089 self.vpp_tra_spi = 4000
Klement Sekera611864f2018-09-26 11:19:00 +020090
Neale Ranns9ec846c2021-02-09 14:04:02 +000091 self.outer_hop_limit = 64
92 self.inner_hop_limit = 255
93 self.outer_flow_label = 0
94 self.inner_flow_label = 0x12345
95
Neale Ranns17dcec02019-01-09 21:22:20 -080096 self.auth_algo_vpp_id = (VppEnum.vl_api_ipsec_integ_alg_t.
Neale Ranns1091c4a2019-04-08 14:48:23 +000097 IPSEC_API_INTEG_ALG_SHA1_96)
98 self.auth_algo = 'HMAC-SHA1-96' # scapy name
Ole Troan64e978b2019-10-17 21:40:36 +020099 self.auth_key = b'C91KUR9GYMm5GfkEvNjX'
Neale Ranns17dcec02019-01-09 21:22:20 -0800100
101 self.crypt_algo_vpp_id = (VppEnum.vl_api_ipsec_crypto_alg_t.
Neale Ranns4f33c802019-04-10 12:39:10 +0000102 IPSEC_API_CRYPTO_ALG_AES_CBC_128)
Neale Ranns17dcec02019-01-09 21:22:20 -0800103 self.crypt_algo = 'AES-CBC' # scapy name
Ole Troan64e978b2019-10-17 21:40:36 +0200104 self.crypt_key = b'JPjyOWBeVEQiMe7h'
Neale Ranns80f6fd52019-04-16 02:41:34 +0000105 self.salt = 0
Neale Ranns53f526b2019-02-25 14:32:02 +0000106 self.flags = 0
107 self.nat_header = None
Neale Ranns041add72020-01-02 04:06:10 +0000108 self.tun_flags = (VppEnum.vl_api_tunnel_encap_decap_flags_t.
109 TUNNEL_API_ENCAP_DECAP_FLAG_NONE)
110 self.dscp = 0
Neale Ranns8c609af2021-02-25 10:05:32 +0000111 self.async_mode = False
Klement Sekera611864f2018-09-26 11:19:00 +0200112
113
Neale Ranns12989b52019-09-26 16:20:19 +0000114def mk_scapy_crypt_key(p):
Benoît Ganne490b9272021-01-22 18:03:09 +0100115 if p.crypt_algo in ("AES-GCM", "AES-CTR"):
Neale Ranns6afaae12019-07-17 15:07:14 +0000116 return p.crypt_key + struct.pack("!I", p.salt)
117 else:
118 return p.crypt_key
119
120
Neale Ranns2ac885c2019-03-20 18:24:43 +0000121def config_tun_params(p, encryption_type, tun_if):
122 ip_class_by_addr_type = {socket.AF_INET: IP, socket.AF_INET6: IPv6}
snaramre5d4b8912019-12-13 23:39:35 +0000123 esn_en = bool(p.flags & (VppEnum.vl_api_ipsec_sad_flags_t.
124 IPSEC_API_SAD_FLAG_USE_ESN))
Neale Rannsf3a66222020-01-02 05:04:00 +0000125 p.tun_dst = tun_if.remote_addr[p.addr_type]
126 p.tun_src = tun_if.local_addr[p.addr_type]
Neale Ranns12989b52019-09-26 16:20:19 +0000127 crypt_key = mk_scapy_crypt_key(p)
Neale Ranns2ac885c2019-03-20 18:24:43 +0000128 p.scapy_tun_sa = SecurityAssociation(
129 encryption_type, spi=p.vpp_tun_spi,
Neale Ranns80f6fd52019-04-16 02:41:34 +0000130 crypt_algo=p.crypt_algo,
131 crypt_key=crypt_key,
Neale Ranns2ac885c2019-03-20 18:24:43 +0000132 auth_algo=p.auth_algo, auth_key=p.auth_key,
133 tunnel_header=ip_class_by_addr_type[p.addr_type](
Neale Rannsf3a66222020-01-02 05:04:00 +0000134 src=p.tun_dst,
135 dst=p.tun_src),
Neale Ranns3833ffd2019-03-21 14:34:09 +0000136 nat_t_header=p.nat_header,
snaramre5d4b8912019-12-13 23:39:35 +0000137 esn_en=esn_en)
Neale Ranns2ac885c2019-03-20 18:24:43 +0000138 p.vpp_tun_sa = SecurityAssociation(
139 encryption_type, spi=p.scapy_tun_spi,
Neale Ranns80f6fd52019-04-16 02:41:34 +0000140 crypt_algo=p.crypt_algo,
141 crypt_key=crypt_key,
Neale Ranns2ac885c2019-03-20 18:24:43 +0000142 auth_algo=p.auth_algo, auth_key=p.auth_key,
143 tunnel_header=ip_class_by_addr_type[p.addr_type](
Neale Rannsf3a66222020-01-02 05:04:00 +0000144 dst=p.tun_dst,
145 src=p.tun_src),
Neale Ranns3833ffd2019-03-21 14:34:09 +0000146 nat_t_header=p.nat_header,
snaramre5d4b8912019-12-13 23:39:35 +0000147 esn_en=esn_en)
Neale Ranns2ac885c2019-03-20 18:24:43 +0000148
149
150def config_tra_params(p, encryption_type):
snaramre5d4b8912019-12-13 23:39:35 +0000151 esn_en = bool(p.flags & (VppEnum.vl_api_ipsec_sad_flags_t.
152 IPSEC_API_SAD_FLAG_USE_ESN))
Neale Ranns12989b52019-09-26 16:20:19 +0000153 crypt_key = mk_scapy_crypt_key(p)
Neale Ranns2ac885c2019-03-20 18:24:43 +0000154 p.scapy_tra_sa = SecurityAssociation(
155 encryption_type,
156 spi=p.vpp_tra_spi,
157 crypt_algo=p.crypt_algo,
Neale Ranns80f6fd52019-04-16 02:41:34 +0000158 crypt_key=crypt_key,
Neale Ranns2ac885c2019-03-20 18:24:43 +0000159 auth_algo=p.auth_algo,
160 auth_key=p.auth_key,
Neale Ranns3833ffd2019-03-21 14:34:09 +0000161 nat_t_header=p.nat_header,
snaramre5d4b8912019-12-13 23:39:35 +0000162 esn_en=esn_en)
Neale Ranns2ac885c2019-03-20 18:24:43 +0000163 p.vpp_tra_sa = SecurityAssociation(
164 encryption_type,
165 spi=p.scapy_tra_spi,
166 crypt_algo=p.crypt_algo,
Neale Ranns80f6fd52019-04-16 02:41:34 +0000167 crypt_key=crypt_key,
Neale Ranns2ac885c2019-03-20 18:24:43 +0000168 auth_algo=p.auth_algo,
169 auth_key=p.auth_key,
Neale Ranns3833ffd2019-03-21 14:34:09 +0000170 nat_t_header=p.nat_header,
snaramre5d4b8912019-12-13 23:39:35 +0000171 esn_en=esn_en)
Neale Ranns2ac885c2019-03-20 18:24:43 +0000172
173
Klement Sekera31da2e32018-06-24 22:49:55 +0200174class TemplateIpsec(VppTestCase):
175 """
Dave Wallaced1706812021-08-12 18:36:02 -0400176 TRANSPORT MODE::
Klement Sekera31da2e32018-06-24 22:49:55 +0200177
Dave Wallaced1706812021-08-12 18:36:02 -0400178 ------ encrypt ---
179 |tra_if| <-------> |VPP|
180 ------ decrypt ---
Klement Sekera31da2e32018-06-24 22:49:55 +0200181
Dave Wallaced1706812021-08-12 18:36:02 -0400182 TUNNEL MODE::
Klement Sekera31da2e32018-06-24 22:49:55 +0200183
Dave Wallaced1706812021-08-12 18:36:02 -0400184 ------ encrypt --- plain ---
185 |tun_if| <------- |VPP| <------ |pg1|
186 ------ --- ---
Klement Sekera31da2e32018-06-24 22:49:55 +0200187
Dave Wallaced1706812021-08-12 18:36:02 -0400188 ------ decrypt --- plain ---
189 |tun_if| -------> |VPP| ------> |pg1|
190 ------ --- ---
Klement Sekera31da2e32018-06-24 22:49:55 +0200191 """
Neale Ranns4f33c802019-04-10 12:39:10 +0000192 tun_spd_id = 1
193 tra_spd_id = 2
Klement Sekera31da2e32018-06-24 22:49:55 +0200194
Neale Ranns8e4a89b2019-01-23 08:16:17 -0800195 def ipsec_select_backend(self):
Klement Sekerab4d30532018-11-08 13:00:02 +0100196 """ empty method to be overloaded when necessary """
197 pass
198
Paul Vinciguerra7f9b7f92019-03-12 19:23:27 -0700199 @classmethod
200 def setUpClass(cls):
201 super(TemplateIpsec, cls).setUpClass()
202
203 @classmethod
204 def tearDownClass(cls):
205 super(TemplateIpsec, cls).tearDownClass()
206
Neale Ranns3833ffd2019-03-21 14:34:09 +0000207 def setup_params(self):
Neale Ranns041add72020-01-02 04:06:10 +0000208 if not hasattr(self, 'ipv4_params'):
209 self.ipv4_params = IPsecIPv4Params()
210 if not hasattr(self, 'ipv6_params'):
211 self.ipv6_params = IPsecIPv6Params()
Neale Ranns8e4a89b2019-01-23 08:16:17 -0800212 self.params = {self.ipv4_params.addr_type: self.ipv4_params,
213 self.ipv6_params.addr_type: self.ipv6_params}
214
Neale Ranns4f33c802019-04-10 12:39:10 +0000215 def config_interfaces(self):
Neale Ranns8e4a89b2019-01-23 08:16:17 -0800216 self.create_pg_interfaces(range(3))
217 self.interfaces = list(self.pg_interfaces)
218 for i in self.interfaces:
Klement Sekera31da2e32018-06-24 22:49:55 +0200219 i.admin_up()
220 i.config_ip4()
221 i.resolve_arp()
Klement Sekera611864f2018-09-26 11:19:00 +0200222 i.config_ip6()
223 i.resolve_ndp()
Neale Ranns4f33c802019-04-10 12:39:10 +0000224
225 def setUp(self):
226 super(TemplateIpsec, self).setUp()
227
228 self.setup_params()
229
230 self.vpp_esp_protocol = (VppEnum.vl_api_ipsec_proto_t.
231 IPSEC_API_PROTO_ESP)
232 self.vpp_ah_protocol = (VppEnum.vl_api_ipsec_proto_t.
233 IPSEC_API_PROTO_AH)
234
235 self.config_interfaces()
Paul Vinciguerra90cf21b2019-03-13 09:23:05 -0700236
Neale Ranns8e4a89b2019-01-23 08:16:17 -0800237 self.ipsec_select_backend()
Klement Sekera31da2e32018-06-24 22:49:55 +0200238
Neale Ranns4f33c802019-04-10 12:39:10 +0000239 def unconfig_interfaces(self):
Neale Ranns8e4a89b2019-01-23 08:16:17 -0800240 for i in self.interfaces:
241 i.admin_down()
242 i.unconfig_ip4()
243 i.unconfig_ip6()
244
Neale Ranns4f33c802019-04-10 12:39:10 +0000245 def tearDown(self):
246 super(TemplateIpsec, self).tearDown()
247
248 self.unconfig_interfaces()
249
Paul Vinciguerra90cf21b2019-03-13 09:23:05 -0700250 def show_commands_at_teardown(self):
251 self.logger.info(self.vapi.cli("show hardware"))
Klement Sekera31da2e32018-06-24 22:49:55 +0200252
Neale Ranns28287212019-12-16 00:53:11 +0000253 def gen_encrypt_pkts(self, p, sa, sw_intf, src, dst, count=1,
Neale Rannsd7603d92019-03-28 08:56:10 +0000254 payload_size=54):
Klement Sekera31da2e32018-06-24 22:49:55 +0200255 return [Ether(src=sw_intf.remote_mac, dst=sw_intf.local_mac) /
Neale Rannsd7603d92019-03-28 08:56:10 +0000256 sa.encrypt(IP(src=src, dst=dst) /
Ole Troan8b76c232019-10-21 20:55:13 +0200257 ICMP() / Raw(b'X' * payload_size))
Klement Sekera31da2e32018-06-24 22:49:55 +0200258 for i in range(count)]
259
Neale Ranns28287212019-12-16 00:53:11 +0000260 def gen_encrypt_pkts6(self, p, sa, sw_intf, src, dst, count=1,
Neale Rannsd7603d92019-03-28 08:56:10 +0000261 payload_size=54):
Klement Sekera611864f2018-09-26 11:19:00 +0200262 return [Ether(src=sw_intf.remote_mac, dst=sw_intf.local_mac) /
Neale Ranns9ec846c2021-02-09 14:04:02 +0000263 sa.encrypt(IPv6(src=src, dst=dst,
264 hlim=p.inner_hop_limit,
265 fl=p.inner_flow_label) /
Neale Rannsd7603d92019-03-28 08:56:10 +0000266 ICMPv6EchoRequest(id=0, seq=1,
267 data='X' * payload_size))
Klement Sekera611864f2018-09-26 11:19:00 +0200268 for i in range(count)]
269
Neale Rannsd7603d92019-03-28 08:56:10 +0000270 def gen_pkts(self, sw_intf, src, dst, count=1, payload_size=54):
Klement Sekera31da2e32018-06-24 22:49:55 +0200271 return [Ether(src=sw_intf.remote_mac, dst=sw_intf.local_mac) /
Ole Troan8b76c232019-10-21 20:55:13 +0200272 IP(src=src, dst=dst) / ICMP() / Raw(b'X' * payload_size)
Klement Sekera31da2e32018-06-24 22:49:55 +0200273 for i in range(count)]
274
Neale Ranns9ec846c2021-02-09 14:04:02 +0000275 def gen_pkts6(self, p, sw_intf, src, dst, count=1, payload_size=54):
Klement Sekera611864f2018-09-26 11:19:00 +0200276 return [Ether(src=sw_intf.remote_mac, dst=sw_intf.local_mac) /
Neale Ranns9ec846c2021-02-09 14:04:02 +0000277 IPv6(src=src, dst=dst,
278 hlim=p.inner_hop_limit, fl=p.inner_flow_label) /
Neale Rannsd7603d92019-03-28 08:56:10 +0000279 ICMPv6EchoRequest(id=0, seq=1, data='X' * payload_size)
Klement Sekera611864f2018-09-26 11:19:00 +0200280 for i in range(count)]
281
Klement Sekera31da2e32018-06-24 22:49:55 +0200282
Neale Ranns4f33c802019-04-10 12:39:10 +0000283class IpsecTcp(object):
284 def verify_tcp_checksum(self):
Klement Sekera31da2e32018-06-24 22:49:55 +0200285 self.vapi.cli("test http server")
Klement Sekera611864f2018-09-26 11:19:00 +0200286 p = self.params[socket.AF_INET]
Klement Sekera31da2e32018-06-24 22:49:55 +0200287 send = (Ether(src=self.tun_if.remote_mac, dst=self.tun_if.local_mac) /
Neale Ranns2ac885c2019-03-20 18:24:43 +0000288 p.scapy_tun_sa.encrypt(IP(src=p.remote_tun_if_host,
289 dst=self.tun_if.local_ip4) /
290 TCP(flags='S', dport=80)))
Klement Sekera31da2e32018-06-24 22:49:55 +0200291 self.logger.debug(ppp("Sending packet:", send))
Klement Sekera611864f2018-09-26 11:19:00 +0200292 recv = self.send_and_expect(self.tun_if, [send], self.tun_if)
Klement Sekera31da2e32018-06-24 22:49:55 +0200293 recv = recv[0]
Neale Ranns2ac885c2019-03-20 18:24:43 +0000294 decrypted = p.vpp_tun_sa.decrypt(recv[IP])
Klement Sekera31da2e32018-06-24 22:49:55 +0200295 self.assert_packet_checksums_valid(decrypted)
296
297
Neale Ranns4f33c802019-04-10 12:39:10 +0000298class IpsecTcpTests(IpsecTcp):
299 def test_tcp_checksum(self):
300 """ verify checksum correctness for vpp generated packets """
301 self.verify_tcp_checksum()
302
303
304class IpsecTra4(object):
305 """ verify methods for Transport v4 """
Neale Ranns8c609af2021-02-25 10:05:32 +0000306 def get_replay_counts(self, p):
307 replay_node_name = ('/err/%s/SA replayed packet' %
308 self.tra4_decrypt_node_name[0])
309 count = self.statistics.get_err_counter(replay_node_name)
310
311 if p.async_mode:
312 replay_post_node_name = ('/err/%s/SA replayed packet' %
313 self.tra4_decrypt_node_name[p.async_mode])
314 count += self.statistics.get_err_counter(replay_post_node_name)
315
316 return count
317
318 def get_hash_failed_counts(self, p):
319 if ESP == self.encryption_type and p.crypt_algo == "AES-GCM":
320 hash_failed_node_name = ('/err/%s/ESP decryption failed' %
321 self.tra4_decrypt_node_name[p.async_mode])
322 else:
323 hash_failed_node_name = ('/err/%s/Integrity check failed' %
324 self.tra4_decrypt_node_name[p.async_mode])
325 count = self.statistics.get_err_counter(hash_failed_node_name)
326
327 if p.async_mode:
328 count += self.statistics.get_err_counter(
329 '/err/crypto-dispatch/bad-hmac')
330
331 return count
332
Neale Ranns5b891102021-06-28 13:31:28 +0000333 def verify_hi_seq_num(self):
334 p = self.params[socket.AF_INET]
335 saf = VppEnum.vl_api_ipsec_sad_flags_t
336 esn_on = p.vpp_tra_sa.esn_en
337 ar_on = p.flags & saf.IPSEC_API_SAD_FLAG_USE_ANTI_REPLAY
338
339 seq_cycle_node_name = \
340 ('/err/%s/sequence number cycled (packet dropped)' %
341 self.tra4_encrypt_node_name)
342 replay_count = self.get_replay_counts(p)
343 hash_failed_count = self.get_hash_failed_counts(p)
344 seq_cycle_count = self.statistics.get_err_counter(seq_cycle_node_name)
345
346 # a few packets so we get the rx seq number above the window size and
347 # thus can simulate a wrap with an out of window packet
348 pkts = [(Ether(src=self.tra_if.remote_mac,
349 dst=self.tra_if.local_mac) /
350 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
351 dst=self.tra_if.local_ip4) /
352 ICMP(),
353 seq_num=seq))
354 for seq in range(63, 80)]
355 recv_pkts = self.send_and_expect(self.tra_if, pkts, self.tra_if)
356
357 # these 4 packets will all choose seq-num 0 to decrpyt since none
358 # are out of window when first checked. however, once #200 has
359 # decrypted it will move the window to 200 and has #81 is out of
360 # window. this packet should be dropped.
361 pkts = [(Ether(src=self.tra_if.remote_mac,
362 dst=self.tra_if.local_mac) /
363 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
364 dst=self.tra_if.local_ip4) /
365 ICMP(),
366 seq_num=200)),
367 (Ether(src=self.tra_if.remote_mac,
368 dst=self.tra_if.local_mac) /
369 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
370 dst=self.tra_if.local_ip4) /
371 ICMP(),
372 seq_num=81)),
373 (Ether(src=self.tra_if.remote_mac,
374 dst=self.tra_if.local_mac) /
375 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
376 dst=self.tra_if.local_ip4) /
377 ICMP(),
378 seq_num=201)),
379 (Ether(src=self.tra_if.remote_mac,
380 dst=self.tra_if.local_mac) /
381 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
382 dst=self.tra_if.local_ip4) /
383 ICMP(),
384 seq_num=202))]
385
386 # if anti-replay is off then we won't drop #81
387 n_rx = 3 if ar_on else 4
388 self.send_and_expect(self.tra_if, pkts, self.tra_if, n_rx=n_rx)
389 # this packet is one before the wrap
390 pkts = [(Ether(src=self.tra_if.remote_mac,
391 dst=self.tra_if.local_mac) /
392 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
393 dst=self.tra_if.local_ip4) /
394 ICMP(),
395 seq_num=203))]
396 recv_pkts = self.send_and_expect(self.tra_if, pkts, self.tra_if)
397
398 # move the window over half way to a wrap
399 pkts = [(Ether(src=self.tra_if.remote_mac,
400 dst=self.tra_if.local_mac) /
401 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
402 dst=self.tra_if.local_ip4) /
403 ICMP(),
404 seq_num=0x80000001))]
405 recv_pkts = self.send_and_expect(self.tra_if, pkts, self.tra_if)
406
407 # anti-replay will drop old packets, no anti-replay will not
408 pkts = [(Ether(src=self.tra_if.remote_mac,
409 dst=self.tra_if.local_mac) /
410 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
411 dst=self.tra_if.local_ip4) /
412 ICMP(),
413 seq_num=0x44000001))]
414
415 if ar_on:
416 self.send_and_assert_no_replies(self.tra_if, pkts)
417 else:
418 recv_pkts = self.send_and_expect(self.tra_if, pkts, self.tra_if)
419
420 if esn_on:
421 #
422 # validate wrapping the ESN
423 #
424
425 # wrap scapy's TX SA SN
426 p.scapy_tra_sa.seq_num = 0x100000005
427
428 # send a packet that wraps the window for both AR and no AR
429 pkts = [(Ether(src=self.tra_if.remote_mac,
430 dst=self.tra_if.local_mac) /
431 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
432 dst=self.tra_if.local_ip4) /
433 ICMP(),
434 seq_num=0x100000005))]
435
436 rxs = self.send_and_expect(self.tra_if, pkts, self.tra_if)
437 for rx in rxs:
438 decrypted = p.vpp_tra_sa.decrypt(rx[0][IP])
439
440 # move the window forward to half way to the next wrap
441 pkts = [(Ether(src=self.tra_if.remote_mac,
442 dst=self.tra_if.local_mac) /
443 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
444 dst=self.tra_if.local_ip4) /
445 ICMP(),
446 seq_num=0x180000005))]
447
448 rxs = self.send_and_expect(self.tra_if, pkts, self.tra_if)
449
450 # a packet less than 2^30 from the current position is:
451 # - AR: out of window and dropped
452 # - non-AR: accepted
453 pkts = [(Ether(src=self.tra_if.remote_mac,
454 dst=self.tra_if.local_mac) /
455 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
456 dst=self.tra_if.local_ip4) /
457 ICMP(),
458 seq_num=0x170000005))]
459
460 if ar_on:
461 self.send_and_assert_no_replies(self.tra_if, pkts)
462 else:
463 self.send_and_expect(self.tra_if, pkts, self.tra_if)
464
465 # a packet more than 2^30 from the current position is:
466 # - AR: out of window and dropped
467 # - non-AR: considered a wrap, but since it's not a wrap
468 # it won't decrpyt and so will be dropped
469 pkts = [(Ether(src=self.tra_if.remote_mac,
470 dst=self.tra_if.local_mac) /
471 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
472 dst=self.tra_if.local_ip4) /
473 ICMP(),
474 seq_num=0x130000005))]
475
476 self.send_and_assert_no_replies(self.tra_if, pkts)
477
478 # a packet less than 2^30 from the current position and is a
479 # wrap; (the seq is currently at 0x180000005).
480 # - AR: out of window so considered a wrap, so accepted
481 # - non-AR: not considered a wrap, so won't decrypt
482 p.scapy_tra_sa.seq_num = 0x260000005
483 pkts = [(Ether(src=self.tra_if.remote_mac,
484 dst=self.tra_if.local_mac) /
485 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
486 dst=self.tra_if.local_ip4) /
487 ICMP(),
488 seq_num=0x260000005))]
489 if ar_on:
490 self.send_and_expect(self.tra_if, pkts, self.tra_if)
491 else:
492 self.send_and_assert_no_replies(self.tra_if, pkts)
493
494 #
495 # window positions are different now for AR/non-AR
496 # move non-AR forward
497 #
498 if not ar_on:
499 # a packet more than 2^30 from the current position and is a
500 # wrap; (the seq is currently at 0x180000005).
501 # - AR: accepted
502 # - non-AR: not considered a wrap, so won't decrypt
503
504 pkts = [(Ether(src=self.tra_if.remote_mac,
505 dst=self.tra_if.local_mac) /
506 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
507 dst=self.tra_if.local_ip4) /
508 ICMP(),
509 seq_num=0x200000005)),
510 (Ether(src=self.tra_if.remote_mac,
511 dst=self.tra_if.local_mac) /
512 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
513 dst=self.tra_if.local_ip4) /
514 ICMP(),
515 seq_num=0x200000006))]
516 self.send_and_expect(self.tra_if, pkts, self.tra_if)
517
518 pkts = [(Ether(src=self.tra_if.remote_mac,
519 dst=self.tra_if.local_mac) /
520 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
521 dst=self.tra_if.local_ip4) /
522 ICMP(),
523 seq_num=0x260000005))]
524 self.send_and_expect(self.tra_if, pkts, self.tra_if)
525
Neale Ranns6afaae12019-07-17 15:07:14 +0000526 def verify_tra_anti_replay(self):
Neale Rannsde847272018-11-28 01:38:34 -0800527 p = self.params[socket.AF_INET]
snaramre5d4b8912019-12-13 23:39:35 +0000528 esn_en = p.vpp_tra_sa.esn_en
Neale Rannsde847272018-11-28 01:38:34 -0800529
Ole Troane66443c2021-03-18 11:12:01 +0100530 seq_cycle_node_name = \
531 ('/err/%s/sequence number cycled (packet dropped)' %
532 self.tra4_encrypt_node_name)
Neale Ranns8c609af2021-02-25 10:05:32 +0000533 replay_count = self.get_replay_counts(p)
534 hash_failed_count = self.get_hash_failed_counts(p)
Neale Ranns6afaae12019-07-17 15:07:14 +0000535 seq_cycle_count = self.statistics.get_err_counter(seq_cycle_node_name)
Neale Rannsde847272018-11-28 01:38:34 -0800536
Neale Ranns6afaae12019-07-17 15:07:14 +0000537 if ESP == self.encryption_type:
538 undersize_node_name = ('/err/%s/undersized packet' %
Neale Ranns8c609af2021-02-25 10:05:32 +0000539 self.tra4_decrypt_node_name[0])
Neale Ranns6afaae12019-07-17 15:07:14 +0000540 undersize_count = self.statistics.get_err_counter(
541 undersize_node_name)
542
543 #
544 # send packets with seq numbers 1->34
545 # this means the window size is still in Case B (see RFC4303
546 # Appendix A)
547 #
548 # for reasons i haven't investigated Scapy won't create a packet with
549 # seq_num=0
550 #
551 pkts = [(Ether(src=self.tra_if.remote_mac,
552 dst=self.tra_if.local_mac) /
553 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
554 dst=self.tra_if.local_ip4) /
555 ICMP(),
556 seq_num=seq))
557 for seq in range(1, 34)]
558 recv_pkts = self.send_and_expect(self.tra_if, pkts, self.tra_if)
559
560 # replayed packets are dropped
Neale Ranns5b891102021-06-28 13:31:28 +0000561 self.send_and_assert_no_replies(self.tra_if, pkts, timeout=0.2)
Neale Ranns6afaae12019-07-17 15:07:14 +0000562 replay_count += len(pkts)
Neale Ranns8c609af2021-02-25 10:05:32 +0000563 self.assertEqual(self.get_replay_counts(p), replay_count)
Neale Ranns6afaae12019-07-17 15:07:14 +0000564
565 #
Neale Ranns3b9374f2019-08-01 04:45:15 -0700566 # now send a batch of packets all with the same sequence number
567 # the first packet in the batch is legitimate, the rest bogus
568 #
Neale Ranns8c609af2021-02-25 10:05:32 +0000569 self.vapi.cli("clear error")
570 self.vapi.cli("clear node counters")
Neale Ranns3b9374f2019-08-01 04:45:15 -0700571 pkts = (Ether(src=self.tra_if.remote_mac,
572 dst=self.tra_if.local_mac) /
573 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
574 dst=self.tra_if.local_ip4) /
575 ICMP(),
576 seq_num=35))
577 recv_pkts = self.send_and_expect(self.tra_if, pkts * 8,
578 self.tra_if, n_rx=1)
579 replay_count += 7
Neale Ranns8c609af2021-02-25 10:05:32 +0000580 self.assertEqual(self.get_replay_counts(p), replay_count)
Neale Ranns3b9374f2019-08-01 04:45:15 -0700581
582 #
Neale Ranns6afaae12019-07-17 15:07:14 +0000583 # now move the window over to 257 (more than one byte) and into Case A
584 #
Neale Ranns8c609af2021-02-25 10:05:32 +0000585 self.vapi.cli("clear error")
Neale Rannsde847272018-11-28 01:38:34 -0800586 pkt = (Ether(src=self.tra_if.remote_mac,
587 dst=self.tra_if.local_mac) /
588 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
589 dst=self.tra_if.local_ip4) /
590 ICMP(),
Neale Ranns6afaae12019-07-17 15:07:14 +0000591 seq_num=257))
Neale Rannsde847272018-11-28 01:38:34 -0800592 recv_pkts = self.send_and_expect(self.tra_if, [pkt], self.tra_if)
593
Neale Ranns3833ffd2019-03-21 14:34:09 +0000594 # replayed packets are dropped
Neale Ranns5b891102021-06-28 13:31:28 +0000595 self.send_and_assert_no_replies(self.tra_if, pkt * 3, timeout=0.2)
Neale Ranns6afaae12019-07-17 15:07:14 +0000596 replay_count += 3
Neale Ranns8c609af2021-02-25 10:05:32 +0000597 self.assertEqual(self.get_replay_counts(p), replay_count)
Neale Ranns3833ffd2019-03-21 14:34:09 +0000598
Neale Rannsde847272018-11-28 01:38:34 -0800599 # the window size is 64 packets
600 # in window are still accepted
601 pkt = (Ether(src=self.tra_if.remote_mac,
602 dst=self.tra_if.local_mac) /
603 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
604 dst=self.tra_if.local_ip4) /
605 ICMP(),
Neale Ranns6afaae12019-07-17 15:07:14 +0000606 seq_num=200))
Neale Rannsde847272018-11-28 01:38:34 -0800607 recv_pkts = self.send_and_expect(self.tra_if, [pkt], self.tra_if)
608
Neale Rannsde847272018-11-28 01:38:34 -0800609 # a packet that does not decrypt does not move the window forward
610 bogus_sa = SecurityAssociation(self.encryption_type,
Damjan Mariona829b132019-04-24 23:39:16 +0200611 p.vpp_tra_spi,
612 crypt_algo=p.crypt_algo,
Neale Ranns12989b52019-09-26 16:20:19 +0000613 crypt_key=mk_scapy_crypt_key(p)[::-1],
Damjan Mariona829b132019-04-24 23:39:16 +0200614 auth_algo=p.auth_algo,
615 auth_key=p.auth_key[::-1])
Neale Rannsde847272018-11-28 01:38:34 -0800616 pkt = (Ether(src=self.tra_if.remote_mac,
617 dst=self.tra_if.local_mac) /
618 bogus_sa.encrypt(IP(src=self.tra_if.remote_ip4,
619 dst=self.tra_if.local_ip4) /
620 ICMP(),
621 seq_num=350))
Neale Ranns5b891102021-06-28 13:31:28 +0000622 self.send_and_assert_no_replies(self.tra_if, pkt * 17, timeout=0.2)
Neale Rannsde847272018-11-28 01:38:34 -0800623
Neale Ranns6afaae12019-07-17 15:07:14 +0000624 hash_failed_count += 17
Neale Ranns8c609af2021-02-25 10:05:32 +0000625 self.assertEqual(self.get_hash_failed_counts(p), hash_failed_count)
Neale Rannsde847272018-11-28 01:38:34 -0800626
Damjan Mariona829b132019-04-24 23:39:16 +0200627 # a malformed 'runt' packet
628 # created by a mis-constructed SA
Neale Ranns2cdcd0c2019-08-27 12:26:14 +0000629 if (ESP == self.encryption_type and p.crypt_algo != "NULL"):
Damjan Mariona829b132019-04-24 23:39:16 +0200630 bogus_sa = SecurityAssociation(self.encryption_type,
631 p.vpp_tra_spi)
632 pkt = (Ether(src=self.tra_if.remote_mac,
633 dst=self.tra_if.local_mac) /
634 bogus_sa.encrypt(IP(src=self.tra_if.remote_ip4,
635 dst=self.tra_if.local_ip4) /
636 ICMP(),
637 seq_num=350))
Neale Ranns5b891102021-06-28 13:31:28 +0000638 self.send_and_assert_no_replies(self.tra_if, pkt * 17, timeout=0.2)
Damjan Mariona829b132019-04-24 23:39:16 +0200639
Neale Ranns6afaae12019-07-17 15:07:14 +0000640 undersize_count += 17
641 self.assert_error_counter_equal(undersize_node_name,
642 undersize_count)
Damjan Mariona829b132019-04-24 23:39:16 +0200643
Neale Rannsde847272018-11-28 01:38:34 -0800644 # which we can determine since this packet is still in the window
645 pkt = (Ether(src=self.tra_if.remote_mac,
646 dst=self.tra_if.local_mac) /
647 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
648 dst=self.tra_if.local_ip4) /
649 ICMP(),
650 seq_num=234))
Klement Sekera14d7e902018-12-10 13:46:09 +0100651 self.send_and_expect(self.tra_if, [pkt], self.tra_if)
Neale Rannsde847272018-11-28 01:38:34 -0800652
Neale Ranns6afaae12019-07-17 15:07:14 +0000653 #
Neale Ranns3833ffd2019-03-21 14:34:09 +0000654 # out of window are dropped
Neale Ranns6afaae12019-07-17 15:07:14 +0000655 # this is Case B. So VPP will consider this to be a high seq num wrap
656 # and so the decrypt attempt will fail
657 #
Neale Ranns3833ffd2019-03-21 14:34:09 +0000658 pkt = (Ether(src=self.tra_if.remote_mac,
659 dst=self.tra_if.local_mac) /
660 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
661 dst=self.tra_if.local_ip4) /
662 ICMP(),
663 seq_num=17))
Neale Ranns5b891102021-06-28 13:31:28 +0000664 self.send_and_assert_no_replies(self.tra_if, pkt * 17, timeout=0.2)
Neale Ranns00a44202019-03-21 16:36:28 +0000665
snaramre5d4b8912019-12-13 23:39:35 +0000666 if esn_en:
Neale Ranns3833ffd2019-03-21 14:34:09 +0000667 # an out of window error with ESN looks like a high sequence
668 # wrap. but since it isn't then the verify will fail.
Neale Ranns6afaae12019-07-17 15:07:14 +0000669 hash_failed_count += 17
Neale Ranns8c609af2021-02-25 10:05:32 +0000670 self.assertEqual(self.get_hash_failed_counts(p), hash_failed_count)
Neale Ranns3833ffd2019-03-21 14:34:09 +0000671
672 else:
Neale Ranns6afaae12019-07-17 15:07:14 +0000673 replay_count += 17
Neale Ranns8c609af2021-02-25 10:05:32 +0000674 self.assertEqual(self.get_replay_counts(p), replay_count)
Neale Ranns3833ffd2019-03-21 14:34:09 +0000675
Neale Ranns6afaae12019-07-17 15:07:14 +0000676 # valid packet moves the window over to 258
Neale Ranns00a44202019-03-21 16:36:28 +0000677 pkt = (Ether(src=self.tra_if.remote_mac,
678 dst=self.tra_if.local_mac) /
679 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
680 dst=self.tra_if.local_ip4) /
681 ICMP(),
Neale Ranns6afaae12019-07-17 15:07:14 +0000682 seq_num=258))
Neale Ranns3833ffd2019-03-21 14:34:09 +0000683 rx = self.send_and_expect(self.tra_if, [pkt], self.tra_if)
684 decrypted = p.vpp_tra_sa.decrypt(rx[0][IP])
685
Neale Ranns6afaae12019-07-17 15:07:14 +0000686 #
687 # move VPP's SA TX seq-num to just before the seq-number wrap.
688 # then fire in a packet that VPP should drop on TX because it
689 # causes the TX seq number to wrap; unless we're using extened sequence
690 # numbers.
691 #
Neale Ranns3833ffd2019-03-21 14:34:09 +0000692 self.vapi.cli("test ipsec sa %d seq 0xffffffff" % p.scapy_tra_sa_id)
Neale Ranns6afaae12019-07-17 15:07:14 +0000693 self.logger.info(self.vapi.ppcli("show ipsec sa 0"))
694 self.logger.info(self.vapi.ppcli("show ipsec sa 1"))
Neale Ranns3833ffd2019-03-21 14:34:09 +0000695
Neale Ranns6afaae12019-07-17 15:07:14 +0000696 pkts = [(Ether(src=self.tra_if.remote_mac,
697 dst=self.tra_if.local_mac) /
698 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
699 dst=self.tra_if.local_ip4) /
700 ICMP(),
701 seq_num=seq))
702 for seq in range(259, 280)]
Neale Ranns3833ffd2019-03-21 14:34:09 +0000703
snaramre5d4b8912019-12-13 23:39:35 +0000704 if esn_en:
Neale Ranns6afaae12019-07-17 15:07:14 +0000705 rxs = self.send_and_expect(self.tra_if, pkts, self.tra_if)
Neale Ranns3833ffd2019-03-21 14:34:09 +0000706
Neale Ranns6afaae12019-07-17 15:07:14 +0000707 #
708 # in order for scapy to decrypt its SA's high order number needs
709 # to wrap
710 #
711 p.vpp_tra_sa.seq_num = 0x100000000
712 for rx in rxs:
713 decrypted = p.vpp_tra_sa.decrypt(rx[0][IP])
714
715 #
716 # wrap scapy's TX high sequence number. VPP is in case B, so it
717 # will consider this a high seq wrap also.
718 # The low seq num we set it to will place VPP's RX window in Case A
719 #
Neale Ranns3833ffd2019-03-21 14:34:09 +0000720 p.scapy_tra_sa.seq_num = 0x100000005
721 pkt = (Ether(src=self.tra_if.remote_mac,
722 dst=self.tra_if.local_mac) /
723 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
724 dst=self.tra_if.local_ip4) /
725 ICMP(),
726 seq_num=0x100000005))
727 rx = self.send_and_expect(self.tra_if, [pkt], self.tra_if)
Neale Ranns5b891102021-06-28 13:31:28 +0000728
Neale Ranns3833ffd2019-03-21 14:34:09 +0000729 decrypted = p.vpp_tra_sa.decrypt(rx[0][IP])
Neale Ranns6afaae12019-07-17 15:07:14 +0000730
731 #
732 # A packet that has seq num between (2^32-64) and 5 is within
733 # the window
734 #
735 p.scapy_tra_sa.seq_num = 0xfffffffd
736 pkt = (Ether(src=self.tra_if.remote_mac,
737 dst=self.tra_if.local_mac) /
738 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
739 dst=self.tra_if.local_ip4) /
740 ICMP(),
741 seq_num=0xfffffffd))
742 rx = self.send_and_expect(self.tra_if, [pkt], self.tra_if)
743 decrypted = p.vpp_tra_sa.decrypt(rx[0][IP])
744
745 #
746 # While in case A we cannot wrap the high sequence number again
Neale Ranns5b891102021-06-28 13:31:28 +0000747 # because VPP will consider this packet to be one that moves the
Neale Ranns6afaae12019-07-17 15:07:14 +0000748 # window forward
749 #
750 pkt = (Ether(src=self.tra_if.remote_mac,
751 dst=self.tra_if.local_mac) /
752 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
753 dst=self.tra_if.local_ip4) /
754 ICMP(),
755 seq_num=0x200000999))
Neale Ranns5b891102021-06-28 13:31:28 +0000756 self.send_and_assert_no_replies(self.tra_if, [pkt], self.tra_if,
757 timeout=0.2)
Neale Ranns6afaae12019-07-17 15:07:14 +0000758
759 hash_failed_count += 1
Neale Ranns8c609af2021-02-25 10:05:32 +0000760 self.assertEqual(self.get_hash_failed_counts(p), hash_failed_count)
Neale Ranns6afaae12019-07-17 15:07:14 +0000761
762 #
Neale Ranns5b891102021-06-28 13:31:28 +0000763 # but if we move the window forward to case B, then we can wrap
Neale Ranns6afaae12019-07-17 15:07:14 +0000764 # again
765 #
766 p.scapy_tra_sa.seq_num = 0x100000555
767 pkt = (Ether(src=self.tra_if.remote_mac,
768 dst=self.tra_if.local_mac) /
769 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
770 dst=self.tra_if.local_ip4) /
771 ICMP(),
772 seq_num=0x100000555))
773 rx = self.send_and_expect(self.tra_if, [pkt], self.tra_if)
774 decrypted = p.vpp_tra_sa.decrypt(rx[0][IP])
775
776 p.scapy_tra_sa.seq_num = 0x200000444
777 pkt = (Ether(src=self.tra_if.remote_mac,
778 dst=self.tra_if.local_mac) /
779 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
780 dst=self.tra_if.local_ip4) /
781 ICMP(),
782 seq_num=0x200000444))
783 rx = self.send_and_expect(self.tra_if, [pkt], self.tra_if)
784 decrypted = p.vpp_tra_sa.decrypt(rx[0][IP])
785
Neale Ranns3833ffd2019-03-21 14:34:09 +0000786 else:
Neale Ranns6afaae12019-07-17 15:07:14 +0000787 #
788 # without ESN TX sequence numbers can't wrap and packets are
789 # dropped from here on out.
790 #
Neale Ranns5b891102021-06-28 13:31:28 +0000791 self.send_and_assert_no_replies(self.tra_if, pkts, timeout=0.2)
Neale Ranns6afaae12019-07-17 15:07:14 +0000792 seq_cycle_count += len(pkts)
793 self.assert_error_counter_equal(seq_cycle_node_name,
794 seq_cycle_count)
Neale Ranns00a44202019-03-21 16:36:28 +0000795
Neale Rannsde847272018-11-28 01:38:34 -0800796 # move the security-associations seq number on to the last we used
Neale Ranns00a44202019-03-21 16:36:28 +0000797 self.vapi.cli("test ipsec sa %d seq 0x15f" % p.scapy_tra_sa_id)
Neale Rannsde847272018-11-28 01:38:34 -0800798 p.scapy_tra_sa.seq_num = 351
799 p.vpp_tra_sa.seq_num = 351
800
Neale Rannse11203e2021-09-21 12:34:19 +0000801 def verify_tra_lost(self):
802 p = self.params[socket.AF_INET]
803 esn_en = p.vpp_tra_sa.esn_en
804
805 #
806 # send packets with seq numbers 1->34
807 # this means the window size is still in Case B (see RFC4303
808 # Appendix A)
809 #
810 # for reasons i haven't investigated Scapy won't create a packet with
811 # seq_num=0
812 #
813 pkts = [(Ether(src=self.tra_if.remote_mac,
814 dst=self.tra_if.local_mac) /
815 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
816 dst=self.tra_if.local_ip4) /
817 ICMP(),
818 seq_num=seq))
819 for seq in range(1, 3)]
820 self.send_and_expect(self.tra_if, pkts, self.tra_if)
821
822 self.assertEqual(p.tra_sa_out.get_lost(), 0)
823
824 # skip a sequence number
825 pkts = [(Ether(src=self.tra_if.remote_mac,
826 dst=self.tra_if.local_mac) /
827 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
828 dst=self.tra_if.local_ip4) /
829 ICMP(),
830 seq_num=seq))
831 for seq in range(4, 6)]
832 self.send_and_expect(self.tra_if, pkts, self.tra_if)
833
834 self.assertEqual(p.tra_sa_out.get_lost(), 0)
835
836 # the lost packet are counted untill we get up past the first
837 # sizeof(replay_window) packets
838 pkts = [(Ether(src=self.tra_if.remote_mac,
839 dst=self.tra_if.local_mac) /
840 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
841 dst=self.tra_if.local_ip4) /
842 ICMP(),
843 seq_num=seq))
844 for seq in range(6, 100)]
845 self.send_and_expect(self.tra_if, pkts, self.tra_if)
846
847 self.assertEqual(p.tra_sa_out.get_lost(), 1)
848
849 # lost of holes in the sequence
850 pkts = [(Ether(src=self.tra_if.remote_mac,
851 dst=self.tra_if.local_mac) /
852 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
853 dst=self.tra_if.local_ip4) /
854 ICMP(),
855 seq_num=seq))
856 for seq in range(100, 200, 2)]
857 self.send_and_expect(self.tra_if, pkts, self.tra_if, n_rx=50)
858
859 pkts = [(Ether(src=self.tra_if.remote_mac,
860 dst=self.tra_if.local_mac) /
861 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
862 dst=self.tra_if.local_ip4) /
863 ICMP(),
864 seq_num=seq))
865 for seq in range(200, 300)]
866 self.send_and_expect(self.tra_if, pkts, self.tra_if)
867
868 self.assertEqual(p.tra_sa_out.get_lost(), 51)
869
870 # a big hole in the seq number space
871 pkts = [(Ether(src=self.tra_if.remote_mac,
872 dst=self.tra_if.local_mac) /
873 p.scapy_tra_sa.encrypt(IP(src=self.tra_if.remote_ip4,
874 dst=self.tra_if.local_ip4) /
875 ICMP(),
876 seq_num=seq))
877 for seq in range(400, 500)]
878 self.send_and_expect(self.tra_if, pkts, self.tra_if)
879
880 self.assertEqual(p.tra_sa_out.get_lost(), 151)
881
Filip Tehlarefcad1a2020-02-04 09:36:04 +0000882 def verify_tra_basic4(self, count=1, payload_size=54):
Klement Sekera31da2e32018-06-24 22:49:55 +0200883 """ ipsec v4 transport basic test """
Klement Sekera10d066e2018-11-13 11:12:57 +0100884 self.vapi.cli("clear errors")
Neale Ranns6afaae12019-07-17 15:07:14 +0000885 self.vapi.cli("clear ipsec sa")
Klement Sekera31da2e32018-06-24 22:49:55 +0200886 try:
Klement Sekera611864f2018-09-26 11:19:00 +0200887 p = self.params[socket.AF_INET]
Neale Ranns28287212019-12-16 00:53:11 +0000888 send_pkts = self.gen_encrypt_pkts(p, p.scapy_tra_sa, self.tra_if,
Klement Sekera31da2e32018-06-24 22:49:55 +0200889 src=self.tra_if.remote_ip4,
890 dst=self.tra_if.local_ip4,
Filip Tehlarefcad1a2020-02-04 09:36:04 +0000891 count=count,
892 payload_size=payload_size)
Klement Sekera31da2e32018-06-24 22:49:55 +0200893 recv_pkts = self.send_and_expect(self.tra_if, send_pkts,
Klement Sekera611864f2018-09-26 11:19:00 +0200894 self.tra_if)
Neale Rannsde847272018-11-28 01:38:34 -0800895 for rx in recv_pkts:
Neale Ranns1b582b82019-04-18 19:49:13 -0700896 self.assertEqual(len(rx) - len(Ether()), rx[IP].len)
897 self.assert_packet_checksums_valid(rx)
Klement Sekera611864f2018-09-26 11:19:00 +0200898 try:
Neale Rannsde847272018-11-28 01:38:34 -0800899 decrypted = p.vpp_tra_sa.decrypt(rx[IP])
Klement Sekera611864f2018-09-26 11:19:00 +0200900 self.assert_packet_checksums_valid(decrypted)
901 except:
Neale Rannsde847272018-11-28 01:38:34 -0800902 self.logger.debug(ppp("Unexpected packet:", rx))
Klement Sekera611864f2018-09-26 11:19:00 +0200903 raise
Klement Sekera31da2e32018-06-24 22:49:55 +0200904 finally:
905 self.logger.info(self.vapi.ppcli("show error"))
Paul Vinciguerra9673e3e2019-05-10 20:41:08 -0400906 self.logger.info(self.vapi.ppcli("show ipsec all"))
Klement Sekera31da2e32018-06-24 22:49:55 +0200907
Neale Rannseba31ec2019-02-17 18:04:27 +0000908 pkts = p.tra_sa_in.get_stats()['packets']
909 self.assertEqual(pkts, count,
910 "incorrect SA in counts: expected %d != %d" %
911 (count, pkts))
912 pkts = p.tra_sa_out.get_stats()['packets']
913 self.assertEqual(pkts, count,
914 "incorrect SA out counts: expected %d != %d" %
915 (count, pkts))
Neale Rannse11203e2021-09-21 12:34:19 +0000916 self.assertEqual(p.tra_sa_out.get_lost(), 0)
917 self.assertEqual(p.tra_sa_in.get_lost(), 0)
Neale Rannseba31ec2019-02-17 18:04:27 +0000918
Klement Sekera10d066e2018-11-13 11:12:57 +0100919 self.assert_packet_counter_equal(self.tra4_encrypt_node_name, count)
Neale Ranns8c609af2021-02-25 10:05:32 +0000920 self.assert_packet_counter_equal(self.tra4_decrypt_node_name[0], count)
Klement Sekera10d066e2018-11-13 11:12:57 +0100921
Neale Ranns4f33c802019-04-10 12:39:10 +0000922
923class IpsecTra4Tests(IpsecTra4):
924 """ UT test methods for Transport v4 """
925 def test_tra_anti_replay(self):
Paul Vinciguerra6e20e032019-12-27 00:19:23 -0500926 """ ipsec v4 transport anti-replay test """
Neale Ranns6afaae12019-07-17 15:07:14 +0000927 self.verify_tra_anti_replay()
Neale Ranns4f33c802019-04-10 12:39:10 +0000928
Neale Rannse11203e2021-09-21 12:34:19 +0000929 def test_tra_lost(self):
930 """ ipsec v4 transport lost packet test """
931 self.verify_tra_lost()
932
Neale Ranns4f33c802019-04-10 12:39:10 +0000933 def test_tra_basic(self, count=1):
934 """ ipsec v4 transport basic test """
935 self.verify_tra_basic4(count=1)
936
Klement Sekera31da2e32018-06-24 22:49:55 +0200937 def test_tra_burst(self):
938 """ ipsec v4 transport burst test """
Neale Ranns4f33c802019-04-10 12:39:10 +0000939 self.verify_tra_basic4(count=257)
Klement Sekera611864f2018-09-26 11:19:00 +0200940
Neale Ranns53f526b2019-02-25 14:32:02 +0000941
Neale Ranns4f33c802019-04-10 12:39:10 +0000942class IpsecTra6(object):
943 """ verify methods for Transport v6 """
Filip Tehlarefcad1a2020-02-04 09:36:04 +0000944 def verify_tra_basic6(self, count=1, payload_size=54):
Klement Sekera10d066e2018-11-13 11:12:57 +0100945 self.vapi.cli("clear errors")
Filip Tehlarefcad1a2020-02-04 09:36:04 +0000946 self.vapi.cli("clear ipsec sa")
Klement Sekera31da2e32018-06-24 22:49:55 +0200947 try:
Klement Sekera611864f2018-09-26 11:19:00 +0200948 p = self.params[socket.AF_INET6]
Neale Ranns28287212019-12-16 00:53:11 +0000949 send_pkts = self.gen_encrypt_pkts6(p, p.scapy_tra_sa, self.tra_if,
Klement Sekera611864f2018-09-26 11:19:00 +0200950 src=self.tra_if.remote_ip6,
951 dst=self.tra_if.local_ip6,
Filip Tehlarefcad1a2020-02-04 09:36:04 +0000952 count=count,
953 payload_size=payload_size)
Klement Sekera611864f2018-09-26 11:19:00 +0200954 recv_pkts = self.send_and_expect(self.tra_if, send_pkts,
955 self.tra_if)
Neale Rannsde847272018-11-28 01:38:34 -0800956 for rx in recv_pkts:
Neale Rannsd207fd72019-04-18 17:18:12 -0700957 self.assertEqual(len(rx) - len(Ether()) - len(IPv6()),
958 rx[IPv6].plen)
Klement Sekera611864f2018-09-26 11:19:00 +0200959 try:
Neale Rannsde847272018-11-28 01:38:34 -0800960 decrypted = p.vpp_tra_sa.decrypt(rx[IPv6])
Klement Sekera611864f2018-09-26 11:19:00 +0200961 self.assert_packet_checksums_valid(decrypted)
962 except:
Neale Rannsde847272018-11-28 01:38:34 -0800963 self.logger.debug(ppp("Unexpected packet:", rx))
Klement Sekera611864f2018-09-26 11:19:00 +0200964 raise
Klement Sekera31da2e32018-06-24 22:49:55 +0200965 finally:
966 self.logger.info(self.vapi.ppcli("show error"))
Paul Vinciguerra9673e3e2019-05-10 20:41:08 -0400967 self.logger.info(self.vapi.ppcli("show ipsec all"))
Klement Sekera31da2e32018-06-24 22:49:55 +0200968
Neale Rannseba31ec2019-02-17 18:04:27 +0000969 pkts = p.tra_sa_in.get_stats()['packets']
970 self.assertEqual(pkts, count,
971 "incorrect SA in counts: expected %d != %d" %
972 (count, pkts))
973 pkts = p.tra_sa_out.get_stats()['packets']
974 self.assertEqual(pkts, count,
975 "incorrect SA out counts: expected %d != %d" %
976 (count, pkts))
Klement Sekera10d066e2018-11-13 11:12:57 +0100977 self.assert_packet_counter_equal(self.tra6_encrypt_node_name, count)
Neale Ranns8c609af2021-02-25 10:05:32 +0000978 self.assert_packet_counter_equal(self.tra6_decrypt_node_name[0], count)
Klement Sekera10d066e2018-11-13 11:12:57 +0100979
Neale Ranns02950402019-12-20 00:54:57 +0000980 def gen_encrypt_pkts_ext_hdrs6(self, sa, sw_intf, src, dst, count=1,
981 payload_size=54):
982 return [Ether(src=sw_intf.remote_mac, dst=sw_intf.local_mac) /
983 sa.encrypt(IPv6(src=src, dst=dst) /
984 ICMPv6EchoRequest(id=0, seq=1,
985 data='X' * payload_size))
986 for i in range(count)]
987
988 def gen_pkts_ext_hdrs6(self, sw_intf, src, dst, count=1, payload_size=54):
989 return [Ether(src=sw_intf.remote_mac, dst=sw_intf.local_mac) /
990 IPv6(src=src, dst=dst) /
991 IPv6ExtHdrHopByHop() /
992 IPv6ExtHdrFragment(id=2, offset=200) /
993 Raw(b'\xff' * 200)
994 for i in range(count)]
995
996 def verify_tra_encrypted6(self, p, sa, rxs):
997 decrypted = []
998 for rx in rxs:
999 self.assert_packet_checksums_valid(rx)
1000 try:
1001 decrypt_pkt = p.vpp_tra_sa.decrypt(rx[IPv6])
1002 decrypted.append(decrypt_pkt)
1003 self.assert_equal(decrypt_pkt.src, self.tra_if.local_ip6)
1004 self.assert_equal(decrypt_pkt.dst, self.tra_if.remote_ip6)
1005 except:
1006 self.logger.debug(ppp("Unexpected packet:", rx))
1007 try:
1008 self.logger.debug(ppp("Decrypted packet:", decrypt_pkt))
1009 except:
1010 pass
1011 raise
1012 return decrypted
1013
1014 def verify_tra_66_ext_hdrs(self, p):
1015 count = 63
1016
1017 #
1018 # check we can decrypt with options
1019 #
1020 tx = self.gen_encrypt_pkts_ext_hdrs6(p.scapy_tra_sa, self.tra_if,
1021 src=self.tra_if.remote_ip6,
1022 dst=self.tra_if.local_ip6,
1023 count=count)
1024 self.send_and_expect(self.tra_if, tx, self.tra_if)
1025
1026 #
1027 # injecting a packet from ourselves to be routed of box is a hack
1028 # but it matches an outbout policy, alors je ne regrette rien
1029 #
1030
1031 # one extension before ESP
1032 tx = (Ether(src=self.pg2.remote_mac, dst=self.pg2.local_mac) /
1033 IPv6(src=self.tra_if.local_ip6,
1034 dst=self.tra_if.remote_ip6) /
1035 IPv6ExtHdrFragment(id=2, offset=200) /
1036 Raw(b'\xff' * 200))
1037
1038 rxs = self.send_and_expect(self.pg2, [tx], self.tra_if)
1039 dcs = self.verify_tra_encrypted6(p, p.vpp_tra_sa, rxs)
1040
1041 for dc in dcs:
1042 # for reasons i'm not going to investigate scapy does not
1043 # created the correct headers after decrypt. but reparsing
1044 # the ipv6 packet fixes it
1045 dc = IPv6(raw(dc[IPv6]))
1046 self.assert_equal(dc[IPv6ExtHdrFragment].id, 2)
1047
1048 # two extensions before ESP
1049 tx = (Ether(src=self.pg2.remote_mac, dst=self.pg2.local_mac) /
1050 IPv6(src=self.tra_if.local_ip6,
1051 dst=self.tra_if.remote_ip6) /
1052 IPv6ExtHdrHopByHop() /
1053 IPv6ExtHdrFragment(id=2, offset=200) /
1054 Raw(b'\xff' * 200))
1055
1056 rxs = self.send_and_expect(self.pg2, [tx], self.tra_if)
1057 dcs = self.verify_tra_encrypted6(p, p.vpp_tra_sa, rxs)
1058
1059 for dc in dcs:
1060 dc = IPv6(raw(dc[IPv6]))
1061 self.assertTrue(dc[IPv6ExtHdrHopByHop])
1062 self.assert_equal(dc[IPv6ExtHdrFragment].id, 2)
1063
1064 # two extensions before ESP, one after
1065 tx = (Ether(src=self.pg2.remote_mac, dst=self.pg2.local_mac) /
1066 IPv6(src=self.tra_if.local_ip6,
1067 dst=self.tra_if.remote_ip6) /
1068 IPv6ExtHdrHopByHop() /
1069 IPv6ExtHdrFragment(id=2, offset=200) /
1070 IPv6ExtHdrDestOpt() /
1071 Raw(b'\xff' * 200))
1072
1073 rxs = self.send_and_expect(self.pg2, [tx], self.tra_if)
1074 dcs = self.verify_tra_encrypted6(p, p.vpp_tra_sa, rxs)
1075
1076 for dc in dcs:
1077 dc = IPv6(raw(dc[IPv6]))
1078 self.assertTrue(dc[IPv6ExtHdrDestOpt])
1079 self.assertTrue(dc[IPv6ExtHdrHopByHop])
1080 self.assert_equal(dc[IPv6ExtHdrFragment].id, 2)
1081
Neale Ranns4f33c802019-04-10 12:39:10 +00001082
1083class IpsecTra6Tests(IpsecTra6):
1084 """ UT test methods for Transport v6 """
1085 def test_tra_basic6(self):
1086 """ ipsec v6 transport basic test """
1087 self.verify_tra_basic6(count=1)
1088
Klement Sekera611864f2018-09-26 11:19:00 +02001089 def test_tra_burst6(self):
1090 """ ipsec v6 transport burst test """
Neale Ranns4f33c802019-04-10 12:39:10 +00001091 self.verify_tra_basic6(count=257)
Klement Sekera31da2e32018-06-24 22:49:55 +02001092
Klement Sekera611864f2018-09-26 11:19:00 +02001093
Neale Ranns02950402019-12-20 00:54:57 +00001094class IpsecTra6ExtTests(IpsecTra6):
1095 def test_tra_ext_hdrs_66(self):
1096 """ ipsec 6o6 tra extension headers test """
1097 self.verify_tra_66_ext_hdrs(self.params[socket.AF_INET6])
1098
1099
Neale Ranns53f526b2019-02-25 14:32:02 +00001100class IpsecTra46Tests(IpsecTra4Tests, IpsecTra6Tests):
Neale Ranns4f33c802019-04-10 12:39:10 +00001101 """ UT test methods for Transport v6 and v4"""
Neale Ranns53f526b2019-02-25 14:32:02 +00001102 pass
1103
1104
Neale Ranns2ac885c2019-03-20 18:24:43 +00001105class IpsecTun4(object):
Neale Ranns4f33c802019-04-10 12:39:10 +00001106 """ verify methods for Tunnel v4 """
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001107 def verify_counters4(self, p, count, n_frags=None, worker=None):
Klement Sekera6aa58b72019-05-16 14:34:55 +02001108 if not n_frags:
1109 n_frags = count
Neale Ranns987aea82019-03-27 13:40:35 +00001110 if (hasattr(p, "spd_policy_in_any")):
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001111 pkts = p.spd_policy_in_any.get_stats(worker)['packets']
Neale Ranns987aea82019-03-27 13:40:35 +00001112 self.assertEqual(pkts, count,
1113 "incorrect SPD any policy: expected %d != %d" %
1114 (count, pkts))
1115
1116 if (hasattr(p, "tun_sa_in")):
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001117 pkts = p.tun_sa_in.get_stats(worker)['packets']
Neale Ranns987aea82019-03-27 13:40:35 +00001118 self.assertEqual(pkts, count,
1119 "incorrect SA in counts: expected %d != %d" %
1120 (count, pkts))
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001121 pkts = p.tun_sa_out.get_stats(worker)['packets']
Neale Rannsa9e27742020-12-23 16:22:28 +00001122 self.assertEqual(pkts, n_frags,
Neale Ranns987aea82019-03-27 13:40:35 +00001123 "incorrect SA out counts: expected %d != %d" %
1124 (count, pkts))
1125
Klement Sekera6aa58b72019-05-16 14:34:55 +02001126 self.assert_packet_counter_equal(self.tun4_encrypt_node_name, n_frags)
Neale Ranns8c609af2021-02-25 10:05:32 +00001127 self.assert_packet_counter_equal(self.tun4_decrypt_node_name[0], count)
Neale Ranns987aea82019-03-27 13:40:35 +00001128
Neale Rannsf05e7322019-03-29 20:23:58 +00001129 def verify_decrypted(self, p, rxs):
1130 for rx in rxs:
1131 self.assert_equal(rx[IP].src, p.remote_tun_if_host)
1132 self.assert_equal(rx[IP].dst, self.pg1.remote_ip4)
1133 self.assert_packet_checksums_valid(rx)
1134
Christian Hoppsfb7e7ed2019-11-03 07:02:15 -05001135 def verify_esp_padding(self, sa, esp_payload, decrypt_pkt):
1136 align = sa.crypt_algo.block_size
1137 if align < 4:
1138 align = 4
1139 exp_len = (len(decrypt_pkt) + 2 + (align - 1)) & ~(align - 1)
1140 exp_len += sa.crypt_algo.iv_size
1141 exp_len += sa.crypt_algo.icv_size or sa.auth_algo.icv_size
1142 self.assertEqual(exp_len, len(esp_payload))
1143
Neale Rannsf05e7322019-03-29 20:23:58 +00001144 def verify_encrypted(self, p, sa, rxs):
1145 decrypt_pkts = []
1146 for rx in rxs:
Neale Ranns41afb332019-07-16 06:19:35 -07001147 if p.nat_header:
1148 self.assertEqual(rx[UDP].dport, 4500)
Neale Ranns1b582b82019-04-18 19:49:13 -07001149 self.assert_packet_checksums_valid(rx)
1150 self.assertEqual(len(rx) - len(Ether()), rx[IP].len)
Neale Rannsf05e7322019-03-29 20:23:58 +00001151 try:
Christian Hoppsfb7e7ed2019-11-03 07:02:15 -05001152 rx_ip = rx[IP]
1153 decrypt_pkt = p.vpp_tun_sa.decrypt(rx_ip)
Neale Rannsf05e7322019-03-29 20:23:58 +00001154 if not decrypt_pkt.haslayer(IP):
1155 decrypt_pkt = IP(decrypt_pkt[Raw].load)
Christian Hoppsfb7e7ed2019-11-03 07:02:15 -05001156 if rx_ip.proto == socket.IPPROTO_ESP:
1157 self.verify_esp_padding(sa, rx_ip[ESP].data, decrypt_pkt)
Neale Rannsf05e7322019-03-29 20:23:58 +00001158 decrypt_pkts.append(decrypt_pkt)
1159 self.assert_equal(decrypt_pkt.src, self.pg1.remote_ip4)
1160 self.assert_equal(decrypt_pkt.dst, p.remote_tun_if_host)
1161 except:
1162 self.logger.debug(ppp("Unexpected packet:", rx))
1163 try:
1164 self.logger.debug(ppp("Decrypted packet:", decrypt_pkt))
1165 except:
1166 pass
1167 raise
1168 pkts = reassemble4(decrypt_pkts)
1169 for pkt in pkts:
1170 self.assert_packet_checksums_valid(pkt)
1171
Neale Rannsd7603d92019-03-28 08:56:10 +00001172 def verify_tun_44(self, p, count=1, payload_size=64, n_rx=None):
Klement Sekera10d066e2018-11-13 11:12:57 +01001173 self.vapi.cli("clear errors")
Neale Ranns02950402019-12-20 00:54:57 +00001174 self.vapi.cli("clear ipsec counters")
Neale Ranns28287212019-12-16 00:53:11 +00001175 self.vapi.cli("clear ipsec sa")
Neale Rannsd7603d92019-03-28 08:56:10 +00001176 if not n_rx:
1177 n_rx = count
Klement Sekera31da2e32018-06-24 22:49:55 +02001178 try:
Neale Ranns28287212019-12-16 00:53:11 +00001179 send_pkts = self.gen_encrypt_pkts(p, p.scapy_tun_sa, self.tun_if,
Klement Sekera611864f2018-09-26 11:19:00 +02001180 src=p.remote_tun_if_host,
Klement Sekera31da2e32018-06-24 22:49:55 +02001181 dst=self.pg1.remote_ip4,
Filip Tehlarefcad1a2020-02-04 09:36:04 +00001182 count=count,
1183 payload_size=payload_size)
Klement Sekera611864f2018-09-26 11:19:00 +02001184 recv_pkts = self.send_and_expect(self.tun_if, send_pkts, self.pg1)
Neale Rannsf05e7322019-03-29 20:23:58 +00001185 self.verify_decrypted(p, recv_pkts)
1186
Klement Sekera31da2e32018-06-24 22:49:55 +02001187 send_pkts = self.gen_pkts(self.pg1, src=self.pg1.remote_ip4,
Neale Rannsd7603d92019-03-28 08:56:10 +00001188 dst=p.remote_tun_if_host, count=count,
1189 payload_size=payload_size)
1190 recv_pkts = self.send_and_expect(self.pg1, send_pkts,
1191 self.tun_if, n_rx)
Neale Rannsf05e7322019-03-29 20:23:58 +00001192 self.verify_encrypted(p, p.vpp_tun_sa, recv_pkts)
1193
Neale Rannsf3a66222020-01-02 05:04:00 +00001194 for rx in recv_pkts:
1195 self.assertEqual(rx[IP].src, p.tun_src)
1196 self.assertEqual(rx[IP].dst, p.tun_dst)
1197
Klement Sekera31da2e32018-06-24 22:49:55 +02001198 finally:
1199 self.logger.info(self.vapi.ppcli("show error"))
Paul Vinciguerra9673e3e2019-05-10 20:41:08 -04001200 self.logger.info(self.vapi.ppcli("show ipsec all"))
Klement Sekera31da2e32018-06-24 22:49:55 +02001201
Neale Ranns02950402019-12-20 00:54:57 +00001202 self.logger.info(self.vapi.ppcli("show ipsec sa 0"))
1203 self.logger.info(self.vapi.ppcli("show ipsec sa 4"))
Klement Sekera6aa58b72019-05-16 14:34:55 +02001204 self.verify_counters4(p, count, n_rx)
Neale Rannseba31ec2019-02-17 18:04:27 +00001205
Neale Ranns28287212019-12-16 00:53:11 +00001206 def verify_tun_dropped_44(self, p, count=1, payload_size=64, n_rx=None):
1207 self.vapi.cli("clear errors")
1208 if not n_rx:
1209 n_rx = count
1210 try:
1211 send_pkts = self.gen_encrypt_pkts(p, p.scapy_tun_sa, self.tun_if,
1212 src=p.remote_tun_if_host,
1213 dst=self.pg1.remote_ip4,
1214 count=count)
1215 self.send_and_assert_no_replies(self.tun_if, send_pkts)
1216
1217 send_pkts = self.gen_pkts(self.pg1, src=self.pg1.remote_ip4,
1218 dst=p.remote_tun_if_host, count=count,
1219 payload_size=payload_size)
1220 self.send_and_assert_no_replies(self.pg1, send_pkts)
1221
1222 finally:
1223 self.logger.info(self.vapi.ppcli("show error"))
1224 self.logger.info(self.vapi.ppcli("show ipsec all"))
1225
Neale Ranns14046982019-07-29 14:49:52 +00001226 def verify_tun_reass_44(self, p):
1227 self.vapi.cli("clear errors")
1228 self.vapi.ip_reassembly_enable_disable(
1229 sw_if_index=self.tun_if.sw_if_index, enable_ip4=True)
1230
1231 try:
Neale Ranns28287212019-12-16 00:53:11 +00001232 send_pkts = self.gen_encrypt_pkts(p, p.scapy_tun_sa, self.tun_if,
Neale Ranns14046982019-07-29 14:49:52 +00001233 src=p.remote_tun_if_host,
1234 dst=self.pg1.remote_ip4,
1235 payload_size=1900,
1236 count=1)
1237 send_pkts = fragment_rfc791(send_pkts[0], 1400)
1238 recv_pkts = self.send_and_expect(self.tun_if, send_pkts,
1239 self.pg1, n_rx=1)
1240 self.verify_decrypted(p, recv_pkts)
1241
1242 send_pkts = self.gen_pkts(self.pg1, src=self.pg1.remote_ip4,
1243 dst=p.remote_tun_if_host, count=1)
1244 recv_pkts = self.send_and_expect(self.pg1, send_pkts,
1245 self.tun_if)
1246 self.verify_encrypted(p, p.vpp_tun_sa, recv_pkts)
1247
1248 finally:
1249 self.logger.info(self.vapi.ppcli("show error"))
1250 self.logger.info(self.vapi.ppcli("show ipsec all"))
1251
1252 self.verify_counters4(p, 1, 1)
1253 self.vapi.ip_reassembly_enable_disable(
1254 sw_if_index=self.tun_if.sw_if_index, enable_ip4=False)
1255
Neale Ranns987aea82019-03-27 13:40:35 +00001256 def verify_tun_64(self, p, count=1):
1257 self.vapi.cli("clear errors")
Neale Rannsdd4ccf22020-06-30 07:47:14 +00001258 self.vapi.cli("clear ipsec sa")
Neale Ranns987aea82019-03-27 13:40:35 +00001259 try:
Neale Ranns28287212019-12-16 00:53:11 +00001260 send_pkts = self.gen_encrypt_pkts6(p, p.scapy_tun_sa, self.tun_if,
Neale Ranns987aea82019-03-27 13:40:35 +00001261 src=p.remote_tun_if_host6,
1262 dst=self.pg1.remote_ip6,
1263 count=count)
1264 recv_pkts = self.send_and_expect(self.tun_if, send_pkts, self.pg1)
1265 for recv_pkt in recv_pkts:
1266 self.assert_equal(recv_pkt[IPv6].src, p.remote_tun_if_host6)
1267 self.assert_equal(recv_pkt[IPv6].dst, self.pg1.remote_ip6)
1268 self.assert_packet_checksums_valid(recv_pkt)
Neale Ranns9ec846c2021-02-09 14:04:02 +00001269 send_pkts = self.gen_pkts6(p, self.pg1, src=self.pg1.remote_ip6,
Neale Ranns987aea82019-03-27 13:40:35 +00001270 dst=p.remote_tun_if_host6, count=count)
1271 recv_pkts = self.send_and_expect(self.pg1, send_pkts, self.tun_if)
1272 for recv_pkt in recv_pkts:
1273 try:
1274 decrypt_pkt = p.vpp_tun_sa.decrypt(recv_pkt[IP])
1275 if not decrypt_pkt.haslayer(IPv6):
1276 decrypt_pkt = IPv6(decrypt_pkt[Raw].load)
1277 self.assert_equal(decrypt_pkt.src, self.pg1.remote_ip6)
1278 self.assert_equal(decrypt_pkt.dst, p.remote_tun_if_host6)
1279 self.assert_packet_checksums_valid(decrypt_pkt)
1280 except:
1281 self.logger.error(ppp("Unexpected packet:", recv_pkt))
1282 try:
1283 self.logger.debug(
1284 ppp("Decrypted packet:", decrypt_pkt))
1285 except:
1286 pass
1287 raise
1288 finally:
1289 self.logger.info(self.vapi.ppcli("show error"))
Paul Vinciguerra9673e3e2019-05-10 20:41:08 -04001290 self.logger.info(self.vapi.ppcli("show ipsec all"))
Neale Rannseba31ec2019-02-17 18:04:27 +00001291
Klement Sekera6aa58b72019-05-16 14:34:55 +02001292 self.verify_counters4(p, count)
Klement Sekera10d066e2018-11-13 11:12:57 +01001293
Neale Ranns41afb332019-07-16 06:19:35 -07001294 def verify_keepalive(self, p):
1295 pkt = (Ether(src=self.tun_if.remote_mac, dst=self.tun_if.local_mac) /
1296 IP(src=p.remote_tun_if_host, dst=self.tun_if.local_ip4) /
1297 UDP(sport=333, dport=4500) /
Ole Troan8b76c232019-10-21 20:55:13 +02001298 Raw(b'\xff'))
Neale Ranns41afb332019-07-16 06:19:35 -07001299 self.send_and_assert_no_replies(self.tun_if, pkt*31)
1300 self.assert_error_counter_equal(
1301 '/err/%s/NAT Keepalive' % self.tun4_input_node, 31)
1302
1303 pkt = (Ether(src=self.tun_if.remote_mac, dst=self.tun_if.local_mac) /
1304 IP(src=p.remote_tun_if_host, dst=self.tun_if.local_ip4) /
1305 UDP(sport=333, dport=4500) /
Ole Troan8b76c232019-10-21 20:55:13 +02001306 Raw(b'\xfe'))
Neale Ranns41afb332019-07-16 06:19:35 -07001307 self.send_and_assert_no_replies(self.tun_if, pkt*31)
1308 self.assert_error_counter_equal(
1309 '/err/%s/Too Short' % self.tun4_input_node, 31)
1310
Neale Ranns2ac885c2019-03-20 18:24:43 +00001311
1312class IpsecTun4Tests(IpsecTun4):
Neale Ranns4f33c802019-04-10 12:39:10 +00001313 """ UT test methods for Tunnel v4 """
Neale Ranns2ac885c2019-03-20 18:24:43 +00001314 def test_tun_basic44(self):
1315 """ ipsec 4o4 tunnel basic test """
1316 self.verify_tun_44(self.params[socket.AF_INET], count=1)
Neale Ranns02950402019-12-20 00:54:57 +00001317 self.tun_if.admin_down()
1318 self.tun_if.resolve_arp()
1319 self.tun_if.admin_up()
1320 self.verify_tun_44(self.params[socket.AF_INET], count=1)
Neale Ranns2ac885c2019-03-20 18:24:43 +00001321
Neale Ranns14046982019-07-29 14:49:52 +00001322 def test_tun_reass_basic44(self):
1323 """ ipsec 4o4 tunnel basic reassembly test """
1324 self.verify_tun_reass_44(self.params[socket.AF_INET])
1325
Klement Sekera611864f2018-09-26 11:19:00 +02001326 def test_tun_burst44(self):
Klement Sekera31da2e32018-06-24 22:49:55 +02001327 """ ipsec 4o4 tunnel burst test """
Neale Ranns02950402019-12-20 00:54:57 +00001328 self.verify_tun_44(self.params[socket.AF_INET], count=127)
1329
1330
Neale Ranns2ac885c2019-03-20 18:24:43 +00001331class IpsecTun6(object):
Neale Ranns4f33c802019-04-10 12:39:10 +00001332 """ verify methods for Tunnel v6 """
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001333 def verify_counters6(self, p_in, p_out, count, worker=None):
Neale Rannsc87b66c2019-02-07 07:26:12 -08001334 if (hasattr(p_in, "tun_sa_in")):
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001335 pkts = p_in.tun_sa_in.get_stats(worker)['packets']
Neale Ranns987aea82019-03-27 13:40:35 +00001336 self.assertEqual(pkts, count,
1337 "incorrect SA in counts: expected %d != %d" %
1338 (count, pkts))
Neale Rannsc87b66c2019-02-07 07:26:12 -08001339 if (hasattr(p_out, "tun_sa_out")):
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001340 pkts = p_out.tun_sa_out.get_stats(worker)['packets']
Neale Ranns987aea82019-03-27 13:40:35 +00001341 self.assertEqual(pkts, count,
1342 "incorrect SA out counts: expected %d != %d" %
1343 (count, pkts))
1344 self.assert_packet_counter_equal(self.tun6_encrypt_node_name, count)
Neale Ranns8c609af2021-02-25 10:05:32 +00001345 self.assert_packet_counter_equal(self.tun6_decrypt_node_name[0], count)
Neale Ranns987aea82019-03-27 13:40:35 +00001346
Neale Rannsc87b66c2019-02-07 07:26:12 -08001347 def verify_decrypted6(self, p, rxs):
1348 for rx in rxs:
1349 self.assert_equal(rx[IPv6].src, p.remote_tun_if_host)
1350 self.assert_equal(rx[IPv6].dst, self.pg1.remote_ip6)
1351 self.assert_packet_checksums_valid(rx)
1352
1353 def verify_encrypted6(self, p, sa, rxs):
1354 for rx in rxs:
1355 self.assert_packet_checksums_valid(rx)
1356 self.assertEqual(len(rx) - len(Ether()) - len(IPv6()),
1357 rx[IPv6].plen)
Neale Ranns9ec846c2021-02-09 14:04:02 +00001358 self.assert_equal(rx[IPv6].hlim, p.outer_hop_limit)
1359 if p.outer_flow_label:
1360 self.assert_equal(rx[IPv6].fl, p.outer_flow_label)
Neale Rannsc87b66c2019-02-07 07:26:12 -08001361 try:
1362 decrypt_pkt = p.vpp_tun_sa.decrypt(rx[IPv6])
1363 if not decrypt_pkt.haslayer(IPv6):
1364 decrypt_pkt = IPv6(decrypt_pkt[Raw].load)
1365 self.assert_packet_checksums_valid(decrypt_pkt)
1366 self.assert_equal(decrypt_pkt.src, self.pg1.remote_ip6)
1367 self.assert_equal(decrypt_pkt.dst, p.remote_tun_if_host)
Neale Ranns9ec846c2021-02-09 14:04:02 +00001368 self.assert_equal(decrypt_pkt.hlim, p.inner_hop_limit - 1)
1369 self.assert_equal(decrypt_pkt.fl, p.inner_flow_label)
Neale Rannsc87b66c2019-02-07 07:26:12 -08001370 except:
1371 self.logger.debug(ppp("Unexpected packet:", rx))
1372 try:
1373 self.logger.debug(ppp("Decrypted packet:", decrypt_pkt))
1374 except:
1375 pass
1376 raise
1377
Neale Ranns49378f22022-01-10 10:38:43 +00001378 def verify_drop_tun_tx_66(self, p_in, count=1, payload_size=64):
1379 self.vapi.cli("clear errors")
1380 self.vapi.cli("clear ipsec sa")
1381
1382 send_pkts = self.gen_pkts6(p_in, self.pg1, src=self.pg1.remote_ip6,
1383 dst=p_in.remote_tun_if_host, count=count,
1384 payload_size=payload_size)
1385 self.send_and_assert_no_replies(self.tun_if, send_pkts)
1386 self.logger.info(self.vapi.cli("sh punt stats"))
1387
1388 def verify_drop_tun_rx_66(self, p_in, count=1, payload_size=64):
Klement Sekera10d066e2018-11-13 11:12:57 +01001389 self.vapi.cli("clear errors")
Neale Rannsc87b66c2019-02-07 07:26:12 -08001390 self.vapi.cli("clear ipsec sa")
1391
Neale Ranns28287212019-12-16 00:53:11 +00001392 send_pkts = self.gen_encrypt_pkts6(p_in, p_in.scapy_tun_sa,
1393 self.tun_if,
Neale Rannsc87b66c2019-02-07 07:26:12 -08001394 src=p_in.remote_tun_if_host,
1395 dst=self.pg1.remote_ip6,
1396 count=count)
1397 self.send_and_assert_no_replies(self.tun_if, send_pkts)
Neale Ranns49378f22022-01-10 10:38:43 +00001398
1399 def verify_drop_tun_66(self, p_in, count=1, payload_size=64):
1400 self.verify_drop_tun_tx_66(p_in, count=count,
1401 payload_size=payload_size)
1402 self.verify_drop_tun_rx_66(p_in, count=count,
1403 payload_size=payload_size)
Neale Rannsc87b66c2019-02-07 07:26:12 -08001404
1405 def verify_tun_66(self, p_in, p_out=None, count=1, payload_size=64):
1406 self.vapi.cli("clear errors")
1407 self.vapi.cli("clear ipsec sa")
1408 if not p_out:
1409 p_out = p_in
Klement Sekera31da2e32018-06-24 22:49:55 +02001410 try:
Neale Ranns28287212019-12-16 00:53:11 +00001411 send_pkts = self.gen_encrypt_pkts6(p_in, p_in.scapy_tun_sa,
1412 self.tun_if,
Neale Rannsc87b66c2019-02-07 07:26:12 -08001413 src=p_in.remote_tun_if_host,
Klement Sekera611864f2018-09-26 11:19:00 +02001414 dst=self.pg1.remote_ip6,
Filip Tehlarefcad1a2020-02-04 09:36:04 +00001415 count=count,
1416 payload_size=payload_size)
Klement Sekera611864f2018-09-26 11:19:00 +02001417 recv_pkts = self.send_and_expect(self.tun_if, send_pkts, self.pg1)
Neale Rannsc87b66c2019-02-07 07:26:12 -08001418 self.verify_decrypted6(p_in, recv_pkts)
1419
Neale Ranns9ec846c2021-02-09 14:04:02 +00001420 send_pkts = self.gen_pkts6(p_in, self.pg1, src=self.pg1.remote_ip6,
Neale Rannsc87b66c2019-02-07 07:26:12 -08001421 dst=p_out.remote_tun_if_host,
1422 count=count,
1423 payload_size=payload_size)
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001424 recv_pkts = self.send_and_expect(self.pg1, send_pkts, self.tun_if)
Neale Rannsc87b66c2019-02-07 07:26:12 -08001425 self.verify_encrypted6(p_out, p_out.vpp_tun_sa, recv_pkts)
1426
Neale Rannsf3a66222020-01-02 05:04:00 +00001427 for rx in recv_pkts:
1428 self.assertEqual(rx[IPv6].src, p_out.tun_src)
1429 self.assertEqual(rx[IPv6].dst, p_out.tun_dst)
1430
Klement Sekera31da2e32018-06-24 22:49:55 +02001431 finally:
1432 self.logger.info(self.vapi.ppcli("show error"))
Paul Vinciguerra9673e3e2019-05-10 20:41:08 -04001433 self.logger.info(self.vapi.ppcli("show ipsec all"))
Neale Rannsc87b66c2019-02-07 07:26:12 -08001434 self.verify_counters6(p_in, p_out, count)
Klement Sekera31da2e32018-06-24 22:49:55 +02001435
Neale Ranns14046982019-07-29 14:49:52 +00001436 def verify_tun_reass_66(self, p):
1437 self.vapi.cli("clear errors")
1438 self.vapi.ip_reassembly_enable_disable(
1439 sw_if_index=self.tun_if.sw_if_index, enable_ip6=True)
1440
1441 try:
Neale Ranns28287212019-12-16 00:53:11 +00001442 send_pkts = self.gen_encrypt_pkts6(p, p.scapy_tun_sa, self.tun_if,
Neale Ranns14046982019-07-29 14:49:52 +00001443 src=p.remote_tun_if_host,
1444 dst=self.pg1.remote_ip6,
1445 count=1,
Neale Ranns02950402019-12-20 00:54:57 +00001446 payload_size=1850)
Neale Ranns14046982019-07-29 14:49:52 +00001447 send_pkts = fragment_rfc8200(send_pkts[0], 1, 1400, self.logger)
1448 recv_pkts = self.send_and_expect(self.tun_if, send_pkts,
1449 self.pg1, n_rx=1)
1450 self.verify_decrypted6(p, recv_pkts)
1451
Neale Ranns9ec846c2021-02-09 14:04:02 +00001452 send_pkts = self.gen_pkts6(p, self.pg1, src=self.pg1.remote_ip6,
Neale Ranns14046982019-07-29 14:49:52 +00001453 dst=p.remote_tun_if_host,
1454 count=1,
1455 payload_size=64)
1456 recv_pkts = self.send_and_expect(self.pg1, send_pkts,
1457 self.tun_if)
1458 self.verify_encrypted6(p, p.vpp_tun_sa, recv_pkts)
1459 finally:
1460 self.logger.info(self.vapi.ppcli("show error"))
1461 self.logger.info(self.vapi.ppcli("show ipsec all"))
1462 self.verify_counters6(p, p, 1)
1463 self.vapi.ip_reassembly_enable_disable(
1464 sw_if_index=self.tun_if.sw_if_index, enable_ip6=False)
1465
Neale Ranns987aea82019-03-27 13:40:35 +00001466 def verify_tun_46(self, p, count=1):
1467 """ ipsec 4o6 tunnel basic test """
1468 self.vapi.cli("clear errors")
Neale Rannsdd4ccf22020-06-30 07:47:14 +00001469 self.vapi.cli("clear ipsec sa")
Neale Ranns987aea82019-03-27 13:40:35 +00001470 try:
Neale Ranns28287212019-12-16 00:53:11 +00001471 send_pkts = self.gen_encrypt_pkts(p, p.scapy_tun_sa, self.tun_if,
Neale Ranns987aea82019-03-27 13:40:35 +00001472 src=p.remote_tun_if_host4,
1473 dst=self.pg1.remote_ip4,
1474 count=count)
1475 recv_pkts = self.send_and_expect(self.tun_if, send_pkts, self.pg1)
1476 for recv_pkt in recv_pkts:
1477 self.assert_equal(recv_pkt[IP].src, p.remote_tun_if_host4)
1478 self.assert_equal(recv_pkt[IP].dst, self.pg1.remote_ip4)
1479 self.assert_packet_checksums_valid(recv_pkt)
1480 send_pkts = self.gen_pkts(self.pg1, src=self.pg1.remote_ip4,
1481 dst=p.remote_tun_if_host4,
1482 count=count)
1483 recv_pkts = self.send_and_expect(self.pg1, send_pkts, self.tun_if)
1484 for recv_pkt in recv_pkts:
1485 try:
1486 decrypt_pkt = p.vpp_tun_sa.decrypt(recv_pkt[IPv6])
1487 if not decrypt_pkt.haslayer(IP):
1488 decrypt_pkt = IP(decrypt_pkt[Raw].load)
1489 self.assert_equal(decrypt_pkt.src, self.pg1.remote_ip4)
1490 self.assert_equal(decrypt_pkt.dst, p.remote_tun_if_host4)
1491 self.assert_packet_checksums_valid(decrypt_pkt)
1492 except:
1493 self.logger.debug(ppp("Unexpected packet:", recv_pkt))
1494 try:
1495 self.logger.debug(ppp("Decrypted packet:",
1496 decrypt_pkt))
1497 except:
1498 pass
1499 raise
1500 finally:
1501 self.logger.info(self.vapi.ppcli("show error"))
Paul Vinciguerra9673e3e2019-05-10 20:41:08 -04001502 self.logger.info(self.vapi.ppcli("show ipsec all"))
Neale Rannsc87b66c2019-02-07 07:26:12 -08001503 self.verify_counters6(p, p, count)
Klement Sekera10d066e2018-11-13 11:12:57 +01001504
Neale Ranns2ac885c2019-03-20 18:24:43 +00001505
1506class IpsecTun6Tests(IpsecTun6):
Neale Ranns4f33c802019-04-10 12:39:10 +00001507 """ UT test methods for Tunnel v6 """
Neale Ranns2ac885c2019-03-20 18:24:43 +00001508
1509 def test_tun_basic66(self):
1510 """ ipsec 6o6 tunnel basic test """
1511 self.verify_tun_66(self.params[socket.AF_INET6], count=1)
1512
Neale Ranns14046982019-07-29 14:49:52 +00001513 def test_tun_reass_basic66(self):
1514 """ ipsec 6o6 tunnel basic reassembly test """
1515 self.verify_tun_reass_66(self.params[socket.AF_INET6])
1516
Klement Sekera611864f2018-09-26 11:19:00 +02001517 def test_tun_burst66(self):
1518 """ ipsec 6o6 tunnel burst test """
Neale Ranns2ac885c2019-03-20 18:24:43 +00001519 self.verify_tun_66(self.params[socket.AF_INET6], count=257)
Klement Sekera611864f2018-09-26 11:19:00 +02001520
1521
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001522class IpsecTun6HandoffTests(IpsecTun6):
1523 """ UT test methods for Tunnel v6 with multiple workers """
Klement Sekera8d815022021-03-15 16:58:10 +01001524 vpp_worker_count = 2
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001525
1526 def test_tun_handoff_66(self):
1527 """ ipsec 6o6 tunnel worker hand-off test """
Brian Russell7a29a2d2021-02-22 18:42:24 +00001528 self.vapi.cli("clear errors")
1529 self.vapi.cli("clear ipsec sa")
1530
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001531 N_PKTS = 15
1532 p = self.params[socket.AF_INET6]
1533
1534 # inject alternately on worker 0 and 1. all counts on the SA
1535 # should be against worker 0
1536 for worker in [0, 1, 0, 1]:
Neale Ranns28287212019-12-16 00:53:11 +00001537 send_pkts = self.gen_encrypt_pkts6(p, p.scapy_tun_sa, self.tun_if,
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001538 src=p.remote_tun_if_host,
1539 dst=self.pg1.remote_ip6,
1540 count=N_PKTS)
1541 recv_pkts = self.send_and_expect(self.tun_if, send_pkts,
1542 self.pg1, worker=worker)
1543 self.verify_decrypted6(p, recv_pkts)
1544
Neale Ranns9ec846c2021-02-09 14:04:02 +00001545 send_pkts = self.gen_pkts6(p, self.pg1, src=self.pg1.remote_ip6,
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001546 dst=p.remote_tun_if_host,
1547 count=N_PKTS)
1548 recv_pkts = self.send_and_expect(self.pg1, send_pkts,
1549 self.tun_if, worker=worker)
1550 self.verify_encrypted6(p, p.vpp_tun_sa, recv_pkts)
1551
1552 # all counts against the first worker that was used
1553 self.verify_counters6(p, p, 4*N_PKTS, worker=0)
1554
1555
1556class IpsecTun4HandoffTests(IpsecTun4):
1557 """ UT test methods for Tunnel v4 with multiple workers """
Klement Sekera8d815022021-03-15 16:58:10 +01001558 vpp_worker_count = 2
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001559
1560 def test_tun_handooff_44(self):
1561 """ ipsec 4o4 tunnel worker hand-off test """
Brian Russell7a29a2d2021-02-22 18:42:24 +00001562 self.vapi.cli("clear errors")
1563 self.vapi.cli("clear ipsec sa")
1564
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001565 N_PKTS = 15
1566 p = self.params[socket.AF_INET]
1567
1568 # inject alternately on worker 0 and 1. all counts on the SA
1569 # should be against worker 0
1570 for worker in [0, 1, 0, 1]:
Neale Ranns28287212019-12-16 00:53:11 +00001571 send_pkts = self.gen_encrypt_pkts(p, p.scapy_tun_sa, self.tun_if,
Neale Ranns4a56f4e2019-12-23 04:10:25 +00001572 src=p.remote_tun_if_host,
1573 dst=self.pg1.remote_ip4,
1574 count=N_PKTS)
1575 recv_pkts = self.send_and_expect(self.tun_if, send_pkts,
1576 self.pg1, worker=worker)
1577 self.verify_decrypted(p, recv_pkts)
1578
1579 send_pkts = self.gen_pkts(self.pg1, src=self.pg1.remote_ip4,
1580 dst=p.remote_tun_if_host,
1581 count=N_PKTS)
1582 recv_pkts = self.send_and_expect(self.pg1, send_pkts,
1583 self.tun_if, worker=worker)
1584 self.verify_encrypted(p, p.vpp_tun_sa, recv_pkts)
1585
1586 # all counts against the first worker that was used
1587 self.verify_counters4(p, 4*N_PKTS, worker=0)
1588
1589
Neale Ranns53f526b2019-02-25 14:32:02 +00001590class IpsecTun46Tests(IpsecTun4Tests, IpsecTun6Tests):
Neale Ranns4f33c802019-04-10 12:39:10 +00001591 """ UT test methods for Tunnel v6 & v4 """
Klement Sekera611864f2018-09-26 11:19:00 +02001592 pass
1593
Klement Sekera31da2e32018-06-24 22:49:55 +02001594
Govindarajan Mohandoss6d7dfcb2021-03-19 19:20:49 +00001595class SpdFlowCacheTemplate(VppTestCase):
1596 @classmethod
1597 def setUpConstants(cls):
1598 super(SpdFlowCacheTemplate, cls).setUpConstants()
1599 # Override this method with required cmdline parameters e.g.
1600 # cls.vpp_cmdline.extend(["ipsec", "{",
1601 # "ipv4-outbound-spd-flow-cache on",
1602 # "}"])
1603 # cls.logger.info("VPP modified cmdline is %s" % " "
1604 # .join(cls.vpp_cmdline))
1605
1606 def setUp(self):
1607 super(SpdFlowCacheTemplate, self).setUp()
1608 # store SPD objects so we can remove configs on tear down
1609 self.spd_objs = []
1610 self.spd_policies = []
1611
1612 def tearDown(self):
1613 # remove SPD policies
1614 for obj in self.spd_policies:
1615 obj.remove_vpp_config()
1616 self.spd_policies = []
1617 # remove SPD items (interface bindings first, then SPD)
1618 for obj in reversed(self.spd_objs):
1619 obj.remove_vpp_config()
1620 self.spd_objs = []
1621 # close down pg intfs
1622 for pg in self.pg_interfaces:
1623 pg.unconfig_ip4()
1624 pg.admin_down()
1625 super(SpdFlowCacheTemplate, self).tearDown()
1626
1627 def create_interfaces(self, num_ifs=2):
1628 # create interfaces pg0 ... pg<num_ifs>
1629 self.create_pg_interfaces(range(num_ifs))
1630 for pg in self.pg_interfaces:
1631 # put the interface up
1632 pg.admin_up()
1633 # configure IPv4 address on the interface
1634 pg.config_ip4()
1635 # resolve ARP, so that we know VPP MAC
1636 pg.resolve_arp()
1637 self.logger.info(self.vapi.ppcli("show int addr"))
1638
1639 def spd_create_and_intf_add(self, spd_id, pg_list):
1640 spd = VppIpsecSpd(self, spd_id)
1641 spd.add_vpp_config()
1642 self.spd_objs.append(spd)
1643 for pg in pg_list:
1644 spdItf = VppIpsecSpdItfBinding(self, spd, pg)
1645 spdItf.add_vpp_config()
1646 self.spd_objs.append(spdItf)
1647
1648 def get_policy(self, policy_type):
1649 e = VppEnum.vl_api_ipsec_spd_action_t
1650 if policy_type == "protect":
1651 return e.IPSEC_API_SPD_ACTION_PROTECT
1652 elif policy_type == "bypass":
1653 return e.IPSEC_API_SPD_ACTION_BYPASS
1654 elif policy_type == "discard":
1655 return e.IPSEC_API_SPD_ACTION_DISCARD
1656 else:
1657 raise Exception("Invalid policy type: %s", policy_type)
1658
1659 def spd_add_rem_policy(self, spd_id, src_if, dst_if,
1660 proto, is_out, priority, policy_type,
1661 remove=False, all_ips=False):
1662 spd = VppIpsecSpd(self, spd_id)
1663
1664 if all_ips:
1665 src_range_low = ip_address("0.0.0.0")
1666 src_range_high = ip_address("255.255.255.255")
1667 dst_range_low = ip_address("0.0.0.0")
1668 dst_range_high = ip_address("255.255.255.255")
1669 else:
1670 src_range_low = src_if.remote_ip4
1671 src_range_high = src_if.remote_ip4
1672 dst_range_low = dst_if.remote_ip4
1673 dst_range_high = dst_if.remote_ip4
1674
1675 spdEntry = VppIpsecSpdEntry(self, spd, 0,
1676 src_range_low,
1677 src_range_high,
1678 dst_range_low,
1679 dst_range_high,
1680 proto,
1681 priority=priority,
1682 policy=self.get_policy(policy_type),
1683 is_outbound=is_out)
1684
1685 if(remove is False):
1686 spdEntry.add_vpp_config()
1687 self.spd_policies.append(spdEntry)
1688 else:
1689 spdEntry.remove_vpp_config()
1690 self.spd_policies.remove(spdEntry)
1691 self.logger.info(self.vapi.ppcli("show ipsec all"))
1692 return spdEntry
1693
1694 def create_stream(self, src_if, dst_if, pkt_count,
1695 src_prt=1234, dst_prt=5678):
1696 packets = []
1697 for i in range(pkt_count):
1698 # create packet info stored in the test case instance
1699 info = self.create_packet_info(src_if, dst_if)
1700 # convert the info into packet payload
1701 payload = self.info_to_payload(info)
1702 # create the packet itself
1703 p = (Ether(dst=src_if.local_mac, src=src_if.remote_mac) /
1704 IP(src=src_if.remote_ip4, dst=dst_if.remote_ip4) /
1705 UDP(sport=src_prt, dport=dst_prt) /
1706 Raw(payload))
1707 # store a copy of the packet in the packet info
1708 info.data = p.copy()
1709 # append the packet to the list
1710 packets.append(p)
1711 # return the created packet list
1712 return packets
1713
1714 def verify_capture(self, src_if, dst_if, capture):
1715 packet_info = None
1716 for packet in capture:
1717 try:
1718 ip = packet[IP]
1719 udp = packet[UDP]
1720 # convert the payload to packet info object
1721 payload_info = self.payload_to_info(packet)
1722 # make sure the indexes match
1723 self.assert_equal(payload_info.src, src_if.sw_if_index,
1724 "source sw_if_index")
1725 self.assert_equal(payload_info.dst, dst_if.sw_if_index,
1726 "destination sw_if_index")
1727 packet_info = self.get_next_packet_info_for_interface2(
1728 src_if.sw_if_index,
1729 dst_if.sw_if_index,
1730 packet_info)
1731 # make sure we didn't run out of saved packets
1732 self.assertIsNotNone(packet_info)
1733 self.assert_equal(payload_info.index, packet_info.index,
1734 "packet info index")
1735 saved_packet = packet_info.data # fetch the saved packet
1736 # assert the values match
1737 self.assert_equal(ip.src, saved_packet[IP].src,
1738 "IP source address")
1739 # ... more assertions here
1740 self.assert_equal(udp.sport, saved_packet[UDP].sport,
1741 "UDP source port")
1742 except Exception as e:
1743 self.logger.error(ppp("Unexpected or invalid packet:",
1744 packet))
1745 raise
1746 remaining_packet = self.get_next_packet_info_for_interface2(
1747 src_if.sw_if_index,
1748 dst_if.sw_if_index,
1749 packet_info)
1750 self.assertIsNone(remaining_packet,
1751 "Interface %s: Packet expected from interface "
1752 "%s didn't arrive" % (dst_if.name, src_if.name))
1753
1754 def verify_policy_match(self, pkt_count, spdEntry):
1755 self.logger.info(
1756 "XXXX %s %s", str(spdEntry), str(spdEntry.get_stats()))
1757 matched_pkts = spdEntry.get_stats().get('packets')
1758 self.logger.info(
1759 "Policy %s matched: %d pkts", str(spdEntry), matched_pkts)
1760 self.assert_equal(pkt_count, matched_pkts)
1761
1762 def get_spd_flow_cache_entries(self):
1763 """ 'show ipsec spd' output:
1764 ip4-outbound-spd-flow-cache-entries: 0
1765 """
1766 show_ipsec_reply = self.vapi.cli("show ipsec spd")
1767 # match the relevant section of 'show ipsec spd' output
1768 regex_match = re.search(
1769 'ip4-outbound-spd-flow-cache-entries: (.*)',
1770 show_ipsec_reply, re.DOTALL)
1771 if regex_match is None:
1772 raise Exception("Unable to find spd flow cache entries \
1773 in \'show ipsec spd\' CLI output - regex failed to match")
1774 else:
1775 try:
1776 num_entries = int(regex_match.group(1))
1777 except ValueError:
1778 raise Exception("Unable to get spd flow cache entries \
1779 from \'show ipsec spd\' string: %s", regex_match.group(0))
1780 self.logger.info("%s", regex_match.group(0))
1781 return num_entries
1782
1783 def verify_num_outbound_flow_cache_entries(self, expected_elements):
1784 self.assertEqual(self.get_spd_flow_cache_entries(), expected_elements)
1785
1786 def crc32_supported(self):
1787 # lscpu is part of util-linux package, available on all Linux Distros
1788 stream = os.popen('lscpu')
1789 cpu_info = stream.read()
1790 # feature/flag "crc32" on Aarch64 and "sse4_2" on x86
1791 # see vppinfra/crc32.h
1792 if "crc32" or "sse4_2" in cpu_info:
1793 self.logger.info("\ncrc32 supported:\n" + cpu_info)
1794 return True
1795 else:
1796 self.logger.info("\ncrc32 NOT supported:\n" + cpu_info)
1797 return False
1798
1799
Klement Sekera31da2e32018-06-24 22:49:55 +02001800if __name__ == '__main__':
1801 unittest.main(testRunner=VppTestRunner)