BenoƮt Ganne | 40aa27e | 2020-11-06 14:14:23 +0100 | [diff] [blame] | 1 | |
| 2 | create packet-generator interface pg0 |
| 3 | set int mac addr pg0 4.5.6 |
| 4 | |
| 5 | create sub-interfaces pg0 1 |
| 6 | create sub-interfaces pg0 2 |
| 7 | create sub-interfaces pg0 3 |
| 8 | |
| 9 | ip table add 1 |
| 10 | ip table add 2 |
| 11 | ip table add 3 |
| 12 | |
| 13 | set int ip table pg0.1 1 |
| 14 | set int ip table pg0.2 2 |
| 15 | set int ip table pg0.3 3 |
| 16 | |
| 17 | set int ip address pg0.1 192.168.0.1/24 |
| 18 | set int ip address pg0.2 192.168.0.1/24 |
| 19 | set int ip address pg0.3 192.168.0.1/24 |
| 20 | |
| 21 | set int state pg0 up |
| 22 | set int state pg0.1 up |
| 23 | set int state pg0.2 up |
| 24 | set int state pg0.3 up |
| 25 | |
| 26 | ipsec sa add 2 spi 2 crypto-key 6541686776336961656264656f6f6579 crypto-alg aes-cbc-128 tunnel-src 192.168.0.1 tunnel-dst 192.168.0.2 tx-table-id 2 |
| 27 | ipsec sa add 3 spi 3 crypto-key 6541686776336961656264656f6f6579 crypto-alg aes-cbc-128 tunnel-src 192.168.0.1 tunnel-dst 192.168.0.2 tx-table-id 3 |
| 28 | |
| 29 | ipsec spd add 1 |
| 30 | set interface ipsec spd pg0.1 1 |
| 31 | ipsec policy add spd 1 priority 100 outbound action bypass protocol 50 |
| 32 | ipsec policy add spd 1 priority 10 outbound action protect sa 2 local-ip-range 10.5.0.0 - 10.5.0.255 remote-ip-range 10.6.0.0 - 10.6.0.16 |
| 33 | ipsec policy add spd 1 priority 10 outbound action protect sa 3 local-ip-range 10.5.0.0 - 10.5.0.255 remote-ip-range 10.6.0.17 - 10.6.0.32 |
| 34 | |
| 35 | ip route table 1 add 10.6.0.0/16 via 192.168.0.2 pg0.1 |
| 36 | set ip neighbor pg0.1 192.168.0.2 00:11:22:33:44:55 |
| 37 | set ip neighbor pg0.2 192.168.0.2 00:11:22:33:44:55 |
| 38 | set ip neighbor pg0.3 192.168.0.2 00:11:22:33:44:55 |
| 39 | |
| 40 | trace add pg-input 100 |
| 41 | |
| 42 | packet-generator new { |
| 43 | name ipsec2 |
| 44 | limit 1 |
| 45 | rate 1e4 |
| 46 | node ethernet-input |
| 47 | interface pg0 |
| 48 | size 100-100 |
| 49 | data { |
| 50 | IP4: 1.2.3 -> 4.5.6 vlan 1 |
| 51 | UDP: 10.5.0.1 -> 10.6.0.1 |
| 52 | UDP: 4321 -> 1234 |
| 53 | length 72 |
| 54 | incrementing 100 |
| 55 | } |
| 56 | } |
| 57 | |
| 58 | packet-generator new { |
| 59 | name ipsec3 |
| 60 | limit 1 |
| 61 | rate 1e4 |
| 62 | node ethernet-input |
| 63 | interface pg0 |
| 64 | size 100-100 |
| 65 | data { |
| 66 | IP4: 1.2.3 -> 4.5.6 vlan 1 |
| 67 | UDP: 10.5.0.1 -> 10.6.0.22 |
| 68 | UDP: 4321 -> 1234 |
| 69 | length 72 |
| 70 | incrementing 100 |
| 71 | } |
| 72 | } |