Renato Botelho do Couto | ead1e53 | 2019-10-31 13:31:07 -0500 | [diff] [blame] | 1 | #!/usr/bin/env python3 |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 2 | import unittest |
| 3 | |
| 4 | from framework import VppTestCase, VppTestRunner |
Neale Ranns | 097fa66 | 2018-05-01 05:17:55 -0700 | [diff] [blame] | 5 | from vpp_ip_route import VppIpRoute, VppRoutePath, FibPathType |
Paul Vinciguerra | 95c0ca4 | 2019-03-28 13:07:00 -0700 | [diff] [blame] | 6 | from vpp_l2 import L2_PORT_TYPE |
| 7 | from vpp_sub_interface import L2_VTR_OP, VppDot1QSubint |
Jakub Grajciar | 2f8cd91 | 2020-03-27 06:55:06 +0100 | [diff] [blame] | 8 | from vpp_acl import AclRule, VppAcl, VppAclInterface |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 9 | |
| 10 | from scapy.packet import Raw |
Klement Sekera | b9ef273 | 2018-06-24 22:49:33 +0200 | [diff] [blame] | 11 | from scapy.layers.l2 import Ether, Dot1Q |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 12 | from scapy.layers.inet import IP, UDP |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 13 | from socket import AF_INET, inet_pton |
Jakub Grajciar | 2f8cd91 | 2020-03-27 06:55:06 +0100 | [diff] [blame] | 14 | from ipaddress import IPv4Network |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 15 | |
Paul Vinciguerra | 4271c97 | 2019-05-14 13:25:49 -0400 | [diff] [blame] | 16 | NUM_PKTS = 67 |
| 17 | |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 18 | |
| 19 | class TestDVR(VppTestCase): |
Neale Ranns | 62fe07c | 2017-10-31 12:28:22 -0700 | [diff] [blame] | 20 | """ Distributed Virtual Router """ |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 21 | |
Paul Vinciguerra | 7f9b7f9 | 2019-03-12 19:23:27 -0700 | [diff] [blame] | 22 | @classmethod |
| 23 | def setUpClass(cls): |
| 24 | super(TestDVR, cls).setUpClass() |
| 25 | |
| 26 | @classmethod |
| 27 | def tearDownClass(cls): |
| 28 | super(TestDVR, cls).tearDownClass() |
| 29 | |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 30 | def setUp(self): |
| 31 | super(TestDVR, self).setUp() |
| 32 | |
| 33 | self.create_pg_interfaces(range(4)) |
Klement Sekera | b9ef273 | 2018-06-24 22:49:33 +0200 | [diff] [blame] | 34 | self.create_loopback_interfaces(1) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 35 | |
| 36 | for i in self.pg_interfaces: |
| 37 | i.admin_up() |
| 38 | |
| 39 | self.loop0.config_ip4() |
| 40 | |
| 41 | def tearDown(self): |
| 42 | for i in self.pg_interfaces: |
| 43 | i.admin_down() |
| 44 | self.loop0.unconfig_ip4() |
| 45 | |
| 46 | super(TestDVR, self).tearDown() |
| 47 | |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 48 | def assert_same_mac_addr(self, tx, rx): |
| 49 | t_eth = tx[Ether] |
| 50 | for p in rx: |
| 51 | r_eth = p[Ether] |
| 52 | self.assertEqual(t_eth.src, r_eth.src) |
| 53 | self.assertEqual(t_eth.dst, r_eth.dst) |
| 54 | |
| 55 | def assert_has_vlan_tag(self, tag, rx): |
| 56 | for p in rx: |
| 57 | r_1q = p[Dot1Q] |
| 58 | self.assertEqual(tag, r_1q.vlan) |
| 59 | |
| 60 | def assert_has_no_tag(self, rx): |
| 61 | for p in rx: |
| 62 | self.assertFalse(p.haslayer(Dot1Q)) |
| 63 | |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 64 | def test_dvr(self): |
| 65 | """ Distributed Virtual Router """ |
| 66 | |
| 67 | # |
| 68 | # A packet destined to an IP address that is L2 bridged via |
| 69 | # a non-tag interface |
| 70 | # |
| 71 | ip_non_tag_bridged = "10.10.10.10" |
| 72 | ip_tag_bridged = "10.10.10.11" |
| 73 | any_src_addr = "1.1.1.1" |
| 74 | |
| 75 | pkt_no_tag = (Ether(src=self.pg0.remote_mac, |
| 76 | dst=self.loop0.local_mac) / |
| 77 | IP(src=any_src_addr, |
| 78 | dst=ip_non_tag_bridged) / |
| 79 | UDP(sport=1234, dport=1234) / |
Ole Troan | 770a0de | 2019-11-07 13:52:21 +0100 | [diff] [blame] | 80 | Raw(b'\xa5' * 100)) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 81 | pkt_tag = (Ether(src=self.pg0.remote_mac, |
| 82 | dst=self.loop0.local_mac) / |
| 83 | IP(src=any_src_addr, |
| 84 | dst=ip_tag_bridged) / |
| 85 | UDP(sport=1234, dport=1234) / |
Ole Troan | 770a0de | 2019-11-07 13:52:21 +0100 | [diff] [blame] | 86 | Raw(b'\xa5' * 100)) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 87 | |
| 88 | # |
| 89 | # Two sub-interfaces so we can test VLAN tag push/pop |
| 90 | # |
| 91 | sub_if_on_pg2 = VppDot1QSubint(self, self.pg2, 92) |
| 92 | sub_if_on_pg3 = VppDot1QSubint(self, self.pg3, 93) |
| 93 | sub_if_on_pg2.admin_up() |
| 94 | sub_if_on_pg3.admin_up() |
| 95 | |
| 96 | # |
| 97 | # Put all the interfaces into a new bridge domain |
| 98 | # |
Ole Troan | a5b2eec | 2019-03-11 19:23:25 +0100 | [diff] [blame] | 99 | self.vapi.sw_interface_set_l2_bridge( |
| 100 | rx_sw_if_index=self.pg0.sw_if_index, bd_id=1) |
| 101 | self.vapi.sw_interface_set_l2_bridge( |
| 102 | rx_sw_if_index=self.pg1.sw_if_index, bd_id=1) |
| 103 | self.vapi.sw_interface_set_l2_bridge( |
| 104 | rx_sw_if_index=sub_if_on_pg2.sw_if_index, bd_id=1) |
| 105 | self.vapi.sw_interface_set_l2_bridge( |
| 106 | rx_sw_if_index=sub_if_on_pg3.sw_if_index, bd_id=1) |
| 107 | self.vapi.sw_interface_set_l2_bridge( |
| 108 | rx_sw_if_index=self.loop0.sw_if_index, bd_id=1, |
| 109 | port_type=L2_PORT_TYPE.BVI) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 110 | |
Ole Troan | e1ade68 | 2019-03-04 23:55:43 +0100 | [diff] [blame] | 111 | self.vapi.l2_interface_vlan_tag_rewrite( |
Ole Troan | a5b2eec | 2019-03-11 19:23:25 +0100 | [diff] [blame] | 112 | sw_if_index=sub_if_on_pg2.sw_if_index, vtr_op=L2_VTR_OP.L2_POP_1, |
| 113 | push_dot1q=92) |
Ole Troan | e1ade68 | 2019-03-04 23:55:43 +0100 | [diff] [blame] | 114 | self.vapi.l2_interface_vlan_tag_rewrite( |
Ole Troan | a5b2eec | 2019-03-11 19:23:25 +0100 | [diff] [blame] | 115 | sw_if_index=sub_if_on_pg3.sw_if_index, vtr_op=L2_VTR_OP.L2_POP_1, |
| 116 | push_dot1q=93) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 117 | |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 118 | # |
| 119 | # Add routes to bridge the traffic via a tagged an nontagged interface |
| 120 | # |
| 121 | route_no_tag = VppIpRoute( |
| 122 | self, ip_non_tag_bridged, 32, |
| 123 | [VppRoutePath("0.0.0.0", |
| 124 | self.pg1.sw_if_index, |
Neale Ranns | 097fa66 | 2018-05-01 05:17:55 -0700 | [diff] [blame] | 125 | type=FibPathType.FIB_PATH_TYPE_DVR)]) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 126 | route_no_tag.add_vpp_config() |
| 127 | |
| 128 | # |
| 129 | # Inject the packet that arrives and leaves on a non-tagged interface |
| 130 | # Since it's 'bridged' expect that the MAC headed is unchanged. |
| 131 | # |
Paul Vinciguerra | 4271c97 | 2019-05-14 13:25:49 -0400 | [diff] [blame] | 132 | rx = self.send_and_expect(self.pg0, pkt_no_tag * NUM_PKTS, self.pg1) |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 133 | self.assert_same_mac_addr(pkt_no_tag, rx) |
| 134 | self.assert_has_no_tag(rx) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 135 | |
| 136 | # |
| 137 | # Add routes to bridge the traffic via a tagged interface |
| 138 | # |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 139 | route_with_tag = VppIpRoute( |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 140 | self, ip_tag_bridged, 32, |
| 141 | [VppRoutePath("0.0.0.0", |
| 142 | sub_if_on_pg3.sw_if_index, |
Neale Ranns | 097fa66 | 2018-05-01 05:17:55 -0700 | [diff] [blame] | 143 | type=FibPathType.FIB_PATH_TYPE_DVR)]) |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 144 | route_with_tag.add_vpp_config() |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 145 | |
| 146 | # |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 147 | # Inject the packet that arrives non-tag and leaves on a tagged |
| 148 | # interface |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 149 | # |
Paul Vinciguerra | 4271c97 | 2019-05-14 13:25:49 -0400 | [diff] [blame] | 150 | rx = self.send_and_expect(self.pg0, pkt_tag * NUM_PKTS, self.pg3) |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 151 | self.assert_same_mac_addr(pkt_tag, rx) |
| 152 | self.assert_has_vlan_tag(93, rx) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 153 | |
| 154 | # |
| 155 | # Tag to tag |
| 156 | # |
| 157 | pkt_tag_to_tag = (Ether(src=self.pg2.remote_mac, |
| 158 | dst=self.loop0.local_mac) / |
| 159 | Dot1Q(vlan=92) / |
| 160 | IP(src=any_src_addr, |
| 161 | dst=ip_tag_bridged) / |
| 162 | UDP(sport=1234, dport=1234) / |
Ole Troan | 770a0de | 2019-11-07 13:52:21 +0100 | [diff] [blame] | 163 | Raw(b'\xa5' * 100)) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 164 | |
Paul Vinciguerra | 4271c97 | 2019-05-14 13:25:49 -0400 | [diff] [blame] | 165 | rx = self.send_and_expect(self.pg2, |
| 166 | pkt_tag_to_tag * NUM_PKTS, |
| 167 | self.pg3) |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 168 | self.assert_same_mac_addr(pkt_tag_to_tag, rx) |
| 169 | self.assert_has_vlan_tag(93, rx) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 170 | |
| 171 | # |
| 172 | # Tag to non-Tag |
| 173 | # |
| 174 | pkt_tag_to_non_tag = (Ether(src=self.pg2.remote_mac, |
| 175 | dst=self.loop0.local_mac) / |
| 176 | Dot1Q(vlan=92) / |
| 177 | IP(src=any_src_addr, |
| 178 | dst=ip_non_tag_bridged) / |
| 179 | UDP(sport=1234, dport=1234) / |
Ole Troan | 770a0de | 2019-11-07 13:52:21 +0100 | [diff] [blame] | 180 | Raw(b'\xa5' * 100)) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 181 | |
Paul Vinciguerra | 4271c97 | 2019-05-14 13:25:49 -0400 | [diff] [blame] | 182 | rx = self.send_and_expect(self.pg2, |
| 183 | pkt_tag_to_non_tag * NUM_PKTS, |
| 184 | self.pg1) |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 185 | self.assert_same_mac_addr(pkt_tag_to_tag, rx) |
| 186 | self.assert_has_no_tag(rx) |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 187 | |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 188 | # |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 189 | # Add an output L3 ACL that will block the traffic |
| 190 | # |
Jakub Grajciar | 2f8cd91 | 2020-03-27 06:55:06 +0100 | [diff] [blame] | 191 | rule_1 = AclRule(is_permit=0, proto=17, ports=1234, |
| 192 | src_prefix=IPv4Network((any_src_addr, 32)), |
| 193 | dst_prefix=IPv4Network((ip_non_tag_bridged, 32))) |
| 194 | acl = VppAcl(self, rules=[rule_1]) |
| 195 | acl.add_vpp_config() |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 196 | |
| 197 | # |
| 198 | # Apply the ACL on the output interface |
| 199 | # |
Jakub Grajciar | 2f8cd91 | 2020-03-27 06:55:06 +0100 | [diff] [blame] | 200 | acl_if1 = VppAclInterface(self, sw_if_index=self.pg1.sw_if_index, |
| 201 | n_input=0, acls=[acl]) |
| 202 | acl_if1.add_vpp_config() |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 203 | |
| 204 | # |
| 205 | # Send packet's that should match the ACL and be dropped |
| 206 | # |
Paul Vinciguerra | 4271c97 | 2019-05-14 13:25:49 -0400 | [diff] [blame] | 207 | rx = self.send_and_assert_no_replies(self.pg2, |
| 208 | pkt_tag_to_non_tag * NUM_PKTS) |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 209 | |
| 210 | # |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 211 | # cleanup |
| 212 | # |
Jakub Grajciar | 2f8cd91 | 2020-03-27 06:55:06 +0100 | [diff] [blame] | 213 | acl_if1.remove_vpp_config() |
| 214 | acl.remove_vpp_config() |
Neale Ranns | f068c3e | 2018-01-03 04:18:48 -0800 | [diff] [blame] | 215 | |
Ole Troan | a5b2eec | 2019-03-11 19:23:25 +0100 | [diff] [blame] | 216 | self.vapi.sw_interface_set_l2_bridge( |
| 217 | rx_sw_if_index=self.pg0.sw_if_index, bd_id=1, enable=0) |
| 218 | self.vapi.sw_interface_set_l2_bridge( |
| 219 | rx_sw_if_index=self.pg1.sw_if_index, bd_id=1, enable=0) |
| 220 | self.vapi.sw_interface_set_l2_bridge( |
| 221 | rx_sw_if_index=sub_if_on_pg2.sw_if_index, bd_id=1, enable=0) |
| 222 | self.vapi.sw_interface_set_l2_bridge( |
| 223 | rx_sw_if_index=sub_if_on_pg3.sw_if_index, bd_id=1, enable=0) |
| 224 | self.vapi.sw_interface_set_l2_bridge( |
| 225 | rx_sw_if_index=self.loop0.sw_if_index, bd_id=1, |
| 226 | port_type=L2_PORT_TYPE.BVI, enable=0) |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 227 | |
| 228 | # |
Neale Ranns | 8145842 | 2018-03-12 06:59:36 -0700 | [diff] [blame] | 229 | # Do a FIB dump to make sure the paths are correctly reported as DVR |
| 230 | # |
Neale Ranns | 097fa66 | 2018-05-01 05:17:55 -0700 | [diff] [blame] | 231 | routes = self.vapi.ip_route_dump(0) |
Neale Ranns | 8145842 | 2018-03-12 06:59:36 -0700 | [diff] [blame] | 232 | |
| 233 | for r in routes: |
Neale Ranns | 097fa66 | 2018-05-01 05:17:55 -0700 | [diff] [blame] | 234 | if (ip_tag_bridged == str(r.route.prefix.network_address)): |
| 235 | self.assertEqual(r.route.paths[0].sw_if_index, |
Neale Ranns | 8145842 | 2018-03-12 06:59:36 -0700 | [diff] [blame] | 236 | sub_if_on_pg3.sw_if_index) |
Neale Ranns | 097fa66 | 2018-05-01 05:17:55 -0700 | [diff] [blame] | 237 | self.assertEqual(r.route.paths[0].type, |
| 238 | FibPathType.FIB_PATH_TYPE_DVR) |
| 239 | if (ip_non_tag_bridged == str(r.route.prefix.network_address)): |
| 240 | self.assertEqual(r.route.paths[0].sw_if_index, |
Neale Ranns | 8145842 | 2018-03-12 06:59:36 -0700 | [diff] [blame] | 241 | self.pg1.sw_if_index) |
Neale Ranns | 097fa66 | 2018-05-01 05:17:55 -0700 | [diff] [blame] | 242 | self.assertEqual(r.route.paths[0].type, |
| 243 | FibPathType.FIB_PATH_TYPE_DVR) |
Neale Ranns | 8145842 | 2018-03-12 06:59:36 -0700 | [diff] [blame] | 244 | |
| 245 | # |
Neale Ranns | 55d0378 | 2017-10-21 06:34:22 -0700 | [diff] [blame] | 246 | # the explicit route delete is require so it happens before |
| 247 | # the sbu-interface delete. subinterface delete is required |
| 248 | # because that object type does not use the object registry |
| 249 | # |
| 250 | route_no_tag.remove_vpp_config() |
| 251 | route_with_tag.remove_vpp_config() |
| 252 | sub_if_on_pg3.remove_vpp_config() |
| 253 | sub_if_on_pg2.remove_vpp_config() |
| 254 | |
Neale Ranns | 6f63115 | 2017-10-03 08:20:21 -0700 | [diff] [blame] | 255 | |
| 256 | if __name__ == '__main__': |
| 257 | unittest.main(testRunner=VppTestRunner) |