^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 1) #!/bin/bash
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 2) # SPDX-License-Identifier: GPL-2.0
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 3) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 4) # L2TPv3 tunnel between 2 hosts
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 5) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 6) # host-1 | router | host-2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 7) # | |
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 8) # lo l2tp | | l2tp lo
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 9) # 172.16.101.1 172.16.1.1 | | 172.16.1.2 172.16.101.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 10) # fc00:101::1 fc00:1::1 | | fc00:1::2 fc00:101::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 11) # | |
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 12) # eth0 | | eth0
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 13) # 10.1.1.1 | | 10.1.2.1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 14) # 2001:db8:1::1 | | 2001:db8:2::1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 15)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 16) VERBOSE=0
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 17) PAUSE_ON_FAIL=no
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 18)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 19) which ping6 > /dev/null 2>&1 && ping6=$(which ping6) || ping6=$(which ping)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 20)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 21) ################################################################################
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 22) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 23) log_test()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 24) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 25) local rc=$1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 26) local expected=$2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 27) local msg="$3"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 28)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 29) if [ ${rc} -eq ${expected} ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 30) printf "TEST: %-60s [ OK ]\n" "${msg}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 31) nsuccess=$((nsuccess+1))
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 32) else
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 33) ret=1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 34) nfail=$((nfail+1))
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 35) printf "TEST: %-60s [FAIL]\n" "${msg}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 36) if [ "${PAUSE_ON_FAIL}" = "yes" ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 37) echo
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 38) echo "hit enter to continue, 'q' to quit"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 39) read a
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 40) [ "$a" = "q" ] && exit 1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 41) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 42) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 43) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 44)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 45) run_cmd()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 46) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 47) local ns
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 48) local cmd
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 49) local out
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 50) local rc
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 51)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 52) ns="$1"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 53) shift
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 54) cmd="$*"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 55)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 56) if [ "$VERBOSE" = "1" ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 57) printf " COMMAND: $cmd\n"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 58) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 59)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 60) out=$(eval ip netns exec ${ns} ${cmd} 2>&1)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 61) rc=$?
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 62) if [ "$VERBOSE" = "1" -a -n "$out" ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 63) echo " $out"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 64) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 65)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 66) [ "$VERBOSE" = "1" ] && echo
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 67)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 68) return $rc
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 69) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 70)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 71) ################################################################################
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 72) # create namespaces and interconnects
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 73)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 74) create_ns()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 75) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 76) local ns=$1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 77) local addr=$2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 78) local addr6=$3
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 79)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 80) [ -z "${addr}" ] && addr="-"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 81) [ -z "${addr6}" ] && addr6="-"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 82)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 83) ip netns add ${ns}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 84)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 85) ip -netns ${ns} link set lo up
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 86) if [ "${addr}" != "-" ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 87) ip -netns ${ns} addr add dev lo ${addr}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 88) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 89) if [ "${addr6}" != "-" ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 90) ip -netns ${ns} -6 addr add dev lo ${addr6}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 91) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 92)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 93) ip -netns ${ns} ro add unreachable default metric 8192
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 94) ip -netns ${ns} -6 ro add unreachable default metric 8192
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 95)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 96) ip netns exec ${ns} sysctl -qw net.ipv4.ip_forward=1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 97) ip netns exec ${ns} sysctl -qw net.ipv6.conf.all.keep_addr_on_down=1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 98) ip netns exec ${ns} sysctl -qw net.ipv6.conf.all.forwarding=1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 99) ip netns exec ${ns} sysctl -qw net.ipv6.conf.default.forwarding=1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 100) ip netns exec ${ns} sysctl -qw net.ipv6.conf.default.accept_dad=0
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 101) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 102)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 103) # create veth pair to connect namespaces and apply addresses.
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 104) connect_ns()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 105) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 106) local ns1=$1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 107) local ns1_dev=$2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 108) local ns1_addr=$3
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 109) local ns1_addr6=$4
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 110) local ns2=$5
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 111) local ns2_dev=$6
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 112) local ns2_addr=$7
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 113) local ns2_addr6=$8
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 114)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 115) ip -netns ${ns1} li add ${ns1_dev} type veth peer name tmp
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 116) ip -netns ${ns1} li set ${ns1_dev} up
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 117) ip -netns ${ns1} li set tmp netns ${ns2} name ${ns2_dev}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 118) ip -netns ${ns2} li set ${ns2_dev} up
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 119)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 120) if [ "${ns1_addr}" != "-" ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 121) ip -netns ${ns1} addr add dev ${ns1_dev} ${ns1_addr}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 122) ip -netns ${ns2} addr add dev ${ns2_dev} ${ns2_addr}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 123) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 124)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 125) if [ "${ns1_addr6}" != "-" ]; then
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 126) ip -netns ${ns1} addr add dev ${ns1_dev} ${ns1_addr6}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 127) ip -netns ${ns2} addr add dev ${ns2_dev} ${ns2_addr6}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 128) fi
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 129) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 130)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 131) ################################################################################
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 132) # test setup
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 133)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 134) cleanup()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 135) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 136) local ns
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 137)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 138) for ns in host-1 host-2 router
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 139) do
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 140) ip netns del ${ns} 2>/dev/null
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 141) done
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 142) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 143)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 144) setup_l2tp_ipv4()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 145) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 146) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 147) # configure l2tpv3 tunnel on host-1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 148) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 149) ip -netns host-1 l2tp add tunnel tunnel_id 1041 peer_tunnel_id 1042 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 150) encap ip local 10.1.1.1 remote 10.1.2.1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 151) ip -netns host-1 l2tp add session name l2tp4 tunnel_id 1041 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 152) session_id 1041 peer_session_id 1042
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 153) ip -netns host-1 link set dev l2tp4 up
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 154) ip -netns host-1 addr add dev l2tp4 172.16.1.1 peer 172.16.1.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 155)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 156) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 157) # configure l2tpv3 tunnel on host-2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 158) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 159) ip -netns host-2 l2tp add tunnel tunnel_id 1042 peer_tunnel_id 1041 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 160) encap ip local 10.1.2.1 remote 10.1.1.1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 161) ip -netns host-2 l2tp add session name l2tp4 tunnel_id 1042 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 162) session_id 1042 peer_session_id 1041
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 163) ip -netns host-2 link set dev l2tp4 up
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 164) ip -netns host-2 addr add dev l2tp4 172.16.1.2 peer 172.16.1.1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 165)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 166) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 167) # add routes to loopback addresses
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 168) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 169) ip -netns host-1 ro add 172.16.101.2/32 via 172.16.1.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 170) ip -netns host-2 ro add 172.16.101.1/32 via 172.16.1.1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 171) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 172)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 173) setup_l2tp_ipv6()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 174) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 175) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 176) # configure l2tpv3 tunnel on host-1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 177) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 178) ip -netns host-1 l2tp add tunnel tunnel_id 1061 peer_tunnel_id 1062 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 179) encap ip local 2001:db8:1::1 remote 2001:db8:2::1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 180) ip -netns host-1 l2tp add session name l2tp6 tunnel_id 1061 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 181) session_id 1061 peer_session_id 1062
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 182) ip -netns host-1 link set dev l2tp6 up
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 183) ip -netns host-1 addr add dev l2tp6 fc00:1::1 peer fc00:1::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 184)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 185) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 186) # configure l2tpv3 tunnel on host-2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 187) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 188) ip -netns host-2 l2tp add tunnel tunnel_id 1062 peer_tunnel_id 1061 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 189) encap ip local 2001:db8:2::1 remote 2001:db8:1::1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 190) ip -netns host-2 l2tp add session name l2tp6 tunnel_id 1062 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 191) session_id 1062 peer_session_id 1061
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 192) ip -netns host-2 link set dev l2tp6 up
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 193) ip -netns host-2 addr add dev l2tp6 fc00:1::2 peer fc00:1::1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 194)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 195) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 196) # add routes to loopback addresses
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 197) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 198) ip -netns host-1 -6 ro add fc00:101::2/128 via fc00:1::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 199) ip -netns host-2 -6 ro add fc00:101::1/128 via fc00:1::1
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 200) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 201)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 202) setup()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 203) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 204) # start clean
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 205) cleanup
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 206)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 207) set -e
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 208) create_ns host-1 172.16.101.1/32 fc00:101::1/128
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 209) create_ns host-2 172.16.101.2/32 fc00:101::2/128
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 210) create_ns router
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 211)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 212) connect_ns host-1 eth0 10.1.1.1/24 2001:db8:1::1/64 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 213) router eth1 10.1.1.2/24 2001:db8:1::2/64
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 214)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 215) connect_ns host-2 eth0 10.1.2.1/24 2001:db8:2::1/64 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 216) router eth2 10.1.2.2/24 2001:db8:2::2/64
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 217)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 218) ip -netns host-1 ro add 10.1.2.0/24 via 10.1.1.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 219) ip -netns host-1 -6 ro add 2001:db8:2::/64 via 2001:db8:1::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 220)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 221) ip -netns host-2 ro add 10.1.1.0/24 via 10.1.2.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 222) ip -netns host-2 -6 ro add 2001:db8:1::/64 via 2001:db8:2::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 223)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 224) setup_l2tp_ipv4
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 225) setup_l2tp_ipv6
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 226) set +e
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 227) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 228)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 229) setup_ipsec()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 230) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 231) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 232) # IPv4
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 233) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 234) run_cmd host-1 ip xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 235) src 10.1.1.1 dst 10.1.2.1 dir out \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 236) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 237)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 238) run_cmd host-1 ip xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 239) src 10.1.2.1 dst 10.1.1.1 dir in \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 240) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 241)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 242) run_cmd host-2 ip xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 243) src 10.1.1.1 dst 10.1.2.1 dir in \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 244) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 245)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 246) run_cmd host-2 ip xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 247) src 10.1.2.1 dst 10.1.1.1 dir out \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 248) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 249)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 250) ip -netns host-1 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 251) src 10.1.1.1 dst 10.1.2.1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 252) spi 0x1000 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 253) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 254)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 255) ip -netns host-1 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 256) src 10.1.2.1 dst 10.1.1.1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 257) spi 0x1001 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 258) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 259)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 260) ip -netns host-2 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 261) src 10.1.1.1 dst 10.1.2.1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 262) spi 0x1000 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 263) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 264)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 265) ip -netns host-2 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 266) src 10.1.2.1 dst 10.1.1.1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 267) spi 0x1001 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 268) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 269)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 270) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 271) # IPV6
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 272) #
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 273) run_cmd host-1 ip -6 xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 274) src 2001:db8:1::1 dst 2001:db8:2::1 dir out \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 275) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 276)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 277) run_cmd host-1 ip -6 xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 278) src 2001:db8:2::1 dst 2001:db8:1::1 dir in \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 279) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 280)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 281) run_cmd host-2 ip -6 xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 282) src 2001:db8:1::1 dst 2001:db8:2::1 dir in \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 283) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 284)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 285) run_cmd host-2 ip -6 xfrm policy add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 286) src 2001:db8:2::1 dst 2001:db8:1::1 dir out \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 287) tmpl proto esp mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 288)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 289) ip -netns host-1 -6 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 290) src 2001:db8:1::1 dst 2001:db8:2::1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 291) spi 0x1000 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 292) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 293)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 294) ip -netns host-1 -6 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 295) src 2001:db8:2::1 dst 2001:db8:1::1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 296) spi 0x1001 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 297) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 298)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 299) ip -netns host-2 -6 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 300) src 2001:db8:1::1 dst 2001:db8:2::1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 301) spi 0x1000 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 302) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 303)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 304) ip -netns host-2 -6 xfrm state add \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 305) src 2001:db8:2::1 dst 2001:db8:1::1 \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 306) spi 0x1001 proto esp aead 'rfc4106(gcm(aes))' \
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 307) 0x0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f0f 128 mode transport
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 308) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 309)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 310) teardown_ipsec()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 311) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 312) run_cmd host-1 ip xfrm state flush
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 313) run_cmd host-1 ip xfrm policy flush
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 314) run_cmd host-2 ip xfrm state flush
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 315) run_cmd host-2 ip xfrm policy flush
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 316) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 317)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 318) ################################################################################
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 319) # generate traffic through tunnel for various cases
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 320)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 321) run_ping()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 322) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 323) local desc="$1"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 324)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 325) run_cmd host-1 ping -c1 -w1 172.16.1.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 326) log_test $? 0 "IPv4 basic L2TP tunnel ${desc}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 327)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 328) run_cmd host-1 ping -c1 -w1 -I 172.16.101.1 172.16.101.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 329) log_test $? 0 "IPv4 route through L2TP tunnel ${desc}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 330)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 331) run_cmd host-1 ${ping6} -c1 -w1 fc00:1::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 332) log_test $? 0 "IPv6 basic L2TP tunnel ${desc}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 333)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 334) run_cmd host-1 ${ping6} -c1 -w1 -I fc00:101::1 fc00:101::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 335) log_test $? 0 "IPv6 route through L2TP tunnel ${desc}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 336) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 337)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 338) run_tests()
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 339) {
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 340) local desc
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 341)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 342) setup
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 343) run_ping
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 344)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 345) setup_ipsec
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 346) run_ping "- with IPsec"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 347) run_cmd host-1 ping -c1 -w1 172.16.1.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 348) log_test $? 0 "IPv4 basic L2TP tunnel ${desc}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 349)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 350) run_cmd host-1 ping -c1 -w1 -I 172.16.101.1 172.16.101.2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 351) log_test $? 0 "IPv4 route through L2TP tunnel ${desc}"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 352)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 353) run_cmd host-1 ${ping6} -c1 -w1 fc00:1::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 354) log_test $? 0 "IPv6 basic L2TP tunnel - with IPsec"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 355)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 356) run_cmd host-1 ${ping6} -c1 -w1 -I fc00:101::1 fc00:101::2
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 357) log_test $? 0 "IPv6 route through L2TP tunnel - with IPsec"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 358)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 359) teardown_ipsec
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 360) run_ping "- after IPsec teardown"
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 361) }
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 362)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 363) ################################################################################
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 364) # main
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 365)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 366) declare -i nfail=0
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 367) declare -i nsuccess=0
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 368)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 369) while getopts :pv o
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 370) do
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 371) case $o in
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 372) p) PAUSE_ON_FAIL=yes;;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 373) v) VERBOSE=$(($VERBOSE + 1));;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 374) *) exit 1;;
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 375) esac
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 376) done
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 377)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 378) run_tests
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 379) cleanup
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 380)
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 381) printf "\nTests passed: %3d\n" ${nsuccess}
^8f3ce5b39 (kx 2023-10-28 12:00:06 +0300 382) printf "Tests failed: %3d\n" ${nfail}