Home | History | Annotate | Line # | Download | only in ipsec
      1  1.10    rin #	$NetBSD: t_ipsec_l2tp.sh,v 1.10 2023/08/22 05:40:50 rin Exp $
      2   1.1  ozaki #
      3   1.1  ozaki # Copyright (c) 2017 Internet Initiative Japan Inc.
      4   1.1  ozaki # All rights reserved.
      5   1.1  ozaki #
      6   1.1  ozaki # Redistribution and use in source and binary forms, with or without
      7   1.1  ozaki # modification, are permitted provided that the following conditions
      8   1.1  ozaki # are met:
      9   1.1  ozaki # 1. Redistributions of source code must retain the above copyright
     10   1.1  ozaki #    notice, this list of conditions and the following disclaimer.
     11   1.1  ozaki # 2. Redistributions in binary form must reproduce the above copyright
     12   1.1  ozaki #    notice, this list of conditions and the following disclaimer in the
     13   1.1  ozaki #    documentation and/or other materials provided with the distribution.
     14   1.1  ozaki #
     15   1.1  ozaki # THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     16   1.1  ozaki # ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     17   1.1  ozaki # TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     18   1.1  ozaki # PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     19   1.1  ozaki # BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     20   1.1  ozaki # CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     21   1.1  ozaki # SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     22   1.1  ozaki # INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     23   1.1  ozaki # CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     24   1.1  ozaki # ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     25   1.1  ozaki # POSSIBILITY OF SUCH DAMAGE.
     26   1.1  ozaki #
     27   1.1  ozaki 
     28   1.1  ozaki SOCK_LOCAL=unix://ipsec_l2tp_local
     29   1.1  ozaki SOCK_TUN_LOCAL=unix://ipsec_l2tp_tunel_local
     30   1.1  ozaki SOCK_TUN_REMOTE=unix://ipsec_l2tp_tunnel_remote
     31   1.1  ozaki SOCK_REMOTE=unix://ipsec_l2tp_remote
     32   1.1  ozaki BUS_LOCAL=./bus_ipsec_local
     33   1.1  ozaki BUS_TUNNEL=./bus_ipsec_tunnel
     34   1.1  ozaki BUS_REMOTE=./bus_ipsec_remote
     35   1.1  ozaki 
     36   1.6  ozaki DEBUG=${DEBUG:-true}
     37   1.1  ozaki 
     38   1.1  ozaki make_l2tp_pktstr()
     39   1.1  ozaki {
     40   1.1  ozaki 	local src=$1
     41   1.1  ozaki 	local dst=$2
     42   1.1  ozaki 	local proto=$3
     43   1.1  ozaki 	local ipproto=$4
     44   1.2  ozaki 	local mode=$5
     45   1.1  ozaki 	local proto_cap= proto_str=
     46   1.1  ozaki 
     47   1.1  ozaki 	if [ $proto = esp ]; then
     48   1.1  ozaki 		proto_cap=ESP
     49   1.1  ozaki 	else
     50   1.1  ozaki 		proto_cap=AH
     51   1.1  ozaki 		if [ $ipproto = ipv4 ]; then
     52  1.10    rin 			proto_str="ip-proto-115 102"
     53   1.1  ozaki 		else
     54   1.1  ozaki 			proto_str="ip-proto-115"
     55   1.1  ozaki 		fi
     56   1.1  ozaki 	fi
     57   1.1  ozaki 
     58   1.1  ozaki 	echo "$src > $dst: $proto_cap.+$proto_str"
     59   1.1  ozaki }
     60   1.1  ozaki 
     61   1.9  ozaki wait_for_all_dad_completions()
     62   1.9  ozaki {
     63   1.9  ozaki 
     64   1.9  ozaki 	for sock in $SOCK_LOCAL $SOCK_TUN_LOCAL $SOCK_TUN_REMOTE $SOCK_REMOTE; do
     65   1.9  ozaki 		export RUMP_SERVER=$sock
     66   1.9  ozaki 		atf_check -s exit:0 rump.ifconfig -w 10
     67   1.9  ozaki 	done
     68   1.9  ozaki }
     69   1.9  ozaki 
     70   1.1  ozaki test_ipsec4_l2tp()
     71   1.1  ozaki {
     72   1.2  ozaki 	local mode=$1
     73   1.2  ozaki 	local proto=$2
     74   1.2  ozaki 	local algo=$3
     75   1.1  ozaki 	local ip_local=10.0.0.1
     76   1.2  ozaki 	local ip_gwlo_tun=20.0.0.1
     77   1.2  ozaki 	local ip_gwre_tun=20.0.0.2
     78   1.1  ozaki 	local ip_remote=10.0.0.2
     79   1.1  ozaki 	local subnet_local=20.0.0.0
     80   1.1  ozaki 	local subnet_remote=20.0.0.0
     81   1.1  ozaki 	local tmpfile=./tmp
     82   1.1  ozaki 	local outfile=./out
     83   1.5  ozaki 	local str=
     84   1.5  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
     85   1.1  ozaki 
     86   1.1  ozaki 	# See https://www.netbsd.org/docs/network/ipsec/#sample_vpn
     87   1.1  ozaki 	rump_server_crypto_start $SOCK_LOCAL
     88   1.1  ozaki 	rump_server_crypto_start $SOCK_TUN_LOCAL netipsec l2tp bridge
     89   1.1  ozaki 	rump_server_crypto_start $SOCK_TUN_REMOTE netipsec l2tp bridge
     90   1.1  ozaki 	rump_server_crypto_start $SOCK_REMOTE
     91   1.1  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS_LOCAL
     92   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL shmif0 $BUS_LOCAL
     93   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL shmif1 $BUS_TUNNEL
     94   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE shmif0 $BUS_REMOTE
     95   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE shmif1 $BUS_TUNNEL
     96   1.1  ozaki 	rump_server_add_iface $SOCK_REMOTE shmif0 $BUS_REMOTE
     97   1.1  ozaki 
     98   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
     99   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_local/24
    100   1.1  ozaki 
    101   1.1  ozaki 	export RUMP_SERVER=$SOCK_TUN_LOCAL
    102   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 up
    103   1.2  ozaki 	atf_check -s exit:0 rump.ifconfig shmif1 $ip_gwlo_tun/24
    104   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL l2tp0
    105   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 \
    106   1.2  ozaki 	    tunnel $ip_gwlo_tun $ip_gwre_tun
    107   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 session 1234 4321
    108   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 up
    109   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL bridge0
    110   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig bridge0 up
    111   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add l2tp0
    112   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add shmif0
    113   1.1  ozaki 
    114   1.1  ozaki 	export RUMP_SERVER=$SOCK_TUN_REMOTE
    115   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 up
    116   1.2  ozaki 	atf_check -s exit:0 rump.ifconfig shmif1 $ip_gwre_tun/24
    117   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE l2tp0
    118   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 \
    119   1.2  ozaki 	    tunnel $ip_gwre_tun $ip_gwlo_tun
    120   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 session 4321 1234
    121   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 up
    122   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE bridge0
    123   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig bridge0 up
    124   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add l2tp0
    125   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add shmif0
    126   1.1  ozaki 
    127   1.1  ozaki 	export RUMP_SERVER=$SOCK_REMOTE
    128   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 $ip_remote/24
    129   1.9  ozaki 
    130   1.9  ozaki 	wait_for_all_dad_completions
    131   1.1  ozaki 
    132   1.1  ozaki 	extract_new_packets $BUS_TUNNEL > $outfile
    133   1.1  ozaki 
    134   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    135   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_remote
    136   1.1  ozaki 
    137   1.1  ozaki 	extract_new_packets $BUS_TUNNEL > $outfile
    138   1.1  ozaki 	atf_check -s exit:0 \
    139   1.2  ozaki 	    -o match:"$ip_gwlo_tun > $ip_gwre_tun: +ip-proto-115" \
    140   1.1  ozaki 	    cat $outfile
    141   1.1  ozaki 	atf_check -s exit:0 \
    142   1.2  ozaki 	    -o match:"$ip_gwre_tun > $ip_gwlo_tun: +ip-proto-115" \
    143   1.1  ozaki 	    cat $outfile
    144   1.1  ozaki 
    145   1.2  ozaki 	if [ $mode = tunnel ]; then
    146   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_LOCAL
    147   1.2  ozaki 		# from https://www.netbsd.org/docs/network/ipsec/
    148   1.2  ozaki 		cat > $tmpfile <<-EOF
    149   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    150   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    151   1.2  ozaki 		spdadd $subnet_local/24 $subnet_remote/24 any -P out ipsec
    152   1.2  ozaki 		    $proto/tunnel/$ip_gwlo_tun-$ip_gwre_tun/require;
    153   1.2  ozaki 		spdadd $subnet_remote/24 $subnet_local/24 any -P in ipsec
    154   1.2  ozaki 		    $proto/tunnel/$ip_gwre_tun-$ip_gwlo_tun/require;
    155   1.2  ozaki 		EOF
    156   1.2  ozaki 		$DEBUG && cat $tmpfile
    157   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    158   1.2  ozaki 
    159   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_REMOTE
    160   1.2  ozaki 		cat > $tmpfile <<-EOF
    161   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    162   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    163   1.2  ozaki 		spdadd $subnet_remote/24 $subnet_local/24 any -P out ipsec
    164   1.2  ozaki 		    $proto/tunnel/$ip_gwre_tun-$ip_gwlo_tun/require;
    165   1.2  ozaki 		spdadd $subnet_local/24 $subnet_remote/24 any -P in ipsec
    166   1.2  ozaki 		    $proto/tunnel/$ip_gwlo_tun-$ip_gwre_tun/require;
    167   1.2  ozaki 		EOF
    168   1.2  ozaki 		$DEBUG && cat $tmpfile
    169   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    170   1.2  ozaki 	else # transport mode
    171   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_LOCAL
    172   1.2  ozaki 		# from https://www.netbsd.org/docs/network/ipsec/
    173   1.2  ozaki 		cat > $tmpfile <<-EOF
    174   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    175   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    176   1.2  ozaki 		spdadd $ip_gwlo_tun/32 $ip_gwre_tun/32 any -P out ipsec
    177   1.2  ozaki 		    $proto/transport//require;
    178   1.2  ozaki 		spdadd $ip_gwre_tun/32 $ip_gwlo_tun/32 any -P in ipsec
    179   1.2  ozaki 		    $proto/transport//require;
    180   1.2  ozaki 		EOF
    181   1.2  ozaki 		$DEBUG && cat $tmpfile
    182   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    183   1.2  ozaki 
    184   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_REMOTE
    185   1.2  ozaki 		cat > $tmpfile <<-EOF
    186   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    187   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    188   1.2  ozaki 		spdadd $ip_gwre_tun/32 $ip_gwlo_tun/32 any -P out ipsec
    189   1.2  ozaki 		    $proto/transport//require;
    190   1.2  ozaki 		spdadd $ip_gwlo_tun/32 $ip_gwre_tun/32 any -P in ipsec
    191   1.2  ozaki 		    $proto/transport//require;
    192   1.2  ozaki 		EOF
    193   1.2  ozaki 		$DEBUG && cat $tmpfile
    194   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    195   1.2  ozaki 	fi
    196   1.2  ozaki 
    197   1.4  ozaki 	check_sa_entries $SOCK_TUN_LOCAL $ip_gwlo_tun $ip_gwre_tun
    198   1.4  ozaki 	check_sa_entries $SOCK_TUN_REMOTE $ip_gwlo_tun $ip_gwre_tun
    199   1.1  ozaki 
    200   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    201   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping -c 1 -n -w 3 $ip_remote
    202   1.1  ozaki 
    203   1.1  ozaki 	extract_new_packets $BUS_TUNNEL > $outfile
    204   1.2  ozaki 	str=$(make_l2tp_pktstr $ip_gwlo_tun $ip_gwre_tun $proto ipv4 $mode)
    205   1.1  ozaki 	atf_check -s exit:0 -o match:"$str" cat $outfile
    206   1.2  ozaki 	str=$(make_l2tp_pktstr $ip_gwre_tun $ip_gwlo_tun $proto ipv4 $mode)
    207   1.1  ozaki 	atf_check -s exit:0 -o match:"$str" cat $outfile
    208   1.3  ozaki 
    209   1.3  ozaki 	test_flush_entries $SOCK_TUN_LOCAL
    210   1.3  ozaki 	test_flush_entries $SOCK_TUN_REMOTE
    211   1.1  ozaki }
    212   1.1  ozaki 
    213   1.1  ozaki test_ipsec6_l2tp()
    214   1.1  ozaki {
    215   1.2  ozaki 	local mode=$1
    216   1.2  ozaki 	local proto=$2
    217   1.2  ozaki 	local algo=$3
    218   1.1  ozaki 	local ip_local=fd00::1
    219   1.2  ozaki 	local ip_gwlo_tun=fc00::1
    220   1.2  ozaki 	local ip_gwre_tun=fc00::2
    221   1.1  ozaki 	local ip_remote=fd00::2
    222   1.1  ozaki 	local subnet_local=fc00::
    223   1.1  ozaki 	local subnet_remote=fc00::
    224   1.1  ozaki 	local tmpfile=./tmp
    225   1.1  ozaki 	local outfile=./out
    226   1.5  ozaki 	local str=
    227   1.5  ozaki 	local algo_args="$(generate_algo_args $proto $algo)"
    228   1.1  ozaki 
    229   1.1  ozaki 	rump_server_crypto_start $SOCK_LOCAL netinet6
    230   1.1  ozaki 	rump_server_crypto_start $SOCK_TUN_LOCAL netipsec netinet6 l2tp bridge
    231   1.1  ozaki 	rump_server_crypto_start $SOCK_TUN_REMOTE netipsec netinet6 l2tp bridge
    232   1.1  ozaki 	rump_server_crypto_start $SOCK_REMOTE netinet6
    233   1.1  ozaki 	rump_server_add_iface $SOCK_LOCAL shmif0 $BUS_LOCAL
    234   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL shmif0 $BUS_LOCAL
    235   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL shmif1 $BUS_TUNNEL
    236   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE shmif0 $BUS_REMOTE
    237   1.1  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE shmif1 $BUS_TUNNEL
    238   1.1  ozaki 	rump_server_add_iface $SOCK_REMOTE shmif0 $BUS_REMOTE
    239   1.1  ozaki 
    240   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    241   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 inet6 $ip_local/64
    242   1.1  ozaki 
    243   1.1  ozaki 	export RUMP_SERVER=$SOCK_TUN_LOCAL
    244   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 up
    245   1.2  ozaki 	atf_check -s exit:0 rump.ifconfig shmif1 inet6 $ip_gwlo_tun/64
    246   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL l2tp0
    247   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 \
    248   1.2  ozaki 	    tunnel $ip_gwlo_tun $ip_gwre_tun
    249   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 session 1234 4321
    250   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 up
    251   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_LOCAL bridge0
    252   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig bridge0 up
    253   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add l2tp0
    254   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add shmif0
    255   1.1  ozaki 
    256   1.1  ozaki 	export RUMP_SERVER=$SOCK_TUN_REMOTE
    257   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 up
    258   1.2  ozaki 	atf_check -s exit:0 rump.ifconfig shmif1 inet6 $ip_gwre_tun/64
    259   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE l2tp0
    260   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 \
    261   1.2  ozaki 	    tunnel $ip_gwre_tun $ip_gwlo_tun
    262   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 session 4321 1234
    263   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig l2tp0 up
    264   1.8  ozaki 	rump_server_add_iface $SOCK_TUN_REMOTE bridge0
    265   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig bridge0 up
    266   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add l2tp0
    267   1.1  ozaki 	atf_check -s exit:0 $HIJACKING brconfig bridge0 add shmif0
    268   1.1  ozaki 
    269   1.1  ozaki 	export RUMP_SERVER=$SOCK_REMOTE
    270   1.1  ozaki 	atf_check -s exit:0 rump.ifconfig shmif0 inet6 $ip_remote
    271   1.9  ozaki 
    272   1.9  ozaki 	wait_for_all_dad_completions
    273   1.1  ozaki 
    274   1.1  ozaki 	extract_new_packets $BUS_TUNNEL > $outfile
    275   1.1  ozaki 
    276   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    277   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping6 -c 1 -n -X 3 $ip_remote
    278   1.1  ozaki 
    279   1.1  ozaki 	extract_new_packets $BUS_TUNNEL > $outfile
    280   1.1  ozaki 	atf_check -s exit:0 \
    281   1.2  ozaki 	    -o match:"$ip_gwlo_tun > $ip_gwre_tun: +ip-proto-115" \
    282   1.1  ozaki 	    cat $outfile
    283   1.1  ozaki 	atf_check -s exit:0 \
    284   1.2  ozaki 	    -o match:"$ip_gwre_tun > $ip_gwlo_tun: +ip-proto-115" \
    285   1.1  ozaki 	    cat $outfile
    286   1.1  ozaki 
    287   1.2  ozaki 	if [ $mode = tunnel ]; then
    288   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_LOCAL
    289   1.2  ozaki 		# from https://www.netbsd.org/docs/network/ipsec/
    290   1.2  ozaki 		cat > $tmpfile <<-EOF
    291   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    292   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    293   1.2  ozaki 		spdadd $subnet_local/64 $subnet_remote/64 any -P out ipsec
    294   1.2  ozaki 		    $proto/tunnel/$ip_gwlo_tun-$ip_gwre_tun/require;
    295   1.2  ozaki 		spdadd $subnet_remote/64 $subnet_local/64 any -P in ipsec
    296   1.2  ozaki 		    $proto/tunnel/$ip_gwre_tun-$ip_gwlo_tun/require;
    297   1.2  ozaki 		EOF
    298   1.2  ozaki 		$DEBUG && cat $tmpfile
    299   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    300   1.2  ozaki 
    301   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_REMOTE
    302   1.2  ozaki 		cat > $tmpfile <<-EOF
    303   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    304   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    305   1.2  ozaki 		spdadd $subnet_remote/64 $subnet_local/64 any -P out ipsec
    306   1.2  ozaki 		    $proto/tunnel/$ip_gwre_tun-$ip_gwlo_tun/require;
    307   1.2  ozaki 		spdadd $subnet_local/64 $subnet_remote/64 any -P in ipsec
    308   1.2  ozaki 		    $proto/tunnel/$ip_gwlo_tun-$ip_gwre_tun/require;
    309   1.2  ozaki 		EOF
    310   1.2  ozaki 		$DEBUG && cat $tmpfile
    311   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    312   1.2  ozaki 	else # transport mode
    313   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_LOCAL
    314   1.2  ozaki 		# from https://www.netbsd.org/docs/network/ipsec/
    315   1.2  ozaki 		cat > $tmpfile <<-EOF
    316   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    317   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    318   1.2  ozaki 		spdadd $ip_gwlo_tun/128 $ip_gwre_tun/128 any -P out ipsec
    319   1.2  ozaki 		    $proto/transport//require;
    320   1.2  ozaki 		spdadd $ip_gwre_tun/128 $ip_gwlo_tun/128 any -P in ipsec
    321   1.2  ozaki 		    $proto/transport//require;
    322   1.2  ozaki 		EOF
    323   1.2  ozaki 		$DEBUG && cat $tmpfile
    324   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    325   1.2  ozaki 
    326   1.2  ozaki 		export RUMP_SERVER=$SOCK_TUN_REMOTE
    327   1.2  ozaki 		cat > $tmpfile <<-EOF
    328   1.5  ozaki 		add $ip_gwlo_tun $ip_gwre_tun $proto 10000 $algo_args;
    329   1.5  ozaki 		add $ip_gwre_tun $ip_gwlo_tun $proto 10001 $algo_args;
    330   1.2  ozaki 		spdadd $ip_gwre_tun/128 $ip_gwlo_tun/128 any -P out ipsec
    331   1.2  ozaki 		    $proto/transport//require;
    332   1.2  ozaki 		spdadd $ip_gwlo_tun/128 $ip_gwre_tun/128 any -P in ipsec
    333   1.2  ozaki 		    $proto/transport//require;
    334   1.2  ozaki 		EOF
    335   1.2  ozaki 		$DEBUG && cat $tmpfile
    336   1.2  ozaki 		atf_check -s exit:0 -o empty $HIJACKING setkey -c < $tmpfile
    337   1.2  ozaki 	fi
    338   1.1  ozaki 
    339   1.4  ozaki 	check_sa_entries $SOCK_TUN_LOCAL $ip_gwlo_tun $ip_gwre_tun
    340   1.4  ozaki 	check_sa_entries $SOCK_TUN_REMOTE $ip_gwlo_tun $ip_gwre_tun
    341   1.4  ozaki 
    342   1.1  ozaki 	export RUMP_SERVER=$SOCK_LOCAL
    343   1.1  ozaki 	atf_check -s exit:0 -o ignore rump.ping6 -c 1 -n -X 3 $ip_remote
    344   1.1  ozaki 
    345   1.1  ozaki 	extract_new_packets $BUS_TUNNEL > $outfile
    346   1.2  ozaki 	str=$(make_l2tp_pktstr $ip_gwlo_tun $ip_gwre_tun $proto ipv6 $mode)
    347   1.1  ozaki 	atf_check -s exit:0 -o match:"$str" cat $outfile
    348   1.2  ozaki 	str=$(make_l2tp_pktstr $ip_gwre_tun $ip_gwlo_tun $proto ipv6 $mode)
    349   1.1  ozaki 	atf_check -s exit:0 -o match:"$str" cat $outfile
    350   1.3  ozaki 
    351   1.3  ozaki 	test_flush_entries $SOCK_TUN_LOCAL
    352   1.3  ozaki 	test_flush_entries $SOCK_TUN_REMOTE
    353   1.1  ozaki }
    354   1.1  ozaki 
    355   1.1  ozaki test_ipsec_l2tp_common()
    356   1.1  ozaki {
    357   1.1  ozaki 	local ipproto=$1
    358   1.2  ozaki 	local mode=$2
    359   1.2  ozaki 	local proto=$3
    360   1.2  ozaki 	local algo=$4
    361   1.1  ozaki 
    362   1.1  ozaki 	if [ $ipproto = ipv4 ]; then
    363   1.2  ozaki 		test_ipsec4_l2tp $mode $proto $algo
    364   1.1  ozaki 	else
    365   1.2  ozaki 		test_ipsec6_l2tp $mode $proto $algo
    366   1.1  ozaki 	fi
    367   1.1  ozaki }
    368   1.1  ozaki 
    369   1.1  ozaki add_test_ipsec_l2tp()
    370   1.1  ozaki {
    371   1.1  ozaki 	local ipproto=$1
    372   1.2  ozaki 	local mode=$2
    373   1.2  ozaki 	local proto=$3
    374   1.2  ozaki 	local algo=$4
    375   1.1  ozaki 	local _algo=$(echo $algo | sed 's/-//g')
    376   1.1  ozaki 	local name= desc=
    377   1.1  ozaki 
    378   1.2  ozaki 	name="ipsec_l2tp_${ipproto}_${mode}_${proto}_${_algo}"
    379   1.2  ozaki 	desc="Tests of l2tp/IPsec ($ipproto) ${mode} mode with $proto ($algo)"
    380   1.1  ozaki 
    381   1.1  ozaki 	atf_test_case ${name} cleanup
    382   1.7  ozaki 	eval "
    383   1.7  ozaki 	    ${name}_head() {
    384   1.7  ozaki 	        atf_set descr \"$desc\"
    385   1.7  ozaki 	        atf_set require.progs rump_server setkey
    386   1.7  ozaki 	    }
    387   1.7  ozaki 	    ${name}_body() {
    388   1.7  ozaki 	        test_ipsec_l2tp_common $ipproto $mode $proto $algo
    389   1.7  ozaki 	        rump_server_destroy_ifaces
    390   1.7  ozaki 	    }
    391   1.7  ozaki 	    ${name}_cleanup() {
    392   1.7  ozaki 	        \$DEBUG && dump
    393   1.7  ozaki 	        cleanup
    394   1.7  ozaki 	    }
    395   1.1  ozaki 	"
    396   1.1  ozaki 	atf_add_test_case ${name}
    397   1.1  ozaki }
    398   1.1  ozaki 
    399   1.1  ozaki atf_init_test_cases()
    400   1.1  ozaki {
    401   1.1  ozaki 	local algo=
    402   1.1  ozaki 
    403   1.1  ozaki 	for algo in $ESP_ENCRYPTION_ALGORITHMS_MINIMUM; do
    404   1.2  ozaki 		add_test_ipsec_l2tp ipv4 tunnel esp $algo
    405   1.2  ozaki 		add_test_ipsec_l2tp ipv6 tunnel esp $algo
    406   1.2  ozaki 		add_test_ipsec_l2tp ipv4 transport esp $algo
    407   1.2  ozaki 		add_test_ipsec_l2tp ipv6 transport esp $algo
    408   1.1  ozaki 	done
    409   1.1  ozaki 
    410   1.1  ozaki 	for algo in $AH_AUTHENTICATION_ALGORITHMS_MINIMUM; do
    411   1.2  ozaki 		add_test_ipsec_l2tp ipv4 tunnel ah $algo
    412   1.2  ozaki 		add_test_ipsec_l2tp ipv6 tunnel ah $algo
    413   1.2  ozaki 		add_test_ipsec_l2tp ipv4 transport ah $algo
    414   1.2  ozaki 		add_test_ipsec_l2tp ipv6 transport ah $algo
    415   1.1  ozaki 	done
    416   1.1  ozaki }
    417