testing: Reorganizing IKEv1 and IKEv2 examples
For documentation purposes the new folders ikev1-algs, ikev2-algs, ikev1-multi-ca and ikev2-multi-ca have been created. Most of the test cases have now been converted to the vici interface. The remaining legacy stroke scenarios yet to be converted have been put into the ikev2-stroke-bye folder. For documentation purposes some legacy stroke scenarios will be kept in the ikev1-stroke, ikev2-stroke and ipv6-stroke folders.
This commit is contained in:
@@ -1,15 +0,0 @@
|
||||
A connection between two identical <b>10.0.0.0/14</b> networks behind the gateways <b>moon</b>
|
||||
and <b>sun</b> is set up. In order to make network routing work, the subnet behind <b>moon</b>
|
||||
sees the subnet behind <b>sun</b> as <b>10.4.0.0/14</b> whereas the subnet behind <b>sun</b>
|
||||
sees the subnet behind <b>moon</b> as <b>10.8.0.0/14</b>. The necessary network mappings are
|
||||
done on gateway <b>sun</b> using the iptables <b>MARK</b> and <b>NETMAP</b> targets.
|
||||
<p/>
|
||||
Upon the successful establishment of the IPsec tunnel, on gateway <b>moon</b> the directive
|
||||
<b>leftfirewall=yes</b> automatically inserts iptables-based firewall rules that let pass
|
||||
the tunneled traffic whereas on gateway <b>sun</b> the script indicated by
|
||||
<b>leftupdown=/etc/mark_updown</b> inserts iptables rules that set marks defined in the
|
||||
connection definition of <b>ipsec.conf</b> both on the inbound and outbound traffic, create
|
||||
the necessary NETMAP operations and forward the tunneled traffic.
|
||||
<p/>
|
||||
In order to test both tunnel and firewall, client <b>alice</b> behind gateway <b>moon</b>
|
||||
pings client <b>bob</b> located behind gateway <b>sun</b> and vice versa.
|
||||
@@ -1,12 +0,0 @@
|
||||
moon:: ipsec status 2> /dev/null::net-net.*ESTABLISHED.*moon.strongswan.org.*sun.strongswan.org::YES
|
||||
sun:: ipsec status 2> /dev/null::net-net.*ESTABLISHED.*sun.strongswan.org.*moon.strongswan.org::YES
|
||||
moon:: ipsec status 2> /dev/null::net-net.*INSTALLED, TUNNEL::YES
|
||||
sun:: ipsec status 2> /dev/null::net-net.*INSTALLED, TUNNEL::YES
|
||||
alice::ping -c 1 10.6.0.10::64 bytes from 10.6.0.10: icmp_.eq=1::YES
|
||||
bob:: ping -c 1 10.9.0.10::64 bytes from 10.9.0.10: icmp_.eq=1::YES
|
||||
sun::tcpdump::IP moon.strongswan.org > sun.strongswan.org: ESP::YES
|
||||
sun::tcpdump::IP sun.strongswan.org > moon.strongswan.org: ESP::YES
|
||||
bob::tcpdump::IP 10.9.0.10 > bob.strongswan.org: ICMP echo request::YES
|
||||
bob::tcpdump::IP bob.strongswan.org > 10.9.0.10: ICMP echo reply::YES
|
||||
bob::tcpdump::IP bob.strongswan.org > 10.9.0.10: ICMP echo request::YES
|
||||
bob::tcpdump::IP 10.9.0.10 > bob.strongswan.org: ICMP echo reply::YES
|
||||
@@ -1,22 +0,0 @@
|
||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||
|
||||
config setup
|
||||
|
||||
conn %default
|
||||
ikelifetime=60m
|
||||
keylife=20m
|
||||
rekeymargin=3m
|
||||
keyingtries=1
|
||||
keyexchange=ikev2
|
||||
mobike=no
|
||||
|
||||
conn net-net
|
||||
left=PH_IP_MOON
|
||||
leftcert=moonCert.pem
|
||||
[email protected]
|
||||
leftsubnet=10.0.0.0/14
|
||||
leftfirewall=yes
|
||||
right=PH_IP_SUN
|
||||
[email protected]
|
||||
rightsubnet=10.4.0.0/14
|
||||
auto=add
|
||||
@@ -1,6 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac stroke kernel-netlink socket-default updown
|
||||
multiple_authentication = no
|
||||
}
|
||||
@@ -1,24 +0,0 @@
|
||||
# /etc/ipsec.conf - strongSwan IPsec configuration file
|
||||
|
||||
config setup
|
||||
|
||||
conn %default
|
||||
ikelifetime=60m
|
||||
keylife=20m
|
||||
rekeymargin=3m
|
||||
keyingtries=1
|
||||
keyexchange=ikev2
|
||||
mobike=no
|
||||
|
||||
conn net-net
|
||||
left=PH_IP_SUN
|
||||
leftcert=sunCert.pem
|
||||
[email protected]
|
||||
leftsubnet=10.4.0.0/14
|
||||
leftupdown=/etc/mark_updown
|
||||
right=PH_IP_MOON
|
||||
[email protected]
|
||||
rightsubnet=10.0.0.0/14
|
||||
mark_in=8
|
||||
mark_out=4
|
||||
auto=add
|
||||
@@ -1,234 +0,0 @@
|
||||
#!/bin/sh
|
||||
# updown script setting inbound marks on ESP traffic in the mangle chain
|
||||
#
|
||||
# Copyright (C) 2003-2004 Nigel Meteringham
|
||||
# Copyright (C) 2003-2004 Tuomo Soini
|
||||
# Copyright (C) 2002-2004 Michael Richardson
|
||||
# Copyright (C) 2005-2010 Andreas Steffen <[email protected]>
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify it
|
||||
# under the terms of the GNU General Public License as published by the
|
||||
# Free Software Foundation; either version 2 of the License, or (at your
|
||||
# option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful, but
|
||||
# WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
# or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
# for more details.
|
||||
|
||||
# CAUTION: Installing a new version of strongSwan will install a new
|
||||
# copy of this script, wiping out any custom changes you make. If
|
||||
# you need changes, make a copy of this under another name, and customize
|
||||
# that, and use the (left/right)updown parameters in ipsec.conf to make
|
||||
# strongSwan use yours instead of this default one.
|
||||
|
||||
# PLUTO_VERSION
|
||||
# indicates what version of this interface is being
|
||||
# used. This document describes version 1.1. This
|
||||
# is upwardly compatible with version 1.0.
|
||||
#
|
||||
# PLUTO_VERB
|
||||
# specifies the name of the operation to be performed
|
||||
# (prepare-host, prepare-client, up-host, up-client,
|
||||
# down-host, or down-client). If the address family
|
||||
# for security gateway to security gateway communica-
|
||||
# tions is IPv6, then a suffix of -v6 is added to the
|
||||
# verb.
|
||||
#
|
||||
# PLUTO_CONNECTION
|
||||
# is the name of the connection for which we are
|
||||
# routing.
|
||||
#
|
||||
# PLUTO_INTERFACE
|
||||
# is the name of the ipsec interface to be used.
|
||||
#
|
||||
# PLUTO_REQID
|
||||
# is the reqid of the AH|ESP policy
|
||||
#
|
||||
# PLUTO_PROTO
|
||||
# is the negotiated IPsec protocol, ah|esp
|
||||
#
|
||||
# PLUTO_IPCOMP
|
||||
# is not empty if IPComp was negotiated
|
||||
#
|
||||
# PLUTO_UNIQUEID
|
||||
# is the unique identifier of the associated IKE_SA
|
||||
#
|
||||
# PLUTO_ME
|
||||
# is the IP address of our host.
|
||||
#
|
||||
# PLUTO_MY_ID
|
||||
# is the ID of our host.
|
||||
#
|
||||
# PLUTO_MY_CLIENT
|
||||
# is the IP address / count of our client subnet. If
|
||||
# the client is just the host, this will be the
|
||||
# host's own IP address / max (where max is 32 for
|
||||
# IPv4 and 128 for IPv6).
|
||||
#
|
||||
# PLUTO_MY_SOURCEIP
|
||||
# PLUTO_MY_SOURCEIP4_$i
|
||||
# PLUTO_MY_SOURCEIP6_$i
|
||||
# contains IPv4/IPv6 virtual IP received from a responder,
|
||||
# $i enumerates from 1 to the number of IP per address family.
|
||||
# PLUTO_MY_SOURCEIP is a legacy variable and equal to the first
|
||||
# virtual IP, IPv4 or IPv6.
|
||||
#
|
||||
# PLUTO_MY_PROTOCOL
|
||||
# is the IP protocol that will be transported.
|
||||
#
|
||||
# PLUTO_MY_PORT
|
||||
# is the UDP/TCP port to which the IPsec SA is
|
||||
# restricted on our side. For ICMP/ICMPv6 this contains the
|
||||
# message type, and PLUTO_PEER_PORT the message code.
|
||||
#
|
||||
# PLUTO_PEER
|
||||
# is the IP address of our peer.
|
||||
#
|
||||
# PLUTO_PEER_ID
|
||||
# is the ID of our peer.
|
||||
#
|
||||
# PLUTO_PEER_CLIENT
|
||||
# is the IP address / count of the peer's client sub-
|
||||
# net. If the client is just the peer, this will be
|
||||
# the peer's own IP address / max (where max is 32
|
||||
# for IPv4 and 128 for IPv6).
|
||||
#
|
||||
# PLUTO_PEER_SOURCEIP
|
||||
# PLUTO_PEER_SOURCEIP4_$i
|
||||
# PLUTO_PEER_SOURCEIP6_$i
|
||||
# contains IPv4/IPv6 virtual IP sent to an initiator,
|
||||
# $i enumerates from 1 to the number of IP per address family.
|
||||
# PLUTO_PEER_SOURCEIP is a legacy variable and equal to the first
|
||||
# virtual IP, IPv4 or IPv6.
|
||||
#
|
||||
# PLUTO_PEER_PROTOCOL
|
||||
# is the IP protocol that will be transported.
|
||||
#
|
||||
# PLUTO_PEER_PORT
|
||||
# is the UDP/TCP port to which the IPsec SA is
|
||||
# restricted on the peer side. For ICMP/ICMPv6 this contains the
|
||||
# message code, and PLUTO_MY_PORT the message type.
|
||||
#
|
||||
# PLUTO_XAUTH_ID
|
||||
# is an optional user ID employed by the XAUTH protocol
|
||||
#
|
||||
# PLUTO_MARK_IN
|
||||
# is an optional XFRM mark set on the inbound IPsec SA
|
||||
#
|
||||
# PLUTO_MARK_OUT
|
||||
# is an optional XFRM mark set on the outbound IPsec SA
|
||||
#
|
||||
# PLUTO_IF_ID_IN
|
||||
# is an optional XFRM interface ID set on the inbound IPsec SA
|
||||
#
|
||||
# PLUTO_IF_ID_OUT
|
||||
# is an optional XFRM interface ID set on the outbound IPsec SA
|
||||
#
|
||||
# PLUTO_UDP_ENC
|
||||
# contains the remote UDP port in the case of ESP_IN_UDP
|
||||
# encapsulation
|
||||
#
|
||||
# PLUTO_DNS4_$i
|
||||
# PLUTO_DNS6_$i
|
||||
# contains IPv4/IPv6 DNS server attribute received from a
|
||||
# responder, $i enumerates from 1 to the number of servers per
|
||||
# address family.
|
||||
#
|
||||
|
||||
# define a minimum PATH environment in case it is not set
|
||||
PATH="/sbin:/bin:/usr/sbin:/usr/bin:/usr/sbin:/usr/local/sbin"
|
||||
export PATH
|
||||
|
||||
# check parameter(s)
|
||||
case "$1:$*" in
|
||||
':') # no parameters
|
||||
;;
|
||||
iptables:iptables) # due to (left/right)firewall; for default script only
|
||||
;;
|
||||
custom:*) # custom parameters (see above CAUTION comment)
|
||||
;;
|
||||
*) echo "$0: unknown parameters \`$*'" >&2
|
||||
exit 2
|
||||
;;
|
||||
esac
|
||||
|
||||
# define NETMAP
|
||||
SAME_NET=$PLUTO_PEER_CLIENT
|
||||
IN_NET=$PLUTO_MY_CLIENT
|
||||
OUT_NET="10.8.0.0/14"
|
||||
|
||||
# define internal interface
|
||||
INT_INTERFACE="eth1"
|
||||
|
||||
# is there an inbound mark to be set?
|
||||
if [ -n "$PLUTO_MARK_IN" ]
|
||||
then
|
||||
if [ -n "$PLUTO_UDP_ENC" ]
|
||||
then
|
||||
SET_MARK_IN="-p udp --sport $PLUTO_UDP_ENC"
|
||||
else
|
||||
SET_MARK_IN="-p esp"
|
||||
fi
|
||||
SET_MARK_IN="$SET_MARK_IN -s $PLUTO_PEER -j MARK --set-mark $PLUTO_MARK_IN"
|
||||
fi
|
||||
|
||||
# is there an outbound mark to be set?
|
||||
if [ -n "$PLUTO_MARK_OUT" ]
|
||||
then
|
||||
SET_MARK_OUT="-i $INT_INTERFACE -s $SAME_NET -d $OUT_NET -j MARK --set-mark $PLUTO_MARK_OUT"
|
||||
fi
|
||||
|
||||
# resolve octal escape sequences
|
||||
PLUTO_MY_ID=`printf "$PLUTO_MY_ID"`
|
||||
PLUTO_PEER_ID=`printf "$PLUTO_PEER_ID"`
|
||||
|
||||
case "$PLUTO_VERB:$1" in
|
||||
up-client:)
|
||||
# connection to my client subnet coming up
|
||||
# If you are doing a custom version, firewall commands go here.
|
||||
if [ -n "$PLUTO_MARK_IN" ]
|
||||
then
|
||||
iptables -t mangle -A PREROUTING $SET_MARK_IN
|
||||
iptables -t nat -A PREROUTING -i $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_IN \
|
||||
-d $IN_NET -j NETMAP --to $SAME_NET
|
||||
iptables -I FORWARD 1 -i $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_IN -j ACCEPT
|
||||
iptables -t nat -A POSTROUTING -o $INT_INTERFACE -m mark --mark $PLUTO_MARK_IN \
|
||||
-s $SAME_NET -j NETMAP --to $OUT_NET
|
||||
fi
|
||||
if [ -n "$PLUTO_MARK_OUT" ]
|
||||
then
|
||||
iptables -t mangle -A PREROUTING $SET_MARK_OUT
|
||||
iptables -t nat -A PREROUTING -i $INT_INTERFACE -m mark --mark $PLUTO_MARK_OUT \
|
||||
-d $OUT_NET -j NETMAP --to $SAME_NET
|
||||
iptables -I FORWARD 1 -o $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_OUT -j ACCEPT
|
||||
iptables -t nat -A POSTROUTING -o $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_OUT \
|
||||
-s $SAME_NET -j NETMAP --to $IN_NET
|
||||
fi
|
||||
;;
|
||||
down-client:)
|
||||
# connection to my client subnet going down
|
||||
# If you are doing a custom version, firewall commands go here.
|
||||
if [ -n "$PLUTO_MARK_IN" ]
|
||||
then
|
||||
iptables -t mangle -D PREROUTING $SET_MARK_IN
|
||||
iptables -t nat -D PREROUTING -i $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_IN \
|
||||
-d $IN_NET -j NETMAP --to $SAME_NET
|
||||
iptables -D FORWARD -i $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_IN -j ACCEPT
|
||||
iptables -t nat -D POSTROUTING -o eth1 -m mark --mark $PLUTO_MARK_IN \
|
||||
-s $SAME_NET -j NETMAP --to $OUT_NET
|
||||
fi
|
||||
if [ -n "$PLUTO_MARK_OUT" ]
|
||||
then
|
||||
iptables -t mangle -D PREROUTING $SET_MARK_OUT
|
||||
iptables -t nat -D PREROUTING -i $INT_INTERFACE -m mark --mark $PLUTO_MARK_OUT \
|
||||
-d $OUT_NET -j NETMAP --to $SAME_NET
|
||||
iptables -D FORWARD -o $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_OUT -j ACCEPT
|
||||
iptables -t nat -D POSTROUTING -o $PLUTO_INTERFACE -m mark --mark $PLUTO_MARK_OUT \
|
||||
-s $SAME_NET -j NETMAP --to $IN_NET
|
||||
fi
|
||||
;;
|
||||
*) echo "$0: unknown verb \`$PLUTO_VERB' or parameter \`$1'" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
@@ -1,6 +0,0 @@
|
||||
# /etc/strongswan.conf - strongSwan configuration file
|
||||
|
||||
charon {
|
||||
load = random nonce aes sha1 sha2 pem pkcs1 curve25519 gmp x509 curl revocation hmac stroke kernel-netlink socket-default updown
|
||||
multiple_authentication = no
|
||||
}
|
||||
@@ -1,6 +0,0 @@
|
||||
sun::iptables -t mangle -n -v -L PREROUTING
|
||||
sun::iptables -t nat -n -v -L
|
||||
moon::ipsec stop
|
||||
sun::ipsec stop
|
||||
moon::iptables-restore < /etc/iptables.flush
|
||||
sun::iptables-restore < /etc/iptables.flush
|
||||
@@ -1,7 +0,0 @@
|
||||
moon::iptables-restore < /etc/iptables.rules
|
||||
sun::iptables-restore < /etc/iptables.rules
|
||||
moon::ipsec start
|
||||
sun::ipsec start
|
||||
moon::expect-connection net-net
|
||||
sun::expect-connection net-net
|
||||
moon::ipsec up net-net
|
||||
@@ -1,21 +0,0 @@
|
||||
#!/bin/bash
|
||||
#
|
||||
# This configuration file provides information on the
|
||||
# guest instances used for this test
|
||||
|
||||
# All guest instances that are required for this test
|
||||
#
|
||||
VIRTHOSTS="alice moon winnetou sun bob"
|
||||
|
||||
# Corresponding block diagram
|
||||
#
|
||||
DIAGRAM="a-m-w-s-b.png"
|
||||
|
||||
# Guest instances on which tcpdump is to be started
|
||||
#
|
||||
TCPDUMPHOSTS="sun bob"
|
||||
|
||||
# Guest instances on which IPsec is started
|
||||
# Used for IPsec logging purposes
|
||||
#
|
||||
IPSECHOSTS="moon sun"
|
||||
Reference in New Issue
Block a user