testing: Add scenarios to test ICMP forwarding

This commit is contained in:
Tobias Brunner
2026-02-12 16:21:37 +01:00
parent 22e502b286
commit a7c03a415e
26 changed files with 692 additions and 0 deletions
@@ -0,0 +1,55 @@
*filter
# default policy is DROP
-P INPUT DROP
-P OUTPUT DROP
-P FORWARD DROP
# allow esp
-A INPUT -i eth0 -p 50 -j ACCEPT
-A OUTPUT -o eth0 -p 50 -j ACCEPT
# allow IKE
-A INPUT -i eth0 -p udp --sport 500 --dport 500 -j ACCEPT
-A OUTPUT -o eth0 -p udp --dport 500 --sport 500 -j ACCEPT
# allow MobIKE
-A INPUT -i eth0 -p udp --sport 4500 --dport 4500 -j ACCEPT
-A OUTPUT -o eth0 -p udp --dport 4500 --sport 4500 -j ACCEPT
# allow last UDP fragment
-A INPUT -i eth0 -p udp -m frag --fraglast -j ACCEPT
# allow ICMPv6 neighbor-solicitations
-A INPUT -p icmpv6 --icmpv6-type neighbor-solicitation -j ACCEPT
-A OUTPUT -p icmpv6 --icmpv6-type neighbor-solicitation -j ACCEPT
# allow ICMPv6 neighbor-advertisements
-A INPUT -p icmpv6 --icmpv6-type neighbor-advertisement -j ACCEPT
-A OUTPUT -p icmpv6 --icmpv6-type neighbor-advertisement -j ACCEPT
# allow crl and certificate fetch from winnetou
-A INPUT -i eth0 -p tcp --sport 80 -s fec0::15 -j ACCEPT
-A OUTPUT -o eth0 -p tcp --dport 80 -d fec0::15 -j ACCEPT
# allow decrypted ICMPv6s from any source IP
-A INPUT -p icmpv6 --icmpv6-type destination-unreachable -m policy --dir in -j ACCEPT
-A FORWARD -p icmpv6 --icmpv6-type destination-unreachable -m policy --dir in -j ACCEPT
# allow venus to connect and fetch crls
-A INPUT -i eth1 -p udp --sport 500 --dport 500 -j ACCEPT
-A OUTPUT -o eth1 -p udp --dport 500 --sport 500 -j ACCEPT
-A INPUT -i eth1 -p 50 -j ACCEPT
-A OUTPUT -o eth1 -p 50 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -p tcp --sport 80 -s fec0::15 -j ACCEPT
-A FORWARD -o eth0 -i eth1 -p tcp --dport 80 -d fec0::15 -j ACCEPT
# forward specific errors to venus
-A FORWARD -d fec1::20/128 -p icmpv6 --icmpv6-type time-exceeded -j ACCEPT
-A FORWARD -d fec1::20/128 -p icmpv6 --icmpv6-type packet-too-big -j ACCEPT
# log dropped packets
-A INPUT -j LOG --log-prefix " IN: "
-A OUTPUT -j LOG --log-prefix " OUT: "
COMMIT
@@ -0,0 +1,10 @@
# /etc/strongswan.conf - strongSwan configuration file
swanctl {
load = pem pkcs1 pubkey openssl random
}
charon-systemd {
load = random nonce openssl pem pkcs1 curl revocation vici kernel-netlink socket-default updown
fragment_size = 1400
}
@@ -0,0 +1,55 @@
connections {
net-net {
local_addrs = fec0::1
remote_addrs = fec0::2
local {
auth = pubkey
certs = moonCert.pem
id = moon.strongswan.org
}
remote {
auth = pubkey
id = sun.strongswan.org
}
children {
net-net {
local_ts = fec1::0/16
remote_ts = fec2::0/16
icmp = yes
updown = /usr/local/libexec/ipsec/_updown iptables
hostaccess = yes
esp_proposals = aes128-sha256-x25519
}
}
version = 2
mobike = no
proposals = aes128-sha256-x25519
}
venus : connections.net-net {
local_addrs = fec1::1
remote_addrs = fec1::20
remote {
id = venus.strongswan.org
}
children {
net-net {
# exclude sun but include bob
local_ts = fec2::10/124
remote_ts = dynamic
hostaccess = no
}
}
}
}
authorities {
strongswan {
cacert = strongswanCert.pem
crl_uris = http://ip6-winnetou.strongswan.org/strongswan.crl
}
}
@@ -0,0 +1,49 @@
*filter
# default policy is DROP
-P INPUT DROP
-P OUTPUT DROP
-P FORWARD DROP
# allow esp
-A INPUT -i eth0 -p 50 -j ACCEPT
-A OUTPUT -o eth0 -p 50 -j ACCEPT
# allow IKE
-A INPUT -i eth0 -p udp --sport 500 --dport 500 -j ACCEPT
-A OUTPUT -o eth0 -p udp --dport 500 --sport 500 -j ACCEPT
# allow MobIKE
-A INPUT -i eth0 -p udp --sport 4500 --dport 4500 -j ACCEPT
-A OUTPUT -o eth0 -p udp --dport 4500 --sport 4500 -j ACCEPT
# allow last UDP fragment
-A INPUT -i eth0 -p udp -m frag --fraglast -j ACCEPT
# allow ICMPv6 neighbor-solicitations
-A INPUT -p icmpv6 --icmpv6-type neighbor-solicitation -j ACCEPT
-A OUTPUT -p icmpv6 --icmpv6-type neighbor-solicitation -j ACCEPT
# allow ICMPv6 neighbor-advertisements
-A INPUT -p icmpv6 --icmpv6-type neighbor-advertisement -j ACCEPT
-A OUTPUT -p icmpv6 --icmpv6-type neighbor-advertisement -j ACCEPT
# allow crl and certificate fetch from winnetou
-A INPUT -i eth0 -p tcp --sport 80 -s fec0::15 -j ACCEPT
-A OUTPUT -o eth0 -p tcp --dport 80 -d fec0::15 -j ACCEPT
# explicitly allow ICMPv6 responses we don't actually want to see as they should get encrypted
-A OUTPUT -p icmpv6 --icmpv6-type destination-unreachable -j ACCEPT
-A FORWARD -p icmpv6 --icmpv6-type destination-unreachable -j ACCEPT
# allow only specific ICMPs from/to venus for this scenario
-A FORWARD -s fec1::20/128 -p icmpv6 --icmpv6-type echo-request -j ACCEPT
-A FORWARD -d fec1::20/128 -p icmpv6 --icmpv6-type echo-reply -j ACCEPT
-A OUTPUT -d fec1::20/128 -p icmpv6 --icmpv6-type time-exceeded -j ACCEPT
-A OUTPUT -d fec1::20/128 -p icmpv6 --icmpv6-type packet-too-big -j ACCEPT
# log dropped packets
-A INPUT -j LOG --log-prefix " IN: "
-A OUTPUT -j LOG --log-prefix " OUT: "
COMMIT
@@ -0,0 +1,10 @@
# /etc/strongswan.conf - strongSwan configuration file
swanctl {
load = pem pkcs1 pubkey openssl random
}
charon-systemd {
load = random nonce openssl pem pkcs1 curl revocation vici kernel-netlink socket-default updown
fragment_size = 1400
}
@@ -0,0 +1,38 @@
connections {
net-net {
local_addrs = fec0::2
remote_addrs = fec0::1
local {
auth = pubkey
certs = sunCert.pem
id = sun.strongswan.org
}
remote {
auth = pubkey
id = moon.strongswan.org
}
children {
net-net {
# exclude sun's and bob's IPs
local_ts = fec2::20/124
remote_ts = fec1::0/16
icmp = yes
updown = /usr/local/libexec/ipsec/_updown iptables
esp_proposals = aes128-sha256-x25519
}
}
version = 2
mobike = no
proposals = aes128-sha256-x25519
}
}
authorities {
strongswan {
cacert = strongswanCert.pem
crl_uris = http://ip6-winnetou.strongswan.org/strongswan.crl
}
}
@@ -0,0 +1,10 @@
# /etc/strongswan.conf - strongSwan configuration file
swanctl {
load = pem pkcs1 pubkey openssl random
}
charon-systemd {
load = random nonce openssl pem pkcs1 curl revocation vici kernel-netlink socket-default updown
fragment_size = 1400
}
@@ -0,0 +1,37 @@
connections {
rw {
local_addrs = fec1::20
remote_addrs = fec1::1
local {
auth = pubkey
certs = venusCert.pem
id = venus.strongswan.org
}
remote {
auth = pubkey
id = moon.strongswan.org
}
children {
rw {
remote_ts = fec2::0/16
icmp = yes
updown = /usr/local/libexec/ipsec/_updown iptables
hostaccess = yes
esp_proposals = aes128-sha256-x25519
}
}
version = 2
mobike = no
proposals = aes128-sha256-x25519
}
}
authorities {
strongswan {
cacert = strongswanCert.pem
crl_uris = http://ip6-winnetou.strongswan.org/strongswan.crl
}
}