File: description.txt

package info (click to toggle)
libreswan 5.2-2.3
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 81,644 kB
  • sloc: ansic: 129,988; sh: 32,018; xml: 20,646; python: 10,303; makefile: 3,022; javascript: 1,506; sed: 574; yacc: 511; perl: 264; awk: 52
file content (31 lines) | stat: -rw-r--r-- 1,281 bytes parent folder | download | duplicates (3)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31

NETKEY test for passthrough of a single port

A standard westnet-eastnet IPsec SA is established. A passthrough IPsec SA is
setup for port 7 with. Packets for port 7 SHOULD NOT be encrypted with IPsec.
Packets for port 222 SHOULD be encrypted with IPsec

This test case fails the policy checks within NETKEY. The passthrough connection
on west yields:

src 192.0.1.0/24 dst 192.0.2.0/24 proto tcp dport 7
	dir fwd priority 1768 ptype main
src 192.0.1.0/24 dst 192.0.2.0/24 proto tcp dport 7
	dir in priority 1768 ptype main
src 192.0.1.0/24 dst 192.0.2.0/24 proto tcp dport 7
	dir out priority 1768 ptype main

West should yield:

src 192.0.2.0/24 dst 192.0.1.0/24 proto tcp sport 7
	dir fwd priority 1704 ptype main
src 192.0.2.0/24 dst 192.0.1.0/24 proto tcp sport 7
	dir in priority 1704 ptype main
src 192.0.1.0/24 dst 192.0.2.0/24 proto tcp dport 7
	dir out priority 1704 ptype main

which was confirmed using no passthrough route and running the below on west:

ip xfrm policy add src 192.0.2.0/24 dst 192.0.1.0/24 proto tcp sport 7 dir fwd priority 1704 ptype main
ip xfrm policy add src 192.0.2.0/24 dst 192.0.1.0/24 proto tcp sport 7 dir  in priority 1704 ptype main
ip xfrm policy add src 192.0.1.0/24 dst 192.0.2.0/24 proto tcp dport 7 dir out priority 1704 ptype main