From 6721e7f09aa95bff6622068332a3f56afad9c87b Mon Sep 17 00:00:00 2001 From: Tibor Frank Date: Tue, 20 Jun 2017 13:57:08 +0200 Subject: CSIT-687: Directory structure reorganization Change-Id: I772c9e214be2461adf58124998d272e7d795220f Signed-off-by: Tibor Frank Signed-off-by: Maciek Konstantynowicz --- .../eth2p-ethip6-ip6base-copblklistbase-func.robot | 101 ++++ .../eth2p-ethip6-ip6base-copwhlistbase-func.robot | 101 ++++ tests/vpp/func/ip6/eth2p-ethip6-ip6base-func.robot | 120 +++++ .../ip6/eth2p-ethip6-ip6base-iaclbase-func.robot | 577 +++++++++++++++++++++ .../eth2p-ethip6-ip6base-ip6dhcpproxy-func.robot | 66 +++ .../ip6/eth2p-ethip6-ip6base-ip6ecmp-func.robot | 74 +++ .../func/ip6/eth2p-ethip6-ip6base-ip6ra-func.robot | 107 ++++ ...eth2p-ethip6-ip6base-ipolicemarkbase-func.robot | 161 ++++++ .../func/ip6/eth2p-ethip6-ip6basevrf-func.robot | 409 +++++++++++++++ 9 files changed, 1716 insertions(+) create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-copblklistbase-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-copwhlistbase-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-iaclbase-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6dhcpproxy-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ecmp-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ra-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6base-ipolicemarkbase-func.robot create mode 100644 tests/vpp/func/ip6/eth2p-ethip6-ip6basevrf-func.robot (limited to 'tests/vpp/func/ip6') diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-copblklistbase-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-copblklistbase-func.robot new file mode 100644 index 0000000000..f4314500e5 --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-copblklistbase-func.robot @@ -0,0 +1,101 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Library | resources.libraries.python.Trace +| Library | resources.libraries.python.Cop +| Resource | resources/libraries/robot/shared/default.robot +| Resource | resources/libraries/robot/shared/interfaces.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Resource | resources/libraries/robot/shared/traffic.robot +| Resource | resources/libraries/robot/shared/testing_path.robot +| Resource | resources/libraries/robot/l2/l2_xconnect.robot +| Variables | resources/libraries/python/IPv6NodesAddr.py | ${nodes} +| Force Tags | HW_ENV | VM_ENV | 3_NODE_SINGLE_LINK_TOPO +| Test Setup | Set up functional test +| Test Teardown | Tear down functional test +| Documentation | *COP Security IPv6 Blacklist Tests* +| ... +| ... | *[Top] Network Topologies:* TG-DUT1-DUT2-TG 3-node circular topology +| ... | with single links between nodes. +| ... | *[Enc] Packet Encapsulations:* Eth-IPv6-ICMPv6 on all links. +| ... | *[Cfg] DUT configuration:* DUT1 is configured with IPv6 routing and +| ... | static routes. COP security black-lists are applied on DUT1 ingress +| ... | interface from TG. DUT2 is configured with L2XC. +| ... | *[Ver] TG verification:* Test ICMPv6 Echo Request packets are sent in +| ... | one direction by TG on link to DUT1; on receive TG verifies packets for +| ... | correctness and drops as applicable. +| ... | *[Ref] Applicable standard specifications:* + +*** Variables *** +| ${tg_node}= | ${nodes['TG']} +| ${dut1_node}= | ${nodes['DUT1']} +| ${dut2_node}= | ${nodes['DUT2']} + +| ${dut1_if1_ip}= | 3ffe:62::1 +| ${dut1_if2_ip}= | 3ffe:63::1 +| ${dut1_if1_ip_GW}= | 3ffe:62::2 +| ${dut1_if2_ip_GW}= | 3ffe:63::2 + +| ${dut2_if1_ip}= | 3ffe:72::1 +| ${dut2_if2_ip}= | 3ffe:73::1 + +| ${test_dst_ip}= | 3ffe:64::1 +| ${test_src_ip}= | 3ffe:61::1 + +| ${cop_dut_ip}= | 3ffe:61:: + +| ${ip_prefix}= | 64 + +| ${nodes_ipv6_addresses}= | ${nodes_ipv6_addr} + +| ${fib_table_number}= | 1 + +*** Test Cases *** +| TC01: DUT drops IPv6 pkts with COP blacklist set with IPv6 src-addr +| | [Documentation] +| | ... | [Top] TG-DUT1-DUT2-TG. [Enc] Eth-IPv6-ICMPv6. [Cfg] On DUT1 \ +| | ... | configure interface IPv6 addresses and routes in the main +| | ... | routing domain, add COP blacklist on interface to TG with IPv6 +| | ... | src-addr matching packets generated by TG; on DUT2 configure L2 +| | ... | xconnect. [Ver] Make TG send ICMPv6 Echo Req on its interface to +| | ... | DUT1; verify no ICMPv6 Echo Req pkts are received. [Ref] +| | Given Configure path in 3-node circular topology +| | ... | ${tg_node} | ${dut1_node} | ${dut2_node} | ${tg_node} +| | And Set interfaces in 3-node circular topology up +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut1_node} | ${dut1_to_tg} | ${dut1_if1_ip} | ${ip_prefix} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_if2_ip} | ${ip_prefix} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_if1_ip} | ${ip_prefix} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut2_node} | ${dut2_to_tg} | ${dut2_if2_ip} | ${ip_prefix} +| | And Add IP Neighbor +| | ... | ${dut1_node} | ${dut1_to_tg} | ${dut1_if1_ip_GW} | ${tg_to_dut1_mac} +| | And Add IP Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_if2_ip_GW} | ${tg_to_dut2_mac} +| | And Vpp Route Add | ${dut1_node} +| | ... | ${test_dst_ip} | ${ip_prefix} | ${dut1_if2_ip_GW} | ${dut1_to_dut2} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | And Add fib table | ${dut1_node} +| | ... | ${cop_dut_ip} | ${ip_prefix} | ${fib_table_number} | drop +| | When COP Add whitelist Entry +| | ... | ${dut1_node} | ${dut1_to_tg} | ip6 | ${fib_table_number} +| | And COP interface enable or disable | ${dut1_node} | ${dut1_to_tg} | enable +| | Then Packet transmission from port to port should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} | ${dut1_to_dut2_mac} +| | ... | ${tg_to_dut2_mac} diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-copwhlistbase-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-copwhlistbase-func.robot new file mode 100644 index 0000000000..a60aa7760c --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-copwhlistbase-func.robot @@ -0,0 +1,101 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Library | resources.libraries.python.Trace +| Library | resources.libraries.python.Cop +| Resource | resources/libraries/robot/shared/default.robot +| Resource | resources/libraries/robot/shared/interfaces.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Resource | resources/libraries/robot/shared/traffic.robot +| Resource | resources/libraries/robot/shared/testing_path.robot +| Resource | resources/libraries/robot/l2/l2_xconnect.robot +| Variables | resources/libraries/python/IPv6NodesAddr.py | ${nodes} +| Force Tags | HW_ENV | VM_ENV | 3_NODE_SINGLE_LINK_TOPO +| Test Setup | Set up functional test +| Test Teardown | Tear down functional test +| Documentation | *COP Security IPv6 Whitelist Tests* +| ... +| ... | *[Top] Network Topologies:* TG-DUT1-DUT2-TG 3-node circular topology +| ... | with single links between nodes. +| ... | *[Enc] Packet Encapsulations:* Eth-IPv6-ICMPv6 on all links. +| ... | *[Cfg] DUT configuration:* DUT1 is configured with IPv6 routing and +| ... | static routes. COP security white-lists are applied on DUT1 ingress +| ... | interface from TG. DUT2 is configured with L2XC. +| ... | *[Ver] TG verification:* Test ICMPv6 Echo Request packets are sent in +| ... | one direction by TG on link to DUT1; on receive TG verifies packets for +| ... | correctness and drops as applicable. +| ... | *[Ref] Applicable standard specifications:* + +*** Variables *** +| ${tg_node}= | ${nodes['TG']} +| ${dut1_node}= | ${nodes['DUT1']} +| ${dut2_node}= | ${nodes['DUT2']} + +| ${dut1_if1_ip}= | 3ffe:62::1 +| ${dut1_if2_ip}= | 3ffe:63::1 +| ${dut1_if1_ip_GW}= | 3ffe:62::2 +| ${dut1_if2_ip_GW}= | 3ffe:63::2 + +| ${dut2_if1_ip}= | 3ffe:72::1 +| ${dut2_if2_ip}= | 3ffe:73::1 + +| ${test_dst_ip}= | 3ffe:64::1 +| ${test_src_ip}= | 3ffe:61::1 + +| ${cop_dut_ip}= | 3ffe:61:: + +| ${ip_prefix}= | 64 + +| ${nodes_ipv6_addresses}= | ${nodes_ipv6_addr} + +| ${fib_table_number}= | 1 + +*** Test Cases *** +| TC01: DUT permits IPv6 pkts with COP whitelist set with IPv6 src-addr +| | [Documentation] +| | ... | [Top] TG-DUT1-DUT2-TG. [Enc] Eth-IPv6-ICMPv6. [Cfg] On DUT1 \ +| | ... | configure interface IPv6 addresses and routes in the main +| | ... | routing domain, add COP whitelist on interface to TG with IPv6 +| | ... | src-addr matching packets generated by TG; on DUT2 configure L2 +| | ... | xconnect. [Ver] Make TG send ICMPv6 Echo Req on its interface to +| | ... | DUT1; verify received ICMPv6 Echo Req pkts are correct. [Ref] +| | Given Configure path in 3-node circular topology +| | ... | ${tg_node} | ${dut1_node} | ${dut2_node} | ${tg_node} +| | And Set interfaces in 3-node circular topology up +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut1_node} | ${dut1_to_tg} | ${dut1_if1_ip} | ${ip_prefix} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_if2_ip} | ${ip_prefix} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_if1_ip} | ${ip_prefix} +| | And VPP Set IF IPv6 Addr +| | ... | ${dut2_node} | ${dut2_to_tg} | ${dut2_if2_ip} | ${ip_prefix} +| | And Add IP Neighbor +| | ... | ${dut1_node} | ${dut1_to_tg} | ${dut1_if1_ip_GW} | ${tg_to_dut1_mac} +| | And Add IP Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_if2_ip_GW} | ${tg_to_dut2_mac} +| | And Vpp Route Add | ${dut1_node} +| | ... | ${test_dst_ip} | ${ip_prefix} | ${dut1_if2_ip_GW} | ${dut1_to_dut2} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | And Add fib table | ${dut1_node} | ${cop_dut_ip} | ${ip_prefix} | +| | ... | ${fib_table_number} | local +| | When COP Add whitelist Entry | ${dut1_node} | ${dut1_to_tg} | ip6 | +| | ... | ${fib_table_number} +| | And COP interface enable or disable | ${dut1_node} | ${dut1_to_tg} | enable +| | Then Send packet and verify headers | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} | ${dut1_to_dut2_mac} +| | ... | ${tg_to_dut2_mac} diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-func.robot new file mode 100644 index 0000000000..bd0b2a6b64 --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-func.robot @@ -0,0 +1,120 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Library | resources.libraries.python.Trace +| Resource | resources/libraries/robot/shared/interfaces.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Resource | resources/libraries/robot/shared/counters.robot +| Resource | resources/libraries/robot/shared/default.robot +| Variables | resources/libraries/python/IPv6NodesAddr.py | ${nodes} +| Force Tags | 3_NODE_SINGLE_LINK_TOPO | HW_ENV | SKIP_VPP_PATCH +| Suite Setup | Run Keywords +| ... | Configure IPv6 on all DUTs in topology | ${nodes} | ${nodes_ipv6_addr} | AND +| ... | Suppress ICMPv6 router advertisement message | ${nodes} | AND +| ... | Configure IPv6 routing on all DUTs | ${nodes} | ${nodes_ipv6_addr} | AND +| ... | Configure all TGs for traffic script +| Test Setup | Run Keywords | Save VPP PIDs | AND +| ... | Reset VAT History On All DUTs | ${nodes} | AND +| ... | Clear interface counters on all vpp nodes in topology | ${nodes} +| Test Teardown | Run Keywords +| ... | Show packet trace on all DUTs | ${nodes} | AND +| ... | Show VAT History On All DUTs | ${nodes} | AND +| ... | Verify VPP PID in Teardown +| Documentation | *IPv6 routing test cases* +| ... +| ... | RFC2460 IPv6, RFC4443 ICMPv6, RFC4861 Neighbor Discovery. +| ... | Encapsulations: Eth-IPv6-ICMPv6 on links TG-DUT1, TG-DUT2, DUT1-DUT2; +| ... | Eth-IPv6-NS/NA on links TG-DUT. IPv6 routing tests use circular 3-node +| ... | topology TG - DUT1 - DUT2 - TG with one link between the nodes. DUT1 and +| ... | DUT2 are configured with IPv6 routing and static routes. Test ICMPv6 +| ... | Echo Request packets are sent in both directions by TG on links to DUT1 +| ... | and DUT2 and received on TG links on the other side of circular +| ... | topology. On receive TG verifies packets IPv6 src-addr, dst-addr and MAC +| ... | addresses. + +*** Test Cases *** +| TC01: DUT replies to ICMPv6 Echo Req to its ingress interface +| | [Tags] | VM_ENV +| | [Documentation] +| | ... | Make TG send ICMPv6 Echo Req to DUT ingress interface. Make TG\ +| | ... | verify ICMPv6 Echo Reply is correct. +| | Send IPv6 icmp echo request to DUT1 ingress inteface and verify answer | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes_ipv6_addr} + +| TC02: DUT replies to ICMPv6 Echo Req pkt with size 64B-to-1500B-incr-1B +| | [Tags] | VM_ENV +| | [Documentation] +| | ... | Make TG send ICMPv6 Echo Reqs to DUT ingress interface,\ +| | ... | incrementating frame size from 64B to 1500B with increment step +| | ... | of 1Byte. Make TG verify ICMP Echo Replies are correct. +| | Execute IPv6 ICMP echo sweep | ${nodes['TG']} | ${nodes['DUT1']} | 0 | 1452 | 1 | ${nodes_ipv6_addr} + +| TC03: DUT replies to ICMPv6 Echo Req pkt with size 1500B-to-9000B-incr-10B +| | [Documentation] +| | ... | Make TG send ICMPv6 Echo Reqs to DUT ingress interface,\ +| | ... | incrementating frame size from 1500B to 9000B with increment +| | ... | step of 10Bytes. Make TG verify ICMPv6 Echo Replies are correct. +| | [Setup] | Configure MTU on TG based on MTU on DUT | ${nodes['TG']} | ${nodes['DUT1']} +| | [Teardown] | Run keywords +| | ... | Set default Ethernet MTU on all interfaces on node | ${nodes['TG']} +| | ... | AND | Verify VPP PID in Teardown +| | Append Nodes | ${nodes['TG']} | ${nodes['DUT1']} +| | Compute Path +| | ${dut_port} | ${dut_node}= | Last Interface +| | ${mtu}= | Get Interface MTU | ${dut_node} | ${dut_port} +| | # ICMPv6 payload size is frame size minus size of Ehternet header, FCS, +| | # IPv6 header and ICMPv6 header +| | ${end_size}= | Evaluate | ${mtu} - 14 - 4 - 40 - 8 +| | Run Keyword If | ${mtu} > 1518 +| | ... | Execute IPv6 ICMP echo sweep | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | 1452 | ${end_size} | 10 | ${nodes_ipv6_addr} + +| TC04: DUT routes to its egress interface +| | [Tags] | VM_ENV +| | [Documentation] +| | ... | Make TG send ICMPv6 Echo Req towards DUT1 egress interface\ +| | ... | connected to DUT2. Make TG verify ICMPv6 Echo Reply is correct. +| | Send IPv6 ICMP echo request to DUT1 egress interface and verify answer | ${nodes['TG']} | ${nodes['DUT1']} | +| | ... | ${nodes['DUT2']} | ${nodes_ipv6_addr} + +| TC05: DUT1 routes to DUT2 ingress interface +| | [Tags] | VM_ENV +| | [Documentation] +| | ... | Make TG send ICMPv6 Echo Req towards DUT2 ingress interface\ +| | ... | connected to DUT1. Make TG verify ICMPv6 Echo Reply is correct. +| | Send IPv6 ICMP echo request to DUT2 via DUT1 and verify answer | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes_ipv6_addr} + +| TC06: DUT1 routes to DUT2 egress interface +| | [Tags] | VM_ENV +| | [Documentation] +| | ... | Make TG send ICMPv6 Echo Req towards DUT2 egress interface\ +| | ... | connected to TG. Make TG verify ICMPv6 Echo Reply is correct. +| | Send IPv6 ICMP echo request to DUT2 egress interface via DUT1 and verify answer | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes_ipv6_addr} + +| TC07: DUT1 and DUT2 route between TG interfaces +| | [Tags] | VM_ENV +| | [Documentation] +| | ... | Make TG send ICMPv6 Echo Req between its interfaces across DUT1\ +| | ... | and DUT2. Make TG verify ICMPv6 Echo Replies are correct. +| | Ipv6 tg to tg routed | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} +| | ... | ${nodes_ipv6_addr} + +| TC08: DUT replies to IPv6 Neighbor Solicitation +| | [Tags] | VM_ENV +| | [Documentation] +| | ... | On DUT configure interface IPv6 address in the main routing\ +| | ... | domain. Make TG send Neighbor Solicitation message on the link +| | ... | to DUT and verify DUT Neighbor Advertisement reply is correct. +| | Send IPv6 neighbor solicitation and verify answer | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes_ipv6_addr} diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-iaclbase-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-iaclbase-func.robot new file mode 100644 index 0000000000..e0862ab9ef --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-iaclbase-func.robot @@ -0,0 +1,577 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Resource | resources/libraries/robot/shared/default.robot +| Resource | resources/libraries/robot/shared/counters.robot +| Resource | resources/libraries/robot/shared/interfaces.robot +| Resource | resources/libraries/robot/shared/testing_path.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Resource | resources/libraries/robot/l2/l2_xconnect.robot +| Resource | resources/libraries/robot/shared/traffic.robot +| Library | resources.libraries.python.Classify.Classify +| Library | resources.libraries.python.Trace +| Force Tags | HW_ENV | VM_ENV | 3_NODE_SINGLE_LINK_TOPO +| Test Setup | Set up functional test +| Test Teardown | Tear down functional test +| Documentation | *IPv6 routing with ingress ACL test cases* +| ... +| ... | Encapsulations: Eth-IPv6 on links TG-DUT1, TG-DUT2, DUT1-DUT2. IPv6 +| ... | ingress ACL (iACL) tests use 3-node topology TG - DUT1 - DUT2 - TG with +| ... | one link between the nodes. DUT1 and DUT2 are configured with IPv6 +| ... | routing and static routes. DUT1 is configured with iACL on link to TG, +| ... | iACL classification and permit/deny action are configured on a per test +| ... | case basis. Test ICMPv6 Echo Request packets are sent in one direction +| ... | by TG on link to DUT1 and received on TG link to DUT2. On receive TG +| ... | verifies if packets are dropped, or if received verifies packet IPv6 +| ... | src-addr, dst-addr and MAC addresses. + +*** Variables *** +| ${dut1_to_tg_ip}= | 3ffe:62::1 +| ${dut1_to_dut2_ip}= | 3ffe:63::1 +| ${dut1_to_dut2_ip_GW}= | 3ffe:63::2 +| ${dut2_to_dut1_ip}= | 3ffe:72::1 +| ${dut2_to_tg_ip}= | 3ffe:73::1 +| ${test_dst_ip}= | 3ffe:64::1 +| ${test_src_ip}= | 3ffe:61::1 +| ${non_drop_dst_ip}= | 3ffe:54::1 +| ${non_drop_src_ip}= | 3ffe:51::1 +| ${prefix_length}= | 64 +| ${ip_version}= | ip6 +| ${l2_table}= | l2 + +*** Test Cases *** +| TC01: DUT with iACL IPv6 src-addr drops matching pkts +| | [Documentation] +| | ... | On DUT1 add source IPv6 address to classify table with 'deny'.\ +| | ... | Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send packet and verify headers | ${tg_node} +| | ... | ${non_drop_src_ip} | ${test_dst_ip} | ${tg_to_dut1} +| | ... | ${tg_to_dut1_mac} | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | And Send packet and verify headers | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table L3 | ${dut1_node} +| | ... | ${ip_version} | src +| | And Vpp Configures Classify Session L3 +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${ip_version} | src | ${test_src_ip} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then Packet transmission from port to port should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | And Send packet and verify headers | ${tg_node} +| | ... | ${non_drop_src_ip} | ${test_dst_ip} | ${tg_to_dut1} +| | ... | ${tg_to_dut1_mac} | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} + +| TC02: DUT with iACL IPv6 dst-addr drops matching pkts +| | [Documentation] +| | ... | On DUT1 add destination IPv6 address to classify table with 'deny'.\ +| | ... | Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${non_drop_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send packet and verify headers | ${tg_node} +| | ... | ${test_src_ip} | ${non_drop_dst_ip} | ${tg_to_dut1} +| | ... | ${tg_to_dut1_mac} | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | And Send packet and verify headers | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table L3 | ${dut1_node} +| | ... | ${ip_version} | dst +| | And Vpp Configures Classify Session L3 +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${ip_version} | dst | ${test_dst_ip} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then Packet transmission from port to port should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | And Send packet and verify headers | ${tg_node} +| | ... | ${test_src_ip} | ${non_drop_dst_ip} | ${tg_to_dut1} +| | ... | ${tg_to_dut1_mac} | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} + +| TC03: DUT with iACL IPv6 src-addr and dst-addr drops matching pkts +| | [Documentation] +| | ... | On DUT1 add source and destination IPv6 addresses to classify table\ +| | ... | with 'deny'. Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${non_drop_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send packet and verify headers | ${tg_node} +| | ... | ${non_drop_src_ip} | ${non_drop_dst_ip} | ${tg_to_dut1} +| | ... | ${tg_to_dut1_mac} | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | And Send packet and verify headers | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | ${table_index_1} | ${skip_n_1} | ${match_n_1}= +| | ... | When Vpp Creates Classify Table L3 | ${dut1_node} +| | ... | ${ip_version} | src +| | ${table_index_2} | ${skip_n_2} | ${match_n_2}= +| | ... | And Vpp Creates Classify Table L3 | ${dut1_node} | ${ip_version} | dst +| | And Vpp Configures Classify Session L3 +| | ... | ${dut1_node} | deny | ${table_index_1} | ${skip_n_1} | ${match_n_2} +| | ... | ${ip_version} | src | ${test_src_ip} +| | And Vpp Configures Classify Session L3 +| | ... | ${dut1_node} | deny | ${table_index_2} | ${skip_n_2} | ${match_n_2} +| | ... | ${ip_version} | dst | ${test_dst_ip} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index_1} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index_2} +| | Then Packet transmission from port to port should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} +| | And Send packet and verify headers | ${tg_node} +| | ... | ${non_drop_src_ip} | ${non_drop_dst_ip} | ${tg_to_dut1} +| | ... | ${tg_to_dut1_mac} | ${dut1_to_tg_mac} | ${tg_to_dut2} +| | ... | ${dut1_to_dut2_mac} | ${tg_to_dut2_mac} + +| TC04: DUT with iACL IPv6 protocol set to TCP drops matching pkts +| | [Documentation] +| | ... | On DUT1 add protocol mask and TCP protocol (0x06) to classify table\ +| | ... | with 'deny'. Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex +| | ... | ${dut1_node} | 0000000000000000000000000000000000000000FF +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | 000000000000000000000000000000000000000006 +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 + +| TC05: DUT with iACL IPv6 protocol set to UDP drops matching pkts +| | [Documentation] +| | ... | On DUT1 add protocol mask and UDP protocol (0x11) to classify table\ +| | ... | with 'deny'. Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex +| | ... | ${dut1_node} | 0000000000000000000000000000000000000000FF +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | 000000000000000000000000000000000000000011 +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 + +| TC06: DUT with iACL IPv6 TCP src-ports drops matching pkts +| | [Documentation] +| | ... | On DUT1 add TCP source ports to classify table with 'deny'.\ +| | ... | Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 110 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 +| | ${hex_mask}= | Compute Classify Hex Mask | ${ip_version} | TCP | source +| | ${hex_value}= | Compute Classify Hex Value | ${hex_mask} | 80 | 0 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex | ${dut1_node} | ${hex_mask} +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${hex_value} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 110 | 20 + +| TC07: DUT with iACL IPv6 TCP dst-ports drops matching pkts +| | [Documentation] +| | ... | On DUT1 add TCP destination ports to classify table with 'deny'.\ +| | ... | Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 20 | 110 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 20 | 80 +| | ${hex_mask}= | Compute Classify Hex Mask | ${ip_version} | TCP | destination +| | ${hex_value}= | Compute Classify Hex Value | ${hex_mask} | 0 | 80 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex | ${dut1_node} | ${hex_mask} +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${hex_value} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 20 | 80 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 20 | 110 + +| TC08: DUT with iACL IPv6 TCP src-ports and dst-ports drops matching pkts +| | [Documentation] +| | ... | On DUT1 add TCP source and destination ports to classify table\ +| | ... | with 'deny'. Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 110 | 25 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 +| | ${hex_mask}= | Compute Classify Hex Mask | ${ip_version} | TCP +| | ... | source + destination +| | ${hex_value}= | Compute Classify Hex Value | ${hex_mask} | 80 | 20 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex | ${dut1_node} | ${hex_mask} +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${hex_value} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | TCP | 110 | 25 + +| TC09: DUT with iACL IPv6 UDP src-ports drops matching pkts +| | [Documentation] +| | ... | On DUT1 add UDP source ports to classify table with 'deny'.\ +| | ... | Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 110 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | ${hex_mask}= | Compute Classify Hex Mask | ${ip_version} | UDP | source +| | ${hex_value}= | Compute Classify Hex Value | ${hex_mask} | 80 | 0 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex | ${dut1_node} | ${hex_mask} +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${hex_value} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 110 | 20 + +| TC10: DUT with iACL IPv6 UDP dst-ports drops matching pkts +| | [Documentation] +| | ... | On DUT1 add TCP destination ports to classify table with 'deny'.\ +| | ... | Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 20 | 110 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 20 | 80 +| | ${hex_mask}= | Compute Classify Hex Mask | ${ip_version} | UDP | destination +| | ${hex_value}= | Compute Classify Hex Value | ${hex_mask} | 0 | 80 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex | ${dut1_node} | ${hex_mask} +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${hex_value} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 20 | 80 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 20 | 110 + +| TC11: DUT with iACL IPv6 UDP src-ports and dst-ports drops matching pkts +| | [Documentation] +| | ... | On DUT1 add UDP source and destination ports to classify table\ +| | ... | with 'deny'. Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_dut2} | ${dut1_to_dut2_ip} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_dut2_ip_GW} +| | ... | ${tg_to_dut2_mac} +| | And Vpp Route Add +| | ... | ${dut1_node} | ${test_dst_ip} | ${prefix_length} +| | ... | ${dut1_to_dut2_ip_GW} | ${dut1_to_dut2} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 110 | 25 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | ${hex_mask}= | Compute Classify Hex Mask | ${ip_version} | UDP +| | ... | source + destination +| | ${hex_value}= | Compute Classify Hex Value | ${hex_mask} | 80 | 20 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex | ${dut1_node} | ${hex_mask} +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${hex_value} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${ip_version} | ${table_index} +| | Then TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 110 | 25 + +| TC12: DUT with iACL MAC src-addr and iACL IPv6 UDP src-ports and dst-ports drops matching pkts +| | [Documentation] +| | ... | On DUT1 add source MAC address to classify (L2) table and add UDP\ +| | ... | source and destination ports to classify (hex) table with 'deny'. +| | ... | Make TG verify matching packets are dropped. +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Configure L2XC +| | ... | ${dut1_node} | ${dut1_to_dut2} | ${dut1_to_tg} +| | And Configure L2XC +| | ... | ${dut2_node} | ${dut2_to_dut1} | ${dut2_to_tg} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 110 | 25 +| | And Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table L2 | ${dut1_node} | src +| | And Vpp Configures Classify Session L2 +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | src | ${tg_to_dut1_mac} +| | ${hex_mask}= | Compute Classify Hex Mask | ${ip_version} | UDP +| | ... | source + destination +| | ${hex_value}= | Compute Classify Hex Value | ${hex_mask} | 80 | 20 +| | ${table_index} | ${skip_n} | ${match_n}= +| | ... | When Vpp Creates Classify Table Hex | ${dut1_node} | ${hex_mask} +| | And Vpp Configures Classify Session Hex +| | ... | ${dut1_node} | deny | ${table_index} | ${skip_n} | ${match_n} +| | ... | ${hex_value} +| | And Vpp Enable Input Acl Interface +| | ... | ${dut1_node} | ${dut1_to_tg} | ${l2_table} | ${table_index} +| | Then Send TCP or UDP packet and verify received packet | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 110 | 25 +| | And TCP or UDP packet transmission should fail | ${tg_node} +| | ... | ${test_src_ip} | ${test_dst_ip} | ${tg_to_dut1} | ${tg_to_dut1_mac} +| | ... | ${tg_to_dut2} | ${dut1_to_tg_mac} | UDP | 80 | 20 diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6dhcpproxy-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6dhcpproxy-func.robot new file mode 100644 index 0000000000..2858f3743e --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6dhcpproxy-func.robot @@ -0,0 +1,66 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Resource | resources/libraries/robot/shared/default.robot +| Resource | resources/libraries/robot/shared/testing_path.robot +| Resource | resources/libraries/robot/features/dhcp_proxy.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Library | resources.libraries.python.Trace +| Force Tags | HW_ENV | VM_ENV | 3_NODE_DOUBLE_LINK_TOPO | SKIP_VPP_PATCH +| Test Setup | Set up functional test +| Test Teardown | Tear down functional test +| Documentation | *DHCPv6 proxy test cases* +| ... +| ... | *[Top] Network Topologies:* TG = DUT +| ... | with two links between the nodes. +| ... | *[Cfg] DUT configuration:* DUT is configured with DHCPv6 proxy. +| ... | *[Ver] TG verification:* Test DHCPv6 packets are sent +| ... | on TG on first link to DUT and received on TG on second link. +| ... | On receive TG verifies if DHCPv6 packets are valid +| ... | *[Ref] Applicable standard specifications:* RFC 3315 + + +*** Variables *** +| ${dut_to_tg_if1_ip}= | 3ffe:62::1 +| ${dut_to_tg_if2_ip}= | 3ffe:63::1 +| ${dhcp_server_ip}= | 3ffe:63::2 +| ${prefix_length}= | 64 + + +*** Test Cases *** +| TC01: VPP proxies valid DHCPv6 request to DHCPv6 server +| | [Documentation] | +| | ... | [Top] TG=DUT +| | ... | [Cfg] On DUT setup DHCP proxy. +| | ... | [Ver] Make TG verify matching DHCPv6 packets between client and \ +| | ... | DHCPv6 server through DHCPv6 proxy. +| | ... | [Ref] RFC 3315 +| | ... +| | Given Configure path in 2-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['TG']} +| | And Set interfaces in 2-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut_node} +| | ... | ${dut_to_tg_if1} | ${dut_to_tg_if1_ip} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut_node} +| | ... | ${dut_to_tg_if2} | ${dut_to_tg_if2_ip} | ${prefix_length} +| | And VPP Route Add | ${dut_node} | ff02::1:2 | 128 | ${NONE} | local +| | ... | ${FALSE} | ${NONE} +| | And Add IP Neighbor | ${dut_node} | ${dut_to_tg_if2} | ${dhcp_server_ip} +| | ... | ${tg_to_dut_if2_mac} +| | And Vpp All Ra Suppress Link Layer | ${nodes} +| | When DHCP Proxy Config | ${dut_node} | ${dhcp_server_ip} +| | ... | ${dut_to_tg_if1_ip} +| | Then Send DHCPv6 Messages | ${tg_node} | ${tg_to_dut_if1} | ${tg_to_dut_if2} +| | ... | ${dut_to_tg_if1_ip} | ${dut_to_tg_if1_mac} | ${dhcp_server_ip} +| | ... | ${tg_to_dut_if2_mac} | ${tg_to_dut_if1_mac} | ${dut_to_tg_if2_mac} diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ecmp-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ecmp-func.robot new file mode 100644 index 0000000000..1f4b6c7270 --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ecmp-func.robot @@ -0,0 +1,74 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + + +*** Settings *** +| Resource | resources/libraries/robot/shared/default.robot +| Resource | resources/libraries/robot/shared/counters.robot +| Resource | resources/libraries/robot/shared/interfaces.robot +| Resource | resources/libraries/robot/shared/testing_path.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Resource | resources/libraries/robot/shared/traffic.robot +| Library | resources.libraries.python.Trace +| Force Tags | HW_ENV | VM_ENV | 3_NODE_DOUBLE_LINK_TOPO +| Test Setup | Set up functional test +| Test Teardown | Tear down functional test +| Documentation | *Ipv6 Multipath routing test cases* +| ... +| ... | *[Top] Network topologies:* TG=DUT 2-node topology with two links\ +| ... | between nodes. +| ... | *[Cfg] DUT configuration:* On DUT configure interfaces IPv4 adresses,\ +| ... | and multipath routing. +| ... | *[Ver] TG verification:* Test packets are sent from TG on the first\ +| ... | link to DUT. Packet is received on TG on the second link from DUT1. + +*** Variables *** +| ${ip_1}= | 3ffe:61::1 +| ${ip_2}= | 3ffe:62::1 +| ${test_dst_ip}= | 3ffe:71::1 +| ${test_src_ip}= | 3ffe:51::1 +| ${prefix_length}= | 64 +| ${neighbor_1_ip}= | 3ffe:62::2 +| ${neighbor_1_mac}= | 02:00:00:00:00:02 +| ${neighbor_2_ip}= | 3ffe:62::3 +| ${neighbor_2_mac}= | 02:00:00:00:00:03 + +*** Test Cases *** +| TC01: IPv6 Equal-cost multipath routing +| | [Documentation] +| | ... | [Top] TG=DUT +| | ... | [Cfg] On DUT configure multipath routing wiht two equal-cost paths. +| | ... | [Ver] TG sends 100 IPv6 ICMP packets traffic on the first link to\ +| | ... | DUT. On second link to TG verify if traffic is divided into two paths. +| | Given Configure path in 2-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['TG']} +| | And Set interfaces in 2-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut_node} +| | ... | ${dut_to_tg_if2} | ${ip_1} | ${prefix_length} +| | And Vpp Set If Ipv6 Addr | ${dut_node} +| | ... | ${dut_to_tg_if1} | ${ip_2} | ${prefix_length} +| | And Add Ip Neighbor +| | ... | ${dut_node} | ${dut_to_tg_if1} | ${neighbor_1_ip} | ${neighbor_1_mac} +| | And Add Ip Neighbor +| | ... | ${dut_node} | ${dut_to_tg_if1} | ${neighbor_2_ip} | ${neighbor_2_mac} +| | And Suppress ICMPv6 router advertisement message | ${nodes} +| | When Vpp Route Add +| | ... | ${dut_node} | ${test_dst_ip} | ${prefix_length} | ${neighbor_1_ip} +| | ... | ${dut_to_tg_if1} | resolve_attempts=${NONE} | multipath=${TRUE} +| | And Vpp Route Add +| | ... | ${dut_node} | ${test_dst_ip} | ${prefix_length} | ${neighbor_2_ip} +| | ... | ${dut_to_tg_if1} | resolve_attempts=${NONE} | multipath=${TRUE} +| | Then Send packets and verify multipath routing | ${tg_node} +| | ... | ${tg_to_dut_if2} | ${tg_to_dut_if1} | ${test_src_ip} | ${test_dst_ip} +| | ... | ${tg_to_dut_if2_mac} | ${dut_to_tg_if2_mac} | ${dut_to_tg_if1_mac} +| | ... | ${neighbor_1_mac} | ${neighbor_2_mac} diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ra-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ra-func.robot new file mode 100644 index 0000000000..20fa1bd876 --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ip6ra-func.robot @@ -0,0 +1,107 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Resource | resources/libraries/robot/shared/default.robot +| Resource | resources/libraries/robot/shared/counters.robot +| Resource | resources/libraries/robot/shared/interfaces.robot +| Resource | resources/libraries/robot/shared/testing_path.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Resource | resources/libraries/robot/shared/traffic.robot +| Library | resources.libraries.python.Trace +| Force Tags | HW_ENV | VM_ENV | 3_NODE_SINGLE_LINK_TOPO +| Test Setup | Set up functional test +| Test Teardown | Tear down functional test +| Documentation | *IPv6 Router Advertisement test cases* +| ... +| ... | RFC4861 Neighbor Discovery. Encapsulations: Eth-IPv6-RA on links +| ... | TG-DUT1. IPv6 Router Advertisement tests use 3-node topology TG - DUT1 - +| ... | DUT2 - TG with one link between the nodes. DUT1 and DUT2 are configured +| ... | with IPv6 routing and static routes. TG verifies received RA packets. + + +*** Variables *** +| ${dut1_to_tg_ip}= | 3ffe:62::1 +| ${tg_to_dut1_ip}= | 3ffe:62::2 +| ${prefix_length}= | 64 +| ${interval}= | 2 + +*** Test Cases *** +| TC01: DUT transmits RA on IPv6 enabled interface +| | [Documentation] +| | ... | [Top] TG-DUT1-DUT2-TG. +| | ... | [Cfg] On DUT1 configure IPv6 interface on the link to TG. +| | ... | [Ver] Make TG wait for IPv6 Router Advertisement packet to be sent\ +| | ... | by DUT1 and verify the received RA packet is correct. +| | [Tags] | EXPECTED_FAILING +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | When Vpp RA Send After Interval | ${dut1_node} | ${dut1_to_tg} +| | Then Receive and verify router advertisement packet +| | ... | ${tg_node} | ${tg_to_dut1} | ${dut1_to_tg_mac} + +| TC02: DUT retransmits RA on IPv6 enabled interface after a set interval +| | [Documentation] +| | ... | [Top] TG-DUT1-DUT2-TG. +| | ... | [Cfg] On DUT1 configure IPv6 interface on the link to TG. +| | ... | [Ver] Make TG wait for two IPv6 Router Advertisement packets\ +| | ... | to be sent by DUT1 and verify the received RA packets are correct. +| | [Tags] | EXPECTED_FAILING +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | When Vpp RA Send After Interval | ${dut1_node} | ${dut1_to_tg} +| | ... | interval=${interval} +| | :FOR | ${n} | IN RANGE | ${2} +| | | Then Receive and verify router advertisement packet +| | | ... | ${tg_node} | ${tg_to_dut1} | ${dut1_to_tg_mac} | ${interval} + +| TC03: DUT responds to Router Solicitation request +| | [Documentation] +| | ... | [Top] TG-DUT1-DUT2-TG. +| | ... | [Cfg] On DUT1 configure IPv6 interface on the link to TG and suppress\ +| | ... | sending of Router Advertisement packets periodically. +| | ... | [Ver] Make TG send IPv6 Router Solicitation request to DUT1, listen\ +| | ... | for response from DUT1 and verify the received RA packet is correct. +| | [Tags] | EXPECTED_FAILING +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | When VPP RA Suppress Link Layer | ${dut1_node} | ${dut1_to_tg} +| | Then Send router solicitation and verify response +| | ... | ${tg_node} | ${dut1_node} | ${tg_to_dut1} | ${dut1_to_tg} +| | ... | ${tg_to_dut1_ip} + +| TC04: DUT responds to Router Solicitation request sent from link local address +| | [Documentation] +| | ... | [Top] TG-DUT1-DUT2-TG. +| | ... | [Cfg] On DUT1 configure IPv6 interface on the link to TG and suppress\ +| | ... | sending of Router Advertisement packets periodically. +| | ... | [Ver] Make TG send IPv6 Router Solicitation request to DUT1, listen\ +| | ... | for response from DUT1 and verify the received RA packet is correct. +| | [Tags] | EXPECTED_FAILING +| | Given Configure path in 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in 3-node circular topology up +| | And Vpp Set If Ipv6 Addr | ${dut1_node} +| | ... | ${dut1_to_tg} | ${dut1_to_tg_ip} | ${prefix_length} +| | When VPP RA Suppress Link Layer | ${dut1_node} | ${dut1_to_tg} +| | Then Send router solicitation and verify response +| | ... | ${tg_node} | ${dut1_node} | ${tg_to_dut1} | ${dut1_to_tg} diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ipolicemarkbase-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ipolicemarkbase-func.robot new file mode 100644 index 0000000000..788d74ba92 --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6base-ipolicemarkbase-func.robot @@ -0,0 +1,161 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Force Tags | 3_NODE_DOUBLE_LINK_TOPO | VM_ENV | HW_ENV +| Resource | resources/libraries/robot/features/policer.robot +| Library | resources.libraries.python.Trace +| Test Setup | Run Keywords | Set up functional test +| ... | AND | Configure topology for IPv6 policer test +| Test Teardown | Tear down functional test +| Documentation | *IPv6 policer test cases* +| ... +| ... | *[Top] Network topologies:* TG=DUT1 2-node topology with two links\ +| ... | between nodes. +| ... | *[Cfg] DUT configuration:* On DUT1 configure interfaces IPv6 adresses,\ +| ... | and static neighbor record on the second interface. +| ... | *[Ver] TG verification:* Test packet is sent from TG on the first link\ +| ... | to DUT1. Packet is received on TG on the second link from DUT1. +| ... | *[Ref] Applicable standard specifications:* RFC2474, RFC2697, RFC2698. + +*** Variables *** +| ${tg_to_dut_if1_ip6}= | 3ffe:5f::2 +| ${tg_to_dut_if2_ip6}= | 3ffe:60::2 +| ${dut_to_tg_if1_ip6}= | 3ffe:5f::1 +| ${dut_to_tg_if2_ip6}= | 3ffe:60::1 +| ${ip6_plen}= | ${64} + +| ${cir}= | ${100} +| ${eir}= | ${150} +| ${cb}= | ${200} +| ${eb}= | ${300} + +*** Test Cases *** +| TC01: VPP policer 2R3C Color-aware marks packet +| | [Documentation] +| | ... | [Top] TG=DUT1. +| | ... | [Ref] RFC2474, RFC2698. +| | ... | [Cfg] On DUT1 configure 2R3C color-aware policer on the first\ +| | ... | interface. +| | ... | [Ver] TG sends IPv6 TCP packet on the first link to DUT1.\ +| | ... | On DUT1 packet is marked with DSCP tag. Verify if DUT1 sends\ +| | ... | correct IPv6 TCP packet with correct DSCP on the second link to TG. +| | ${dscp}= | DSCP AF22 +| | Given Policer Set Name | policer1 +| | And Policer Set Node | ${dut_node} +| | And Policer Set CIR | ${cir} +| | And Policer Set EIR | ${eir} +| | And Policer Set CB | ${cb} +| | And Policer Set EB | ${eb} +| | And Policer Set Rate Type pps +| | And Policer Set Round Type Closest +| | And Policer Set Type 2R3C 2698 +| | And Policer Set Conform Action Transmit +| | And Policer Set Exceed Action Mark and Transmit | ${dscp} +| | And Policer Set Violate Action Drop +| | And Policer Enable Color Aware +| | And Policer Classify Set Precolor Exceed +| | And Policer Classify Set Interface | ${dut_to_tg_if1} +| | And Policer Classify Set Match IP | ${tg_to_dut_if1_ip} +| | When Policer Set Configuration +| | Then Send packet and verify marking | ${tg_node} | ${tg_to_dut_if1} +| | ... | ${tg_to_dut_if2} | ${tg_to_dut_if1_mac} | ${dut_to_tg_if1_mac} +| | ... | ${tg_to_dut_if1_ip} | ${tg_to_dut_if2_ip} | ${dscp} + +| TC02: VPP policer 2R3C Color-blind marks packet +| | [Documentation] +| | ... | [Top] TG=DUT1. +| | ... | [Ref] RFC2474, RFC2698. +| | ... | [Cfg] On DUT1 configure 2R3C color-blind policer on the first\ +| | ... | interface. +| | ... | [Ver] TG sends IPv6 TCP packet on the first link to DUT1.\ +| | ... | On DUT1 packet is marked with DSCP tag. Verify if DUT1 sends\ +| | ... | correct IPv6 TCP packet with correct DSCP on the second link to TG. +| | ${dscp}= | DSCP AF22 +| | Given Policer Set Name | policer1 +| | And Policer Set Node | ${dut_node} +| | And Policer Set CIR | ${cir} +| | And Policer Set EIR | ${eir} +| | And Policer Set CB | ${cb} +| | And Policer Set EB | ${eb} +| | And Policer Set Rate Type pps +| | And Policer Set Round Type Closest +| | And Policer Set Type 2R3C 2698 +| | And Policer Set Conform Action Mark and Transmit | ${dscp} +| | And Policer Set Exceed Action Transmit +| | And Policer Set Violate Action Drop +| | And Policer Classify Set Precolor Conform +| | And Policer Classify Set Interface | ${dut_to_tg_if1} +| | And Policer Classify Set Match IP | ${tg_to_dut_if1_ip} +| | When Policer Set Configuration +| | Then Send packet and verify marking | ${tg_node} | ${tg_to_dut_if1} +| | ... | ${tg_to_dut_if2} | ${tg_to_dut_if1_mac} | ${dut_to_tg_if1_mac} +| | ... | ${tg_to_dut_if1_ip} | ${tg_to_dut_if2_ip} | ${dscp} + +| TC03: VPP policer 1R3C Color-aware marks packet +| | [Documentation] +| | ... | [Top] TG=DUT1. +| | ... | [Ref] RFC2474, RFC2697. +| | ... | [Cfg] On DUT1 configure 1R3C color-aware policer on the first\ +| | ... | interface. +| | ... | [Ver] TG sends IPv6 TCP packet on the first link to DUT1.\ +| | ... | On DUT1 packet is marked with DSCP tag. Verify if DUT1 sends\ +| | ... | correct IPv6 TCP packet with correct DSCP on the second link to TG. +| | ${dscp}= | DSCP AF22 +| | Given Policer Set Name | policer1 +| | And Policer Set Node | ${dut_node} +| | And Policer Set CIR | ${1} +| | And Policer Set CB | ${2} +| | And Policer Set EB | ${eb} +| | And Policer Set Rate Type pps +| | And Policer Set Round Type Closest +| | And Policer Set Type 1R3C +| | And Policer Set Conform Action Transmit +| | And Policer Set Exceed Action Mark and Transmit | ${dscp} +| | And Policer Set Violate Action Drop +| | And Policer Enable Color Aware +| | And Policer Classify Set Precolor Exceed +| | And Policer Classify Set Interface | ${dut_to_tg_if1} +| | And Policer Classify Set Match IP | ${tg_to_dut_if1_ip} +| | When Policer Set Configuration +| | Then Send packet and verify marking | ${tg_node} | ${tg_to_dut_if1} +| | ... | ${tg_to_dut_if2} | ${tg_to_dut_if1_mac} | ${dut_to_tg_if1_mac} +| | ... | ${tg_to_dut_if1_ip} | ${tg_to_dut_if2_ip} | ${dscp} + +| TC04: VPP policer 1R3C Color-blind marks packet +| | [Documentation] +| | ... | [Top] TG=DUT1. +| | ... | [Ref] RFC2474, RFC2697. +| | ... | [Cfg] On DUT1 configure 1R3C color-blind policer on the first\ +| | ... | interface. +| | ... | [Ver] TG sends IPv6 TCP packet on the first link to DUT1.\ +| | ... | On DUT1 packet is marked with DSCP tag. Verify if DUT1 sends\ +| | ... | correct IPv6 TCP packet with correct DSCP on the second link to TG. +| | ${dscp}= | DSCP AF22 +| | Given Policer Set Name | policer1 +| | And Policer Set Node | ${dut_node} +| | And Policer Set CIR | ${cir} +| | And Policer Set CB | ${cb} +| | And Policer Set Rate Type pps +| | And Policer Set Round Type Closest +| | And Policer Set Type 1R3C +| | And Policer Set Conform Action Mark and Transmit | ${dscp} +| | And Policer Set Exceed Action Transmit +| | And Policer Set Violate Action Drop +| | And Policer Classify Set Precolor Conform +| | And Policer Classify Set Interface | ${dut_to_tg_if1} +| | And Policer Classify Set Match IP | ${tg_to_dut_if1_ip} +| | When Policer Set Configuration +| | Then Send packet and verify marking | ${tg_node} | ${tg_to_dut_if1} +| | ... | ${tg_to_dut_if2} | ${tg_to_dut_if1_mac} | ${dut_to_tg_if1_mac} +| | ... | ${tg_to_dut_if1_ip} | ${tg_to_dut_if2_ip} | ${dscp} diff --git a/tests/vpp/func/ip6/eth2p-ethip6-ip6basevrf-func.robot b/tests/vpp/func/ip6/eth2p-ethip6-ip6basevrf-func.robot new file mode 100644 index 0000000000..cf0ed43a4a --- /dev/null +++ b/tests/vpp/func/ip6/eth2p-ethip6-ip6basevrf-func.robot @@ -0,0 +1,409 @@ +# Copyright (c) 2016 Cisco and/or its affiliates. +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at: +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +*** Settings *** +| Resource | resources/libraries/robot/shared/default.robot +| Resource | resources/libraries/robot/ip/ip4.robot +| Resource | resources/libraries/robot/ip/ip6.robot +| Resource | resources/libraries/robot/shared/interfaces.robot +| Resource | resources/libraries/robot/shared/testing_path.robot +| Resource | resources/libraries/robot/shared/traffic.robot +| Resource | resources/libraries/robot/l2/l2_traffic.robot +| Library | resources.libraries.python.Trace +| Library | resources.libraries.python.IPUtil +| Force Tags | HW_ENV | VM_ENV | 3_NODE_DOUBLE_LINK_TOPO | SKIP_VPP_PATCH +| Test Setup | Set up functional test +| Test Teardown | Tear down functional test +| Documentation | *Vpn routed forwarding - baseline IPv6* +| ... | *[Top] Network Topologies:* TG=DUT1=DUT2=TG 3-node topology with two +| ... | links in between nodes. +| ... | *[Enc] Packet Encapsulations:* Eth-IPv6-ICMPv6 +| ... | *[Cfg] DUT configuration:* Each DUT is configured with two VRF tables; +| ... | Separation of traffic is tested by IP packets; Neighbors and Routes are +| ... | set on DUT nodes; IP addresses are set on DUT interfaces. +| ... | *[Ver] TG verification:* Test ICMPv6 Echo Request packets +| ... | are sent by TG on link to DUT1, DUT2 or back to TG; On receipt TG +| ... | verifies packets for correctness and their IPv6 src-addr, dst-addr, +| ... | and MAC addresses. +| ... | *[Ref] Applicable standard specifications:* + +*** Variables *** +| ${fib_table_1}= | 9 +| ${fib_table_2}= | 99 + +| ${dut1_to_tg_ip1}= | 2001:62::3 +| ${dut1_to_tg_ip2}= | 2001:62::4 +| ${dut2_to_tg_ip1}= | 2003:62::3 +| ${dut2_to_tg_ip2}= | 2003:62::4 + +| ${dut1_to_dut2_ip1}= | 2002:62::1 +| ${dut1_to_dut2_ip2}= | 2002:62::2 +| ${dut2_to_dut1_ip1}= | 2002:62::3 +| ${dut2_to_dut1_ip2}= | 2002:62::4 + +| ${tg_dut1_ip1}= | 2001:62::1 +| ${tg_dut1_ip2}= | 2001:62::2 +| ${tg_dut2_ip1}= | 2003:62::1 +| ${tg_dut2_ip2}= | 2003:62::2 + +| ${ip_prefix}= | 64 +| ${timeout}= | 5 + +*** Test Cases *** +| TC01: TG packets routed to DUT ingress interface, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT1->TG-if1 and from +| | ... | TG->DUT1-if2 to DUT1->TG-if2 and checked if arrived. +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Send ICMP echo request and verify answer | ${tg_node} +| | ... | ${tg_to_dut1_if1} | ${dut1_to_tg_if1_mac} +| | ... | ${tg_to_dut1_if1_mac} | ${dut1_to_tg_ip1} +| | ... | ${tg_dut1_ip1} | ${timeout} +| | And Send ICMP echo request and verify answer | ${tg_node} +| | ... | ${tg_to_dut1_if2} | ${dut1_to_tg_if2_mac} +| | ... | ${tg_to_dut1_if2_mac} | ${dut1_to_tg_ip2} +| | ... | ${tg_dut1_ip2} | ${timeout} + +| TC02: TG packets routed to DUT egress interface, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT1->DUT2-if1 and from +| | ... | TG->DUT1-if2 to DUT1->DUT2-if2 and checked if arrived. +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Send ICMP echo request and verify answer | ${tg_node} | ${tg_to_dut1_if1} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut1_if1_mac} +| | ... | ${dut1_to_dut2_ip1} | ${tg_dut1_ip1} | ${timeout} +| | And Send ICMP echo request and verify answer | ${tg_node} | ${tg_to_dut1_if2} +| | ... | ${dut1_to_tg_if2_mac} | ${tg_to_dut1_if2_mac} +| | ... | ${dut1_to_dut2_ip2} | ${tg_dut1_ip2} | ${timeout} + +| TC03: TG packets routed to DUT2 ingress interface through DUT1, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT2->DUT1-if1 and from +| | ... | TG->DUT1-if2 to DUT2->DUT1-if2 and checked if arrived. +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Send ICMP echo request and verify answer | ${tg_node} | ${tg_to_dut1_if1} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut1_if1_mac} +| | ... | ${dut2_to_dut1_ip1} | ${tg_dut1_ip1} | ${timeout} +| | And Send ICMP echo request and verify answer | ${tg_node} | ${tg_to_dut1_if2} +| | ... | ${dut1_to_tg_if2_mac} | ${tg_to_dut1_if2_mac} +| | ... | ${dut2_to_dut1_ip2} | ${tg_dut1_ip2} | ${timeout} + +| TC04: TG packets routed to DUT2 egress interface through DUT1, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT2->TG-if1 and from +| | ... | TG->DUT1-if2 to DUT2->TG-if2 and checked if arrived. +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Send ICMP echo request and verify answer | ${tg_node} | ${tg_to_dut1_if1} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut1_if1_mac} +| | ... | ${dut2_to_tg_ip1} | ${tg_dut1_ip1} | ${timeout} +| | And Send ICMP echo request and verify answer | ${tg_node} | ${tg_to_dut1_if2} +| | ... | ${dut1_to_tg_if2_mac} | ${tg_to_dut1_if2_mac} +| | ... | ${dut2_to_tg_ip2} | ${tg_dut1_ip2} | ${timeout} + +| TC05: TG packets routed to TG through DUT1 and DUT2, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to TG->DUT2-if1 and from +| | ... | TG->DUT1-if2 to TG->DUT2-if2 and checked if arrived. +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Send packet and verify headers | ${tg_node} | ${tg_dut1_ip1} +| | ... | ${tg_dut2_ip1} | ${tg_to_dut1_if1} | ${tg_to_dut1_if1_mac} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut2_if1} | ${dut2_to_tg_if1_mac} +| | ... | ${tg_to_dut2_if1_mac} +| | And Send packet and verify headers | ${tg_node} +| | ... | ${tg_dut1_ip2} | ${tg_dut2_ip2} | ${tg_to_dut1_if2} +| | ... | ${tg_to_dut1_if2_mac} | ${dut1_to_tg_if2_mac} | ${tg_to_dut2_if2} +| | ... | ${dut2_to_tg_if2_mac} | ${tg_to_dut2_if2_mac} + +| TC06: TG packets not routed to DUT ingress interface in different VRF, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT1->TG-if2 where it +| | ... | should not arrive. +| | [Tags] | SKIP_PATCH +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if1} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut1_if1_mac} +| | ... | ${dut1_to_tg_ip2} | ${tg_dut1_ip1} | ${timeout} +| | And Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if2} +| | ... | ${dut1_to_tg_if2_mac} | ${tg_to_dut1_if2_mac} +| | ... | ${dut1_to_tg_ip1} | ${tg_dut1_ip2} | ${timeout} + +| TC07: TG packets not routed to DUT egress interface in different VRF, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT1->DUT2-if2 where it +| | ... | should not arrive. +| | [Tags] | SKIP_PATCH +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if1} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut1_if1_mac} +| | ... | ${dut1_to_dut2_ip2} | ${tg_dut1_ip1} | ${timeout} +| | And Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if2} +| | ... | ${dut1_to_tg_if2_mac} | ${tg_to_dut1_if2_mac} +| | ... | ${dut1_to_dut2_ip1} | ${tg_dut1_ip2} | ${timeout} + + +| TC08: TG packets not routed to DUT2 ingress interface in different VRF through DUT1, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT2->DUT1-if2 where it +| | ... | should not arrive. +| | [Tags] | SKIP_PATCH +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if1} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut1_if1_mac} +| | ... | ${dut2_to_dut1_ip2} | ${tg_dut1_ip1} | ${timeout} +| | And Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if2} +| | ... | ${dut1_to_tg_if2_mac} | ${tg_to_dut1_if2_mac} +| | ... | ${dut2_to_dut1_ip1} | ${tg_dut1_ip2} | ${timeout} + +| TC09: TG packets not routed to DUT2 egress interface in different VRF through DUT1, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to DUT2->TG-if2 where it +| | ... | should not arrive. +| | [Tags] | SKIP_PATCH +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if1} +| | ... | ${dut1_to_tg_if1_mac} | ${tg_to_dut1_if1_mac} +| | ... | ${dut2_to_tg_ip2} | ${tg_dut1_ip1} | ${timeout} +| | And Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send ICMP echo request and verify answer +| | ... | ${tg_node} | ${tg_to_dut1_if2} +| | ... | ${dut1_to_tg_if2_mac} | ${tg_to_dut1_if2_mac} +| | ... | ${dut2_to_tg_ip1} | ${tg_dut1_ip2} | ${timeout} + +| TC10: TG packets not routed to TG in different VRF through DUT1 and DUT2, VPP configured with two VRFs +| | [Documentation] +| | ... | [Top] TG=DUT1=DUT2=TG. +| | ... | [Enc] Eth-IPv6-ICMPv6. +| | ... | [Cfg] DUT1 and DUT2 are both configured with two fib tables. Each +| | ... | table is assigned to 2 interfaces to separate the traffic. Interfaces +| | ... | are configured with IP addresses from *Variables*. Neighbors are +| | ... | configured for each DUTs ingress/egress ports, and each VRF is +| | ... | configured with just one route. +| | ... | [Ver] Packet is sent from TG->DUT1-if1 to TG->DUT2-if2 where it +| | ... | should not arrive. +| | [Tags] | SKIP_PATCH +| | Given Configure path in double-link 3-node circular topology +| | ... | ${nodes['TG']} | ${nodes['DUT1']} +| | ... | ${nodes['DUT2']} | ${nodes['TG']} +| | And Set interfaces in double-link 3-node circular topology up +| | When Setup Env - 2xVRF Each Node +| | Then Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send packet and verify headers | ${tg_node} | ${tg_dut1_ip1} +| | ... | ${tg_dut2_ip2} | ${tg_to_dut1_if1} +| | ... | ${tg_to_dut1_if1_mac} | ${dut1_to_tg_if1_mac} | ${tg_to_dut2_if2} +| | ... | ${dut2_to_tg_if2_mac} | ${tg_to_dut2_if2_mac} +| | And Run Keyword And Expect Error | ICMP echo Rx timeout +| | ... | Send packet and verify headers | ${tg_node} | ${tg_dut1_ip2} +| | ... | ${tg_dut2_ip1} | ${tg_to_dut1_if2} +| | ... | ${tg_to_dut1_if2_mac} | ${dut1_to_tg_if2_mac} | ${tg_to_dut2_if1} +| | ... | ${dut2_to_tg_if1_mac} | ${tg_to_dut2_if1_mac} + +*** Keywords *** +| Setup Env - 2xVRF Each Node +| | [Documentation] +| | ... | Environment is set up with 2 fib tables on each DUT. DUT1-TG-IF1 and \ +| | ... | DUT1-DUT2-IF1 are assigned to FIB1, and DUT1-TG-IF2 and DUT1-DUT2-IF2 +| | ... | are assigned to FIB2 (the same done on DUT2, just opposite). +| | ... | IP addresses and IP Neighbors are subsequently set for interfaces. +| | ... | The last setting is route for each fib table. +| | ... +| | ${dut1_if1_idx}= | Get Interface SW Index +| | ... | ${dut1_node} | ${dut1_to_dut2_if1} +| | ${dut1_if2_idx}= | Get Interface SW Index +| | ... | ${dut1_node} | ${dut1_to_dut2_if2} +| | ${dut2_if1_idx}= | Get Interface SW Index +| | ... | ${dut2_node} | ${dut2_to_dut1_if1} +| | ${dut2_if2_idx}= | Get Interface SW Index +| | ... | ${dut2_node} | ${dut2_to_dut1_if2} + +| | Assign Interface To Fib Table +| | ... | ${dut1_node} | ${dut1_to_dut2_if1} | ${fib_table_1} | ipv6=${TRUE} +| | Assign Interface To Fib Table +| | ... | ${dut1_node} | ${dut1_to_dut2_if2} | ${fib_table_2} | ipv6=${TRUE} +| | Assign Interface To Fib Table +| | ... | ${dut1_node} | ${dut1_to_tg_if1} | ${fib_table_1} | ipv6=${TRUE} +| | Assign Interface To Fib Table +| | ... | ${dut1_node} | ${dut1_to_tg_if2} | ${fib_table_2} | ipv6=${TRUE} + +| | Assign Interface To Fib Table +| | ... | ${dut2_node} | ${dut2_to_dut1_if1} | ${fib_table_1} | ipv6=${TRUE} +| | Assign Interface To Fib Table +| | ... | ${dut2_node} | ${dut2_to_dut1_if2} | ${fib_table_2} | ipv6=${TRUE} +| | Assign Interface To Fib Table +| | ... | ${dut2_node} | ${dut2_to_tg_if1} | ${fib_table_1} | ipv6=${TRUE} +| | Assign Interface To Fib Table +| | ... | ${dut2_node} | ${dut2_to_tg_if2} | ${fib_table_2} | ipv6=${TRUE} + +| | And Set Interface Address +| | ... | ${dut1_node} | ${dut1_to_tg_if1} | ${dut1_to_tg_ip1} | ${ip_prefix} +| | And Set Interface Address +| | ... | ${dut1_node} | ${dut1_to_tg_if2} | ${dut1_to_tg_ip2} | ${ip_prefix} +| | And Set Interface Address +| | ... | ${dut1_node} | ${dut1_to_dut2_if1} +| | ... | ${dut1_to_dut2_ip1} | ${ip_prefix} +| | And Set Interface Address +| | ... | ${dut1_node} | ${dut1_to_dut2_if2} +| | ... | ${dut1_to_dut2_ip2} | ${ip_prefix} + +| | And Set Interface Address +| | ... | ${dut2_node} | ${dut2_to_tg_if1} | ${dut2_to_tg_ip1} | ${ip_prefix} +| | And Set Interface Address +| | ... | ${dut2_node} | ${dut2_to_tg_if2} | ${dut2_to_tg_ip2} | ${ip_prefix} +| | And Set Interface Address +| | ... | ${dut2_node} | ${dut2_to_dut1_if1} +| | ... | ${dut2_to_dut1_ip1} | ${ip_prefix} +| | And Set Interface Address +| | ... | ${dut2_node} | ${dut2_to_dut1_if2} +| | ... | ${dut2_to_dut1_ip2} | ${ip_prefix} + +| | And Add IP Neighbor | ${dut1_node} | ${dut1_to_tg_if1} +| | ... | ${tg_dut1_ip1} | ${tg_to_dut1_if1_mac} +| | And Add IP Neighbor | ${dut1_node} | ${dut1_to_dut2_if1} +| | ... | ${dut2_to_dut1_ip1} | ${dut2_to_dut1_if1_mac} +| | And Add IP Neighbor | ${dut2_node} | ${dut2_to_tg_if1} +| | ... | ${tg_dut2_ip1} | ${tg_to_dut2_if1_mac} +| | And Add IP Neighbor | ${dut2_node} | ${dut2_to_dut1_if1} +| | ... | ${dut1_to_dut2_ip1} | ${dut1_to_dut2_if1_mac} + +| | And Add IP Neighbor | ${dut1_node} | ${dut1_to_tg_if2} +| | ... | ${tg_dut1_ip2} | ${tg_to_dut1_if2_mac} +| | And Add IP Neighbor | ${dut1_node} | ${dut1_to_dut2_if2} +| | ... | ${dut2_to_dut1_ip2} | ${dut2_to_dut1_if2_mac} +| | And Add IP Neighbor | ${dut2_node} | ${dut2_to_tg_if2} +| | ... | ${tg_dut2_ip2} | ${tg_to_dut2_if2_mac} +| | And Add IP Neighbor | ${dut2_node} | ${dut2_to_dut1_if2} +| | ... | ${dut1_to_dut2_ip2} | ${dut1_to_dut2_if2_mac} + +| | And Vpp Route Add | ${dut1_node} | ${tg_dut2_ip1} | ${ip_prefix} +| | ... | ${dut2_to_dut1_ip1} | ${dut1_to_dut2_if1} | vrf=${fib_table_1} +| | And Vpp Route Add | ${dut2_node} | ${tg_dut1_ip1} | ${ip_prefix} +| | ... | ${dut1_to_dut2_ip1} | ${dut2_to_dut1_if1} | vrf=${fib_table_1} + +| | And Vpp Route Add | ${dut1_node} | ${tg_dut2_ip2} | ${ip_prefix} +| | ... | ${dut2_to_dut1_ip2} | ${dut1_to_dut2_if2} | vrf=${fib_table_2} +| | And Vpp Route Add | ${dut2_node} | ${tg_dut1_ip2} | ${ip_prefix} +| | ... | ${dut1_to_dut2_ip2} | ${dut2_to_dut1_if2} | vrf=${fib_table_2} + +| | Vpp All RA Suppress Link Layer | ${nodes} -- cgit 1.2.3-korg