aboutsummaryrefslogtreecommitdiffstats
path: root/resources/test_data/honeycomb/ietf_acl.py
blob: d5c3040d7abb25f74a41836ea9f48267019b0f8d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
# Copyright (c) 2016 Cisco and/or its affiliates.
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at:
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

"""Test variables for ietf-ACL test suite."""


def get_variables(test_case, name):
    """Create and return a dictionary of test variables for the specified
    test case.

    :param test_case: Determines which test variables to return.
    :param name: Name for the classify chain used in test.
    :type test_case: str
    :type name: str

    :return: Dictionary of test variables - settings for Honeycomb's
    ietf-acl node and packet fields to use in verification.
    :rtype: dict
    """

    variables = {
        # generic packet data
        "src_ip": "16.0.0.1",
        "dst_ip": "16.0.1.1",
        "dst_net": "16.0.1.0",
        "src_port": "1234",
        "dst_port": "1234",
        "src_mac": "01:02:03:04:05:06",
        "dst_mac": "10:20:30:40:50:60"}

    if test_case.lower() == "l2":
        classify_vars = {
            "classify_src": "12:23:34:45:56:67",
            "classify_dst": "89:9A:AB:BC:CD:DE",
            "classify_src2": "01:02:03:04:56:67",
            "classify_dst2": "89:9A:AB:BC:50:60",
            "src_mask": "00:00:00:00:FF:FF",
            "dst_mask": "FF:FF:FF:FF:00:00",
            }

        acl_settings = {
            "acl": [{
                "acl-type":
                    "ietf-access-control-list:eth-acl",
                "acl-name": name,
                "access-list-entries": {"ace": [{
                    "rule-name": "rule1",
                    "matches": {
                        "source-mac-address":
                            classify_vars["classify_src"],
                        "source-mac-address-mask":
                            classify_vars["src_mask"],
                        "destination-mac-address":
                            classify_vars["classify_dst"],
                        "destination-mac-address-mask":
                            classify_vars["dst_mask"]
                    },
                    "actions": {
                        "deny": {}
                    }
                }]}
            }]
        }

    elif test_case.lower() in ("l3_ip4", "l3_ip6", "l4"):
        raise NotImplementedError
    else:
        raise Exception("Unrecognized test case {0}".format(test_case))

    variables.update(classify_vars)
    variables["acl_settings"] = acl_settings
    return variables