summaryrefslogtreecommitdiffstats
path: root/src/plugins/ikev2/ikev2.api
blob: ff9ed72e88840c919778a1463d554f95c3f5e220 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34

@media only all and (prefers-color-scheme: dark) {
.highlight .hll { background-color: #49483e }
.highlight .c { color: #75715e } /* Comment */
.highlight .err { color: #960050; background-color: #1e0010 } /* Error */
.highlight .k { color: #66d9ef } /* Keyword */
.highlight .l { color: #ae81ff } /* Literal */
.highlight .n { color: #f8f8f2 } /* Name */
.highlight .o { color: #f92672 } /* Operator */
.highlight .p { color: #f8f8f2 } /* Punctuation */
.highlight .ch { color: #75715e } /* Comment.Hashbang */
.highlight .cm { color: #75715e } /* Comment.Multiline */
.highlight .cp { color: #75715e } /* Comment.Preproc */
.highlight .cpf { color: #75715e } /* Comment.PreprocFile */
.highlight .c1 { color: #75715e } /* Comment.Single */
.highlight .cs { color: #75715e } /* Comment.Special */
.highlight .gd { color: #f92672 } /* Generic.Deleted */
.highlight .ge { font-style: italic } /* Generic.Emph */
.highlight .gi { color: #a6e22e } /* Generic.Inserted */
.highlight .gs { font-weight: bold } /* Generic.Strong */
.highlight .gu { color: #75715e } /* Generic.Subheading */
.highlight .kc { color: #66d9ef } /* Keyword.Constant */
.highlight .kd { color: #66d9ef } /* Keyword.Declaration */
.highlight .kn { color: #f92672 } /* Keyword.Namespace */
.highlight .kp { color: #66d9ef } /* Keyword.Pseudo */
.highlight .kr { color: #66d9ef } /* Keyword.Reserved */
.highlight .kt { color: #66d9ef } /* Keyword.Type */
.highlight .ld { color: #e6db74 } /* Literal.Date */
.highlight .m { color: #ae81ff } /* Literal.Number */
.highlight .s { color: #e6db74 } /* Literal.String */
.highlight .na { color: #a6e22e } /* Name.Attribute */
.highlight .nb { color: #f8f8f2 } /* Name.Builtin */
.highlight .nc { color: #a6e22e } /* Name.Class */
.highlight .no { color: #66d9ef } /* Name.Constant */
.highlight .nd { color: #a6e22e } /* Name.Decorator */
.highlight .ni { color: #f8f8f2 } /* Name.Entity */
.highlight .ne { color: #a6e22e } /* Name.Exception */
.highlight .nf { color: #a6e22e } /* Name.Function */
.highlight .nl { color: #f8f8f2 } /* Name.Label */
.highlight .nn { color: #f8f8f2 } /* Name.Namespace */
.highlight .nx { color: #a6e22e } /* Name.Other */
.highlight .py { color: #f8f8f2 } /* Name.Property */
.highlight .nt { color: #f92672 } /* Name.Tag */
.highlight .nv { color: #f8f8f2 } /* Name.Variable */
.highlight .ow { color: #f92672 } /* Operator.Word */
.highlight .w { color: #f8f8f2 } /* Text.Whitespace */
.highlight .mb { color: #ae81ff } /* Literal.Number.Bin */
.highlight .mf { color: #ae81ff } /* Literal.Number.Float */
.highlight .mh { color: #ae81ff } /* Literal.Number.Hex */
.highlight .mi { color: #ae81ff } /* Literal.Number.Integer */
.highlight .mo { color: #ae81ff } /* Literal.Number.Oct */
.highlight .sa { color: #e6db74 } /* Literal.String.Affix */
.highlight .sb { color: #e6db74 } /* Literal.String.Backtick */
.highlight .sc { color: #e6db74 } /* Literal.String.Char */
.highlight .dl { color: #e6db74 } /* Literal.String.Delimiter */
.highlight .sd { color: #e6db74 } /* Literal.String.Doc */
.highlight .s2 { color: #e6db74 } /* Literal.String.Double */
.highlight .se { color: #ae81ff } /* Literal.String.Escape */
.highlight .sh { color: #e6db74 } /* Literal.String.Heredoc */
.highlight .si { color: #e6db74 } /* Literal.String.Interpol */
.highlight .sx { color: #e6db74 } /* Literal.String.Other */
.highlight .sr { color: #e6db74 } /* Literal.String.Regex */
.highlight .s1 { color: #e6db74 } /* Literal.String.Single */
.highlight .ss { color: #e6db74 } /* Literal.String.Symbol */
.highlight .bp { color: #f8f8f2 } /* Name.Builtin.Pseudo */
.highlight .fm { color: #a6e22e } /* Name.Function.Magic */
.highlight .vc { color: #f8f8f2 } /* Name.Variable.Class */
.highlight .vg { color: #f8f8f2 } /* Name.Variable.Global */
.highlight .vi { color: #f8f8f2 } /* Name.Variable.Instance */
.highlight .vm { color: #f8f8f2 } /* Name.Variable.Magic */
.highlight .il { color: #ae81ff } /* Literal.Number.Integer.Long */
}
@media (prefers-color-scheme: light) {
.highlight .hll { background-color: #ffffcc }
.highlight .c { color: #888888 } /* Comment */
.highlight .err { color: #a61717; background-color: #e3d2d2 } /* Error */
.highlight .k { color: #008800; font-weight: bold } /* Keyword */
.highlight .ch { color: #888888 } /* Comment.Hashbang */
.highlight .cm { color: #888888 } /* Comment.Multiline */
.highlight .cp { color: #cc0000; font-weight: bold } /* Comment.Preproc */
.highlight .cpf { color: #888888 } /* Comment.PreprocFile */
.highlight .c1 { color: #888888 } /* Comment.Single */
.highlight .cs { color: #cc0000; font-weight: bold; background-color: #fff0f0 } /* Comment.Special */
.highlight .gd { color: #000000; background-color: #ffdddd } /* Generic.Deleted */
.highlight .ge { font-style: italic } /* Generic.Emph */
.highlight .gr { color: #aa0000 } /* Generic.Error */
.highlight .gh { color: #333333 } /* Generic.Heading */
.highlight .gi { color: #000000; background-color: #ddffdd } /* Generic.Inserted */
.highlight .go { color: #888888 } /* Generic.Output */
.highlight .gp { color: #555555 } /* Generic.Prompt */
.highlight .gs { font-weight: bold } /* Generic.Strong */
.highlight .gu { color: #666666 } /* Generic.Subheading */
.highlight .gt { color: #aa0000 } /* Generic.Traceback */
.highlight .kc { color: #008800; font-weight: bold } /* Keyword.Constant */
.highlight .kd { color: #008800; font-weight: bold } /* Keyword.Declaration */
.highlight .kn { color: #008800; font-weight: bold } /* Keyword.Namespace */
.highlight .kp { color: #008800 } /* Keyword.Pseudo */
.highlight .kr { color: #008800; font-weight: bold } /* Keyword.Reserved */
.highlight .kt { color: #888888; font-weight: bold } /* Keyword.Type */
.highlight .m { color: #0000DD; font-weight: bold } /* Literal.Number */
.highlight .s { color: #dd2200; background-color: #fff0f0 } /* Literal.String */
.highlight .na { color: #336699 } /* Name.Attribute */
.highlight .nb { color: #003388 } /* Name.Builtin */
.highlight .nc { color: #bb0066; font-weight: bold } /* Name.Class */
.highlight .no { color: #003366; font-weight: bold } /* Name.Constant */
.highlight .nd { color: #555555 } /* Name.Decorator */
.highlight .ne { color: #bb0066; font-weight: bold } /* Name.Exception */
.highlight .nf { color: #0066bb; font-weight: bold } /* Name.Function */
.highlight .nl { color: #336699; font-style: italic } /* Name.Label */
.highlight .nn { color: #bb0066; font-weight: bold } /* Name.Namespace */
.highlight .py { color: #336699; font-weight: bold } /* Name.Property */
.highlight .nt { color: #bb0066; font-weight: bold } /* Name.Tag */
.highlight .nv { color: #336699 } /* Name.Variable */
.highlight .ow { color: #008800 } /* Operator.Word */
.highlight .w { color: #bbbbbb } /* Text.Whitespace */
.highlight .mb { color: #0000DD; font-weight: bold } /* Literal.Number.Bin */
.highlight .mf { color: #0000DD; font-weight: bold } /* Literal.Number.Float */
.highlight .mh { color: #0000DD; font-weight: bold } /* Literal.Number.Hex */
.highlight .mi { color: #0000DD; font-weight: bold } /* Literal.Number.Integer */
.highlight .mo { color: #0000DD; font-weight: bold } /* Literal.Number.Oct */
.highlight .sa { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Affix */
.highlight .sb { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Backtick */
.highlight .sc { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Char */
.highlight .dl { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Delimiter */
.highlight .sd { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Doc */
.highlight .s2 { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Double */
.highlight .se { color: #0044dd; background-color: #fff0f0 } /* Literal.String.Escape */
.highlight .sh { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Heredoc */
.highlight .si { color: #3333bb; background-color: #fff0f0 } /* Literal.String.Interpol */
.highlight .sx { color: #22bb22; background-color: #f0fff0 } /* Literal.String.Other */
.highlight .sr { color: #008800; background-color: #fff0ff } /* Literal.String.Regex */
.highlight .s1 { color: #dd2200; background-color: #fff0f0 } /* Literal.String.Single */
.highlight .ss { color: #aa6600; background-color: #fff0f0 } /* Literal.String.Symbol */
.highlight .bp { color: #003388 } /* Name.Builtin.Pseudo */
.highlight .fm { color: #0066bb; font-weight: bold } /* Name.Function.Magic */
.highlight .vc { color: #336699 } /* Name.Variable.Class */
.highlight .vg { color: #dd7700 } /* Name.Variable.Global */
.highlight .vi { color: #3333bb } /* Name.Variable.Instance */
.highlight .vm { color: #336699 } /* Name.Variable.Magic */
.highlight .il { color: #0000DD; font-weight: bold } /* Literal.Number.Integer.Long */
}
/*
 * Copyright (c) 2018 Cisco and/or its affiliates.
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at:
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

#ifndef __GBP_SCANNER_H__
#define __GBP_SCANNER_H__

#include <vlib/vlib.h>

typedef enum gbp_scan_event_t_
{
  GBP_ENDPOINT_SCAN_START,
  GBP_ENDPOINT_SCAN_STOP,
  GBP_ENDPOINT_SCAN_SET_TIME,
} gbp_scan_event_t;

extern vlib_node_registration_t gbp_scanner_node;

#endif
380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600
/* Hey Emacs use -*- mode: C -*- */
/*
 * Copyright (c) 2015-2020 Cisco and/or its affiliates.
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at:
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

option version = "1.0.1";

import "plugins/ikev2/ikev2_types.api";
import "vnet/ip/ip_types.api";
import "vnet/interface_types.api";

/** \brief Get the plugin version
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
*/
define ikev2_plugin_get_version
{
  u32 client_index;
  u32 context;
};

/** \brief Reply to get the plugin version
    @param context - returned sender context, to match reply w/ request
    @param major - Incremented every time a known breaking behavior change is introduced
    @param minor - Incremented with small changes, may be used to avoid buggy versions
*/
define ikev2_plugin_get_version_reply
{
  u32 context;
  u32 major;
  u32 minor;
};

/** \brief Dump all profiles
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
*/
define ikev2_profile_dump
{
  u32 client_index;
  u32 context;
  option status="in_progress";
};

/** \brief Details about all profiles
    @param context - returned sender context, to match reply w/ request
    @param profile - profile element with encapsulated attributes
*/
define ikev2_profile_details
{
  u32 context;
  vl_api_ikev2_profile_t profile;
  option status="in_progress";
};

/** \brief Dump all SAs
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
*/
define ikev2_sa_dump
{
  u32 client_index;
  u32 context;

  option status = "in_progress";
};

/** \brief Details about IKE SA
    @param context - sender context, to match reply w/ request
    @param retval - return code
    @param sa - SA data
*/
define ikev2_sa_details
{
  u32 context;
  i32 retval;

  vl_api_ikev2_sa_t sa;
  option status = "in_progress";
};

/** \brief Dump child SA of specific SA
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param sa_index - index of specific sa
*/
define ikev2_child_sa_dump
{
  u32 client_index;
  u32 context;

  u32 sa_index;
  option vat_help = "sa_index <index>";
  option status = "in_progress";
};

/** \brief Child SA details
    @param context - sender context, to match reply w/ request
    @param retval - return code
    @param child_sa - child SA data
*/
define ikev2_child_sa_details
{
  u32 context;
  i32 retval;

  vl_api_ikev2_child_sa_t child_sa;
  option status = "in_progress";
};

/** \brief get specific nonce
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param is_initiator - specify type initiator|responder of nonce
    @param sa_index - index of specific sa
*/
define ikev2_nonce_get
{
  u32 client_index;
  u32 context;

  bool is_initiator;
  u32 sa_index;
  option vat_help = "initiator|responder sa_index <index>";
  option status = "in_progress";
};

/** \brief reply on specific nonce
    @param context - sender context, to match reply w/ request
    @param retval - return code
    @param data_len - nonce length
    @param nonce - nonce data
*/

define ikev2_nonce_get_reply
{
  u32 context;
  i32 retval;

  u32 data_len;
  u8 nonce[data_len];
  option status = "in_progress";
};

/** \brief dump traffic selectors
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param is_initiator - specify type initiator|responder of nonce
    @param sa_index - index of specific sa
    @param child_sa_index - index of specific sa child of specific sa
*/

define ikev2_traffic_selector_dump
{
  u32 client_index;
  u32 context;

  bool is_initiator;
  u32 sa_index;
  u32 child_sa_index;
  option vat_help = "initiator|responder sa_index <index> child_sa_index <index>";
  option status = "in_progress";
};

/** \brief details on specific traffic selector
    @param context - sender context, to match reply w/ request
    @param retval - return code
    @param ts - traffic selector data
*/

define ikev2_traffic_selector_details
{
  u32 context;
  i32 retval;

  vl_api_ikev2_ts_t ts;
  option status = "in_progress";
};

/** \brief IKEv2: Add/delete profile
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param is_add - Add IKEv2 profile if non-zero, else delete
*/
autoreply define ikev2_profile_add_del
{
  u32 client_index;
  u32 context;

  string name[64];
  bool is_add;
  option vat_help = "name <profile_name> [del]";
  option status="in_progress";
};

/** \brief IKEv2: Set IKEv2 profile authentication method
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param auth_method - IKEv2 authentication method (shared-key-mic/rsa-sig)
    @param is_hex - Authentication data in hex format if non-zero, else string
    @param data_len - Authentication data length
    @param data - Authentication data (for rsa-sig cert file path)
*/
autoreply define ikev2_profile_set_auth
{
  u32 client_index;
  u32 context;

  string name[64];
  u8 auth_method;
  bool is_hex;
  u32 data_len;
  u8 data[data_len];
  option vat_help = "name <profile_name> auth_method <method> (auth_data 0x<data> | auth_data <data>)";
  option status="in_progress";
};

/** \brief IKEv2: Set IKEv2 profile local/remote identification
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param is_local - Identification is local if non-zero, else remote
    @param id_type - Identification type
    @param data_len - Identification data length
    @param data - Identification data
*/
autoreply define ikev2_profile_set_id
{
  u32 client_index;
  u32 context;

  string name[64];
  bool is_local;
  u8 id_type;
  u32 data_len;
  u8 data[data_len];
  option vat_help = "name <profile_name> id_type <type> (id_data 0x<data> | id_data <data>) (local|remote)";
  option status="in_progress";
};

/** \brief IKEv2: Disable NAT traversal
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
*/
autoreply define ikev2_profile_disable_natt
{
  u32 client_index;
  u32 context;

  string name[64];
  option status="in_progress";
};

/** \brief IKEv2: Set IKEv2 profile traffic selector parameters
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param ts - traffic selector data
*/
autoreply define ikev2_profile_set_ts
{
  u32 client_index;
  u32 context;

  string name[64];
  vl_api_ikev2_ts_t ts;
  option vat_help = "name <profile_name> protocol <proto> start_port <port> end_port <port> start_addr <ip> end_addr <ip> (local|remote)";
  option status="in_progress";
};

/** \brief IKEv2: Set IKEv2 local RSA private key
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param key_file - Key file absolute path
*/
autoreply define ikev2_set_local_key
{
  u32 client_index;
  u32 context;

  string key_file[256];
  option vat_help = "file <absolute_file_path>";
  option status="in_progress";
};

/** \brief IKEv2: Set the tunnel interface which will be protected by IKE
    If this API is not called, a new tunnel will be created
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param sw_if_index - Of an existing tunnel
*/
autoreply define ikev2_set_tunnel_interface
{
  u32 client_index;
  u32 context;
  string name[64];

  vl_api_interface_index_t sw_if_index;
  option status="in_progress";
};

/** \brief IKEv2: Set IKEv2 responder interface and IP address
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param responder - responder data
*/
autoreply define ikev2_set_responder
{
  u32 client_index;
  u32 context;

  string name[64];
  vl_api_ikev2_responder_t responder;
  option vat_help = "<profile_name> interface <interface> address <addr>";
  option status="in_progress";
};

autoreply define ikev2_set_responder_hostname
{
  u32 client_index;
  u32 context;

  string name[64];
  string hostname[64];
  vl_api_interface_index_t sw_if_index;
  option status="in_progress";
};

/** \brief IKEv2: Set IKEv2 IKE transforms in SA_INIT proposal (RFC 7296)
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param tr - IKE transforms
*/
autoreply define ikev2_set_ike_transforms
{
  u32 client_index;
  u32 context;

  string name[64];
  vl_api_ikev2_ike_transforms_t tr;
  option vat_help = "<profile_name> <crypto alg> <key size> <integrity alg> <DH group>";
  option status="in_progress";
};

/** \brief IKEv2: Set IKEv2 ESP transforms in SA_INIT proposal (RFC 7296)
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param tr - ESP transforms
*/
autoreply define ikev2_set_esp_transforms
{
  u32 client_index;
  u32 context;

  string name[64];
  vl_api_ikev2_esp_transforms_t tr;
  option vat_help = "<profile_name> <crypto alg> <key size> <integrity alg>";
  option status="in_progress";
};

/** \brief IKEv2: Set Child SA lifetime, limited by time and/or data
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
    @param lifetime - SA maximum life time in seconds (0 to disable)
    @param lifetime_jitter - Jitter added to prevent simultaneous rekeying
    @param handover - Hand over time
    @param lifetime_maxdata - SA maximum life time in bytes (0 to disable)
*/
autoreply define ikev2_set_sa_lifetime
{
  u32 client_index;
  u32 context;

  string name[64];
  u64 lifetime;
  u32 lifetime_jitter;
  u32 handover;
  u64 lifetime_maxdata;
  option vat_help = "<profile_name> <seconds> <jitter> <handover> <max bytes>";
  option status="in_progress";
};

/** \brief IKEv2: Initiate the SA_INIT exchange
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
*/
autoreply define ikev2_initiate_sa_init
{
  u32 client_index;
  u32 context;

  string name[64];
  option vat_help = "<profile_name>";
  option status="in_progress";
};

/** \brief IKEv2: Initiate the delete IKE SA exchange
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param ispi - IKE SA initiator SPI
*/
autoreply define ikev2_initiate_del_ike_sa
{
  u32 client_index;
  u32 context;

  u64 ispi;
  option vat_help = "<ispi>";
  option status="in_progress";
};

/** \brief IKEv2: Initiate the delete Child SA exchange
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param ispi - Child SA initiator SPI
*/
autoreply define ikev2_initiate_del_child_sa
{
  u32 client_index;
  u32 context;

  u32 ispi;
  option vat_help = "<ispi>";
  option status="in_progress";
};

/** \brief IKEv2: Initiate the rekey Child SA exchange
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param ispi - Child SA initiator SPI
*/
autoreply define ikev2_initiate_rekey_child_sa
{
  u32 client_index;
  u32 context;

  u32 ispi;
  option vat_help = "<ispi>";
  option status="in_progress";
};

/** \brief IKEv2: Set UDP encapsulation
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param name - IKEv2 profile name
*/
autoreply define ikev2_profile_set_udp_encap
{
  u32 client_index;
  u32 context;

  string name[64];
  option status="in_progress";
};

/** \brief IKEv2: Set/unset custom ipsec-over-udp port
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param is_set - whether set or unset custom port
    @param port - port number
    @param name - IKEv2 profile name
*/
autoreply define ikev2_profile_set_ipsec_udp_port
{
  u32 client_index;
  u32 context;

  u8 is_set;
  u16 port;
  string name[64];
  option status="in_progress";
};

/** \brief IKEv2: Set liveness parameters
    @param client_index - opaque cookie to identify the sender
    @param context - sender context, to match reply w/ request
    @param period - how often is liveness check performed
    @param max_retries - max retries for liveness check
*/
autoreply define ikev2_profile_set_liveness
{
  u32 client_index;
  u32 context;

  u32 period;
  u32 max_retries;
  option status="in_progress";
};

counters ikev2 {
  processed {
    severity info;
    type counter64;
    units "packets";
    description "packets processed";
  };
  ike_sa_init_retransmit {
    severity info;
    type counter64;
    units "packets";
    description "IKE SA INIT retransmit";
  };
  ike_sa_init_ignore {
    severity error;
    type counter64;
    units "packets";
    description "IKE_SA_INIT ignore (IKE SA already auth)";
  };
  ike_req_retransmit {
    severity error;
    type counter64;
    units "packets";
    description "IKE request retransmit";
  };
  ike_req_ignore {
    severity error;
    type counter64;
    units "packets";
    description "IKE request ignore (old msgid)";
  };
  not_ikev2 {
    severity error;
    type counter64;
    units "packets";
    description "Non IKEv2 packets received";
  };
  bad_length {
    severity error;
    type counter64;
    units "packets";
    description "Bad packet length";
  };
  malformed_packet {
    severity error;
    type counter64;
    units "packets";
    description "Malformed packet";
  };
  no_buff_space {
    severity error;
    type counter64;
    units "packets";
    description "No buffer space";
  };
  keepalive {
    severity info;
    type counter64;
    units "packets";
    description "IKE keepalive messages received";
  };
  rekey_req {
    severity info;
    type counter64;
    units "packets";
    description "IKE rekey requests received";
  };
  init_sa_req {
    severity info;
    type counter64;
    units "packets";
    description "IKE EXCHANGE SA requests received";
  };
  ike_auth_req {
    severity info;
    type counter64;
    units "packets";
    description "IKE AUTH SA requests received";
  };
};
paths {
  "/err/ikev2-ip4" "ike";
  "/err/ikev2-ip6" "ike";
  "/err/ikev2-ip4-natt" "ike";
};

/*
 * Local Variables:
 * eval: (c-set-style "gnu")
 * End:
 */