path: root/tests/py/inet/ipsec.t
authorMáté Eckl <>2018-09-05 11:16:44 +0200
committerFlorian Westphal <>2018-09-21 12:06:27 +0200
commit57c2b152c5f0866be5bf1acda2f341ba26ba9448 (patch)
tree091cabd5ef590d0d0edf0dc972d3cf53ae0008cb /tests/py/inet/ipsec.t
parent8f55ed41d007061bd8aae94fee2bda172c0e8996 (diff)
src: add ipsec (xfrm) expression
This allows matching on ipsec tunnel/beet addresses in xfrm state associated with a packet, ipsec request id and the SPI. Examples: ipsec in ip saddr ipsec out ip6 daddr @endpoints ipsec in spi 1-65536 Joint work with Florian Westphal. Cc: Máté Eckl <> Signed-off-by: Florian Westphal <>
+:ipsec-forw;type filter hook forward priority 0
+ipsec in reqid 1;ok
+ipsec in spnum 0 reqid 1;ok;ipsec in reqid 1
+ipsec out reqid 0xffffffff;ok;ipsec out reqid 4294967295
+ipsec out spnum 0x100000000;fail
+ipsec i reqid 1;fail
+ipsec out spi 1-561;ok
+ipsec in spnum 2 ip saddr {, };ok
+ipsec in ip6 daddr dead::beef;ok
+ipsec out ip6 saddr dead::feed;ok
+ipsec in spnum 256 reqid 1;fail