2 # SPDX-License-Identifier: GPL-2.0
3 # In Namespace 0 (at_ns0) using native tunnel
4 # Overlay IP: 10.1.1.100
5 # local 192.16.1.100 remote 192.16.1.200
6 # veth0 IP: 172.16.1.100, tunnel dev <type>00
8 # Out of Namespace using BPF set/get on lwtunnel
9 # Overlay IP: 10.1.1.200
10 # local 172.16.1.200 remote 172.16.1.100
11 # veth1 IP: 172.16.1.200, tunnel dev <type>11
13 function config_device
{
15 ip link add veth0
type veth peer name veth1
16 ip link
set veth0 netns at_ns0
17 ip netns
exec at_ns0 ip addr add
172.16.1.100/24 dev veth0
18 ip netns
exec at_ns0 ip link
set dev veth0 up
19 ip link
set dev veth1 up mtu
1500
20 ip addr add dev veth1
172.16.1.200/24
23 function add_gre_tunnel
{
25 ip netns
exec at_ns0 \
26 ip link add dev
$DEV_NS type $TYPE key
2 local 172.16.1.100 remote
172.16.1.200
27 ip netns
exec at_ns0 ip link
set dev
$DEV_NS up
28 ip netns
exec at_ns0 ip addr add dev
$DEV_NS 10.1.1.100/24
31 ip link add dev
$DEV type $TYPE key
2 external
32 ip link
set dev
$DEV up
33 ip addr add dev
$DEV 10.1.1.200/24
36 function add_ip6gretap_tunnel
{
39 ip netns
exec at_ns0 ip addr add
::11/96 dev veth0
40 ip netns
exec at_ns0 ip link
set dev veth0 up
41 ip addr add dev veth1
::22/96
42 ip link
set dev veth1 up
45 ip netns
exec at_ns0 \
46 ip link add dev
$DEV_NS type $TYPE flowlabel
0xbcdef key
2 \
47 local ::11 remote
::22
49 ip netns
exec at_ns0 ip addr add dev
$DEV_NS 10.1.1.100/24
50 ip netns
exec at_ns0 ip addr add dev
$DEV_NS fc80
::100/96
51 ip netns
exec at_ns0 ip link
set dev
$DEV_NS up
54 ip link add dev
$DEV type $TYPE external
55 ip addr add dev
$DEV 10.1.1.200/24
56 ip addr add dev
$DEV fc80
::200/24
57 ip link
set dev
$DEV up
60 function add_erspan_tunnel
{
62 if [ "$1" == "v1" ]; then
63 ip netns
exec at_ns0 \
64 ip link add dev
$DEV_NS type $TYPE seq key
2 \
65 local 172.16.1.100 remote
172.16.1.200 \
66 erspan_ver
1 erspan
123
68 ip netns
exec at_ns0 \
69 ip link add dev
$DEV_NS type $TYPE seq key
2 \
70 local 172.16.1.100 remote
172.16.1.200 \
71 erspan_ver
2 erspan_dir egress erspan_hwid
3
73 ip netns
exec at_ns0 ip link
set dev
$DEV_NS up
74 ip netns
exec at_ns0 ip addr add dev
$DEV_NS 10.1.1.100/24
77 ip link add dev
$DEV type $TYPE external
78 ip link
set dev
$DEV up
79 ip addr add dev
$DEV 10.1.1.200/24
82 function add_ip6erspan_tunnel
{
85 ip netns
exec at_ns0 ip addr add
::11/96 dev veth0
86 ip netns
exec at_ns0 ip link
set dev veth0 up
87 ip addr add dev veth1
::22/96
88 ip link
set dev veth1 up
91 if [ "$1" == "v1" ]; then
92 ip netns
exec at_ns0 \
93 ip link add dev
$DEV_NS type $TYPE seq key
2 \
94 local ::11 remote
::22 \
95 erspan_ver
1 erspan
123
97 ip netns
exec at_ns0 \
98 ip link add dev
$DEV_NS type $TYPE seq key
2 \
99 local ::11 remote
::22 \
100 erspan_ver
2 erspan_dir egress erspan_hwid
7
102 ip netns
exec at_ns0 ip addr add dev
$DEV_NS 10.1.1.100/24
103 ip netns
exec at_ns0 ip link
set dev
$DEV_NS up
106 ip link add dev
$DEV type $TYPE external
107 ip addr add dev
$DEV 10.1.1.200/24
108 ip link
set dev
$DEV up
111 function add_vxlan_tunnel
{
112 # Set static ARP entry here because iptables set-mark works
113 # on L3 packet, as a result not applying to ARP packets,
114 # causing errors at get_tunnel_{key/opt}.
117 ip netns
exec at_ns0 \
118 ip link add dev
$DEV_NS type $TYPE id
2 dstport
4789 gbp remote
172.16.1.200
119 ip netns
exec at_ns0 ip link
set dev
$DEV_NS address
52:54:00:d9
:01:00 up
120 ip netns
exec at_ns0 ip addr add dev
$DEV_NS 10.1.1.100/24
121 ip netns
exec at_ns0 arp
-s 10.1.1.200 52:54:00:d9
:02:00
122 ip netns
exec at_ns0 iptables
-A OUTPUT
-j MARK
--set-mark 0x800FF
125 ip link add dev
$DEV type $TYPE external gbp dstport
4789
126 ip link
set dev
$DEV address
52:54:00:d9
:02:00 up
127 ip addr add dev
$DEV 10.1.1.200/24
128 arp
-s 10.1.1.100 52:54:00:d9
:01:00
131 function add_geneve_tunnel
{
133 ip netns
exec at_ns0 \
134 ip link add dev
$DEV_NS type $TYPE id
2 dstport
6081 remote
172.16.1.200
135 ip netns
exec at_ns0 ip link
set dev
$DEV_NS up
136 ip netns
exec at_ns0 ip addr add dev
$DEV_NS 10.1.1.100/24
139 ip link add dev
$DEV type $TYPE dstport
6081 external
140 ip link
set dev
$DEV up
141 ip addr add dev
$DEV 10.1.1.200/24
144 function add_ipip_tunnel
{
146 ip netns
exec at_ns0 \
147 ip link add dev
$DEV_NS type $TYPE local 172.16.1.100 remote
172.16.1.200
148 ip netns
exec at_ns0 ip link
set dev
$DEV_NS up
149 ip netns
exec at_ns0 ip addr add dev
$DEV_NS 10.1.1.100/24
152 ip link add dev
$DEV type $TYPE external
153 ip link
set dev
$DEV up
154 ip addr add dev
$DEV 10.1.1.200/24
157 function attach_bpf
{
161 tc qdisc add dev
$DEV clsact
162 tc filter add dev
$DEV egress bpf da obj tcbpf2_kern.o sec
$SET_TUNNEL
163 tc filter add dev
$DEV ingress bpf da obj tcbpf2_kern.o sec
$GET_TUNNEL
172 attach_bpf
$DEV gre_set_tunnel gre_get_tunnel
174 ip netns
exec at_ns0
ping -c 1 10.1.1.200
178 function test_ip6gre
{
183 # reuse the ip6gretap function
185 attach_bpf
$DEV ip6gretap_set_tunnel ip6gretap_get_tunnel
188 # overlay: ipv4 over ipv6
189 ip netns
exec at_ns0
ping -c 1 10.1.1.200
191 # overlay: ipv6 over ipv6
192 ip netns
exec at_ns0 ping6
-c 1 fc80
::200
196 function test_ip6gretap
{
202 attach_bpf
$DEV ip6gretap_set_tunnel ip6gretap_get_tunnel
205 # overlay: ipv4 over ipv6
206 ip netns
exec at_ns0
ping -i .2 -c 1 10.1.1.200
208 # overlay: ipv6 over ipv6
209 ip netns
exec at_ns0 ping6
-c 1 fc80
::200
213 function test_erspan
{
219 attach_bpf
$DEV erspan_set_tunnel erspan_get_tunnel
221 ip netns
exec at_ns0
ping -c 1 10.1.1.200
225 function test_ip6erspan
{
230 add_ip6erspan_tunnel
$1
231 attach_bpf
$DEV ip4ip6erspan_set_tunnel ip4ip6erspan_get_tunnel
233 ip netns
exec at_ns0
ping -c 1 10.1.1.200
237 function test_vxlan
{
243 attach_bpf
$DEV vxlan_set_tunnel vxlan_get_tunnel
245 ip netns
exec at_ns0
ping -c 1 10.1.1.200
249 function test_geneve
{
255 attach_bpf
$DEV geneve_set_tunnel geneve_get_tunnel
257 ip netns
exec at_ns0
ping -c 1 10.1.1.200
267 cat /sys
/kernel
/debug
/tracing
/trace_pipe
&
269 ethtool
-K veth1 gso off gro off rx off tx off
270 ip link
set dev veth1 mtu
1500
271 attach_bpf
$DEV ipip_set_tunnel ipip_get_tunnel
273 ip netns
exec at_ns0
ping -c 1 10.1.1.200
274 ip netns
exec at_ns0 iperf
-sD -p 5200 > /dev
/null
276 iperf
-c 10.1.1.100 -n 5k
-p 5200
283 ip netns delete at_ns0
288 ip link del ip6gretap11
292 ip link del ip6erspan11
298 trap cleanup
0 2 3 6 9
300 echo "Testing GRE tunnel..."
302 echo "Testing IP6GRE tunnel..."
304 echo "Testing IP6GRETAP tunnel..."
306 echo "Testing ERSPAN tunnel..."
309 echo "Testing IP6ERSPAN tunnel..."
312 echo "Testing VXLAN tunnel..."
314 echo "Testing GENEVE tunnel..."
316 echo "Testing IPIP tunnel..."