Lines Matching refs:xfrm
4 # Check xfrm policy resolution. Topology:
39 ip -net $ns xfrm policy add src $lnet dst $rnet dir out tmpl src $me dst $remote proto esp mode tunnel priority 100 action allow
41 ip -net $ns xfrm policy add src $rnet dst $lnet dir fwd tmpl src $remote dst $me proto esp mode tunnel priority 100 action allow
53 ip -net $ns xfrm state add src $remote dst $me proto esp spi $spi_in enc aes $KEY_AES auth sha1 $KEY_SHA mode tunnel sel src $rnet dst $lnet
54 ip -net $ns xfrm state add src $me dst $remote proto esp spi $spi_out enc aes $KEY_AES auth sha1 $KEY_SHA mode tunnel sel src $lnet dst $rnet
76 ip -net $ns xfrm policy add src 10.1.0.0/24 dst 10.0.0.0/24 dir fwd priority 200 action block
79 ip -net $ns xfrm policy add src 10.2.0.0/24 dst 10.0.0.0/24 dir fwd priority 200 action block
82 ip -net $ns xfrm policy add src 10.2.0.0/23 dst 10.0.1.0/24 dir fwd priority 200 action block
108 ip -net $ns xfrm policy add src 10.1.0.0/24 dst 10.0.0.0/23 dir fwd priority 200 action block
113 ip -net $ns xfrm policy add src 10.253.1.$((RANDOM%255))/$p dst 10.254.1.$((RANDOM%255))/$p dir fwd priority $((200+k)) action block 2>/dev/null
123 ip -net $ns xfrm policy get src $lnet dst $rnet dir out > /dev/null
126 echo "FAIL: ip -net $ns xfrm policy get src $lnet dst $rnet dir out"
130 ip -net $ns xfrm policy get src $rnet dst $lnet dir fwd > /dev/null
133 echo "FAIL: ip -net $ns xfrm policy get src $rnet dst $lnet dir fwd"
146 ip -net $ns xfrm policy add dst $plain dir out priority 10 action allow
149 ip -net $ns xfrm policy add dst $encryptip dir out tmpl src $me dst $remote proto esp mode tunnel priority 1 action allow
158 echo netns exec $ns ip xfrm policy add src 0.0.0.0/0 dst 10.$i.99.0/30 dir out action block
159 echo netns exec $ns ip xfrm policy add src 10.$i.99.0/30 dst 0.0.0.0/0 dir out action block
161 echo netns exec $ns ip xfrm policy add src 10.$i.1.0/30 dst 10.$i.$j.0/30 dir out action block
163 echo netns exec $ns ip xfrm policy add src 10.$i.1.0/29 dst 10.$i.$j.0/29 dir out action block
165 echo netns exec $ns ip xfrm policy add src 10.$i.1.0/24 dst 10.$i.$j.0/24 dir out action block
166 echo netns exec $ns ip xfrm policy add src 10.$i.$j.0/24 dst 10.$i.1.0/24 dir fwd action block
176 echo netns exec $ns ip xfrm policy add src dead:$i::/64 dst dead:$i:$j::/64 dir out action block
177 echo netns exec $ns ip xfrm policy add src dead:$i:$j::/64 dst dead:$i::/24 dir fwd action block
273 ip -net ns1 xfrm policy update src e000:0001::0000 dst ff01::0014:0000:0001 dir in tmpl src :: dst :: proto esp mode tunnel priority 100 action allow || break
274 ip -net ns1 xfrm policy set hthresh6 0 28 || break
276 ip -net ns1 xfrm policy update src e000:0001::0000 dst ff01::01 dir in tmpl src :: dst :: proto esp mode tunnel priority 100 action allow || break
277 ip -net ns1 xfrm policy set hthresh6 0 28 || break
298 ip -net $ns xfrm policy flush
300 ip -net $ns xfrm policy add dst $j.0.0.0/24 dir out priority 10 action allow
303 if ! ip -net $ns xfrm policy get dst $j.0.0.0/24 dir out > /dev/null; then
311 ip -net $ns xfrm policy flush
314 ip -net $ns xfrm policy add dst $addr dir out priority 10 action allow
318 if ! ip -net $ns xfrm policy get dst $addr dir out > /dev/null; then
325 ip -net $ns xfrm policy flush
455 ip -net $n xfrm policy set hthresh4 28 24 hthresh6 126 125
462 ip -net ns3 xfrm policy flush
468 ip -net ns3 xfrm policy set hthresh4 16 16
475 ip -net $n xfrm policy set hthresh4 32 32 hthresh6 128 128