43 #define vl_print(handle, ...) vlib_cli_output (handle, __VA_ARGS__) 50 #define foreach_vpe_api_msg \ 51 _(IPSEC_SPD_ADD_DEL, ipsec_spd_add_del) \ 52 _(IPSEC_INTERFACE_ADD_DEL_SPD, ipsec_interface_add_del_spd) \ 53 _(IPSEC_SPD_ADD_DEL_ENTRY, ipsec_spd_add_del_entry) \ 54 _(IPSEC_SAD_ADD_DEL_ENTRY, ipsec_sad_add_del_entry) \ 55 _(IPSEC_SA_SET_KEY, ipsec_sa_set_key) \ 56 _(IPSEC_SPD_DUMP, ipsec_spd_dump) \ 57 _(IPSEC_TUNNEL_IF_ADD_DEL, ipsec_tunnel_if_add_del) \ 58 _(IKEV2_PROFILE_ADD_DEL, ikev2_profile_add_del) \ 59 _(IKEV2_PROFILE_SET_AUTH, ikev2_profile_set_auth) \ 60 _(IKEV2_PROFILE_SET_ID, ikev2_profile_set_id) \ 61 _(IKEV2_PROFILE_SET_TS, ikev2_profile_set_ts) \ 62 _(IKEV2_SET_LOCAL_KEY, ikev2_set_local_key) \ 63 _(IKEV2_SET_RESPONDER, ikev2_set_responder) \ 64 _(IKEV2_SET_IKE_TRANSFORMS, ikev2_set_ike_transforms) \ 65 _(IKEV2_SET_ESP_TRANSFORMS, ikev2_set_esp_transforms) \ 66 _(IKEV2_SET_SA_LIFETIME, ikev2_set_sa_lifetime) \ 67 _(IKEV2_INITIATE_SA_INIT, ikev2_initiate_sa_init) \ 68 _(IKEV2_INITIATE_DEL_IKE_SA, ikev2_initiate_del_ike_sa) \ 69 _(IKEV2_INITIATE_DEL_CHILD_SA, ikev2_initiate_del_child_sa) \ 70 _(IKEV2_INITIATE_REKEY_CHILD_SA, ikev2_initiate_rekey_child_sa) 80 vl_api_ipsec_spd_add_del_reply_t *rmp;
93 vl_api_ipsec_interface_add_del_spd_reply_t *rmp;
95 u32 sw_if_index __attribute__ ((unused));
96 u32 spd_id __attribute__ ((unused));
99 spd_id = ntohl (mp->
spd_id);
106 rv = VNET_API_ERROR_UNIMPLEMENTED;
111 REPLY_MACRO (VL_API_IPSEC_INTERFACE_ADD_DEL_SPD_REPLY);
118 vl_api_ipsec_spd_add_del_entry_reply_t *rmp;
124 memset (&p, 0,
sizeof (p));
151 if (mp->
policy == IPSEC_POLICY_ACTION_RESOLVE)
154 rv = VNET_API_ERROR_UNIMPLEMENTED;
170 rv = VNET_API_ERROR_UNIMPLEMENTED;
175 REPLY_MACRO (VL_API_IPSEC_SPD_ADD_DEL_ENTRY_REPLY);
182 vl_api_ipsec_sad_add_del_entry_reply_t *rmp;
188 memset (&sa, 0,
sizeof (sa));
196 rv = VNET_API_ERROR_UNIMPLEMENTED;
206 rv = VNET_API_ERROR_UNIMPLEMENTED;
217 rv = VNET_API_ERROR_UNIMPLEMENTED;
243 rv = VNET_API_ERROR_UNIMPLEMENTED;
249 rv = VNET_API_ERROR_UNIMPLEMENTED;
254 REPLY_MACRO (VL_API_IPSEC_SAD_ADD_DEL_ENTRY_REPLY);
264 memset (mp, 0,
sizeof (*mp));
265 mp->_vl_msg_id = ntohs (VL_API_IPSEC_SPD_DETAILS);
323 if (mp->sa_id == ~(0) || ntohl (mp->sa_id) == policy->sa_id)
324 send_ipsec_spd_details (policy, q,
337 vl_api_ipsec_sa_set_key_reply_t *rmp;
349 rv = VNET_API_ERROR_UNIMPLEMENTED;
362 u32 sw_if_index = ~0;
395 rv = VNET_API_ERROR_UNIMPLEMENTED;
409 vl_api_ikev2_profile_add_del_reply_t *rmp;
419 rv = VNET_API_ERROR_UNSPECIFIED;
421 rv = VNET_API_ERROR_UNIMPLEMENTED;
431 vl_api_ikev2_profile_set_auth_reply_t *rmp;
444 rv = VNET_API_ERROR_UNSPECIFIED;
446 rv = VNET_API_ERROR_UNIMPLEMENTED;
455 vl_api_ikev2_profile_add_del_reply_t *rmp;
468 rv = VNET_API_ERROR_UNSPECIFIED;
470 rv = VNET_API_ERROR_UNIMPLEMENTED;
479 vl_api_ikev2_profile_set_ts_reply_t *rmp;
491 rv = VNET_API_ERROR_UNSPECIFIED;
493 rv = VNET_API_ERROR_UNIMPLEMENTED;
502 vl_api_ikev2_profile_set_ts_reply_t *rmp;
511 rv = VNET_API_ERROR_UNSPECIFIED;
513 rv = VNET_API_ERROR_UNIMPLEMENTED;
522 vl_api_ikev2_set_responder_reply_t *rmp;
536 rv = VNET_API_ERROR_UNSPECIFIED;
538 rv = VNET_API_ERROR_UNIMPLEMENTED;
548 vl_api_ikev2_set_ike_transforms_reply_t *rmp;
562 rv = VNET_API_ERROR_UNSPECIFIED;
564 rv = VNET_API_ERROR_UNIMPLEMENTED;
567 REPLY_MACRO (VL_API_IKEV2_SET_IKE_TRANSFORMS_REPLY);
574 vl_api_ikev2_set_esp_transforms_reply_t *rmp;
588 rv = VNET_API_ERROR_UNSPECIFIED;
590 rv = VNET_API_ERROR_UNIMPLEMENTED;
593 REPLY_MACRO (VL_API_IKEV2_SET_ESP_TRANSFORMS_REPLY);
599 vl_api_ikev2_set_sa_lifetime_reply_t *rmp;
613 rv = VNET_API_ERROR_UNSPECIFIED;
615 rv = VNET_API_ERROR_UNIMPLEMENTED;
624 vl_api_ikev2_initiate_sa_init_reply_t *rmp;
636 rv = VNET_API_ERROR_UNSPECIFIED;
638 rv = VNET_API_ERROR_UNIMPLEMENTED;
648 vl_api_ikev2_initiate_del_ike_sa_reply_t *rmp;
657 rv = VNET_API_ERROR_UNSPECIFIED;
659 rv = VNET_API_ERROR_UNIMPLEMENTED;
662 REPLY_MACRO (VL_API_IKEV2_INITIATE_DEL_IKE_SA_REPLY);
669 vl_api_ikev2_initiate_del_child_sa_reply_t *rmp;
678 rv = VNET_API_ERROR_UNSPECIFIED;
680 rv = VNET_API_ERROR_UNIMPLEMENTED;
683 REPLY_MACRO (VL_API_IKEV2_INITIATE_DEL_CHILD_SA_REPLY);
690 vl_api_ikev2_initiate_rekey_child_sa_reply_t *rmp;
699 rv = VNET_API_ERROR_UNSPECIFIED;
701 rv = VNET_API_ERROR_UNIMPLEMENTED;
704 REPLY_MACRO (VL_API_IKEV2_INITIATE_REKEY_CHILD_SA_REPLY);
714 #define vl_msg_name_crc_list 716 #undef vl_msg_name_crc_list 721 #define _(id,n,crc) vl_msg_api_add_msg_name_crc (am, #n "_" #crc, id); 722 foreach_vl_msg_name_crc_ipsec;
732 vl_msg_api_set_handlers(VL_API_##N, #n, \ 733 vl_api_##n##_t_handler, \ 735 vl_api_##n##_t_endian, \ 736 vl_api_##n##_t_print, \ 737 sizeof(vl_api_##n##_t), 1);
static void vl_api_ikev2_profile_set_auth_t_handler(vl_api_ikev2_profile_set_auth_t *mp)
static void vl_api_ipsec_sa_set_key_t_handler(vl_api_ipsec_sa_set_key_t *mp)
static void vl_api_ikev2_set_local_key_t_handler(vl_api_ikev2_set_local_key_t *mp)
u8 use_extended_sequence_number
clib_error_t * ikev2_set_profile_responder(vlib_main_t *vm, u8 *name, u32 sw_if_index, ip4_address_t ip4)
int ipsec_add_del_policy(vlib_main_t *vm, ipsec_policy_t *policy, int is_add)
ip46_address_t tunnel_src_addr
IKEv2: Set Child SA lifetime, limited by time and/or data.
clib_error_t * ikev2_add_del_profile(vlib_main_t *vm, u8 *name, int is_add)
static void vl_api_ikev2_initiate_rekey_child_sa_t_handler(vl_api_ikev2_initiate_rekey_child_sa_t *mp)
u8 tunnel_dst_address[16]
IKEv2: Add/delete profile.
VLIB_API_INIT_FUNCTION(ipsec_api_hookup)
IPsec: Update Security Association keys.
int ipsec_set_interface_spd(vlib_main_t *vm, u32 sw_if_index, u32 spd_id, int is_add)
clib_error_t * ikev2_initiate_delete_ike_sa(vlib_main_t *vm, u64 ispi)
#define REPLY_MACRO2(t, body)
ipsec_integ_alg_t integ_alg
IPsec: Add/delete Security Policy Database entry.
u8 remote_crypto_key[128]
static void setup_message_id_table(api_main_t *am)
static void vl_api_ipsec_spd_add_del_entry_t_handler(vl_api_ipsec_spd_add_del_entry_t *mp)
clib_error_t * ikev2_set_profile_sa_lifetime(vlib_main_t *vm, u8 *name, u64 lifetime, u32 jitter, u32 handover, u64 maxdata)
#define foreach_vpe_api_msg
int ipsec_add_del_spd(vlib_main_t *vm, u32 spd_id, int is_add)
static void vl_api_ipsec_interface_add_del_spd_t_handler(vl_api_ipsec_interface_add_del_spd_t *mp)
u8 local_address_start[16]
#define pool_foreach(VAR, POOL, BODY)
Iterate through pool.
clib_error_t * ikev2_initiate_sa_init(vlib_main_t *vm, u8 *name)
#define vec_new(T, N)
Create new vector of given type and length (unspecified alignment, no header).
clib_error_t * ikev2_set_profile_auth(vlib_main_t *vm, u8 *name, u8 auth_method, u8 *auth_data, u8 data_hex_format)
static void vl_api_ipsec_tunnel_if_add_del_t_handler(vl_api_ipsec_tunnel_if_add_del_t *mp)
static void vl_api_ikev2_set_responder_t_handler(vl_api_ikev2_set_responder_t *mp)
static void vl_api_ipsec_spd_dump_t_handler(vl_api_ipsec_spd_dump_t *mp)
static void vl_api_ikev2_profile_set_ts_t_handler(vl_api_ikev2_profile_set_ts_t *mp)
ipsec_main_callbacks_t cb
IKEv2: Initiate the delete Child SA exchange.
clib_error_t * ikev2_set_profile_esp_transforms(vlib_main_t *vm, u8 *name, ikev2_transform_encr_type_t crypto_alg, ikev2_transform_integ_type_t integ_alg, ikev2_transform_dh_type_t dh_type, u32 crypto_key_size)
IKEv2: Set IKEv2 profile local/remote identification.
IKEv2: Set IKEv2 profile traffic selector parameters.
static void vl_api_ikev2_initiate_del_child_sa_t_handler(vl_api_ikev2_initiate_del_child_sa_t *mp)
u8 * format_ipsec_crypto_alg(u8 *s, va_list *args)
ipsec_policy_t * policies
void * vl_msg_api_alloc(int nbytes)
static void vl_api_ipsec_spd_add_del_t_handler(vl_api_ipsec_spd_add_del_t *mp)
u8 local_address_stop[16]
clib_error_t * ikev2_set_profile_id(vlib_main_t *vm, u8 *name, u8 id_type, u8 *data, int is_local)
#define pool_elt_at_index(p, i)
Returns pointer to element at given index.
u8 remote_crypto_key[128]
counter_t packets
packet counter
Add/delete IPsec tunnel interface response.
IKEv2: Initiate the rekey Child SA exchange.
clib_error_t *(* check_support_cb)(ipsec_sa_t *sa)
IPsec: Add/delete Security Policy Database.
clib_error_t * ikev2_initiate_delete_child_sa(vlib_main_t *vm, u32 ispi)
static void vl_api_ikev2_initiate_sa_init_t_handler(vl_api_ikev2_initiate_sa_init_t *mp)
static void vl_api_ikev2_set_sa_lifetime_t_handler(vl_api_ikev2_set_sa_lifetime_t *mp)
ip46_address_range_t laddr
static void vl_api_ikev2_set_ike_transforms_t_handler(vl_api_ikev2_set_ike_transforms_t *mp)
uword * spd_index_by_spd_id
clib_error_t * ikev2_set_local_key(vlib_main_t *vm, u8 *file)
clib_error_t * ikev2_set_profile_ts(vlib_main_t *vm, u8 *name, u8 protocol_id, u16 start_port, u16 end_port, ip4_address_t start_addr, ip4_address_t end_addr, int is_local)
ip46_address_t tunnel_dst_addr
#define BAD_SW_IF_INDEX_LABEL
IPsec: Add/delete SPD from interface.
clib_error_t * ikev2_initiate_rekey_child_sa(vlib_main_t *vm, u32 ispi)
ipsec_crypto_alg_t crypto_alg
static void vl_api_ikev2_set_esp_transforms_t_handler(vl_api_ikev2_set_esp_transforms_t *mp)
u8 remote_address_stop[16]
int ipsec_add_del_sa(vlib_main_t *vm, ipsec_sa_t *new_sa, int is_add)
#define vec_free(V)
Free vector's memory (no header).
IPsec: Add/delete Security Association Database entry.
#define clib_warning(format, args...)
#define clib_memcpy(a, b, c)
unix_shared_memory_queue_t * vl_api_client_index_to_input_queue(u32 index)
u8 remote_address_start[16]
int ipsec_set_sa_key(vlib_main_t *vm, ipsec_sa_t *sa_update)
u8 tunnel_src_address[16]
IKEv2: Initiate the SA_INIT exchange.
static void vl_api_ipsec_sad_add_del_entry_t_handler(vl_api_ipsec_sad_add_del_entry_t *mp)
ip46_address_range_t raddr
void vl_msg_api_send_shmem(unix_shared_memory_queue_t *q, u8 *elem)
IKEv2: Set IKEv2 responder interface and IP address.
ipsec_integ_alg_t integ_alg
IKEv2: Initiate the delete IKE SA exchange.
IKEv2: Set IKEv2 profile authentication method.
Dump ipsec policy database data.
ipsec_protocol_t protocol
static vlib_main_t * vlib_get_main(void)
IPsec policy database response.
u8 * format_ipsec_integ_alg(u8 *s, va_list *args)
counter_t bytes
byte counter
static void vl_api_ikev2_profile_set_id_t_handler(vl_api_ikev2_profile_set_id_t *mp)
int ipsec_add_del_tunnel_if_internal(vnet_main_t *vnm, ipsec_add_del_tunnel_args_t *args, u32 *sw_if_index)
IKEv2: Set IKEv2 local RSA private key.
static void send_ipsec_spd_details(ipsec_policy_t *p, unix_shared_memory_queue_t *q, u32 context)
clib_error_t * ikev2_set_profile_ike_transforms(vlib_main_t *vm, u8 *name, ikev2_transform_encr_type_t crypto_alg, ikev2_transform_integ_type_t integ_alg, ikev2_transform_dh_type_t dh_type, u32 crypto_key_size)
static void vl_api_ikev2_profile_add_del_t_handler(vl_api_ikev2_profile_add_del_t *mp)
ipsec_crypto_alg_t crypto_alg
static void vl_api_ikev2_initiate_del_ike_sa_t_handler(vl_api_ikev2_initiate_del_ike_sa_t *mp)
static clib_error_t * ipsec_api_hookup(vlib_main_t *vm)
Add or delete IPsec tunnel interface.
#define VALIDATE_SW_IF_INDEX(mp)
struct _unix_shared_memory_queue unix_shared_memory_queue_t