2 # In Namespace 0 (at_ns0) using native tunnel
3 # Overlay IP: 10.1.1.100
4 # local 192.16.1.100 remote 192.16.1.200
5 # veth0 IP: 172.16.1.100, tunnel dev <type>00
7 # Out of Namespace using BPF set/get on lwtunnel
8 # Overlay IP: 10.1.1.200
9 # local 172.16.1.200 remote 172.16.1.100
10 # veth1 IP: 172.16.1.200, tunnel dev <type>11
12 function config_device {
14 ip link add veth0 type veth peer name veth1
15 ip link set veth0 netns at_ns0
16 ip netns exec at_ns0 ip addr add 172.16.1.100/24 dev veth0
17 ip netns exec at_ns0 ip link set dev veth0 up
18 ip link set dev veth1 up mtu 1500
19 ip addr add dev veth1 172.16.1.200/24
22 function add_gre_tunnel {
24 ip netns exec at_ns0 \
25 ip link add dev $DEV_NS type $TYPE key 2 local 172.16.1.100 remote 172.16.1.200
26 ip netns exec at_ns0 ip link set dev $DEV_NS up
27 ip netns exec at_ns0 ip addr add dev $DEV_NS 10.1.1.100/24
30 ip link add dev $DEV type $TYPE key 2 external
31 ip link set dev $DEV up
32 ip addr add dev $DEV 10.1.1.200/24
35 function add_erspan_tunnel {
37 ip netns exec at_ns0 \
38 ip link add dev $DEV_NS type $TYPE seq key 2 local 172.16.1.100 remote 172.16.1.200 erspan 123
39 ip netns exec at_ns0 ip link set dev $DEV_NS up
40 ip netns exec at_ns0 ip addr add dev $DEV_NS 10.1.1.100/24
43 ip link add dev $DEV type $TYPE external
44 ip link set dev $DEV up
45 ip addr add dev $DEV 10.1.1.200/24
48 function add_vxlan_tunnel {
49 # Set static ARP entry here because iptables set-mark works
50 # on L3 packet, as a result not applying to ARP packets,
51 # causing errors at get_tunnel_{key/opt}.
54 ip netns exec at_ns0 \
55 ip link add dev $DEV_NS type $TYPE id 2 dstport 4789 gbp remote 172.16.1.200
56 ip netns exec at_ns0 ip link set dev $DEV_NS address 52:54:00:d9:01:00 up
57 ip netns exec at_ns0 ip addr add dev $DEV_NS 10.1.1.100/24
58 ip netns exec at_ns0 arp -s 10.1.1.200 52:54:00:d9:02:00
59 ip netns exec at_ns0 iptables -A OUTPUT -j MARK --set-mark 0x800FF
62 ip link add dev $DEV type $TYPE external gbp dstport 4789
63 ip link set dev $DEV address 52:54:00:d9:02:00 up
64 ip addr add dev $DEV 10.1.1.200/24
65 arp -s 10.1.1.100 52:54:00:d9:01:00
68 function add_geneve_tunnel {
70 ip netns exec at_ns0 \
71 ip link add dev $DEV_NS type $TYPE id 2 dstport 6081 remote 172.16.1.200
72 ip netns exec at_ns0 ip link set dev $DEV_NS up
73 ip netns exec at_ns0 ip addr add dev $DEV_NS 10.1.1.100/24
76 ip link add dev $DEV type $TYPE dstport 6081 external
77 ip link set dev $DEV up
78 ip addr add dev $DEV 10.1.1.200/24
81 function add_ipip_tunnel {
83 ip netns exec at_ns0 \
84 ip link add dev $DEV_NS type $TYPE local 172.16.1.100 remote 172.16.1.200
85 ip netns exec at_ns0 ip link set dev $DEV_NS up
86 ip netns exec at_ns0 ip addr add dev $DEV_NS 10.1.1.100/24
89 ip link add dev $DEV type $TYPE external
90 ip link set dev $DEV up
91 ip addr add dev $DEV 10.1.1.200/24
98 tc qdisc add dev $DEV clsact
99 tc filter add dev $DEV egress bpf da obj tcbpf2_kern.o sec $SET_TUNNEL
100 tc filter add dev $DEV ingress bpf da obj tcbpf2_kern.o sec $GET_TUNNEL
109 attach_bpf $DEV gre_set_tunnel gre_get_tunnel
111 ip netns exec at_ns0 ping -c 1 10.1.1.200
115 function test_erspan {
121 attach_bpf $DEV erspan_set_tunnel erspan_get_tunnel
123 ip netns exec at_ns0 ping -c 1 10.1.1.200
127 function test_vxlan {
133 attach_bpf $DEV vxlan_set_tunnel vxlan_get_tunnel
135 ip netns exec at_ns0 ping -c 1 10.1.1.200
139 function test_geneve {
145 attach_bpf $DEV geneve_set_tunnel geneve_get_tunnel
147 ip netns exec at_ns0 ping -c 1 10.1.1.200
157 cat /sys/kernel/debug/tracing/trace_pipe &
159 ethtool -K veth1 gso off gro off rx off tx off
160 ip link set dev veth1 mtu 1500
161 attach_bpf $DEV ipip_set_tunnel ipip_get_tunnel
163 ip netns exec at_ns0 ping -c 1 10.1.1.200
164 ip netns exec at_ns0 iperf -sD -p 5200 > /dev/null
166 iperf -c 10.1.1.100 -n 5k -p 5200
173 ip netns delete at_ns0
185 trap cleanup 0 2 3 6 9
187 echo "Testing GRE tunnel..."
189 echo "Testing ERSPAN tunnel..."
191 echo "Testing VXLAN tunnel..."
193 echo "Testing GENEVE tunnel..."
195 echo "Testing IPIP tunnel..."