diff options
author | Joel Sing <jsing@cvs.openbsd.org> | 2009-08-04 15:07:55 +0000 |
---|---|---|
committer | Joel Sing <jsing@cvs.openbsd.org> | 2009-08-04 15:07:55 +0000 |
commit | 5f8fc53e356648169689e69de3773381d04f7d95 (patch) | |
tree | 3c36594f09f25c74432c7d22fdd0a4b86185c805 /regress/sbin/ipsecctl | |
parent | aebe16329c0eba9d780166a62a4c9159c68da6fe (diff) |
Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.
ok hshoexer@
Diffstat (limited to 'regress/sbin/ipsecctl')
-rw-r--r-- | regress/sbin/ipsecctl/Makefile | 3 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike63.in | 2 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike63.ok | 23 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike64.in | 2 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike64.ok | 23 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike65.in | 2 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike65.ok | 26 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike66.in | 2 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike66.ok | 23 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike67.in | 2 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike67.ok | 23 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike68.in | 2 | ||||
-rw-r--r-- | regress/sbin/ipsecctl/ike68.ok | 26 |
13 files changed, 158 insertions, 1 deletions
diff --git a/regress/sbin/ipsecctl/Makefile b/regress/sbin/ipsecctl/Makefile index 963e4d19649..5cc945af13f 100644 --- a/regress/sbin/ipsecctl/Makefile +++ b/regress/sbin/ipsecctl/Makefile @@ -1,4 +1,4 @@ -# $OpenBSD: Makefile,v 1.56 2009/01/30 14:24:52 bluhm Exp $ +# $OpenBSD: Makefile,v 1.57 2009/08/04 15:07:54 jsing Exp $ # you can update the *.ok files with: make -i | patch # TARGETS @@ -20,6 +20,7 @@ IKETESTS=1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 IKETESTS+=16 17 18 19 20 21 22 23 IKETESTS+=29 30 31 32 33 34 35 36 37 38 39 40 IKETESTS+=41 42 43 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 +IKETESTS+=63 64 65 66 67 68 IKEDELTESTS=1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 IKEDELTESTS+=16 17 18 19 20 21 22 23 diff --git a/regress/sbin/ipsecctl/ike63.in b/regress/sbin/ipsecctl/ike63.in new file mode 100644 index 00000000000..3d655f4849a --- /dev/null +++ b/regress/sbin/ipsecctl/ike63.in @@ -0,0 +1,2 @@ +ike from 10.1.1.0/24 to 10.1.2.0/24 peer 1.1.1.1 \ + srcid 2.2.2.2 diff --git a/regress/sbin/ipsecctl/ike63.ok b/regress/sbin/ipsecctl/ike63.ok new file mode 100644 index 00000000000..e01e9f08789 --- /dev/null +++ b/regress/sbin/ipsecctl/ike63.ok @@ -0,0 +1,23 @@ +C set [Phase 1]:1.1.1.1=peer-1.1.1.1 force +C set [peer-1.1.1.1]:Phase=1 force +C set [peer-1.1.1.1]:Address=1.1.1.1 force +C set [peer-1.1.1.1]:Configuration=phase1-peer-1.1.1.1 force +C set [phase1-peer-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force +C add [phase1-peer-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force +C set [peer-1.1.1.1]:ID=id-2.2.2.2 force +C set [id-2.2.2.2]:ID-type=IPV4_ADDR force +C set [id-2.2.2.2]:Address=2.2.2.2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Phase=2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:ISAKMP-peer=peer-1.1.1.1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Configuration=phase2-from-10.1.1.0/24-to-10.1.2.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Local-ID=from-10.1.1.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Remote-ID=to-10.1.2.0/24 force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [from-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [from-10.1.1.0/24]:Network=10.1.1.0 force +C set [from-10.1.1.0/24]:Netmask=255.255.255.0 force +C set [to-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [to-10.1.2.0/24]:Network=10.1.2.0 force +C set [to-10.1.2.0/24]:Netmask=255.255.255.0 force +C add [Phase 2]:Connections=from-10.1.1.0/24-to-10.1.2.0/24 diff --git a/regress/sbin/ipsecctl/ike64.in b/regress/sbin/ipsecctl/ike64.in new file mode 100644 index 00000000000..d0eb1839061 --- /dev/null +++ b/regress/sbin/ipsecctl/ike64.in @@ -0,0 +1,2 @@ +ike from 10.1.1.0/24 to 10.1.2.0/24 peer 1.1.1.1 \ + dstid 1.1.1.1 diff --git a/regress/sbin/ipsecctl/ike64.ok b/regress/sbin/ipsecctl/ike64.ok new file mode 100644 index 00000000000..e0beaef2c31 --- /dev/null +++ b/regress/sbin/ipsecctl/ike64.ok @@ -0,0 +1,23 @@ +C set [Phase 1]:1.1.1.1=peer-1.1.1.1 force +C set [peer-1.1.1.1]:Phase=1 force +C set [peer-1.1.1.1]:Address=1.1.1.1 force +C set [peer-1.1.1.1]:Configuration=phase1-peer-1.1.1.1 force +C set [phase1-peer-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force +C add [phase1-peer-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force +C set [peer-1.1.1.1]:Remote-ID=id-1.1.1.1 force +C set [id-1.1.1.1]:ID-type=IPV4_ADDR force +C set [id-1.1.1.1]:Address=1.1.1.1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Phase=2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:ISAKMP-peer=peer-1.1.1.1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Configuration=phase2-from-10.1.1.0/24-to-10.1.2.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Local-ID=from-10.1.1.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Remote-ID=to-10.1.2.0/24 force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [from-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [from-10.1.1.0/24]:Network=10.1.1.0 force +C set [from-10.1.1.0/24]:Netmask=255.255.255.0 force +C set [to-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [to-10.1.2.0/24]:Network=10.1.2.0 force +C set [to-10.1.2.0/24]:Netmask=255.255.255.0 force +C add [Phase 2]:Connections=from-10.1.1.0/24-to-10.1.2.0/24 diff --git a/regress/sbin/ipsecctl/ike65.in b/regress/sbin/ipsecctl/ike65.in new file mode 100644 index 00000000000..de5aa2ccbd5 --- /dev/null +++ b/regress/sbin/ipsecctl/ike65.in @@ -0,0 +1,2 @@ +ike from 10.1.1.0/24 to 10.1.2.0/24 peer 1.1.1.1 \ + srcid 2.2.2.2 dstid 1.1.1.1 diff --git a/regress/sbin/ipsecctl/ike65.ok b/regress/sbin/ipsecctl/ike65.ok new file mode 100644 index 00000000000..e8bd73fcae1 --- /dev/null +++ b/regress/sbin/ipsecctl/ike65.ok @@ -0,0 +1,26 @@ +C set [Phase 1]:1.1.1.1=peer-1.1.1.1 force +C set [peer-1.1.1.1]:Phase=1 force +C set [peer-1.1.1.1]:Address=1.1.1.1 force +C set [peer-1.1.1.1]:Configuration=phase1-peer-1.1.1.1 force +C set [phase1-peer-1.1.1.1]:EXCHANGE_TYPE=ID_PROT force +C add [phase1-peer-1.1.1.1]:Transforms=AES-SHA-RSA_SIG force +C set [peer-1.1.1.1]:ID=id-2.2.2.2 force +C set [id-2.2.2.2]:ID-type=IPV4_ADDR force +C set [id-2.2.2.2]:Address=2.2.2.2 force +C set [peer-1.1.1.1]:Remote-ID=id-1.1.1.1 force +C set [id-1.1.1.1]:ID-type=IPV4_ADDR force +C set [id-1.1.1.1]:Address=1.1.1.1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Phase=2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:ISAKMP-peer=peer-1.1.1.1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Configuration=phase2-from-10.1.1.0/24-to-10.1.2.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Local-ID=from-10.1.1.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Remote-ID=to-10.1.2.0/24 force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [from-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [from-10.1.1.0/24]:Network=10.1.1.0 force +C set [from-10.1.1.0/24]:Netmask=255.255.255.0 force +C set [to-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [to-10.1.2.0/24]:Network=10.1.2.0 force +C set [to-10.1.2.0/24]:Netmask=255.255.255.0 force +C add [Phase 2]:Connections=from-10.1.1.0/24-to-10.1.2.0/24 diff --git a/regress/sbin/ipsecctl/ike66.in b/regress/sbin/ipsecctl/ike66.in new file mode 100644 index 00000000000..b177fef89f2 --- /dev/null +++ b/regress/sbin/ipsecctl/ike66.in @@ -0,0 +1,2 @@ +ike from 10.1.1.0/24 to 10.1.2.0/24 peer 3ffe::1 \ + srcid 3ffe::2 diff --git a/regress/sbin/ipsecctl/ike66.ok b/regress/sbin/ipsecctl/ike66.ok new file mode 100644 index 00000000000..3c833ea79bf --- /dev/null +++ b/regress/sbin/ipsecctl/ike66.ok @@ -0,0 +1,23 @@ +C set [Phase 1]:3ffe::1=peer-3ffe::1 force +C set [peer-3ffe::1]:Phase=1 force +C set [peer-3ffe::1]:Address=3ffe::1 force +C set [peer-3ffe::1]:Configuration=phase1-peer-3ffe::1 force +C set [phase1-peer-3ffe::1]:EXCHANGE_TYPE=ID_PROT force +C add [phase1-peer-3ffe::1]:Transforms=AES-SHA-RSA_SIG force +C set [peer-3ffe::1]:ID=id-3ffe::2 force +C set [id-3ffe::2]:ID-type=IPV6_ADDR force +C set [id-3ffe::2]:Address=3ffe::2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Phase=2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:ISAKMP-peer=peer-3ffe::1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Configuration=phase2-from-10.1.1.0/24-to-10.1.2.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Local-ID=from-10.1.1.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Remote-ID=to-10.1.2.0/24 force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [from-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [from-10.1.1.0/24]:Network=10.1.1.0 force +C set [from-10.1.1.0/24]:Netmask=255.255.255.0 force +C set [to-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [to-10.1.2.0/24]:Network=10.1.2.0 force +C set [to-10.1.2.0/24]:Netmask=255.255.255.0 force +C add [Phase 2]:Connections=from-10.1.1.0/24-to-10.1.2.0/24 diff --git a/regress/sbin/ipsecctl/ike67.in b/regress/sbin/ipsecctl/ike67.in new file mode 100644 index 00000000000..4bafe357f8c --- /dev/null +++ b/regress/sbin/ipsecctl/ike67.in @@ -0,0 +1,2 @@ +ike from 10.1.1.0/24 to 10.1.2.0/24 peer 3ffe::1 \ + dstid 3ffe::1 diff --git a/regress/sbin/ipsecctl/ike67.ok b/regress/sbin/ipsecctl/ike67.ok new file mode 100644 index 00000000000..5b3db6e7541 --- /dev/null +++ b/regress/sbin/ipsecctl/ike67.ok @@ -0,0 +1,23 @@ +C set [Phase 1]:3ffe::1=peer-3ffe::1 force +C set [peer-3ffe::1]:Phase=1 force +C set [peer-3ffe::1]:Address=3ffe::1 force +C set [peer-3ffe::1]:Configuration=phase1-peer-3ffe::1 force +C set [phase1-peer-3ffe::1]:EXCHANGE_TYPE=ID_PROT force +C add [phase1-peer-3ffe::1]:Transforms=AES-SHA-RSA_SIG force +C set [peer-3ffe::1]:Remote-ID=id-3ffe::1 force +C set [id-3ffe::1]:ID-type=IPV6_ADDR force +C set [id-3ffe::1]:Address=3ffe::1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Phase=2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:ISAKMP-peer=peer-3ffe::1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Configuration=phase2-from-10.1.1.0/24-to-10.1.2.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Local-ID=from-10.1.1.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Remote-ID=to-10.1.2.0/24 force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [from-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [from-10.1.1.0/24]:Network=10.1.1.0 force +C set [from-10.1.1.0/24]:Netmask=255.255.255.0 force +C set [to-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [to-10.1.2.0/24]:Network=10.1.2.0 force +C set [to-10.1.2.0/24]:Netmask=255.255.255.0 force +C add [Phase 2]:Connections=from-10.1.1.0/24-to-10.1.2.0/24 diff --git a/regress/sbin/ipsecctl/ike68.in b/regress/sbin/ipsecctl/ike68.in new file mode 100644 index 00000000000..6caeee5d5ff --- /dev/null +++ b/regress/sbin/ipsecctl/ike68.in @@ -0,0 +1,2 @@ +ike from 10.1.1.0/24 to 10.1.2.0/24 peer 3ffe::1 \ + srcid 3ffe::2 dstid 3ffe::1 diff --git a/regress/sbin/ipsecctl/ike68.ok b/regress/sbin/ipsecctl/ike68.ok new file mode 100644 index 00000000000..020ce55fc2b --- /dev/null +++ b/regress/sbin/ipsecctl/ike68.ok @@ -0,0 +1,26 @@ +C set [Phase 1]:3ffe::1=peer-3ffe::1 force +C set [peer-3ffe::1]:Phase=1 force +C set [peer-3ffe::1]:Address=3ffe::1 force +C set [peer-3ffe::1]:Configuration=phase1-peer-3ffe::1 force +C set [phase1-peer-3ffe::1]:EXCHANGE_TYPE=ID_PROT force +C add [phase1-peer-3ffe::1]:Transforms=AES-SHA-RSA_SIG force +C set [peer-3ffe::1]:ID=id-3ffe::2 force +C set [id-3ffe::2]:ID-type=IPV6_ADDR force +C set [id-3ffe::2]:Address=3ffe::2 force +C set [peer-3ffe::1]:Remote-ID=id-3ffe::1 force +C set [id-3ffe::1]:ID-type=IPV6_ADDR force +C set [id-3ffe::1]:Address=3ffe::1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Phase=2 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:ISAKMP-peer=peer-3ffe::1 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Configuration=phase2-from-10.1.1.0/24-to-10.1.2.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Local-ID=from-10.1.1.0/24 force +C set [from-10.1.1.0/24-to-10.1.2.0/24]:Remote-ID=to-10.1.2.0/24 force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:EXCHANGE_TYPE=QUICK_MODE force +C set [phase2-from-10.1.1.0/24-to-10.1.2.0/24]:Suites=QM-ESP-AES-SHA2-256-PFS-SUITE force +C set [from-10.1.1.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [from-10.1.1.0/24]:Network=10.1.1.0 force +C set [from-10.1.1.0/24]:Netmask=255.255.255.0 force +C set [to-10.1.2.0/24]:ID-type=IPV4_ADDR_SUBNET force +C set [to-10.1.2.0/24]:Network=10.1.2.0 force +C set [to-10.1.2.0/24]:Netmask=255.255.255.0 force +C add [Phase 2]:Connections=from-10.1.1.0/24-to-10.1.2.0/24 |