Conntag

The following scenarios show how to configure traffic policies using the conntag feature. Conntag allows tagging conntrack entries with string values (up to 255 characters) for traffic classification and filtering. This is similar to connmark but uses human-readable string tags instead of numeric marks.

../../../_images/topology34.svg

Test Policy Set Conntag Basic

Description

In this scenario, an ingress traffic policy is configured in DUT0 to set a basic conntag string on incoming packets. The conntag value is stored in the conntrack entry and can be verified using the system conntrack show command.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN rule 1 set conntag my-traffic-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.571 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.571/0.571/0.571/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.624 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.216 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.254 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2027ms
rtt min/avg/max/mdev = 0.216/0.364/0.624/0.184 ms

Step 6: Run the command system conntrack show on DUT0 and check whether the output contains the following tokens:

conntag=my-traffic-tag
Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=359 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=359 packets=3 bytes=252 mark=0 conntag=my-traffic-tag use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Test Policy Set Conntag With Numbers

Description

This scenario tests setting a conntag that includes numeric characters mixed with text, demonstrating that conntag values can contain alphanumeric strings with hyphens.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN rule 1 set conntag traffic-123-test

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.562 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.562/0.562/0.562/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.512 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.252 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.248 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2035ms
rtt min/avg/max/mdev = 0.248/0.337/0.512/0.123 ms

Step 6: Run the command system conntrack show on DUT0 and check whether the output contains the following tokens:

conntag=traffic-123-test
Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=361 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=361 packets=3 bytes=252 mark=0 conntag=traffic-123-test use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Test Policy Set Conntag Special Characters

Description

This scenario tests setting a conntag that includes special characters like underscores, dots, and hyphens, which are commonly used in application versioning and environment naming.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN rule 1 set conntag app_v2.0-prod

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.714 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.714/0.714/0.714/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.394 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.255 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.277 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2041ms
rtt min/avg/max/mdev = 0.255/0.308/0.394/0.061 ms

Step 6: Run the command system conntrack show on DUT0 and check whether the output contains the following tokens:

conntag=app_v2.0-prod
Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=363 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=363 packets=3 bytes=252 mark=0 conntag=app_v2.0-prod use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Test Policy Set Conntag Maximum Length

Description

This scenario tests the conntag feature with the maximum allowed string length of 255 characters. The system should accept and correctly store strings up to this limit.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN rule 1 set conntag Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-sed-do-eiusmod-tempor-incididunt-ut-labore-et-dolore-magna-aliqua-Ut-enim-ad-minim-veniam-quis-nostrud-exercitation-ullamco-laboris-nisi-ut-aliquip-ex-ea-commodo-consequat-Duis-aute-irure-dolor-len255

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.779 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.779/0.779/0.779/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.414 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.261 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.268 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2035ms
rtt min/avg/max/mdev = 0.261/0.314/0.414/0.070 ms

Step 6: Run the command system conntrack show on DUT0 and expect the following output:

Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=365 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=365 packets=3 bytes=252 mark=0 conntag=Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-sed-do-eiusmod-tempor-incididunt-ut-labore-et-dolore-magna-aliqua-Ut-enim-ad-minim-veniam-quis-nostrud-exercitation-ullamco-laboris-nisi-ut-aliquip-ex-ea-commodo-consequat-Duis-aute-
irure-dolor-len255 use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Test Policy Set Conntag Invalid Length

Description

This scenario tests that the system correctly rejects conntag strings that exceed the maximum allowed length of 255 characters with an appropriate error message.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN

Step 2: Expect a failure in the following command: Run the command set traffic policy POLICY_IN rule 1 set conntag Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-sed-do-eiusmod-tempor-incididunt-ut-labore-et-dolore-magna-aliqua-Ut-enim-ad-minim-veniam-quis-nostrud-exercitation-ullamco-laboris-nisi-ut-aliquip-ex-ea-commodo-consequat-Duis-aute-irure-dolor-len_256 on DUT0 and expect the following output:

Show output
tag string must be 1..255 non-space printable characters
Value validation failed
CLI Error: Command error

Test Policy Set Conntag Empty String

Description

This scenario tests that the system correctly rejects empty or whitespace-only conntag strings.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN

Step 2: Run the command configure on DUT0 and expect the following output:

Show output
admin@osdx#

Step 3: Run the command set traffic policy POLICY_IN rule 1 set conntag on DUT0 and check whether the output contains the following tokens:

requires a value
Show output
Configuration path: [traffic policy POLICY_IN rule 1 set conntag] requires a value
CLI Error: Command error

Test Policy Set Conntag With Connmark

Description

This scenario demonstrates using both conntag and connmark together on the same traffic flow. This allows numeric classification (connmark) alongside descriptive string tagging (conntag) for comprehensive traffic identification.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN rule 1 set connmark 42
set traffic policy POLICY_IN rule 1 set conntag my-traffic-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.717 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.717/0.717/0.717/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.416 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.276 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.254 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2039ms
rtt min/avg/max/mdev = 0.254/0.315/0.416/0.071 ms

Step 6: Run the command system conntrack show on DUT0 and expect the following output:

Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=367 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=367 packets=3 bytes=252 mark=42 conntag=my-traffic-tag use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Test Policy Set Conntag With VRF

Description

This scenario demonstrates using conntag in combination with VRF routing. Traffic is tagged with a conntag and also assigned to a specific VRF for routing purposes.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set interfaces ethernet eth0 vif 100 vrf RED
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system vrf RED
set traffic policy POLICY_IN rule 1 set conntag my-traffic-tag
set traffic policy POLICY_IN rule 1 set vrf RED

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.379 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.379/0.379/0.379/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.413 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.249 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.230 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2033ms
rtt min/avg/max/mdev = 0.230/0.297/0.413/0.082 ms

Step 6: Run the command system conntrack show on DUT0 and expect the following output:

Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=369 vrf=RED packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=369 vrf=RED packets=3 bytes=252 mark=0 conntag=my-traffic-tag use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Test Policy Modify Conntag

Description

This scenario demonstrates modifying the conntag value on an existing traffic policy rule and verifying that new connections use the updated tag value.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN rule 1 set conntag initial-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.611 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.611/0.611/0.611/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.481 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.333 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.315 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2042ms
rtt min/avg/max/mdev = 0.315/0.376/0.481/0.074 ms

Step 6: Run the command system conntrack show on DUT0 and check whether the output contains the following tokens:

conntag=initial-tag
Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=371 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=371 packets=3 bytes=252 mark=0 conntag=initial-tag use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Step 7: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 8: Modify the following configuration lines in DUT0 :

set traffic policy POLICY_IN rule 1 set conntag modified-tag

Step 9: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.593 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.254 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.294 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2037ms
rtt min/avg/max/mdev = 0.254/0.380/0.593/0.151 ms

Step 10: Run the command system conntrack show on DUT0 and check whether the output contains the following tokens:

conntag=modified-tag
Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=372 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=372 packets=3 bytes=252 mark=0 conntag=modified-tag use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Test Policy Delete Conntag

Description

This scenario tests removing a conntag configuration from a traffic policy and verifying that new connections no longer have the tag applied.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy in POLICY_IN
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_IN rule 1 set conntag my-traffic-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.819 ms

--- 10.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.819/0.819/0.819/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.458 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.317 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.262 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2045ms
rtt min/avg/max/mdev = 0.262/0.345/0.458/0.082 ms

Step 6: Run the command system conntrack show on DUT0 and check whether the output contains the following tokens:

conntag=my-traffic-tag
Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=374 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=374 packets=3 bytes=252 mark=0 conntag=my-traffic-tag use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Step 7: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 8: Modify the following configuration lines in DUT0 :

delete traffic policy POLICY_IN rule 1 set
set traffic policy POLICY_IN rule 1 action accept

Step 9: Ping the IP address 10.0.0.1 from DUT1:

admin@DUT1$ ping 10.0.0.1 count 3 size 56 timeout 1
Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.628 ms
64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.350 ms
64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.306 ms

--- 10.0.0.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2050ms
rtt min/avg/max/mdev = 0.306/0.428/0.628/0.142 ms

Step 10: Run the command system conntrack show on DUT0 and expect the following output:

Show output
icmp     1 29 src=10.0.0.2 dst=10.0.0.1 type=8 code=0 id=375 packets=3 bytes=252 src=10.0.0.1 dst=10.0.0.2 type=0 code=0 id=375 packets=3 bytes=252 mark=0 use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.