Conntag

The following scenarios show how the conntag feature integrates with conntrack logging and system conntrack show commands. Conntag allows tagging conntrack entries with string values (up to 255 characters) for traffic identification and logging.

Conntag In Conntrack Show

Description

Verify that conntag values appear correctly in the system conntrack show command output. The conntag field should display the string value assigned to the connection via traffic policy.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY_TAG
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_TAG rule 1 set conntag my-logged-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.458 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.458/0.458/0.458/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.503 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.255 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.274 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2051ms
rtt min/avg/max/mdev = 0.255/0.344/0.503/0.112 ms

Step 6: Run the command system conntrack show on DUT0 and expect the following output:

Show output
icmp     1 29 src=192.168.100.2 dst=192.168.100.1 type=8 code=0 id=767 packets=3 bytes=252 src=192.168.100.1 dst=192.168.100.2 type=0 code=0 id=767 packets=3 bytes=252 mark=0 conntag=my-logged-tag use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Conntag In Conntrack Logging

Description

Verify that conntag values appear in conntrack logging events when system conntrack logging events is enabled. The CONNTAG field should be included in log entries for NEW, UPDATE, and DESTROY events.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY_TAG
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_TAG rule 1 set conntag my-logged-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.699 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.699/0.699/0.699/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Run the command system journal clear on DUT0 and expect the following output:

Show output
Deleted archived journal /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5/system@d78f28b39d0744d090b4462d2fc0c95a-000000000000a28a-00065b9f5f8de243.journal (112.0K).
Vacuuming done, freed 112.0K of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Vacuuming done, freed 0B of archived journals from /run/log/journal.
Vacuuming done, freed 0B of archived journals from /var/log/journal.

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.510 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.242 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.262 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2053ms
rtt min/avg/max/mdev = 0.242/0.338/0.510/0.121 ms

Step 7: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

CONNTAG=my-logged-tag
Show output
Sep 16 20:18:44.034731 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:18:44.038515 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:18:44.038582 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:18:44.045546 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:18:44.166623 osdx ulogd[177916]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=my-logged-tag
Sep 16 20:18:44.166654 osdx ulogd[177916]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=my-logged-tag

Conntag In Traffic Policy Log

Description

Verify that conntag values appear in traffic policy log entries when the log option is enabled on a rule that sets conntag.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY_TAG
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_TAG rule 1 log prefix CONNTAG
set traffic policy POLICY_TAG rule 1 set conntag my-logged-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.329 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.329/0.329/0.329/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Run the command system journal clear on DUT0 and expect the following output:

Show output
Deleted archived journal /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5/system@d78f28b39d0744d090b4462d2fc0c95a-000000000000a2db-00065b9f6036e961.journal (84.0K).
Vacuuming done, freed 84.0K of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Vacuuming done, freed 0B of archived journals from /var/log/journal.
Vacuuming done, freed 0B of archived journals from /run/log/journal.

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.555 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.304 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.314 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2045ms
rtt min/avg/max/mdev = 0.304/0.391/0.555/0.116 ms

Step 7: Run the command system journal show | tail on DUT0 and check whether the output contains the following tokens:

[CONNTAG-1] ACCEPT
Show output
Sep 16 20:18:55.644172 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:18:55.646251 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:18:55.646305 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:18:55.654448 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:18:55.753863 osdx kernel: [CONNTAG-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:08:00 SRC=192.168.100.2 DST=192.168.100.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=41623 DF PROTO=ICMP TYPE=8 CODE=0 ID=771 SEQ=1
Sep 16 20:18:56.775062 osdx kernel: [CONNTAG-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:08:00 SRC=192.168.100.2 DST=192.168.100.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=41756 DF PROTO=ICMP TYPE=8 CODE=0 ID=771 SEQ=2
Sep 16 20:18:57.799052 osdx kernel: [CONNTAG-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:08:00 SRC=192.168.100.2 DST=192.168.100.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=41997 DF PROTO=ICMP TYPE=8 CODE=0 ID=771 SEQ=3

Conntag Persistence Through Connection States

Description

Verify that conntag values persist through different connection states (NEW, ESTABLISHED). The tag should remain associated with the connection throughout its lifecycle.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY_TAG
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_TAG rule 1 set conntag my-logged-tag

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.850 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.850/0.850/0.850/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Run the command system journal clear on DUT0 and expect the following output:

Show output
Vacuuming done, freed 0B of archived journals from /var/log/journal.
Vacuuming done, freed 0B of archived journals from /run/log/journal.
Deleted archived journal /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5/system@d78f28b39d0744d090b4462d2fc0c95a-000000000000a30f-00065b9f60dd50a9.journal (112.0K).
Vacuuming done, freed 112.0K of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.447 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.264 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.237 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2040ms
rtt min/avg/max/mdev = 0.237/0.316/0.447/0.093 ms

Step 7: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

\[NEW\].*CONNTAG=my-logged-tag
Show output
Sep 16 20:19:06.195111 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 12.0M free.
Sep 16 20:19:06.198524 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:19:06.198619 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:19:06.206590 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:19:06.299028 osdx ulogd[178748]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=my-logged-tag
Sep 16 20:19:06.299048 osdx ulogd[178748]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=my-logged-tag

Step 8: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

\[UPDATE\].*CONNTAG=my-logged-tag
Show output
Sep 16 20:19:06.195111 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 12.0M free.
Sep 16 20:19:06.198524 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:19:06.198619 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:19:06.206590 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:19:06.299028 osdx ulogd[178748]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=my-logged-tag
Sep 16 20:19:06.299048 osdx ulogd[178748]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=my-logged-tag
Sep 16 20:19:08.416573 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.

Conntag With Long String In Logs

Description

Verify that long conntag strings are correctly logged and displayed. The system should handle strings up to 255 characters without truncation in logs.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY_TAG
set system conntrack logging events new
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_TAG rule 1 set conntag application-traffic-identifier-v1.2.3-production-env

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.540 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.540/0.540/0.540/0.000 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Run the command system journal clear on DUT0 and expect the following output:

Show output
Deleted archived journal /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5/system@d78f28b39d0744d090b4462d2fc0c95a-000000000000a35f-00065b9f61713385.journal (64.0K).
Deleted archived journal /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5/system@d78f28b39d0744d090b4462d2fc0c95a-000000000000a362-00065b9f617625bd.journal (108.0K).
Vacuuming done, freed 172.0K of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Vacuuming done, freed 0B of archived journals from /run/log/journal.
Vacuuming done, freed 0B of archived journals from /var/log/journal.

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.248 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.240 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.286 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2047ms
rtt min/avg/max/mdev = 0.240/0.258/0.286/0.020 ms

Step 7: Run the command system conntrack show on DUT0 and expect the following output:

Show output
icmp     1 29 src=192.168.100.2 dst=192.168.100.1 type=8 code=0 id=775 packets=3 bytes=252 src=192.168.100.1 dst=192.168.100.2 type=0 code=0 id=775 packets=3 bytes=252 mark=0 conntag=application-traffic-identifier-v1.2.3-production-env use=1
conntrack v1.4.7 (conntrack-tools): 1 flow entries have been shown.

Step 8: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

CONNTAG=application-traffic-identifier
Show output
Sep 16 20:19:16.346873 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:19:16.347420 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:19:16.347488 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:19:16.358335 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:19:16.445149 osdx ulogd[179181]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=application-traffic-identifier-v1.2.3-production-env
Sep 16 20:19:18.594858 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system conntrack show'.

Conntag With Multiple Policies

Description

Verify that different traffic policies can set different conntag values, and each connection is tagged appropriately based on which policy rule matched.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY_MULTI
set service ssh
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY_MULTI rule 1 selector SEL_ICMP
set traffic policy POLICY_MULTI rule 1 set conntag icmp-traffic-tag
set traffic policy POLICY_MULTI rule 2 selector SEL_TCP
set traffic policy POLICY_MULTI rule 2 set conntag tcp-traffic-tag
set traffic selector SEL_ICMP rule 1 protocol icmp
set traffic selector SEL_TCP rule 1 protocol tcp

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.539 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.280 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.364 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2050ms
rtt min/avg/max/mdev = 0.280/0.394/0.539/0.107 ms

Step 4: Run the command system conntrack clear on DUT0 and expect the following output:

Show output
Connection tracking table has been emptied

Step 5: Run the command system journal clear on DUT0 and expect the following output:

Show output
Vacuuming done, freed 0B of archived journals from /var/log/journal.
Deleted archived journal /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5/system@d78f28b39d0744d090b4462d2fc0c95a-000000000000a3b1-00065b9f621de52b.journal (120.0K).
Vacuuming done, freed 120.0K of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Vacuuming done, freed 0B of archived journals from /run/log/journal.

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.416 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.223 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.301 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2053ms
rtt min/avg/max/mdev = 0.223/0.313/0.416/0.079 ms

Step 7: Initiate an SSH connection from DUT1 to IP address 192.168.100.1 using user admin:

admin@DUT1$ ssh admin@192.168.100.1 option StrictHostKeyChecking=no option UserKnownHostsFile=/dev/null
Show output
Warning: Permanently added '192.168.100.1' (ECDSA) to the list of known hosts.
admin@192.168.100.1's password:
Welcome to Teldat OSDx v4.2.10.4

This system includes free software.
Contact Teldat for licenses information and source code.

Last login: Wed Sep 16 20:07:39 2026
admin@osdx$

Step 8: Run the command system conntrack show on DUT0 and expect the following output:

Show output
tcp      6 19 TIME_WAIT src=192.168.100.2 dst=192.168.100.1 sport=42058 dport=22 packets=25 bytes=5109 src=192.168.100.1 dst=192.168.100.2 sport=22 dport=42058 packets=19 bytes=4725 [ASSURED] mark=0 conntag=tcp-traffic-tag use=1
icmp     1 29 src=192.168.100.2 dst=192.168.100.1 type=8 code=0 id=777 packets=3 bytes=252 src=192.168.100.1 dst=192.168.100.2 type=0 code=0 id=777 packets=3 bytes=252 mark=0 conntag=icmp-traffic-tag use=1
conntrack v1.4.7 (conntrack-tools): 2 flow entries have been shown.

Step 9: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

CONNTAG=icmp-traffic-tag
Show output
Sep 16 20:19:30.053327 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:19:30.054816 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:19:30.054866 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:19:30.063609 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:19:30.182385 osdx ulogd[179697]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=icmp-traffic-tag
Sep 16 20:19:30.182403 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=icmp-traffic-tag
Sep 16 20:19:32.318292 osdx ulogd[179697]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.318315 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.318418 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.478581 osdx sshd[179755]: Accepted password for admin from 192.168.100.2 port 42058 ssh2
Sep 16 20:19:32.485665 osdx sshd[179755]: pam_env(sshd:session): deprecated reading of user environment enabled
Sep 16 20:19:32.559173 osdx OSDxCLI[179765]: User 'admin' has logged in.
Sep 16 20:19:32.576558 osdx OSDxCLI[179765]: User 'admin' has logged out.
Sep 16 20:19:32.580287 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.580297 osdx sshd[179764]: Received disconnect from 192.168.100.2 port 42058:11: disconnected by user
Sep 16 20:19:32.580315 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.580418 osdx sshd[179764]: Disconnected from user admin 192.168.100.2 port 42058
Sep 16 20:19:32.581432 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.581867 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.738192 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system conntrack show'.

Step 10: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

CONNTAG=tcp-traffic-tag
Show output
Sep 16 20:19:30.053327 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:19:30.054816 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:19:30.054866 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:19:30.063609 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:19:30.182385 osdx ulogd[179697]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=icmp-traffic-tag
Sep 16 20:19:30.182403 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 CONNTAG=icmp-traffic-tag
Sep 16 20:19:32.318292 osdx ulogd[179697]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.318315 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.318418 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.478581 osdx sshd[179755]: Accepted password for admin from 192.168.100.2 port 42058 ssh2
Sep 16 20:19:32.485665 osdx sshd[179755]: pam_env(sshd:session): deprecated reading of user environment enabled
Sep 16 20:19:32.559173 osdx OSDxCLI[179765]: User 'admin' has logged in.
Sep 16 20:19:32.576558 osdx OSDxCLI[179765]: User 'admin' has logged out.
Sep 16 20:19:32.580287 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.580297 osdx sshd[179764]: Received disconnect from 192.168.100.2 port 42058:11: disconnected by user
Sep 16 20:19:32.580315 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.580418 osdx sshd[179764]: Disconnected from user admin 192.168.100.2 port 42058
Sep 16 20:19:32.581432 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.581867 osdx ulogd[179697]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=TCP SPT=42058 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=42058 PKTS=0 BYTES=0 CONNTAG=tcp-traffic-tag
Sep 16 20:19:32.738192 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system conntrack show'.
Sep 16 20:19:32.828821 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.