Logging

The following scenarios show how to configure the conntrack logging option with different traffic policies and services enabled, in order to check that all fields are displayed correctly and all events are captured.

New events

Description

Check NEW sessions events are captured

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set system conntrack logging events new
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.570 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.570/0.570/0.570/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.457 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.457/0.457/0.457/0.000 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[NEW\].*SRC=192.168.100.2
Show output
Sep 16 20:08:54.279367 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 3.8M, max 13.8M, 9.9M free.
Sep 16 20:08:54.281282 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:08:54.281354 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:08:54.290218 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:08:54.532770 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:08:54.769007 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:08:54.870187 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:08:54.931309 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events new'.
Sep 16 20:08:55.066649 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:08:55.132050 osdx ubnt-cfgd[160784]: inactive
Sep 16 20:08:55.160191 osdx INFO[160793]: FRR daemons did not change
Sep 16 20:08:55.197302 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:08:55.248515 osdx WARNING[160867]: No supported link modes on interface eth0
Sep 16 20:08:55.250082 osdx modulelauncher[160867]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:08:55.250095 osdx modulelauncher[160867]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:08:55.251364 osdx modulelauncher[160867]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:08:55.251372 osdx modulelauncher[160867]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:08:55.301562 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:08:55.304920 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:08:55.307900 osdx ulogd[160887]: registering plugin `NFCT'
Sep 16 20:08:55.308789 osdx ulogd[160887]: registering plugin `IP2STR'
Sep 16 20:08:55.308861 osdx ulogd[160887]: registering plugin `PRINTFLOW'
Sep 16 20:08:55.310236 osdx ulogd[160887]: registering plugin `SYSLOG'
Sep 16 20:08:55.310246 osdx ulogd[160887]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:08:55.310305 osdx ulogd[160887]: NFCT plugin working in event mode
Sep 16 20:08:55.310316 osdx ulogd[160887]: Changing UID / GID
Sep 16 20:08:55.310416 osdx ulogd[160887]: initialization finished, entering main loop
Sep 16 20:08:55.495082 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:08:55.495769 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:08:55.511339 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:08:56.472976 osdx ulogd[160887]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:08:56.566769 osdx ulogd[160887]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0

Update events

Description

Check UPDATE sessions events are captured

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set system conntrack logging events update
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.928 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.928/0.928/0.928/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.264 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.264/0.264/0.264/0.000 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[UPDATE\].*SRC=192.168.100.2
Show output
Sep 16 20:09:02.353014 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:09:02.356915 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:02.356997 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:02.365031 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:02.608533 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:02.876039 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:02.979898 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:09:03.048824 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events update'.
Sep 16 20:09:03.173290 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:09:03.239840 osdx ubnt-cfgd[161140]: inactive
Sep 16 20:09:03.271980 osdx INFO[161149]: FRR daemons did not change
Sep 16 20:09:03.308962 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:03.364350 osdx WARNING[161223]: No supported link modes on interface eth0
Sep 16 20:09:03.366364 osdx modulelauncher[161223]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:09:03.366378 osdx modulelauncher[161223]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:09:03.367954 osdx modulelauncher[161223]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:09:03.367969 osdx modulelauncher[161223]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:09:03.409346 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:03.410267 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:03.410399 osdx ulogd[161243]: registering plugin `NFCT'
Sep 16 20:09:03.410448 osdx ulogd[161243]: registering plugin `IP2STR'
Sep 16 20:09:03.410491 osdx ulogd[161243]: registering plugin `PRINTFLOW'
Sep 16 20:09:03.410541 osdx ulogd[161243]: registering plugin `SYSLOG'
Sep 16 20:09:03.410545 osdx ulogd[161243]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:03.410600 osdx ulogd[161243]: NFCT plugin working in event mode
Sep 16 20:09:03.410610 osdx ulogd[161243]: Changing UID / GID
Sep 16 20:09:03.410704 osdx ulogd[161243]: initialization finished, entering main loop
Sep 16 20:09:03.598454 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:03.598936 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:03.637710 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:04.726006 osdx ulogd[161243]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:04.826862 osdx ulogd[161243]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0

Destroy events

Description

Check DESTROY sessions events are captured

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set service ssh
set system conntrack logging events destroy
set system conntrack timeout icmp 1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.872 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.872/0.872/0.872/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.312 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.334 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.310 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2042ms
rtt min/avg/max/mdev = 0.310/0.318/0.334/0.010 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[DESTROY\].*SRC=192.168.100.2
Show output
Sep 16 20:09:10.292093 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:09:10.292788 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:10.292837 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:10.303615 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:10.574542 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:10.847582 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:10.941691 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:09:11.010375 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events destroy'.
Sep 16 20:09:11.105395 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack timeout icmp 1'.
Sep 16 20:09:11.165390 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set service ssh'.
Sep 16 20:09:11.293142 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:09:11.363254 osdx ubnt-cfgd[161498]: inactive
Sep 16 20:09:11.443697 osdx INFO[161522]: FRR daemons did not change
Sep 16 20:09:11.480583 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:11.528023 osdx WARNING[161598]: No supported link modes on interface eth0
Sep 16 20:09:11.529833 osdx modulelauncher[161598]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:09:11.529846 osdx modulelauncher[161598]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:09:11.531028 osdx modulelauncher[161598]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:09:11.531036 osdx modulelauncher[161598]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:09:11.576985 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:11.577946 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:11.578124 osdx ulogd[161618]: registering plugin `NFCT'
Sep 16 20:09:11.578170 osdx ulogd[161618]: registering plugin `IP2STR'
Sep 16 20:09:11.578214 osdx ulogd[161618]: registering plugin `PRINTFLOW'
Sep 16 20:09:11.578262 osdx ulogd[161618]: registering plugin `SYSLOG'
Sep 16 20:09:11.578267 osdx ulogd[161618]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:11.578324 osdx ulogd[161618]: NFCT plugin working in event mode
Sep 16 20:09:11.578334 osdx ulogd[161618]: Changing UID / GID
Sep 16 20:09:11.578427 osdx ulogd[161618]: initialization finished, entering main loop
Sep 16 20:09:11.661043 osdx systemd[1]: Starting ssh.service - OpenBSD Secure Shell server...
Sep 16 20:09:11.675766 osdx sshd[161639]: Server listening on 0.0.0.0 port 22.
Sep 16 20:09:11.675803 osdx sshd[161639]: Server listening on :: port 22.
Sep 16 20:09:11.675994 osdx systemd[1]: Started ssh.service - OpenBSD Secure Shell server.
Sep 16 20:09:11.854790 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:11.855369 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:11.880193 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:14.265495 osdx ulogd[161618]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84
Sep 16 20:09:15.289466 osdx ulogd[161618]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84

Default logging

Description

Set a simple configuration, send a ping command from one device to other and check that default fields appear when running system journal show.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.766 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.766/0.766/0.766/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.557 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.557/0.557/0.557/0.000 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*SRC=192.168.100.2
Show output
Sep 16 20:09:23.403457 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 2.1M, max 13.8M, 11.6M free.
Sep 16 20:09:23.407481 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:23.407548 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:23.417700 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:23.730666 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:24.130594 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:24.246697 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:09:24.303370 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:09:24.435802 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:09:24.500774 osdx ubnt-cfgd[161917]: inactive
Sep 16 20:09:24.527326 osdx INFO[161926]: FRR daemons did not change
Sep 16 20:09:24.567448 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:24.623162 osdx WARNING[162000]: No supported link modes on interface eth0
Sep 16 20:09:24.624780 osdx modulelauncher[162000]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:09:24.624795 osdx modulelauncher[162000]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:09:24.626230 osdx modulelauncher[162000]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:09:24.626241 osdx modulelauncher[162000]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:09:24.667870 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:24.669063 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:24.669138 osdx ulogd[162020]: registering plugin `NFCT'
Sep 16 20:09:24.669187 osdx ulogd[162020]: registering plugin `IP2STR'
Sep 16 20:09:24.669230 osdx ulogd[162020]: registering plugin `PRINTFLOW'
Sep 16 20:09:24.669303 osdx ulogd[162020]: registering plugin `SYSLOG'
Sep 16 20:09:24.669308 osdx ulogd[162020]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:24.669361 osdx ulogd[162020]: NFCT plugin working in event mode
Sep 16 20:09:24.669370 osdx ulogd[162020]: Changing UID / GID
Sep 16 20:09:24.669518 osdx ulogd[162020]: initialization finished, entering main loop
Sep 16 20:09:24.869548 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:24.870041 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:24.886599 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:25.980102 osdx ulogd[162020]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:25.980121 osdx ulogd[162020]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:26.070932 osdx ulogd[162020]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:26.070949 osdx ulogd[162020]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0

Identity logging

Description

Set a simple configuration with identity OSDx_DUT0 for logs entries, send a ping command from one device to other and check that the identity has changed when running system journal show.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set system conntrack logging events all
set system conntrack logging identity OSDx_DUT0
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.830 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.830/0.830/0.830/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.271 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.271/0.271/0.271/0.000 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

OSDx_DUT0\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*SRC=192.168.100.2
Show output
Sep 16 20:09:31.378825 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:09:31.382188 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:31.382258 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:31.391741 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:31.615030 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:31.870371 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:31.966197 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:09:32.058978 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:09:32.173960 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging identity OSDx_DUT0'.
Sep 16 20:09:32.238983 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:09:32.359407 osdx ubnt-cfgd[162274]: inactive
Sep 16 20:09:32.383405 osdx INFO[162283]: FRR daemons did not change
Sep 16 20:09:32.418211 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:32.470117 osdx WARNING[162357]: No supported link modes on interface eth0
Sep 16 20:09:32.471676 osdx modulelauncher[162357]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:09:32.471690 osdx modulelauncher[162357]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:09:32.473343 osdx modulelauncher[162357]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:09:32.473358 osdx modulelauncher[162357]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:09:32.526543 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:32.527542 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:32.527679 osdx ulogd[162377]: registering plugin `NFCT'
Sep 16 20:09:32.527717 osdx ulogd[162377]: registering plugin `IP2STR'
Sep 16 20:09:32.527750 osdx ulogd[162377]: registering plugin `PRINTFLOW'
Sep 16 20:09:32.527787 osdx ulogd[162377]: registering plugin `SYSLOG'
Sep 16 20:09:32.527790 osdx ulogd[162377]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:32.527828 osdx ulogd[162377]: NFCT plugin working in event mode
Sep 16 20:09:32.527835 osdx OSDx_DUT0[162377]: Changing UID / GID
Sep 16 20:09:32.527906 osdx OSDx_DUT0[162377]: initialization finished, entering main loop
Sep 16 20:09:32.701089 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:32.701829 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:32.718140 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:33.717906 osdx OSDx_DUT0[162377]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:33.717926 osdx OSDx_DUT0[162377]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:33.830086 osdx OSDx_DUT0[162377]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:33.830118 osdx OSDx_DUT0[162377]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0

Note

If the identity is not provided, “ulogd” will be used by default.

Step 6: Modify the following configuration lines in DUT0 :

delete system conntrack logging identity

Step 7: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=2.92 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 2.923/2.923/2.923/0.000 ms

Step 8: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*SRC=192.168.100.2
Show output
Sep 16 20:09:31.378825 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:09:31.382188 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:31.382258 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:31.391741 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:31.615030 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:31.870371 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:31.966197 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:09:32.058978 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:09:32.173960 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging identity OSDx_DUT0'.
Sep 16 20:09:32.238983 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:09:32.359407 osdx ubnt-cfgd[162274]: inactive
Sep 16 20:09:32.383405 osdx INFO[162283]: FRR daemons did not change
Sep 16 20:09:32.418211 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:32.470117 osdx WARNING[162357]: No supported link modes on interface eth0
Sep 16 20:09:32.471676 osdx modulelauncher[162357]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:09:32.471690 osdx modulelauncher[162357]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:09:32.473343 osdx modulelauncher[162357]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:09:32.473358 osdx modulelauncher[162357]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:09:32.526543 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:32.527542 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:32.527679 osdx ulogd[162377]: registering plugin `NFCT'
Sep 16 20:09:32.527717 osdx ulogd[162377]: registering plugin `IP2STR'
Sep 16 20:09:32.527750 osdx ulogd[162377]: registering plugin `PRINTFLOW'
Sep 16 20:09:32.527787 osdx ulogd[162377]: registering plugin `SYSLOG'
Sep 16 20:09:32.527790 osdx ulogd[162377]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:32.527828 osdx ulogd[162377]: NFCT plugin working in event mode
Sep 16 20:09:32.527835 osdx OSDx_DUT0[162377]: Changing UID / GID
Sep 16 20:09:32.527906 osdx OSDx_DUT0[162377]: initialization finished, entering main loop
Sep 16 20:09:32.701089 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:32.701829 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:32.718140 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:33.717906 osdx OSDx_DUT0[162377]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:33.717926 osdx OSDx_DUT0[162377]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:33.830086 osdx OSDx_DUT0[162377]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:33.830118 osdx OSDx_DUT0[162377]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:33.922702 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 16 20:09:34.120903 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:34.212210 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'delete system conntrack logging identity'.
Sep 16 20:09:34.286811 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show changes'.
Sep 16 20:09:34.388191 osdx ubnt-cfgd[162429]: inactive
Sep 16 20:09:34.411606 osdx INFO[162436]: FRR daemons did not change
Sep 16 20:09:34.422255 osdx OSDx_DUT0[162377]: Terminal signal received, exiting
Sep 16 20:09:34.422339 osdx systemd[1]: Stopping ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:34.422658 osdx systemd[1]: ulogd2.service: Deactivated successfully.
Sep 16 20:09:34.422784 osdx systemd[1]: Stopped ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:34.438504 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:34.439298 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:34.439504 osdx ulogd[162444]: registering plugin `NFCT'
Sep 16 20:09:34.439555 osdx ulogd[162444]: registering plugin `IP2STR'
Sep 16 20:09:34.439598 osdx ulogd[162444]: registering plugin `PRINTFLOW'
Sep 16 20:09:34.439647 osdx ulogd[162444]: registering plugin `SYSLOG'
Sep 16 20:09:34.439652 osdx ulogd[162444]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:34.439701 osdx ulogd[162444]: NFCT plugin working in event mode
Sep 16 20:09:34.439711 osdx ulogd[162444]: Changing UID / GID
Sep 16 20:09:34.439794 osdx ulogd[162444]: initialization finished, entering main loop
Sep 16 20:09:34.447229 osdx ulogd[162444]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84
Sep 16 20:09:34.447247 osdx ulogd[162444]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84
Sep 16 20:09:34.447682 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:34.448214 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:34.463991 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:34.682742 osdx ulogd[162444]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:34.682765 osdx ulogd[162444]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0

Policies logging

Description

Set a simple configuration with mark and label traffic policies, send a ping command from one device to other and check that default, mark and label fields appear when running system journal show.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic label TEST
set traffic policy POLICY rule 1 set connmark 33
set traffic policy POLICY rule 1 set label TEST

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.829 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.829/0.829/0.829/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 2 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.506 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.286 ms

--- 192.168.100.1 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1008ms
rtt min/avg/max/mdev = 0.286/0.396/0.506/0.110 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*MARK=33.*LABELS=TEST
Show output
Sep 16 20:09:40.344796 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:09:40.347793 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:40.347863 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:40.366662 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:40.706080 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:41.015938 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:41.117892 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 traffic policy in POLICY'.
Sep 16 20:09:41.192274 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic label TEST'.
Sep 16 20:09:41.316167 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy POLICY rule 1 set connmark 33'.
Sep 16 20:09:41.393060 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy POLICY rule 1 set label TEST'.
Sep 16 20:09:41.494948 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:09:41.550131 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:09:41.717462 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:09:41.783909 osdx ubnt-cfgd[162669]: inactive
Sep 16 20:09:41.821521 osdx INFO[162688]: FRR daemons did not change
Sep 16 20:09:41.855769 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:41.905315 osdx WARNING[162762]: No supported link modes on interface eth0
Sep 16 20:09:41.907071 osdx modulelauncher[162762]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:09:41.907082 osdx modulelauncher[162762]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:09:41.908574 osdx modulelauncher[162762]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:09:41.908582 osdx modulelauncher[162762]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:09:41.960081 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:41.961143 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:41.961309 osdx ulogd[162782]: registering plugin `NFCT'
Sep 16 20:09:41.961357 osdx ulogd[162782]: registering plugin `IP2STR'
Sep 16 20:09:41.961402 osdx ulogd[162782]: registering plugin `PRINTFLOW'
Sep 16 20:09:41.961450 osdx ulogd[162782]: registering plugin `SYSLOG'
Sep 16 20:09:41.961454 osdx ulogd[162782]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:41.961507 osdx ulogd[162782]: NFCT plugin working in event mode
Sep 16 20:09:41.961516 osdx ulogd[162782]: Changing UID / GID
Sep 16 20:09:41.961602 osdx ulogd[162782]: initialization finished, entering main loop
Sep 16 20:09:41.973295 osdx systemd[1]: Stopping ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:41.973436 osdx ulogd[162782]: Terminal signal received, exiting
Sep 16 20:09:41.973758 osdx systemd[1]: ulogd2.service: Deactivated successfully.
Sep 16 20:09:41.973863 osdx systemd[1]: Stopped ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:41.974807 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:41.975579 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:41.975810 osdx ulogd[162788]: registering plugin `NFCT'
Sep 16 20:09:41.975848 osdx ulogd[162788]: registering plugin `IP2STR'
Sep 16 20:09:41.975879 osdx ulogd[162788]: registering plugin `PRINTFLOW'
Sep 16 20:09:41.975921 osdx ulogd[162788]: registering plugin `SYSLOG'
Sep 16 20:09:41.975924 osdx ulogd[162788]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:41.975962 osdx ulogd[162788]: NFCT plugin working in event mode
Sep 16 20:09:41.975969 osdx ulogd[162788]: Changing UID / GID
Sep 16 20:09:41.976030 osdx ulogd[162788]: initialization finished, entering main loop
Sep 16 20:09:42.354083 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:42.354759 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:42.394493 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:43.425568 osdx ulogd[162788]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 MARK=33 LABELS=TEST
Sep 16 20:09:43.425588 osdx ulogd[162788]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 MARK=33
Sep 16 20:09:43.508782 osdx ulogd[162788]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 MARK=33 LABELS=TEST
Sep 16 20:09:43.508808 osdx ulogd[162788]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 MARK=33

VRF logging

Description

Set a simple configuration with a vrf, send a ping command from one device to other and check that default and vrf fields appear when running system journal show.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 vrf RED
set protocols vrf RED static route 0.0.0.0/0 next-hop 192.168.100.2
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set system vrf RED

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.647 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.647/0.647/0.647/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.530 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.530/0.530/0.530/0.000 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*VRF=RED
Show output
Sep 16 20:09:50.311057 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:09:50.312354 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:50.312410 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:50.323133 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:50.538031 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:50.795460 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:50.935893 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 vrf RED'.
Sep 16 20:09:51.019781 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set protocols vrf RED static route 0.0.0.0/0 next-hop 192.168.100.2'.
Sep 16 20:09:51.123427 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system vrf RED'.
Sep 16 20:09:51.204112 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:09:51.277708 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:09:51.430559 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:09:51.502205 osdx ubnt-cfgd[163092]: inactive
Sep 16 20:09:51.530074 osdx INFO[163103]: FRR daemons did not change
Sep 16 20:09:51.540458 osdx (udev-worker)[163113]: RED: Could not disable auto negotiation, ignoring: Operation not supported
Sep 16 20:09:51.540482 osdx (udev-worker)[163113]: Network interface NamePolicy= disabled on kernel command line.
Sep 16 20:09:51.584358 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:51.633409 osdx WARNING[163198]: No supported link modes on interface eth0
Sep 16 20:09:51.634889 osdx modulelauncher[163198]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:09:51.634901 osdx modulelauncher[163198]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:09:51.636204 osdx modulelauncher[163198]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:09:51.636214 osdx modulelauncher[163198]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:09:51.648422 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:09:51.740661 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:09:51.741570 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:09:51.741762 osdx ulogd[163279]: registering plugin `NFCT'
Sep 16 20:09:51.741944 osdx ulogd[163279]: registering plugin `IP2STR'
Sep 16 20:09:51.741981 osdx ulogd[163279]: registering plugin `PRINTFLOW'
Sep 16 20:09:51.742020 osdx ulogd[163279]: registering plugin `SYSLOG'
Sep 16 20:09:51.742025 osdx ulogd[163279]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:09:51.742067 osdx ulogd[163279]: NFCT plugin working in event mode
Sep 16 20:09:51.742076 osdx ulogd[163279]: Changing UID / GID
Sep 16 20:09:51.742144 osdx ulogd[163279]: initialization finished, entering main loop
Sep 16 20:09:51.919265 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:09:51.919867 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:09:51.943655 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:09:53.005686 osdx ulogd[163279]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:53.005709 osdx ulogd[163279]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:53.085032 osdx ulogd[163279]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:09:53.085052 osdx ulogd[163279]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 VRF=RED PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0

Not-Bypass logging

Description

Set a simple configuration with a firewall service, send a ping command from one device to other and check that default and bypass fields appear when running system journal show.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Ping the IP address 10.215.168.1 from DUT0:

admin@DUT0$ ping 10.215.168.1 count 1 size 56 timeout 1
Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data.
64 bytes from 10.215.168.1: icmp_seq=1 ttl=64 time=0.735 ms

--- 10.215.168.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.735/0.735/0.735/0.000 ms

Step 3: Run the command file copy http://10.215.168.1/~robot/test-performance.rules running:// force on DUT0 and expect the following output:

Show output
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100   266  100   266    0     0  37031      0 --:--:-- --:--:-- --:--:-- 38000

Step 4: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 traffic policy in POLICY
set service firewall FW mode inline queue FW_Q
set service firewall FW ruleset file 'running://test-performance.rules'
set service firewall FW stream bypass mark 129834765
set service firewall FW stream bypass mask 129834765
set service firewall FW stream bypass set-connmark
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy POLICY rule 1 action enqueue FW_Q
set traffic queue FW_Q elements 1

Step 5: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.922 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.922/0.922/0.922/0.000 ms

Step 7: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.412 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.412/0.412/0.412/0.000 ms

Step 8: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*Sc: not-bypass
Show output
Sep 16 20:09:59.374988 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:09:59.377010 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:09:59.377062 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:09:59.387197 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:09:59.652679 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:09:59.912630 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:09:59.995758 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 16 20:10:00.077471 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:00.170918 osdx ubnt-cfgd[163617]: inactive
Sep 16 20:10:00.192559 osdx INFO[163626]: FRR daemons did not change
Sep 16 20:10:00.221015 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:00.267661 osdx WARNING[163697]: No supported link modes on interface eth0
Sep 16 20:10:00.269108 osdx modulelauncher[163697]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:00.269121 osdx modulelauncher[163697]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:00.270211 osdx modulelauncher[163697]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:00.270222 osdx modulelauncher[163697]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:00.439152 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:00.439653 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:00.459783 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:00.668098 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 16 20:10:00.809674 osdx file_operation[163764]: using src url: http://10.215.168.1/~robot/test-performance.rules dst url: running://
Sep 16 20:10:00.844703 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'file copy http://10.215.168.1/~robot/test-performance.rules running:// force'.
Sep 16 20:10:01.027028 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:01.115973 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 traffic policy in POLICY'.
Sep 16 20:10:01.214422 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set service firewall FW mode inline queue FW_Q'.
Sep 16 20:10:01.288803 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set service firewall FW ruleset file running://test-performance.rules'.
Sep 16 20:10:01.422860 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set service firewall FW stream bypass'.
Sep 16 20:10:01.474049 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set service firewall FW stream bypass mark 129834765'.
Sep 16 20:10:01.602552 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set service firewall FW stream bypass mask 129834765'.
Sep 16 20:10:01.689197 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set service firewall FW stream bypass set-connmark'.
Sep 16 20:10:01.786367 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic queue FW_Q elements 1'.
Sep 16 20:10:01.842711 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy POLICY rule 1 action enqueue FW_Q'.
Sep 16 20:10:01.959463 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:10:02.011131 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:10:02.131393 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:02.203809 osdx ubnt-cfgd[163799]: inactive
Sep 16 20:10:02.249893 osdx INFO[163821]: FRR daemons did not change
Sep 16 20:10:02.313315 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:02.314237 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:02.314336 osdx ulogd[163861]: registering plugin `NFCT'
Sep 16 20:10:02.314377 osdx ulogd[163861]: registering plugin `IP2STR'
Sep 16 20:10:02.314421 osdx ulogd[163861]: registering plugin `PRINTFLOW'
Sep 16 20:10:02.314462 osdx ulogd[163861]: registering plugin `SYSLOG'
Sep 16 20:10:02.314466 osdx ulogd[163861]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:02.314505 osdx ulogd[163861]: NFCT plugin working in event mode
Sep 16 20:10:02.314513 osdx ulogd[163861]: Changing UID / GID
Sep 16 20:10:02.314582 osdx ulogd[163861]: initialization finished, entering main loop
Sep 16 20:10:02.539033 osdx ulogd[163861]: Terminal signal received, exiting
Sep 16 20:10:02.539229 osdx systemd[1]: Stopping ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:02.539575 osdx systemd[1]: ulogd2.service: Deactivated successfully.
Sep 16 20:10:02.539701 osdx systemd[1]: Stopped ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:02.561414 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:02.562381 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:02.562435 osdx ulogd[163890]: registering plugin `NFCT'
Sep 16 20:10:02.562471 osdx ulogd[163890]: registering plugin `IP2STR'
Sep 16 20:10:02.562507 osdx ulogd[163890]: registering plugin `PRINTFLOW'
Sep 16 20:10:02.562554 osdx ulogd[163890]: registering plugin `SYSLOG'
Sep 16 20:10:02.562558 osdx ulogd[163890]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:02.562607 osdx ulogd[163890]: NFCT plugin working in event mode
Sep 16 20:10:02.562616 osdx ulogd[163890]: Changing UID / GID
Sep 16 20:10:02.562697 osdx ulogd[163890]: initialization finished, entering main loop
Sep 16 20:10:02.619696 osdx systemd[1]: Reloading.
Sep 16 20:10:02.657050 osdx systemd-sysv-generator[163911]: stat() failed on /etc/init.d/README, ignoring: No such file or directory
Sep 16 20:10:02.769504 osdx systemd[1]: Starting logrotate.service - Rotate log files...
Sep 16 20:10:02.774856 osdx systemd[1]: Created slice system-suricata.slice - Slice /system/suricata.
Sep 16 20:10:02.775954 osdx systemd[1]: Starting suricata@FW.service - Suricata client "FW" service...
Sep 16 20:10:02.796032 osdx systemd[1]: logrotate.service: Deactivated successfully.
Sep 16 20:10:02.796203 osdx systemd[1]: Finished logrotate.service - Rotate log files.
Sep 16 20:10:03.073756 osdx systemd[1]: Started suricata@FW.service - Suricata client "FW" service.
Sep 16 20:10:03.105617 osdx INFO[163892]: Rules successfully loaded
Sep 16 20:10:03.157623 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:03.158264 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:03.203318 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:04.217862 osdx ulogd[163890]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 (Sc: not-bypass)
Sep 16 20:10:04.217881 osdx ulogd[163890]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 (Sc: not-bypass)
Sep 16 20:10:04.332771 osdx ulogd[163890]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 (Sc: not-bypass)
Sep 16 20:10:04.332790 osdx ulogd[163890]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 (Sc: not-bypass)

Offload flag

Description

Set a simple configuration with DUT0 as an intermediary between DUT1 and DUT2. Initiate a ssh connection from DUT1 to DUT2 and check that default and offload fields appear when running system journal show.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set interfaces ethernet eth0 address 192.168.200.1/24
set system conntrack logging events all
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Set the following configuration in DUT2 :

set interfaces ethernet eth0 address 192.168.200.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.200.1
set service ssh
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.786 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.786/0.786/0.786/0.000 ms

Step 5: Ping the IP address 192.168.200.1 from DUT2:

admin@DUT2$ ping 192.168.200.1 count 1 size 56 timeout 1
Show output
PING 192.168.200.1 (192.168.200.1) 56(84) bytes of data.
64 bytes from 192.168.200.1: icmp_seq=1 ttl=64 time=0.769 ms

--- 192.168.200.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.769/0.769/0.769/0.000 ms

Step 6: Initiate an SSH connection from DUT1 to IP address 192.168.200.2 using user admin:

admin@DUT1$ ssh admin@192.168.200.2 option StrictHostKeyChecking=no option UserKnownHostsFile=/dev/null
Show output
Warning: Permanently added '192.168.200.2' (ECDSA) to the list of known hosts.
admin@192.168.200.2's password:
Welcome to Teldat OSDx v4.2.10.4

This system includes free software.
Contact Teldat for licenses information and source code.

Last login: Wed Sep 16 19:57:56 2026
admin@osdx$

Step 7: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*\[OFFLOAD\]
Show output
Sep 16 20:10:11.000180 osdx systemd-timedated[155024]: Changed local time to Wed 2026-09-16 20:10:11 UTC
Sep 16 20:10:11.001569 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'set date 2026-09-16 20:10:11'.
Sep 16 20:10:11.003891 osdx systemd-journald[2158]: Time jumped backwards, rotating.
Sep 16 20:10:11.292747 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:10:11.295903 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:10:11.295959 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:10:11.302481 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:10:11.518557 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:10:11.796796 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:11.882358 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.200.1/24'.
Sep 16 20:10:11.973558 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:10:12.081652 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:10:12.174712 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:12.259357 osdx ubnt-cfgd[164234]: inactive
Sep 16 20:10:12.285447 osdx INFO[164243]: FRR daemons did not change
Sep 16 20:10:12.323900 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:12.378846 osdx WARNING[164320]: No supported link modes on interface eth0
Sep 16 20:10:12.380672 osdx modulelauncher[164320]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:12.380684 osdx modulelauncher[164320]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:12.381938 osdx modulelauncher[164320]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:12.381947 osdx modulelauncher[164320]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:12.432306 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:12.433134 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:12.433318 osdx ulogd[164340]: registering plugin `NFCT'
Sep 16 20:10:12.433366 osdx ulogd[164340]: registering plugin `IP2STR'
Sep 16 20:10:12.433417 osdx ulogd[164340]: registering plugin `PRINTFLOW'
Sep 16 20:10:12.433466 osdx ulogd[164340]: registering plugin `SYSLOG'
Sep 16 20:10:12.433470 osdx ulogd[164340]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:12.433521 osdx ulogd[164340]: NFCT plugin working in event mode
Sep 16 20:10:12.433530 osdx ulogd[164340]: Changing UID / GID
Sep 16 20:10:12.433619 osdx ulogd[164340]: initialization finished, entering main loop
Sep 16 20:10:12.601725 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:12.602253 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:12.625432 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:14.849859 osdx ulogd[164340]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:10:14.849938 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:10:14.983311 osdx ulogd[164340]: [NEW] ORIG: SRC=192.168.200.2 DST=192.168.200.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.1 DST=192.168.200.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:10:14.983328 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.200.2 DST=192.168.200.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.1 DST=192.168.200.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:10:15.108323 osdx ulogd[164340]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.200.2 PROTO=TCP SPT=46156 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.2 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=46156 PKTS=0 BYTES=0
Sep 16 20:10:15.108602 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.200.2 PROTO=TCP SPT=46156 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.2 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=46156 PKTS=0 BYTES=0
Sep 16 20:10:15.108823 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.200.2 PROTO=TCP SPT=46156 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.2 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=46156 PKTS=0 BYTES=0 [OFFLOAD]
Sep 16 20:10:15.442611 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.200.2 PROTO=TCP SPT=46156 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.2 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=46156 PKTS=0 BYTES=0
Sep 16 20:10:15.442638 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.200.2 PROTO=TCP SPT=46156 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.2 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=46156 PKTS=0 BYTES=0
Sep 16 20:10:15.444158 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.200.2 PROTO=TCP SPT=46156 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.2 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=46156 PKTS=0 BYTES=0
Sep 16 20:10:15.444354 osdx ulogd[164340]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.200.2 PROTO=TCP SPT=46156 DPT=22 PKTS=0 BYTES=0 , REPLY: SRC=192.168.200.2 DST=192.168.100.2 PROTO=TCP SPT=22 DPT=46156 PKTS=0 BYTES=0 [OFFLOAD]

App detect logging

Description

Set a simple configuration enabling app detection in system conntrack, send a ping command from DUT1 and check app detect field appears when running system journal show. After that, enabling app detection in system conntrack for http host, try to copy index.html from a http server and check that the app detect field appears and belongs to the http server when running system journal show.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set system conntrack app-detect
set system conntrack logging events all
set system conntrack timeout icmp 1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.538 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.538/0.538/0.538/0.000 ms

Step 4: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 3 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.437 ms
64 bytes from 192.168.100.1: icmp_seq=2 ttl=64 time=0.268 ms
64 bytes from 192.168.100.1: icmp_seq=3 ttl=64 time=0.294 ms

--- 192.168.100.1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2046ms
rtt min/avg/max/mdev = 0.268/0.333/0.437/0.074 ms

Step 5: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[NEW\].*APPDETECT\[L3:1\]
Show output
Sep 16 20:10:21.619077 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.9M, max 13.8M, 11.8M free.
Sep 16 20:10:21.622100 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:10:21.622178 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:10:21.632181 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:10:21.974490 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:10:22.318790 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:22.422977 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect'.
Sep 16 20:10:22.504152 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack timeout icmp 1'.
Sep 16 20:10:22.607526 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:10:22.702143 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:10:22.819124 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:22.880372 osdx ubnt-cfgd[164596]: inactive
Sep 16 20:10:22.905081 osdx INFO[164605]: FRR daemons did not change
Sep 16 20:10:23.030069 osdx kernel: nfUDPlink: module init
Sep 16 20:10:23.034107 osdx kernel: app-detect: module init
Sep 16 20:10:23.034261 osdx kernel: app-detect: registered: sysctl net.appdetect
Sep 16 20:10:23.034277 osdx kernel: nfUDPlink: connected 127.0.0.1:49000
Sep 16 20:10:23.034289 osdx kernel: nfUDPlink: added destination 127.0.0.1:49000
Sep 16 20:10:23.034300 osdx kernel: app-detect: registered: /proc/net/stat/appdetect
Sep 16 20:10:23.034312 osdx kernel: app-detect: expression init
Sep 16 20:10:23.034323 osdx kernel: app-detect: appid cache initialized (override=yes, chained=yes)
Sep 16 20:10:23.034334 osdx kernel: app-detect: cache changes counter set appid_changes_count found (klen=4, dlen=4)
Sep 16 20:10:23.041569 osdx modulelauncher[164608]: AppDetect: no appdetect_chain refresh needed, nothing more to do
Sep 16 20:10:23.044574 osdx INFO[164633]: Stopping Traffic Categorization (TCATD) service ...
Sep 16 20:10:23.094089 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:23.147126 osdx WARNING[164710]: No supported link modes on interface eth0
Sep 16 20:10:23.148727 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:23.148743 osdx modulelauncher[164710]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:23.150176 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:23.150192 osdx modulelauncher[164710]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:23.194415 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:23.195118 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:23.195169 osdx ulogd[164730]: registering plugin `NFCT'
Sep 16 20:10:23.195212 osdx ulogd[164730]: registering plugin `IP2STR'
Sep 16 20:10:23.195252 osdx ulogd[164730]: registering plugin `PRINTFLOW'
Sep 16 20:10:23.195293 osdx ulogd[164730]: registering plugin `SYSLOG'
Sep 16 20:10:23.195296 osdx ulogd[164730]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:23.195335 osdx ulogd[164730]: NFCT plugin working in event mode
Sep 16 20:10:23.195342 osdx ulogd[164730]: Changing UID / GID
Sep 16 20:10:23.195413 osdx ulogd[164730]: initialization finished, entering main loop
Sep 16 20:10:23.372836 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:23.373475 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:23.390729 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:24.368059 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.368081 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484808 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484832 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506910 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:25.506941 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506958 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530892 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:26.530912 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530927 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]

Step 6: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[UPDATE\].*APPDETECT\[L3:1\]
Show output
Sep 16 20:10:21.619077 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.9M, max 13.8M, 11.8M free.
Sep 16 20:10:21.622100 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:10:21.622178 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:10:21.632181 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:10:21.974490 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:10:22.318790 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:22.422977 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect'.
Sep 16 20:10:22.504152 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack timeout icmp 1'.
Sep 16 20:10:22.607526 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:10:22.702143 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:10:22.819124 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:22.880372 osdx ubnt-cfgd[164596]: inactive
Sep 16 20:10:22.905081 osdx INFO[164605]: FRR daemons did not change
Sep 16 20:10:23.030069 osdx kernel: nfUDPlink: module init
Sep 16 20:10:23.034107 osdx kernel: app-detect: module init
Sep 16 20:10:23.034261 osdx kernel: app-detect: registered: sysctl net.appdetect
Sep 16 20:10:23.034277 osdx kernel: nfUDPlink: connected 127.0.0.1:49000
Sep 16 20:10:23.034289 osdx kernel: nfUDPlink: added destination 127.0.0.1:49000
Sep 16 20:10:23.034300 osdx kernel: app-detect: registered: /proc/net/stat/appdetect
Sep 16 20:10:23.034312 osdx kernel: app-detect: expression init
Sep 16 20:10:23.034323 osdx kernel: app-detect: appid cache initialized (override=yes, chained=yes)
Sep 16 20:10:23.034334 osdx kernel: app-detect: cache changes counter set appid_changes_count found (klen=4, dlen=4)
Sep 16 20:10:23.041569 osdx modulelauncher[164608]: AppDetect: no appdetect_chain refresh needed, nothing more to do
Sep 16 20:10:23.044574 osdx INFO[164633]: Stopping Traffic Categorization (TCATD) service ...
Sep 16 20:10:23.094089 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:23.147126 osdx WARNING[164710]: No supported link modes on interface eth0
Sep 16 20:10:23.148727 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:23.148743 osdx modulelauncher[164710]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:23.150176 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:23.150192 osdx modulelauncher[164710]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:23.194415 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:23.195118 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:23.195169 osdx ulogd[164730]: registering plugin `NFCT'
Sep 16 20:10:23.195212 osdx ulogd[164730]: registering plugin `IP2STR'
Sep 16 20:10:23.195252 osdx ulogd[164730]: registering plugin `PRINTFLOW'
Sep 16 20:10:23.195293 osdx ulogd[164730]: registering plugin `SYSLOG'
Sep 16 20:10:23.195296 osdx ulogd[164730]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:23.195335 osdx ulogd[164730]: NFCT plugin working in event mode
Sep 16 20:10:23.195342 osdx ulogd[164730]: Changing UID / GID
Sep 16 20:10:23.195413 osdx ulogd[164730]: initialization finished, entering main loop
Sep 16 20:10:23.372836 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:23.373475 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:23.390729 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:24.368059 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.368081 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484808 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484832 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506910 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:25.506941 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506958 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530892 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:26.530912 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530927 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.628407 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.

Step 7: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[DESTROY\].*APPDETECT\[L3:1\]
Show output
Sep 16 20:10:21.619077 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.9M, max 13.8M, 11.8M free.
Sep 16 20:10:21.622100 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:10:21.622178 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:10:21.632181 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:10:21.974490 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:10:22.318790 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:22.422977 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect'.
Sep 16 20:10:22.504152 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack timeout icmp 1'.
Sep 16 20:10:22.607526 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:10:22.702143 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:10:22.819124 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:22.880372 osdx ubnt-cfgd[164596]: inactive
Sep 16 20:10:22.905081 osdx INFO[164605]: FRR daemons did not change
Sep 16 20:10:23.030069 osdx kernel: nfUDPlink: module init
Sep 16 20:10:23.034107 osdx kernel: app-detect: module init
Sep 16 20:10:23.034261 osdx kernel: app-detect: registered: sysctl net.appdetect
Sep 16 20:10:23.034277 osdx kernel: nfUDPlink: connected 127.0.0.1:49000
Sep 16 20:10:23.034289 osdx kernel: nfUDPlink: added destination 127.0.0.1:49000
Sep 16 20:10:23.034300 osdx kernel: app-detect: registered: /proc/net/stat/appdetect
Sep 16 20:10:23.034312 osdx kernel: app-detect: expression init
Sep 16 20:10:23.034323 osdx kernel: app-detect: appid cache initialized (override=yes, chained=yes)
Sep 16 20:10:23.034334 osdx kernel: app-detect: cache changes counter set appid_changes_count found (klen=4, dlen=4)
Sep 16 20:10:23.041569 osdx modulelauncher[164608]: AppDetect: no appdetect_chain refresh needed, nothing more to do
Sep 16 20:10:23.044574 osdx INFO[164633]: Stopping Traffic Categorization (TCATD) service ...
Sep 16 20:10:23.094089 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:23.147126 osdx WARNING[164710]: No supported link modes on interface eth0
Sep 16 20:10:23.148727 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:23.148743 osdx modulelauncher[164710]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:23.150176 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:23.150192 osdx modulelauncher[164710]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:23.194415 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:23.195118 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:23.195169 osdx ulogd[164730]: registering plugin `NFCT'
Sep 16 20:10:23.195212 osdx ulogd[164730]: registering plugin `IP2STR'
Sep 16 20:10:23.195252 osdx ulogd[164730]: registering plugin `PRINTFLOW'
Sep 16 20:10:23.195293 osdx ulogd[164730]: registering plugin `SYSLOG'
Sep 16 20:10:23.195296 osdx ulogd[164730]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:23.195335 osdx ulogd[164730]: NFCT plugin working in event mode
Sep 16 20:10:23.195342 osdx ulogd[164730]: Changing UID / GID
Sep 16 20:10:23.195413 osdx ulogd[164730]: initialization finished, entering main loop
Sep 16 20:10:23.372836 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:23.373475 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:23.390729 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:24.368059 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.368081 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484808 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484832 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506910 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:25.506941 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506958 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530892 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:26.530912 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530927 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.628407 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 16 20:10:26.744203 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.

Step 8: Modify the following configuration lines in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set system conntrack app-detect http-host

Step 9: Ping the IP address 10.215.168.1 from DUT0:

admin@DUT0$ ping 10.215.168.1 count 1 size 56 timeout 1
Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data.
64 bytes from 10.215.168.1: icmp_seq=1 ttl=64 time=0.671 ms

--- 10.215.168.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.671/0.671/0.671/0.000 ms

Step 10: Run the command file copy http://10.215.168.1/~robot/ running://index.html force on DUT0 and expect the following output:

Show output
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  1209    0  1209    0     0   174k      0 --:--:-- --:--:-- --:--:--  196k

Step 11: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

ulogd\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*APPDETECT\[L4:80 http-host:10.215.168.1\]
Show output
Sep 16 20:10:21.619077 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.9M, max 13.8M, 11.8M free.
Sep 16 20:10:21.622100 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:10:21.622178 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:10:21.632181 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:10:21.974490 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:10:22.318790 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:22.422977 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect'.
Sep 16 20:10:22.504152 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack timeout icmp 1'.
Sep 16 20:10:22.607526 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:10:22.702143 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:10:22.819124 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:22.880372 osdx ubnt-cfgd[164596]: inactive
Sep 16 20:10:22.905081 osdx INFO[164605]: FRR daemons did not change
Sep 16 20:10:23.030069 osdx kernel: nfUDPlink: module init
Sep 16 20:10:23.034107 osdx kernel: app-detect: module init
Sep 16 20:10:23.034261 osdx kernel: app-detect: registered: sysctl net.appdetect
Sep 16 20:10:23.034277 osdx kernel: nfUDPlink: connected 127.0.0.1:49000
Sep 16 20:10:23.034289 osdx kernel: nfUDPlink: added destination 127.0.0.1:49000
Sep 16 20:10:23.034300 osdx kernel: app-detect: registered: /proc/net/stat/appdetect
Sep 16 20:10:23.034312 osdx kernel: app-detect: expression init
Sep 16 20:10:23.034323 osdx kernel: app-detect: appid cache initialized (override=yes, chained=yes)
Sep 16 20:10:23.034334 osdx kernel: app-detect: cache changes counter set appid_changes_count found (klen=4, dlen=4)
Sep 16 20:10:23.041569 osdx modulelauncher[164608]: AppDetect: no appdetect_chain refresh needed, nothing more to do
Sep 16 20:10:23.044574 osdx INFO[164633]: Stopping Traffic Categorization (TCATD) service ...
Sep 16 20:10:23.094089 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:23.147126 osdx WARNING[164710]: No supported link modes on interface eth0
Sep 16 20:10:23.148727 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:23.148743 osdx modulelauncher[164710]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:23.150176 osdx modulelauncher[164710]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:23.150192 osdx modulelauncher[164710]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:23.194415 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:23.195118 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:23.195169 osdx ulogd[164730]: registering plugin `NFCT'
Sep 16 20:10:23.195212 osdx ulogd[164730]: registering plugin `IP2STR'
Sep 16 20:10:23.195252 osdx ulogd[164730]: registering plugin `PRINTFLOW'
Sep 16 20:10:23.195293 osdx ulogd[164730]: registering plugin `SYSLOG'
Sep 16 20:10:23.195296 osdx ulogd[164730]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:23.195335 osdx ulogd[164730]: NFCT plugin working in event mode
Sep 16 20:10:23.195342 osdx ulogd[164730]: Changing UID / GID
Sep 16 20:10:23.195413 osdx ulogd[164730]: initialization finished, entering main loop
Sep 16 20:10:23.372836 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:23.373475 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:23.390729 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:24.368059 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.368081 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484808 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:24.484832 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506910 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:25.506941 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:25.506958 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530892 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:26.530912 osdx ulogd[164730]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.530927 osdx ulogd[164730]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:26.628407 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 16 20:10:26.744203 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 16 20:10:26.859107 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal show | cat'.
Sep 16 20:10:27.011759 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:27.094774 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 16 20:10:27.167767 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect http-host'.
Sep 16 20:10:27.223546 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show changes'.
Sep 16 20:10:27.327649 osdx ubnt-cfgd[164798]: inactive
Sep 16 20:10:27.355126 osdx INFO[164807]: FRR daemons did not change
Sep 16 20:10:27.394065 osdx kernel: app-detect: expression destroy
Sep 16 20:10:27.406089 osdx kernel: app-detect: expression init
Sep 16 20:10:27.406147 osdx kernel: app-detect: appid cache initialized (override=yes, chained=yes)
Sep 16 20:10:27.406167 osdx kernel: app-detect: cache changes counter set appid_changes_count found (klen=4, dlen=4)
Sep 16 20:10:27.413459 osdx modulelauncher[164810]: AppDetect: no appdetect_chain refresh needed, nothing more to do
Sep 16 20:10:27.416447 osdx INFO[164826]: Stopping Traffic Categorization (TCATD) service ...
Sep 16 20:10:27.526524 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:27.526546 osdx ulogd[164730]: [DESTROY] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=1 BYTES=84 APPDETECT[L3:1]
Sep 16 20:10:27.526976 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:27.527473 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:27.544054 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:27.729820 osdx ulogd[164730]: [NEW] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:27.730441 osdx ulogd[164730]: [UPDATE] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 APPDETECT[L3:1]
Sep 16 20:10:27.732735 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 16 20:10:27.890587 osdx file_operation[164893]: using src url: http://10.215.168.1/~robot/ dst url: running://index.html
Sep 16 20:10:27.897352 osdx ulogd[164730]: [NEW] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=TCP SPT=42714 DPT=80 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=TCP SPT=80 DPT=42714 PKTS=0 BYTES=0 APPDETECT[L4:80]
Sep 16 20:10:27.897470 osdx ulogd[164730]: [UPDATE] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=TCP SPT=42714 DPT=80 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=TCP SPT=80 DPT=42714 PKTS=0 BYTES=0 APPDETECT[L4:80]
Sep 16 20:10:27.897487 osdx ulogd[164730]: [UPDATE] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=TCP SPT=42714 DPT=80 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=TCP SPT=80 DPT=42714 PKTS=0 BYTES=0 APPDETECT[L4:80]
Sep 16 20:10:27.899162 osdx ulogd[164730]: [UPDATE] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=TCP SPT=42714 DPT=80 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=TCP SPT=80 DPT=42714 PKTS=0 BYTES=0 APPDETECT[L4:80 http-host:10.215.168.1]
Sep 16 20:10:27.899286 osdx ulogd[164730]: [UPDATE] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=TCP SPT=42714 DPT=80 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=TCP SPT=80 DPT=42714 PKTS=0 BYTES=0 APPDETECT[L4:80 http-host:10.215.168.1]
Sep 16 20:10:27.899304 osdx ulogd[164730]: [UPDATE] ORIG: SRC=10.215.168.64 DST=10.215.168.1 PROTO=TCP SPT=42714 DPT=80 PKTS=0 BYTES=0 , REPLY: SRC=10.215.168.1 DST=10.215.168.64 PROTO=TCP SPT=80 DPT=42714 PKTS=0 BYTES=0 APPDETECT[L4:80 http-host:10.215.168.1]
Sep 16 20:10:27.921671 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'file copy http://10.215.168.1/~robot/ running://index.html force'.

App Detect Drop Packet

Description

Set a traffic policy with action drop for all the packets matching an appid specified by a traffic selector. Enable http-host and http-url option in system conntrack appdetect path in order to see relevant information about http packets. Finnally, log that packets with app-id option and check that appdetect field appear in journal when running system journal show

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 10.215.168.64/24
set interfaces ethernet eth0 traffic policy out DROP
set system conntrack app-detect dictionary 130 local app-id custom 155 fqdn 10.215.168.1
set system conntrack app-detect enable_dict_match_priv_ip
set system conntrack app-detect http-host
set system conntrack app-detect http-url
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy DROP rule 1 action drop
set traffic policy DROP rule 1 log app-id
set traffic policy DROP rule 1 selector APPID
set traffic selector APPID rule 1 app-detect app-id custom 155

Step 2: Ping the IP address 10.215.168.1 from DUT0:

admin@DUT0$ ping 10.215.168.1 count 1 size 56 timeout 1
Show output
PING 10.215.168.1 (10.215.168.1) 56(84) bytes of data.
64 bytes from 10.215.168.1: icmp_seq=1 ttl=64 time=0.652 ms

--- 10.215.168.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.652/0.652/0.652/0.000 ms

Step 3: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

osdx kernel:.*APPDETECT\[U6:155 http-url:/~robot/ http-host:10.215.168.1\]
Show output
Sep 16 20:10:33.297896 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.9M, max 13.8M, 11.9M free.
Sep 16 20:10:33.299906 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:10:33.299976 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:10:33.309219 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:10:33.535096 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:10:33.779701 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:33.882106 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect dictionary 130 custom app-id 155 fqdn 10.215.168.1'.
Sep 16 20:10:33.933142 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect enable_dict_match_priv_ip'.
Sep 16 20:10:34.028369 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect http-url'.
Sep 16 20:10:34.089023 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic selector APPID rule 1 app-detect app-id custom 155'.
Sep 16 20:10:34.178139 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy DROP rule 1 selector APPID'.
Sep 16 20:10:34.230124 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy DROP rule 1 action drop'.
Sep 16 20:10:34.350343 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set traffic policy DROP rule 1 log app-id'.
Sep 16 20:10:34.481126 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 traffic policy out DROP'.
Sep 16 20:10:34.534543 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 10.215.168.64/24'.
Sep 16 20:10:34.645550 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack app-detect http-host'.
Sep 16 20:10:34.719731 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:34.832104 osdx ubnt-cfgd[165142]: inactive
Sep 16 20:10:34.881684 osdx INFO[165171]: FRR daemons did not change
Sep 16 20:10:34.975933 osdx kernel: nfUDPlink: module init
Sep 16 20:10:34.975987 osdx kernel: app-detect: module init
Sep 16 20:10:34.975998 osdx kernel: app-detect: registered: sysctl net.appdetect
Sep 16 20:10:34.976007 osdx kernel: nfUDPlink: connected 127.0.0.1:49000
Sep 16 20:10:34.976015 osdx kernel: nfUDPlink: added destination 127.0.0.1:49000
Sep 16 20:10:34.976023 osdx kernel: app-detect: registered: /proc/net/stat/appdetect
Sep 16 20:10:34.976033 osdx kernel: app-detect: expression init
Sep 16 20:10:34.976048 osdx kernel: app-detect: appid cache initialized (override=yes, chained=yes)
Sep 16 20:10:34.976058 osdx kernel: app-detect: cache changes counter set appid_changes_count found (klen=4, dlen=4)
Sep 16 20:10:34.999742 osdx INFO[165206]: Updated /etc/default/osdx_tcatd.conf
Sep 16 20:10:34.999776 osdx INFO[165206]: Restarting Traffic Categorization (TCATD) service ...
Sep 16 20:10:35.028346 osdx systemd[1]: Starting osdx-tcatd.service - App-Detect Traffic Categorization daemon...
Sep 16 20:10:35.042077 osdx systemd[1]: Started osdx-tcatd.service - App-Detect Traffic Categorization daemon.
Sep 16 20:10:35.075908 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:35.128620 osdx WARNING[165282]: No supported link modes on interface eth0
Sep 16 20:10:35.130100 osdx modulelauncher[165282]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:35.130114 osdx modulelauncher[165282]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:35.131270 osdx modulelauncher[165282]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:35.131279 osdx modulelauncher[165282]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:35.621664 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:35.622189 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:35.638411 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:35.777243 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'ping 10.215.168.1 count 1 size 56 timeout 1'.
Sep 16 20:10:35.938656 osdx file_operation[165379]: using src url: http://10.215.168.1/~robot/ dst url: running://index.html
Sep 16 20:10:35.947903 osdx kernel: [DROP-1] DROP IN= OUT=eth0 SRC=10.215.168.64 DST=10.215.168.1 LEN=306 TOS=0x00 PREC=0x00 TTL=64 ID=154 DF PROTO=TCP SPT=42716 DPT=80 WINDOW=502 RES=0x00 ACK PSH URGP=0 APPDETECT[U6:155 http-url:/~robot/ http-host:10.215.168.1]
Sep 16 20:10:36.151901 osdx kernel: [DROP-1] DROP IN= OUT=eth0 SRC=10.215.168.64 DST=10.215.168.1 LEN=306 TOS=0x00 PREC=0x00 TTL=64 ID=155 DF PROTO=TCP SPT=42716 DPT=80 WINDOW=502 RES=0x00 ACK PSH URGP=0 APPDETECT[U6:155 http-url:/~robot/ http-host:10.215.168.1]
Sep 16 20:10:36.579952 osdx kernel: [DROP-1] DROP IN= OUT=eth0 SRC=10.215.168.64 DST=10.215.168.1 LEN=306 TOS=0x00 PREC=0x00 TTL=64 ID=156 DF PROTO=TCP SPT=42716 DPT=80 WINDOW=502 RES=0x00 ACK PSH URGP=0 APPDETECT[U6:155 http-url:/~robot/ http-host:10.215.168.1]
Sep 16 20:10:37.411965 osdx kernel: [DROP-1] DROP IN= OUT=eth0 SRC=10.215.168.64 DST=10.215.168.1 LEN=306 TOS=0x00 PREC=0x00 TTL=64 ID=157 DF PROTO=TCP SPT=42716 DPT=80 WINDOW=502 RES=0x00 ACK PSH URGP=0 APPDETECT[U6:155 http-url:/~robot/ http-host:10.215.168.1]
Sep 16 20:10:38.888493 osdx file_operation.py[165379]: Operation aborted by user.
Sep 16 20:10:38.899911 osdx kernel: [DROP-1] DROP IN= OUT=eth0 SRC=10.215.168.64 DST=10.215.168.1 LEN=306 TOS=0x00 PREC=0x00 TTL=64 ID=158 DF PROTO=TCP SPT=42716 DPT=80 WINDOW=502 RES=0x00 ACK PSH FIN URGP=0 APPDETECT[U6:155 http-url:/~robot/ http-host:10.215.168.1]
Sep 16 20:10:38.904990 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'file copy http://10.215.168.1/~robot/ running://index.html force'.

Identity Values

Description

Conntrack identity is able to contain any printed character (max 92 characters) but not spaces

Scenario

Step 1: Run the command configure on DUT0 and expect the following output:

Show output
admin@osdx#

Step 2: Run the command set system conntrack logging identity "he||o w@rld!" on DUT0 and check whether the output contains the following tokens:

Identity name must be 92 characters or less and must contain printable characters except those defined as part of the space character class
Show output
Identity name must be 92 characters or less and must contain printable characters except those defined as part of the space character class
Value validation failed
CLI Error: Command error

Step 3: Run the command set system conntrack logging identity Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-amet-vita on DUT0 and check whether the output contains the following tokens:

Identity name must be 92 characters or less and must contain printable characters except those defined as part of the space character class
Show output
Identity name must be 92 characters or less and must contain printable characters except those defined as part of the space character class
Value validation failed
CLI Error: Command error

Step 4: Set the following configuration in DUT0 :

set interfaces ethernet eth0 address 192.168.100.1/24
set system conntrack logging events all
set system conntrack logging identity Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 5: Set the following configuration in DUT1 :

set interfaces ethernet eth0 address 192.168.100.2/24
set protocols static route 0.0.0.0/0 next-hop 192.168.100.1
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 6: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.658 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.658/0.658/0.658/0.000 ms

Step 7: Ping the IP address 192.168.100.1 from DUT1:

admin@DUT1$ ping 192.168.100.1 count 1 size 56 timeout 1
Show output
PING 192.168.100.1 (192.168.100.1) 56(84) bytes of data.
64 bytes from 192.168.100.1: icmp_seq=1 ttl=64 time=0.493 ms

--- 192.168.100.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.493/0.493/0.493/0.000 ms

Step 8: Run the command system journal show | cat on DUT0 and check whether the output matches the following regular expressions:

Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit\[.*\]:.*\[((NEW)|(UPDATE)|(DESTROY))\].*SRC=192.168.100.2
Show output
Sep 16 20:10:44.315330 osdx systemd-journald[2158]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free.
Sep 16 20:10:44.318163 osdx systemd-journald[2158]: Received client request to rotate journal, rotating.
Sep 16 20:10:44.318222 osdx systemd-journald[2158]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5.
Sep 16 20:10:44.324969 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system journal clear'.
Sep 16 20:10:44.544507 osdx OSDxCLI[157302]: User 'admin' executed a new command: 'system coredump delete all'.
Sep 16 20:10:44.801418 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:44.879032 osdx cfgd[1899]: [157302]Command output:
Identity name must be 92 characters or less and must contain printable characters except those defined as part of the space character class
Value validation failed
Sep 16 20:10:44.880169 osdx OSDxCLI[157302]: User 'admin' entered an invalid command: 'set system conntrack logging identity "he||o w@rld!"'.
Sep 16 20:10:44.997166 osdx cfgd[1899]: [157302]Command output:
Identity name must be 92 characters or less and must contain printable characters except those defined as part of the space character class
Value validation failed
Sep 16 20:10:44.998782 osdx OSDxCLI[157302]: User 'admin' entered an invalid command: 'set system conntrack logging identity Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-amet-vita'.
Sep 16 20:10:45.016452 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:45.200648 osdx OSDxCLI[157302]: User 'admin' entered the configuration menu.
Sep 16 20:10:45.287805 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set interfaces ethernet eth0 address 192.168.100.1/24'.
Sep 16 20:10:45.373099 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging events all'.
Sep 16 20:10:45.488630 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'set system conntrack logging identity Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit'.
Sep 16 20:10:45.561718 osdx OSDxCLI[157302]: User 'admin' added a new cfg line: 'show working'.
Sep 16 20:10:45.665660 osdx ubnt-cfgd[165632]: inactive
Sep 16 20:10:45.690525 osdx INFO[165641]: FRR daemons did not change
Sep 16 20:10:45.726158 osdx kernel: 8021q: adding VLAN 0 to HW filter on device eth0
Sep 16 20:10:45.775503 osdx WARNING[165715]: No supported link modes on interface eth0
Sep 16 20:10:45.776983 osdx modulelauncher[165715]: osdx.utils.xos cmd error: /sbin/ethtool -A eth0 autoneg on
Sep 16 20:10:45.776996 osdx modulelauncher[165715]: Command '/sbin/ethtool -A eth0 autoneg on' returned non-zero exit status 76.
Sep 16 20:10:45.778364 osdx modulelauncher[165715]: osdx.utils.xos cmd error: /sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --
Sep 16 20:10:45.778373 osdx modulelauncher[165715]: Command '/sbin/ethtool -s eth0 autoneg on advertise Pause off Asym_Pause off --' returned non-zero exit status 75.
Sep 16 20:10:45.834720 osdx systemd[1]: Starting ulogd2.service - Netfilter Userspace Logging Daemon...
Sep 16 20:10:45.835846 osdx ulogd[165735]: registering plugin `NFCT'
Sep 16 20:10:45.835913 osdx ulogd[165735]: registering plugin `IP2STR'
Sep 16 20:10:45.835919 osdx systemd[1]: Started ulogd2.service - Netfilter Userspace Logging Daemon.
Sep 16 20:10:45.835956 osdx ulogd[165735]: registering plugin `PRINTFLOW'
Sep 16 20:10:45.836005 osdx ulogd[165735]: registering plugin `SYSLOG'
Sep 16 20:10:45.836010 osdx ulogd[165735]: building new pluginstance stack: 'ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,sys1:SYSLOG'
Sep 16 20:10:45.836065 osdx ulogd[165735]: NFCT plugin working in event mode
Sep 16 20:10:45.836075 osdx Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit[165735]: Changing UID / GID
Sep 16 20:10:45.836201 osdx Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit[165735]: initialization finished, entering main loop
Sep 16 20:10:46.029284 osdx cfgd[1899]: [157302]Completed change to active configuration
Sep 16 20:10:46.029911 osdx OSDxCLI[157302]: User 'admin' committed the configuration.
Sep 16 20:10:46.046293 osdx OSDxCLI[157302]: User 'admin' left the configuration menu.
Sep 16 20:10:47.184169 osdx Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit[165735]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:10:47.184187 osdx Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit[165735]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:10:47.265863 osdx Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit[165735]: [NEW] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0
Sep 16 20:10:47.265886 osdx Lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit-quisque-lorem-ipsum-dolor-sit-ame-vit[165735]: [UPDATE] ORIG: SRC=192.168.100.2 DST=192.168.100.1 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0 , REPLY: SRC=192.168.100.1 DST=192.168.100.2 PROTO=ICMP TYPE=0 CODE=8 PKTS=0 BYTES=0