Link-In
The following scenario shows how to filter packets based on
VLAN attributes using traffic selectors. The policy is
attached to DUT0’s link-in hook; DUT1 originates the
traffic and DUT0’s journal is checked.
Test VLAN Selector (802.1Q) Link-In
Description
A traffic policy MATCH_VLAN is configured on DUT0’s
parent interface (eth0) in the link-in hook.
The traffic selector VLAN filters packets with
ether-type 8021q and vlan id 100, logging
matches with prefix MATCH_VLAN. DUT1 sends a ping
through the 802.1Q VLAN; DUT0 sees it on link-in.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.452 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.452/0.452/0.452/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 18:12:24.212837 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 18:12:24.216161 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=35763 DF PROTO=ICMP TYPE=8 CODE=0 ID=436 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.606 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.606/0.606/0.606/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 08:28:26.789483 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 08:28:26.789772 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=3702 DF PROTO=ICMP TYPE=8 CODE=0 ID=1127 SEQ=1 Sep 17 08:28:27.839782 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=4013 DF PROTO=ICMP TYPE=8 CODE=0 ID=1128 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.359 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.359/0.359/0.359/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 06:18:29.020317 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 06:18:29.308237 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 06:18:29.308526 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=2803 DF PROTO=ICMP TYPE=8 CODE=0 ID=1200 SEQ=1 Sep 17 06:18:30.344807 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=3216 DF PROTO=ICMP TYPE=8 CODE=0 ID=1201 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.28 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.282/1.282/1.282/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0p0.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 06:43:16.152531 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 06:43:16.153259 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=00:a0:26:0e:62:79:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=37899 DF PROTO=ICMP TYPE=8 CODE=0 ID=611 SEQ=1 Sep 17 06:43:16.170671 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=33:33:ff:ef:6c:10:de:ad:be:ef:6c:10:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ffef:6c10 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.618 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.618/0.618/0.618/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth4.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 03:12:30.660429 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 03:12:30.660621 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=49485 DF PROTO=ICMP TYPE=8 CODE=0 ID=1232 SEQ=1 Sep 17 03:12:31.738820 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=50191 DF PROTO=ICMP TYPE=8 CODE=0 ID=1233 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.682 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.682/0.682/0.682/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:33:18.259784 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:33:18.259821 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=40:64:dc:38:ed:02:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=54263 DF PROTO=ICMP TYPE=8 CODE=0 ID=631 SEQ=1
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 10: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.503 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.503/0.503/0.503/0.000 ms
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth5.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:33:30.631783 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:11 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:33:30.631823 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=57047 DF PROTO=ICMP TYPE=8 CODE=0 ID=633 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.834 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.834/0.834/0.834/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 14:32:00.699781 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 14:32:00.700226 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:8b:00:96:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=62454 DF PROTO=ICMP TYPE=8 CODE=0 ID=180 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.567 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.567/0.567/0.567/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 00:33:20.908499 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:33:21.036496 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:33:21.292456 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 00:33:21.295486 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=50422 DF PROTO=ICMP TYPE=8 CODE=0 ID=1149 SEQ=1 Sep 17 00:33:22.325782 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=50609 DF PROTO=ICMP TYPE=8 CODE=0 ID=1150 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.431 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.431/0.431/0.431/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth2.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 20:01:58.430745 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 20:01:58.431017 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=25455 DF PROTO=ICMP TYPE=8 CODE=0 ID=675 SEQ=1 Sep 16 20:01:59.486073 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=25934 DF PROTO=ICMP TYPE=8 CODE=0 ID=676 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.697 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.697/0.697/0.697/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 10:04:59.811174 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 10:04:59.811497 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=20101 DF PROTO=ICMP TYPE=8 CODE=0 ID=1196 SEQ=1 Sep 17 10:05:00.857596 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=20687 DF PROTO=ICMP TYPE=8 CODE=0 ID=1197 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.439 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.439/0.439/0.439/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:49:56.205785 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:49:56.206113 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=22414 DF PROTO=ICMP TYPE=8 CODE=0 ID=381 SEQ=1 Sep 16 23:49:57.268024 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=23060 DF PROTO=ICMP TYPE=8 CODE=0 ID=382 SEQ=1
Test VLAN Selector (QinQ) Link-In
Description
A traffic policy MATCH_VLAN is configured on DUT0’s
parent interface (eth0) in the link-in hook.
The traffic selector VLAN filters packets with
ether-type 8021ad, vlan id 100,
vlan protocol 8021q and vlan inner-id 200. DUT1
sends a ping through the QinQ VLAN; DUT0 sees the
double-tagged packet on link-in.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.373 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.373/0.373/0.373/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 18:12:32.968811 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.720 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.720/0.720/0.720/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 17 08:28:50.349724 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00 Sep 17 08:28:51.415408 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.678 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.678/0.678/0.678/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 06:18:53.012515 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00 Sep 17 06:18:54.066465 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad set interfaces ethernet eth0p0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.941 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.941/0.941/0.941/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0p0.*Show output
Sep 17 06:43:44.270369 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=00:a0:26:0e:62:79:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 ethertype 802.1ad set interfaces ethernet eth4 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.324 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.324/0.324/0.324/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth4.*Show output
Sep 17 03:12:46.329624 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00 Sep 17 03:12:47.385506 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.813 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.813/0.813/0.813/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 23:33:41.539789 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=40:64:dc:38:ed:02:de:ad:be:ef:6c:10:81:00
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 ethertype 802.1ad set interfaces ethernet eth5 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 10: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.465 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.465/0.465/0.465/0.000 ms
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth5.*Show output
Sep 16 23:33:54.323804 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.702 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.702/0.702/0.702/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 14:32:13.955225 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:8b:00:96:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.626 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.626/0.626/0.626/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 00:33:39.901307 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:33:40.937361 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 ethertype 802.1ad set interfaces ethernet eth2 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.780 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.780/0.780/0.780/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth2.*Show output
Sep 16 20:02:29.090011 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:02:31.209157 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.422 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.422/0.422/0.422/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 10:05:23.842636 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00 Sep 17 10:05:24.900074 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.33 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.327/1.327/1.327/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 23:50:21.796084 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:81:00 Sep 16 23:50:22.838734 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:81:00
Test VLAN Selector (QinQ) With PCP Matches Link-In
Description
The traffic selector VLAN filters QinQ packets
matching vlan id 100, vlan pcp 3,
vlan inner-id 200 and vlan inner-pcp 5. Traffic
policies OUTER_COS and INNER_COS on DUT1’s outer
and inner VLAN sub-interfaces set the required PCP
values, which DUT0 matches on link-in.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.666 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.666/0.666/0.666/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 18:12:42.673009 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.589 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.589/0.589/0.589/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 17 08:29:15.654801 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00 Sep 17 08:29:16.722192 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.455 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.455/0.455/0.455/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 06:19:17.505012 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00 Sep 17 06:19:18.551801 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad set interfaces ethernet eth0p0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.10 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.095/1.095/1.095/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0p0.*Show output
Sep 17 06:44:12.548166 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=00:a0:26:0e:62:79:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 ethertype 802.1ad set interfaces ethernet eth4 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.413 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.413/0.413/0.413/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth4.*Show output
Sep 17 03:13:03.054259 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00 Sep 17 03:13:04.085800 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.492 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.492/0.492/0.492/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 23:34:06.319655 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=40:64:dc:38:ed:02:de:ad:be:ef:6c:10:81:00
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 ethertype 802.1ad set interfaces ethernet eth5 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth1 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 10: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.338 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.338/0.338/0.338/0.000 ms
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth5.*Show output
Sep 16 23:34:18.755700 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:81:00 Sep 16 23:34:20.123676 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.953 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.953/0.953/0.953/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 14:32:28.948468 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:8b:00:96:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.653 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.653/0.653/0.653/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 00:33:58.923536 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:01.000751 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 ethertype 802.1ad set interfaces ethernet eth2 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.665 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.665/0.665/0.665/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth2.*Show output
Sep 16 20:02:54.651290 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:02:55.728289 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.626 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.626/0.626/0.626/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 10:05:53.490423 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00 Sep 17 10:05:54.564326 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan inner-protocol ip set traffic selector VLAN rule 1 vlan pcp 3 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 5 set traffic policy OUTER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.805 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.805/0.805/0.805/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 23:50:55.769135 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:81:00
Test VLAN Selector (802.1Q) With Not Vlan Id Link-In
Description
The traffic selector VLAN uses not vlan id 100.
DUT1 sends through VLAN 101, so the negated condition
matches on DUT0’s link-in hook (the packet’s VLAN id
differs from 100), causing rule 1 to log with prefix
MATCH_VLAN.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.573 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.573/0.573/0.573/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 18:12:52.490604 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 18:12:52.491441 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=38018 DF PROTO=ICMP TYPE=8 CODE=0 ID=439 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.452 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.452/0.452/0.452/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 08:29:37.811291 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 08:29:37.843308 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 08:29:37.845709 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=12142 DF PROTO=ICMP TYPE=8 CODE=0 ID=1133 SEQ=1 Sep 17 08:29:38.911717 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=12187 DF PROTO=ICMP TYPE=8 CODE=0 ID=1134 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.762 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.762/0.762/0.762/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 06:19:40.965682 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 06:19:40.966029 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=16000 DF PROTO=ICMP TYPE=8 CODE=0 ID=1206 SEQ=1 Sep 17 06:19:40.997552 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 06:19:42.001405 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=16428 DF PROTO=ICMP TYPE=8 CODE=0 ID=1207 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.28 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.283/1.283/1.283/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0p0.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 06:44:40.427998 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 06:44:40.430862 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=00:a0:26:0e:62:79:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=46798 DF PROTO=ICMP TYPE=8 CODE=0 ID=614 SEQ=1 Sep 17 06:44:40.515081 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=33:33:ff:ef:6c:10:de:ad:be:ef:6c:10:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ffef:6c10 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.559 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.559/0.559/0.559/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth4.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 03:13:18.669839 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 03:13:18.670044 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=55768 DF PROTO=ICMP TYPE=8 CODE=0 ID=1238 SEQ=1 Sep 17 03:13:19.736374 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=55848 DF PROTO=ICMP TYPE=8 CODE=0 ID=1239 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.725 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.725/0.725/0.725/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:34:31.203687 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:34:31.203725 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=40:64:dc:38:ed:02:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=1723 DF PROTO=ICMP TYPE=8 CODE=0 ID=640 SEQ=1
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 10: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.854 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.854/0.854/0.854/0.000 ms
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth5.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:34:43.931640 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:11 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:34:43.931681 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=2898 DF PROTO=ICMP TYPE=8 CODE=0 ID=642 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.14 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.138/1.138/1.138/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 14:32:43.640288 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 14:32:43.640614 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:8b:00:96:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=2740 DF PROTO=ICMP TYPE=8 CODE=0 ID=183 SEQ=1 Sep 16 14:32:43.715255 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.508 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.508/0.508/0.508/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 00:34:17.397994 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:34:18.229920 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 00:34:18.230210 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=57160 DF PROTO=ICMP TYPE=8 CODE=0 ID=1155 SEQ=1 Sep 17 00:34:19.287368 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=57704 DF PROTO=ICMP TYPE=8 CODE=0 ID=1156 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.411 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.411/0.411/0.411/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth2.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 20:03:17.176744 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 16 20:03:17.912693 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 20:03:17.914334 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=35333 DF PROTO=ICMP TYPE=8 CODE=0 ID=684 SEQ=1 Sep 16 20:03:18.960757 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=35558 DF PROTO=ICMP TYPE=8 CODE=0 ID=685 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.851 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.851/0.851/0.851/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 10:06:17.405999 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 10:06:17.565936 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 10:06:17.566217 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=29783 DF PROTO=ICMP TYPE=8 CODE=0 ID=1202 SEQ=1 Sep 17 10:06:18.618242 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=30253 DF PROTO=ICMP TYPE=8 CODE=0 ID=1203 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 101 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 101 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.672 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.672/0.672/0.672/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:51:19.870766 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:51:19.871057 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=35465 DF PROTO=ICMP TYPE=8 CODE=0 ID=389 SEQ=1 Sep 16 23:51:20.926345 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=35853 DF PROTO=ICMP TYPE=8 CODE=0 ID=390 SEQ=1
Test VLAN Selector (802.1Q) With Not Vlan PCP Link-In
Description
The traffic selector VLAN uses vlan id 100 and
not vlan pcp 3. A traffic policy SET_COS on DUT1’s
VLAN sub-interface sets the PCP value to 5, so the negated
condition matches on DUT0’s link-in hook, causing rule 1
to log with prefix MATCH_VLAN.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.15 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.147/1.147/1.147/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 18:13:01.871945 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 18:13:01.875536 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=39379 DF PROTO=ICMP TYPE=8 CODE=0 ID=440 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.996 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.996/0.996/0.996/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 08:30:01.791582 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 08:30:02.856366 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 08:30:02.857479 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=13003 DF PROTO=ICMP TYPE=8 CODE=0 ID=1136 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.691 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.691/0.691/0.691/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 06:20:06.281412 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 06:20:06.281639 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 06:20:06.281723 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=21238 DF PROTO=ICMP TYPE=8 CODE=0 ID=1208 SEQ=1 Sep 17 06:20:06.377275 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 06:20:07.315462 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=21940 DF PROTO=ICMP TYPE=8 CODE=0 ID=1209 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.75 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.749/1.749/1.749/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0p0.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 06:45:08.905418 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=33:33:ff:ef:6c:10:de:ad:be:ef:6c:10:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ffef:6c10 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0 Sep 17 06:45:08.948984 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 06:45:08.951039 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=00:a0:26:0e:62:79:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=49199 DF PROTO=ICMP TYPE=8 CODE=0 ID=615 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.626 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.626/0.626/0.626/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth4.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 03:13:35.118615 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 03:13:35.118802 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=55955 DF PROTO=ICMP TYPE=8 CODE=0 ID=1240 SEQ=1 Sep 17 03:13:36.167239 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=56510 DF PROTO=ICMP TYPE=8 CODE=0 ID=1241 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.772 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.772/0.772/0.772/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:34:54.519627 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:34:54.519667 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=40:64:dc:38:ed:02:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=3345 DF PROTO=ICMP TYPE=8 CODE=0 ID=643 SEQ=1
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 address 10.0.0.2/24 set interfaces ethernet eth1 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 10: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.529 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.529/0.529/0.529/0.000 ms
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth5.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:35:06.387682 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:11 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:35:06.387729 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=4276 DF PROTO=ICMP TYPE=8 CODE=0 ID=644 SEQ=1 Sep 16 23:35:07.643690 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=4546 DF PROTO=ICMP TYPE=8 CODE=0 ID=645 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.793 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.793/0.793/0.793/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 14:32:56.733865 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 16 14:32:56.829891 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:ff:ef:6c:10:de:ad:be:ef:6c:10:86:dd SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ffef:6c10 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0 Sep 16 14:32:56.846126 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 14:32:56.847094 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:8b:00:96:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=5749 DF PROTO=ICMP TYPE=8 CODE=0 ID=184 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.497 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.497/0.497/0.497/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 00:34:35.507367 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 00:34:35.699365 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:34:35.859366 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:34:36.531390 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 00:34:36.532111 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=60056 DF PROTO=ICMP TYPE=8 CODE=0 ID=1157 SEQ=1 Sep 17 00:34:37.618294 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=60122 DF PROTO=ICMP TYPE=8 CODE=0 ID=1158 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.751 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.751/0.751/0.751/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth2.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 20:03:38.584886 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 20:03:38.712860 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 16 20:03:38.874145 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 16 20:03:39.608878 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 20:03:39.609169 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=39692 DF PROTO=ICMP TYPE=8 CODE=0 ID=686 SEQ=1 Sep 16 20:03:40.656718 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=40426 DF PROTO=ICMP TYPE=8 CODE=0 ID=687 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.732 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.732/0.732/0.732/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 17 10:06:41.856654 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 10:06:42.048590 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 17 10:06:42.048893 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=30712 DF PROTO=ICMP TYPE=8 CODE=0 ID=1204 SEQ=1 Sep 17 10:06:42.208630 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 10:06:43.097794 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=31170 DF PROTO=ICMP TYPE=8 CODE=0 ID=1205 SEQ=1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan pcp 3 set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy SET_COS rule 1 set cos-mark 5
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.836 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.836/0.836/0.836/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*10.0.0.2.*10.0.0.1.*Show output
Sep 16 23:51:47.153633 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:51:48.177556 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=00:00:00:00:00:00 IPDST=10.0.0.1 Sep 16 23:51:48.180943 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=40261 DF PROTO=ICMP TYPE=8 CODE=0 ID=392 SEQ=1 Sep 16 23:51:49.234788 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:08:00 SRC=10.0.0.2 DST=10.0.0.1 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=40455 DF PROTO=ICMP TYPE=8 CODE=0 ID=393 SEQ=1
Test VLAN Selector (QinQ) With Not Vlan Inner-id Link-In
Description
The traffic selector VLAN uses vlan id 100,
vlan protocol 8021q and not vlan inner-id 200.
DUT1 sends through C-VLAN 201, so the negated condition
matches on DUT0’s link-in hook (the packet’s inner VLAN
id differs from 200), causing rule 1 to log with prefix
MATCH_VLAN.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.466 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.466/0.466/0.466/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 18:13:11.091526 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 18:13:11.093236 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.378 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.378/0.378/0.378/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 17 08:30:25.244375 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 08:30:25.244592 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00 Sep 17 08:30:26.289839 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.478 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.478/0.478/0.478/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 06:20:29.414119 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 06:20:29.670085 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 06:20:29.798016 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 06:20:29.798299 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00 Sep 17 06:20:30.855650 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad set interfaces ethernet eth0p0 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=1.13 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 1.131/1.131/1.131/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0p0.*Show output
Sep 17 06:45:36.021067 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 06:45:36.021538 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=00:a0:26:0e:62:79:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 ethertype 802.1ad set interfaces ethernet eth4 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.622 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.622/0.622/0.622/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth4.*Show output
Sep 17 03:13:50.287143 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 03:13:50.287362 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00 Sep 17 03:13:51.359311 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.539 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.539/0.539/0.539/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 23:35:19.063684 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 23:35:19.063720 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=40:64:dc:38:ed:02:de:ad:be:ef:6c:10:81:00
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 ethertype 802.1ad set interfaces ethernet eth5 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 10: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.457 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.457/0.457/0.457/0.000 ms
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth5.*Show output
Sep 16 23:35:31.579719 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:11:81:00 Sep 16 23:35:31.579761 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.783 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.783/0.783/0.783/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 14:33:09.982911 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 14:33:10.118786 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 14:33:10.119197 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:8b:00:96:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.342 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.342/0.342/0.342/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 00:34:54.711966 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:54.723917 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:54.839878 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:55.543935 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:55.639990 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:55.863917 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:55.864178 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:34:56.906359 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 ethertype 802.1ad set interfaces ethernet eth2 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.964 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.964/0.964/0.964/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth2.*Show output
Sep 16 20:04:02.049391 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:02.082162 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:02.098156 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:03.009266 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:03.073244 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:03.073535 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:03.106162 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:04.152686 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.420 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.420/0.420/0.420/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 10:07:05.913685 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 10:07:05.913885 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00 Sep 17 10:07:06.983467 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-id 200 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.576 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.576/0.576/0.576/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 23:52:13.445231 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 23:52:13.669179 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 23:52:13.829122 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 23:52:13.832421 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:81:00 Sep 16 23:52:14.929761 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:81:00
Test VLAN Selector (QinQ) With Not Vlan Inner-pcp Link-In
Description
The traffic selector VLAN uses vlan id 100,
vlan protocol 8021q, vlan inner-id 200 and
not vlan inner-pcp 5. A traffic policy INNER_COS
on DUT1’s inner VLAN sub-interface sets the inner PCP
value to 3, so the negated condition matches on DUT0’s
link-in hook, causing rule 1 to log with prefix
MATCH_VLAN.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.985 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.985/0.985/0.985/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 18:13:20.059009 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 18:13:20.059825 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=de:ad:be:ef:6c:00:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.639 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.639/0.639/0.639/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 17 08:30:48.493148 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 08:30:48.717075 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 08:30:48.717274 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00 Sep 17 08:30:49.757039 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=00:a0:26:e3:01:4c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.799 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.799/0.799/0.799/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 06:20:52.571173 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 06:20:53.243081 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 06:20:53.244653 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00 Sep 17 06:20:54.280827 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:99:35:97:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad set interfaces ethernet eth0p0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=5.11 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 5.107/5.107/5.107/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0p0.*Show output
Sep 17 06:46:05.642092 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=33:33:ff:ef:6c:10:de:ad:be:ef:6c:10:81:00 Sep 17 06:46:05.706401 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 06:46:05.708920 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=00:a0:26:0e:62:79:de:ad:be:ef:6c:10:81:00 Sep 17 06:46:05.834345 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 ethertype 802.1ad set interfaces ethernet eth4 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.355 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.355/0.355/0.355/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth4.*Show output
Sep 17 03:14:07.811745 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 03:14:07.811943 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00 Sep 17 03:14:08.883025 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=00:a0:26:04:00:1c:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.816 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.816/0.816/0.816/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth0.*Show output
Sep 16 23:35:44.139684 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 23:35:44.139720 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=40:64:dc:38:ed:02:de:ad:be:ef:6c:10:81:00
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 ethertype 802.1ad set interfaces ethernet eth5 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth1 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 10: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.600 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.600/0.600/0.600/0.000 ms
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth5.*Show output
Sep 16 23:35:56.011619 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:11:81:00 Sep 16 23:35:56.015682 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:81:00 Sep 16 23:35:57.351639 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=40:64:dc:38:ed:07:de:ad:be:ef:6c:11:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.623 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.623/0.623/0.623/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 14:33:25.499498 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 14:33:25.499710 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:8b:00:96:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.858 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.858/0.858/0.858/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 00:35:12.964341 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:35:13.351858 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:35:13.380246 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 00:35:13.383851 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:35:15.537140 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:16:00:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 ethertype 802.1ad set interfaces ethernet eth2 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.546 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.546/0.546/0.546/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth2.*Show output
Sep 16 20:04:27.009544 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:27.009784 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:27.021505 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:27.329624 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:27.329735 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:28.033808 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:28.033942 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:04:29.102080 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=00:a0:26:54:55:16:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.410 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.410/0.410/0.410/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 17 10:07:30.914489 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 17 10:07:30.914820 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00 Sep 17 10:07:31.965581 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:18:00:ca:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-pcp 5 set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy INNER_COS rule 1 set cos-mark 3
Step 3: Ping the IP address 10.0.0.1 from DUT1:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.965 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.965/0.965/0.965/0.000 ms
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
(?i).*MATCH_VLAN-1.*eth1.*Show output
Sep 16 23:52:42.597351 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 23:52:43.653758 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00 Sep 16 23:52:43.654057 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=00:a0:26:12:00:3b:de:ad:be:ef:6c:10:81:00
Test VLAN Selector (802.1Q) With Not Vlan Protocol Link-In
Description
The traffic selector VLAN uses
not vlan protocol ip. DUT1 sends an arping (ARP):
since ARP is not IP, the negated condition matches on
DUT0’s link-in hook and rule 1 logs with prefix
MATCH_VLAN.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [DE:AD:BE:EF:6C:00] 0.951ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*Show output
Sep 16 18:13:29.876450 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:E3:01:4C] 0.899ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*Show output
Sep 17 08:31:12.991945 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:99:35:97] 0.947ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 17 06:21:17.363237 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 06:21:17.747247 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 06:21:18.575289 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:0E:62:79] 1.223ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0p0.*Show output
Sep 17 06:46:33.076244 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:04:00:1C] 0.878ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth4.*Show output
Sep 17 03:14:23.917199 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [40:64:DC:38:ED:02] 0.781ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*Show output
Sep 16 23:36:08.435796 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 10: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth1.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth1.100 Unicast reply from 10.0.0.1 [40:64:DC:38:ED:07] 0.809ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth5.*Show output
Sep 16 23:36:21.167768 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:11 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:8B:00:96] 0.811ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 16 14:33:38.698336 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:16:00:16] 0.866ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 17 00:35:32.452401 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:35:32.468311 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:35:32.612341 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:35:32.804314 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 00:35:34.221822 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:54:55:16] 0.881ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth2.*Show output
Sep 16 20:04:51.097337 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:18:00:CA] 0.899ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 17 10:07:54.739048 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 10:07:54.963004 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 17 10:07:55.725698 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021q set traffic selector VLAN rule 1 not vlan protocol ip set traffic selector VLAN rule 1 vlan id 100
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100 Unicast reply from 10.0.0.1 [00:A0:26:12:00:3B] 0.887ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 16 23:53:06.557772 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:86:dd SRC=fe80:0000:0000:0000:dcad:beff:feef:6c10 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 Sep 16 23:53:07.872941 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:10 IPSRC=10.0.0.2 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.1
Test VLAN Selector (QinQ) With Not Vlan Inner-protocol Link-In
Description
The traffic selector VLAN uses
not vlan inner-protocol ip. DUT1 sends an arping
(ARP): since ARP is not IP, the negated condition matches
on DUT0’s link-in hook and rule 1 logs with prefix
MATCH_VLAN.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [DE:AD:BE:EF:6C:00] 0.976ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*Show output
Sep 16 18:13:39.248679 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:E3:01:4C] 0.855ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*Show output
Sep 17 08:31:36.913280 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:99:35:97] 0.935ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 17 06:21:41.348080 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 06:21:42.600649 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0p0 mtu 1390 set interfaces ethernet eth0p0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad set interfaces ethernet eth0p0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:0E:62:79] 1.136ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0p0.*Show output
Sep 17 06:47:00.660832 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0p0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth4 mtu 1390 set interfaces ethernet eth4 traffic policy link-in MATCH_VLAN set interfaces ethernet eth4 vif 100 ethertype 802.1ad set interfaces ethernet eth4 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:04:00:1C] 0.753ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth4.*Show output
Sep 17 03:14:39.304012 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth4 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 traffic policy link-in MATCH_VLAN set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [40:64:DC:38:ED:02] 1.040ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth0.*Show output
Sep 16 23:36:31.591663 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 5: Clean all the configuration in DUT0:
delete set system login user admin authentication plaintext-password admin
Step 6: Clean all the configuration in DUT1:
delete set system login user admin authentication plaintext-password admin
Step 7: Clean all the configuration in DUT2:
delete set system login user admin authentication plaintext-password admin
Step 8: Set the following configuration in DUT0 :
set interfaces ethernet eth5 mtu 1390 set interfaces ethernet eth5 traffic policy link-in MATCH_VLAN set interfaces ethernet eth5 vif 100 ethertype 802.1ad set interfaces ethernet eth5 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 9: Set the following configuration in DUT1 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 10: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth1.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth1.100.200 Unicast reply from 10.0.0.1 [40:64:DC:38:ED:07] 0.859ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth5.*Show output
Sep 16 23:36:44.175656 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth5 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:11:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:8B:00:96] 0.959ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 16 14:33:53.099925 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:ff:ef:6c:10:de:ad:be:ef:6c:10:81:00 Sep 16 14:33:53.211644 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:16:00:16] 0.843ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 17 00:35:51.245554 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:35:51.405538 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 00:35:52.705395 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth2 mtu 1390 set interfaces ethernet eth2 traffic policy link-in MATCH_VLAN set interfaces ethernet eth2 vif 100 ethertype 802.1ad set interfaces ethernet eth2 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:54:55:16] 0.887ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth2.*Show output
Sep 16 20:05:12.925868 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 16 20:05:15.120601 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth2 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:18:00:CA] 0.883ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 17 10:08:19.079777 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=33:33:00:00:00:16:de:ad:be:ef:6c:10:81:00 Sep 17 10:08:20.037486 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth1 mtu 1390 set interfaces ethernet eth1 traffic policy link-in MATCH_VLAN set interfaces ethernet eth1 vif 100 ethertype 802.1ad set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN set traffic policy MATCH_VLAN rule 1 selector VLAN set traffic selector VLAN rule 1 ether-type 8021ad set traffic selector VLAN rule 1 not vlan inner-protocol ip set traffic selector VLAN rule 1 vlan id 100 set traffic selector VLAN rule 1 vlan inner-id 200 set traffic selector VLAN rule 1 vlan protocol 8021q
Step 2: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mtu 1390 set interfaces ethernet eth0 vif 100 ethertype 802.1ad set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 3: Send an ARP ping from DUT1 to IP address 10.0.0.1:
admin@DUT1$ arping 10.0.0.1 interface eth0.100.200 timeout 5 count 1Show output
ARPING 10.0.0.1 from 10.0.0.2 eth0.100.200 Unicast reply from 10.0.0.1 [00:A0:26:12:00:3B] 1.021ms Sent 1 probes (1 broadcast(s)) Received 1 response(s)
Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:
.*MATCH_VLAN-1.*eth1.*Show output
Sep 16 23:53:35.184811 osdx kernel: [MATCH_VLAN-1] ACCEPT IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:10:81:00