OSDx Documentation Logo
  • About
  • Releases

First steps

  • Setting Up
  • Quick Start
  • Licensing
  • CLI Overview
  • Configuration Management

Admin Guide

  • System Administration
  • Articles
  • Troubleshooting
  • Examples
    • Basic
    • Interfaces
    • Protocols
    • Service
    • System
    • Tech Support
    • Traffic
      • Control
      • Group
      • Policy
      • Selector
        • Rule
        • Selector
      • Zone
    • User-Level
    • Vpn

Command reference

  • Configuration commands
  • Operational commands
OSDx Documentation
  • Examples
  • Traffic
  • Selector
  • Rule
  • Vlan
  • Link-Out
  • View page source

Link-Out

The following scenario shows how to filter packets based on VLAN attributes using traffic selectors. The policy is attached to DUT0’s link-out hook; DUT0 originates the traffic and DUT0’s journal is checked.

Test VLAN Selector (802.1Q)

Description

A traffic policy MATCH_VLAN is configured on DUT0’s parent interface (eth0) in the link-out hook. The traffic selector VLAN filters packets with ether-type 8021q and vlan id 100, logging matches with prefix MATCH_VLAN. A ping through the 802.1Q VLAN verifies that the selector correctly identifies tagged packets.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.550 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.550/0.550/0.550/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 18:10:57.659085 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:00 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 18:10:57.659124 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=64047 DF PROTO=ICMP TYPE=8 CODE=0 ID=363 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.675 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.675/0.675/0.675/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 08:31:58.649444 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=fe80:0000:0000:0000:02a0:26ff:fee3:014c DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 08:31:59.181427 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=fe80:0000:0000:0000:02a0:26ff:fee3:014c DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 08:32:00.185558 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:e3:01:4c IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 08:32:00.185750 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=37006 DF PROTO=ICMP TYPE=8 CODE=0 ID=646 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.680 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.680/0.680/0.680/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 06:22:05.880282 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe99:3597 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 06:22:06.236298 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:99:35:97 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 06:22:06.236523 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=28415 DF PROTO=ICMP TYPE=8 CODE=0 ID=915 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0p0 mtu 1390
set interfaces ethernet eth0p0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0p0 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.962 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.962/0.962/0.962/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0p0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 06:39:02.220747 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:0e:62:79 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 06:39:02.221180 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=17352 DF PROTO=ICMP TYPE=8 CODE=0 ID=669 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth4 mtu 1390
set interfaces ethernet eth4 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth4 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.481 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.481/0.481/0.481/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth4.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 03:10:15.556435 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xb2
Sep 17 03:10:15.664436 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff04:001c LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Sep 17 03:10:15.905640 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:04:00:1c IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 03:10:15.905686 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=61867 DF PROTO=ICMP TYPE=8 CODE=0 ID=659 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.378 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.378/0.378/0.378/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:36:55.203697 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=40:64:dc:38:ed:02 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:36:55.203759 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=35301 DF PROTO=ICMP TYPE=8 CODE=0 ID=152 SEQ=1
Sep 16 23:36:55.247731 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=fe80:0000:0000:0000:4264:dcff:fe38:ed02 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142

Step 5: Clean all the configuration in DUT0:

delete
set system login user admin authentication plaintext-password admin

Step 6: Clean all the configuration in DUT1:

delete
set system login user admin authentication plaintext-password admin

Step 7: Clean all the configuration in DUT2:

delete
set system login user admin authentication plaintext-password admin

Step 8: Set the following configuration in DUT0 :

set interfaces ethernet eth5 mtu 1390
set interfaces ethernet eth5 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth5 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 9: Set the following configuration in DUT1 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 10: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.418 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.418/0.418/0.418/0.000 ms

Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth5.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:37:06.399740 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142
Sep 16 23:37:06.635691 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=40:64:dc:38:ed:07 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:37:06.635758 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=37075 DF PROTO=ICMP TYPE=8 CODE=0 ID=153 SEQ=1
Sep 16 23:37:06.647717 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142
Sep 16 23:37:07.247727 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff38:ed07 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.626 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.626/0.626/0.626/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 14:29:53.496085 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe8b:0096 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 14:29:53.584185 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:8b:00:96 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 14:29:53.584296 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=47102 DF PROTO=ICMP TYPE=8 CODE=0 ID=69 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.672 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.672/0.672/0.672/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 00:30:38.739832 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 00:30:38.931828 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 00:30:39.299841 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:16:00:16 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 00:30:39.299969 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=25556 DF PROTO=ICMP TYPE=8 CODE=0 ID=781 SEQ=1
Sep 17 00:30:39.300005 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff16:0016 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth2 mtu 1390
set interfaces ethernet eth2 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth2 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.646 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.646/0.646/0.646/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth2.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 20:05:37.294763 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 20:05:37.910773 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:54:55:16 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 20:05:37.910922 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=10802 DF PROTO=ICMP TYPE=8 CODE=0 ID=355 SEQ=1
Sep 16 20:05:38.022763 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.433 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.433/0.433/0.433/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 10:08:42.922556 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:18:00:ca IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 10:08:42.922789 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe18:00ca DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 10:08:43.282528 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe18:00ca DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 10:08:43.954524 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:18:00:ca IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 10:08:43.954641 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=23389 DF PROTO=ICMP TYPE=8 CODE=0 ID=90 SEQ=1
Sep 17 10:08:46.102588 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=23556 DF PROTO=ICMP TYPE=8 CODE=0 ID=91 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.753 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.753/0.753/0.753/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:54:00.912818 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 23:54:00.980799 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 23:54:01.572803 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff12:003b LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Sep 16 23:54:02.596812 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe12:003b DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 23:54:02.608795 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe12:003b DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 23:54:02.968902 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:12:00:3b IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:54:02.969146 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=6762 DF PROTO=ICMP TYPE=8 CODE=0 ID=178 SEQ=1

Test VLAN Selector (QinQ)

Description

A traffic policy MATCH_VLAN is configured on DUT0’s parent interface (eth0) in the link-out hook. The traffic selector VLAN filters packets with ether-type 8021ad, vlan id 100, vlan protocol 8021q and vlan inner-id 200, logging matches with prefix MATCH_VLAN. A ping through the QinQ VLAN verifies that the selector correctly identifies double-tagged packets.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.449 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.449/0.449/0.449/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 18:11:06.984887 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:de:ad:be:ef:6c:00:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.722 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.722/0.722/0.722/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 17 08:32:24.077547 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:00:a0:26:e3:01:4c:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.716 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.716/0.716/0.716/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 06:22:29.080090 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:99:35:97:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0p0 mtu 1390
set interfaces ethernet eth0p0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0p0 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.975 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.975/0.975/0.975/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0p0.*
Show output
Sep 17 06:39:31.523368 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 MAC=de:ad:be:ef:6c:10:00:a0:26:0e:62:79:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth4 mtu 1390
set interfaces ethernet eth4 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth4 vif 100 ethertype 802.1ad
set interfaces ethernet eth4 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.780 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.780/0.780/0.780/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth4.*
Show output
Sep 17 03:10:30.241461 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 MAC=de:ad:be:ef:6c:10:00:a0:26:04:00:1c:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.389 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.389/0.389/0.389/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 23:37:17.727832 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:40:64:dc:38:ed:02:81:00

Step 5: Clean all the configuration in DUT0:

delete
set system login user admin authentication plaintext-password admin

Step 6: Clean all the configuration in DUT1:

delete
set system login user admin authentication plaintext-password admin

Step 7: Clean all the configuration in DUT2:

delete
set system login user admin authentication plaintext-password admin

Step 8: Set the following configuration in DUT0 :

set interfaces ethernet eth5 mtu 1390
set interfaces ethernet eth5 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth5 vif 100 ethertype 802.1ad
set interfaces ethernet eth5 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 9: Set the following configuration in DUT1 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 10: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.496 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.496/0.496/0.496/0.000 ms

Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth5.*
Show output
Sep 16 23:37:29.783855 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=de:ad:be:ef:6c:11:40:64:dc:38:ed:07:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.606 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.606/0.606/0.606/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 16 14:30:07.107839 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:8b:00:96:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.581 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.581/0.581/0.581/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 00:30:57.164209 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:16:00:16:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth2 mtu 1390
set interfaces ethernet eth2 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth2 vif 100 ethertype 802.1ad
set interfaces ethernet eth2 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.590 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.590/0.590/0.590/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth2.*
Show output
Sep 16 20:06:00.346771 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=de:ad:be:ef:6c:10:00:a0:26:54:55:16:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.797 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.797/0.797/0.797/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 10:09:09.240783 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:18:00:ca:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=12.1 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 12.097/12.097/12.097/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 16 23:54:28.039118 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:12:00:3b:81:00

Test VLAN Selector (QinQ) With PCP Matches

Description

A traffic policy MATCH_VLAN is configured on DUT0’s parent interface (eth0) in the link-out hook. The traffic selector VLAN filters QinQ packets matching vlan id 100, vlan pcp 3, vlan inner-id 200 and vlan inner-pcp 5. Traffic policies OUTER_COS and INNER_COS on the outer and inner VLAN sub-interfaces set the required PCP values.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=9.62 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 9.616/9.616/9.616/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 18:11:17.601336 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:de:ad:be:ef:6c:00:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.670 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.670/0.670/0.670/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 17 08:32:47.944211 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:00:a0:26:e3:01:4c:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.628 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.628/0.628/0.628/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 06:22:53.676180 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:99:35:97:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0p0 mtu 1390
set interfaces ethernet eth0p0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0p0 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth0p0 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth0p0 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=1.20 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 1.196/1.196/1.196/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0p0.*
Show output
Sep 17 06:40:01.971729 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 MAC=de:ad:be:ef:6c:10:00:a0:26:0e:62:79:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth4 mtu 1390
set interfaces ethernet eth4 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth4 vif 100 ethertype 802.1ad
set interfaces ethernet eth4 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth4 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth4 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.555 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.555/0.555/0.555/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth4.*
Show output
Sep 17 03:10:46.148783 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 MAC=de:ad:be:ef:6c:10:00:a0:26:04:00:1c:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.371 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.371/0.371/0.371/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 23:37:42.307738 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:40:64:dc:38:ed:02:81:00

Step 5: Clean all the configuration in DUT0:

delete
set system login user admin authentication plaintext-password admin

Step 6: Clean all the configuration in DUT1:

delete
set system login user admin authentication plaintext-password admin

Step 7: Clean all the configuration in DUT2:

delete
set system login user admin authentication plaintext-password admin

Step 8: Set the following configuration in DUT0 :

set interfaces ethernet eth5 mtu 1390
set interfaces ethernet eth5 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth5 vif 100 ethertype 802.1ad
set interfaces ethernet eth5 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth5 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth5 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 9: Set the following configuration in DUT1 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 10: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.518 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.518/0.518/0.518/0.000 ms

Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth5.*
Show output
Sep 16 23:37:55.175695 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=de:ad:be:ef:6c:11:40:64:dc:38:ed:07:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.577 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.577/0.577/0.577/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 16 14:30:22.867851 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:8b:00:96:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.625 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.625/0.625/0.625/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 00:31:15.843954 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:16:00:16:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth2 mtu 1390
set interfaces ethernet eth2 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth2 vif 100 ethertype 802.1ad
set interfaces ethernet eth2 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth2 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth2 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.614 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.614/0.614/0.614/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth2.*
Show output
Sep 16 20:06:28.274604 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=de:ad:be:ef:6c:10:00:a0:26:54:55:16:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.663 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.663/0.663/0.663/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 10:09:33.090878 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:18:00:ca:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 traffic policy link-out OUTER_COS
set interfaces ethernet eth1 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 5
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy OUTER_COS rule 1 set cos-mark 3
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan pcp 3
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.690 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.690/0.690/0.690/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 16 23:54:53.232351 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:12:00:3b:81:00

Test VLAN Selector (802.1Q) With Not Vlan Id

Description

The traffic selector VLAN uses not vlan id 100. Traffic is sent through VLAN 101, so the negated condition matches (the packet’s VLAN id differs from 100), causing rule 1 to match and log with prefix MATCH_VLAN.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=1.38 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 1.382/1.382/1.382/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 18:11:26.804935 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:00 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 18:11:26.808562 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=1564 DF PROTO=ICMP TYPE=8 CODE=0 ID=366 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.687 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.687/0.687/0.687/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 08:33:10.217911 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 08:33:10.337905 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ffe3:014c LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Sep 17 08:33:10.681974 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:e3:01:4c IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 08:33:10.682173 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=44155 DF PROTO=ICMP TYPE=8 CODE=0 ID=649 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.912 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.912/0.912/0.912/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 06:23:17.000470 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe99:3597 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 06:23:17.176452 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe99:3597 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 06:23:17.604478 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:99:35:97 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 06:23:17.604706 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=40137 DF PROTO=ICMP TYPE=8 CODE=0 ID=918 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0p0 mtu 1390
set interfaces ethernet eth0p0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0p0 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.993 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.993/0.993/0.993/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0p0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 06:40:29.930338 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:0e:62:79 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 06:40:29.930736 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=31072 DF PROTO=ICMP TYPE=8 CODE=0 ID=672 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth4 mtu 1390
set interfaces ethernet eth4 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth4 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.499 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.499/0.499/0.499/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth4.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 03:11:00.620322 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xb2
Sep 17 03:11:00.636316 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xb2
Sep 17 03:11:00.956322 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:04:00:1c IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 03:11:00.956380 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=2275 DF PROTO=ICMP TYPE=8 CODE=0 ID=662 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.356 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.356/0.356/0.356/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:38:05.007685 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=40:64:dc:38:ed:02 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:38:05.007764 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=45749 DF PROTO=ICMP TYPE=8 CODE=0 ID=158 SEQ=1

Step 5: Clean all the configuration in DUT0:

delete
set system login user admin authentication plaintext-password admin

Step 6: Clean all the configuration in DUT1:

delete
set system login user admin authentication plaintext-password admin

Step 7: Clean all the configuration in DUT2:

delete
set system login user admin authentication plaintext-password admin

Step 8: Set the following configuration in DUT0 :

set interfaces ethernet eth5 mtu 1390
set interfaces ethernet eth5 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth5 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 9: Set the following configuration in DUT1 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 10: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.465 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.465/0.465/0.465/0.000 ms

Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth5.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:38:15.759752 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142
Sep 16 23:38:15.915745 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff38:ed07 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Sep 16 23:38:16.279679 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=40:64:dc:38:ed:07 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:38:16.279759 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=46071 DF PROTO=ICMP TYPE=8 CODE=0 ID=159 SEQ=1
Sep 16 23:38:16.587746 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142
Sep 16 23:38:16.939741 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=fe80:0000:0000:0000:4264:dcff:fe38:ed07 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142
Sep 16 23:38:16.951713 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=fe80:0000:0000:0000:4264:dcff:fe38:ed07 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.719 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.719/0.719/0.719/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 14:30:35.527217 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:8b:00:96 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 14:30:35.531214 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=54189 DF PROTO=ICMP TYPE=8 CODE=0 ID=72 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.649 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.649/0.649/0.649/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 00:31:32.907716 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 00:31:33.343708 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff16:0016 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Sep 17 00:31:33.475728 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 00:31:33.547756 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:16:00:16 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 00:31:33.547862 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=31947 DF PROTO=ICMP TYPE=8 CODE=0 ID=784 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth2 mtu 1390
set interfaces ethernet eth2 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth2 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.706 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.706/0.706/0.706/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth2.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 20:06:49.293399 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 20:06:49.633390 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 20:06:49.857394 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff54:5516 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Sep 16 20:06:49.969432 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:54:55:16 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 20:06:49.969569 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=19309 DF PROTO=ICMP TYPE=8 CODE=0 ID=358 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.690 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.690/0.690/0.690/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 10:09:55.106679 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe18:00ca DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 17 10:09:55.226706 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:18:00:ca IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 10:09:55.226891 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=30359 DF PROTO=ICMP TYPE=8 CODE=0 ID=94 SEQ=1
Sep 17 10:09:55.290665 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe18:00ca DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 101 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 101 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.823 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.823/0.823/0.823/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:55:16.588753 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 23:55:16.896733 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2
Sep 16 23:55:17.056765 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff12:003b LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0
Sep 16 23:55:17.108745 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:12:00:3b IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:55:17.108952 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=14338 DF PROTO=ICMP TYPE=8 CODE=0 ID=181 SEQ=1

Test VLAN Selector (802.1Q) With Not Vlan PCP

Description

The traffic selector VLAN uses vlan id 100 and not vlan pcp 3. A traffic policy SET_COS configured on the VLAN sub-interface sets the PCP value to 5, so the negated condition matches (the packet’s PCP differs from 3), causing rule 1 to match and log with prefix MATCH_VLAN.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.424 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.424/0.424/0.424/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 18:11:36.349413 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:00 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 18:11:36.349457 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=1943 DF PROTO=ICMP TYPE=8 CODE=0 ID=367 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.659 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.659/0.659/0.659/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 08:33:33.609704 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=fe80:0000:0000:0000:02a0:26ff:fee3:014c DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 08:33:33.841677 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=fe80:0000:0000:0000:02a0:26ff:fee3:014c DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 08:33:33.997837 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:e3:01:4c IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 08:33:33.998036 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=47633 DF PROTO=ICMP TYPE=8 CODE=0 ID=650 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.799 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.799/0.799/0.799/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 06:23:39.411885 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe99:3597 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 06:23:39.447866 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe99:3597 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 06:23:39.963902 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:99:35:97 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 06:23:39.964216 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=40536 DF PROTO=ICMP TYPE=8 CODE=0 ID=919 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0p0 mtu 1390
set interfaces ethernet eth0p0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0p0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0p0 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.971 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.971/0.971/0.971/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0p0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 06:40:58.149161 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:0e:62:79 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 06:40:58.149553 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=33833 DF PROTO=ICMP TYPE=8 CODE=0 ID=673 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth4 mtu 1390
set interfaces ethernet eth4 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth4 vif 100 address 10.0.0.1/24
set interfaces ethernet eth4 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.443 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.443/0.443/0.443/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth4.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 03:11:14.987885 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xb2 COS=0x5
Sep 17 03:11:15.043877 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff04:001c LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0 COS=0x5
Sep 17 03:11:15.241073 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:04:00:1c IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 03:11:15.241119 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=3019 DF PROTO=ICMP TYPE=8 CODE=0 ID=663 SEQ=1
Sep 17 03:11:15.331884 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xb2 COS=0x5

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.431 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.431/0.431/0.431/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:38:27.407705 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=fe80:0000:0000:0000:4264:dcff:fe38:ed02 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142 COS=0x5
Sep 16 23:38:27.423727 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=fe80:0000:0000:0000:4264:dcff:fe38:ed02 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142 COS=0x5
Sep 16 23:38:27.527679 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=40:64:dc:38:ed:02 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:38:27.527738 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=46800 DF PROTO=ICMP TYPE=8 CODE=0 ID=160 SEQ=1

Step 5: Clean all the configuration in DUT0:

delete
set system login user admin authentication plaintext-password admin

Step 6: Clean all the configuration in DUT1:

delete
set system login user admin authentication plaintext-password admin

Step 7: Clean all the configuration in DUT2:

delete
set system login user admin authentication plaintext-password admin

Step 8: Set the following configuration in DUT0 :

set interfaces ethernet eth5 mtu 1390
set interfaces ethernet eth5 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth5 vif 100 address 10.0.0.1/24
set interfaces ethernet eth5 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 9: Set the following configuration in DUT1 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 10: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.475 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.475/0.475/0.475/0.000 ms

Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth5.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:38:39.079717 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142 COS=0x5
Sep 16 23:38:39.275685 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=40:64:dc:38:ed:07 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:38:39.275743 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=46811 DF PROTO=ICMP TYPE=8 CODE=0 ID=161 SEQ=1
Sep 16 23:38:39.439732 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0x142 COS=0x5
Sep 16 23:38:39.787709 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff38:ed07 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0 COS=0x5

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.633 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.633/0.633/0.633/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 14:30:50.271484 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:8b:00:96 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 14:30:50.271605 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=57433 DF PROTO=ICMP TYPE=8 CODE=0 ID=73 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.635 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.635/0.635/0.635/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 00:31:50.359074 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 00:31:50.827073 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 00:31:50.987139 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:16:00:16 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 00:31:50.987246 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=36118 DF PROTO=ICMP TYPE=8 CODE=0 ID=785 SEQ=1
Sep 17 00:31:51.083089 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff16:0016 LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0 COS=0x5

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth2 mtu 1390
set interfaces ethernet eth2 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth2 vif 100 address 10.0.0.1/24
set interfaces ethernet eth2 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.659 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.659/0.659/0.659/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth2.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 20:07:11.853418 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 20:07:12.289415 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 20:07:12.357420 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:54:55:16 IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 20:07:12.357545 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=23772 DF PROTO=ICMP TYPE=8 CODE=0 ID=359 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.694 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.694/0.694/0.694/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 17 10:10:17.069756 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe18:00ca DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 10:10:17.217733 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe18:00ca DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 17 10:10:17.645777 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:18:00:ca IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 17 10:10:17.645974 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=30923 DF PROTO=ICMP TYPE=8 CODE=0 ID=95 SEQ=1

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 address 10.0.0.1/24
set interfaces ethernet eth1 vif 100 traffic policy link-out SET_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic policy SET_COS rule 1 set cos-mark 5
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan pcp 3
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.722 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.722/0.722/0.722/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth1.*10.0.0.1.*10.0.0.2.*
Show output
Sep 16 23:55:42.168360 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 23:55:42.444347 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=96 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 23:55:42.796348 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=0000:0000:0000:0000:0000:0000:0000:0000 DST=ff02:0000:0000:0000:0000:0001:ff12:003b LEN=72 TC=0 HOPLIMIT=255 FLOWLBL=0 PROTO=ICMPv6 TYPE=135 CODE=0 COS=0x5
Sep 16 23:55:43.820357 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe12:003b DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 23:55:43.832345 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe12:003b DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 23:55:44.052374 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe12:003b DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=76 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 23:55:44.060394 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=fe80:0000:0000:0000:02a0:26ff:fe12:003b DST=ff02:0000:0000:0000:0000:0000:0000:0016 LEN=116 TC=0 HOPLIMIT=1 FLOWLBL=0 PROTO=ICMPv6 TYPE=143 CODE=0 MARK=0xf2 COS=0x5
Sep 16 23:55:44.079970 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=00:a0:26:12:00:3b IPSRC=10.0.0.1 MACDST=00:00:00:00:00:00 IPDST=10.0.0.2
Sep 16 23:55:44.080216 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 SRC=10.0.0.1 DST=10.0.0.2 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=18188 DF PROTO=ICMP TYPE=8 CODE=0 ID=182 SEQ=1

Test VLAN Selector (QinQ) With Not Vlan Inner-id

Description

The traffic selector VLAN uses vlan id 100, vlan protocol 8021q and not vlan inner-id 200. Traffic is sent through C-VLAN 201, so the negated condition matches (the packet’s inner VLAN id differs from 200), causing rule 1 to match and log with prefix MATCH_VLAN.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.718 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.718/0.718/0.718/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 18:11:46.371621 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:00:81:00
Sep 16 18:11:46.371643 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:de:ad:be:ef:6c:00:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.679 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.679/0.679/0.679/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 17 08:33:57.569714 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=33:33:00:00:00:16:00:a0:26:e3:01:4c:81:00
Sep 17 08:33:58.229725 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=33:33:00:00:00:16:00:a0:26:e3:01:4c:81:00
Sep 17 08:33:59.277754 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:e3:01:4c:81:00
Sep 17 08:33:59.277958 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:00:a0:26:e3:01:4c:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.678 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.678/0.678/0.678/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 06:24:03.964190 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:00:00:00:16:00:a0:26:99:35:97:81:00
Sep 17 06:24:04.144169 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:00:00:00:16:00:a0:26:99:35:97:81:00
Sep 17 06:24:04.820194 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:99:35:97:81:00
Sep 17 06:24:04.820413 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:99:35:97:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0p0 mtu 1390
set interfaces ethernet eth0p0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0p0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0p0 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=1.28 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 1.279/1.279/1.279/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0p0.*
Show output
Sep 17 06:41:25.987242 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:0e:62:79:81:00
Sep 17 06:41:25.988042 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0p0 MAC=de:ad:be:ef:6c:10:00:a0:26:0e:62:79:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth4 mtu 1390
set interfaces ethernet eth4 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth4 vif 100 ethertype 802.1ad
set interfaces ethernet eth4 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.465 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.465/0.465/0.465/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth4.*
Show output
Sep 17 03:11:29.020490 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 MAC=33:33:00:00:00:16:00:a0:26:04:00:1c:81:00
Sep 17 03:11:29.404490 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 MAC=33:33:00:00:00:16:00:a0:26:04:00:1c:81:00
Sep 17 03:11:29.424495 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:04:00:1c:81:00
Sep 17 03:11:29.424585 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 MAC=de:ad:be:ef:6c:10:00:a0:26:04:00:1c:81:00
Sep 17 03:11:29.500476 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth4 MAC=33:33:ff:04:00:1c:00:a0:26:04:00:1c:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.388 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.388/0.388/0.388/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 23:38:50.383660 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=ff:ff:ff:ff:ff:ff:40:64:dc:38:ed:02:81:00
Sep 16 23:38:50.383720 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:40:64:dc:38:ed:02:81:00

Step 5: Clean all the configuration in DUT0:

delete
set system login user admin authentication plaintext-password admin

Step 6: Clean all the configuration in DUT1:

delete
set system login user admin authentication plaintext-password admin

Step 7: Clean all the configuration in DUT2:

delete
set system login user admin authentication plaintext-password admin

Step 8: Set the following configuration in DUT0 :

set interfaces ethernet eth5 mtu 1390
set interfaces ethernet eth5 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth5 vif 100 ethertype 802.1ad
set interfaces ethernet eth5 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 9: Set the following configuration in DUT1 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 10: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.511 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.511/0.511/0.511/0.000 ms

Step 11: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth5.*
Show output
Sep 16 23:39:01.467679 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=33:33:00:00:00:16:40:64:dc:38:ed:07:81:00
Sep 16 23:39:01.803679 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=33:33:ff:38:ed:07:40:64:dc:38:ed:07:81:00
Sep 16 23:39:02.123683 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=33:33:00:00:00:16:40:64:dc:38:ed:07:81:00
Sep 16 23:39:02.287618 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=ff:ff:ff:ff:ff:ff:40:64:dc:38:ed:07:81:00
Sep 16 23:39:02.287690 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=de:ad:be:ef:6c:11:40:64:dc:38:ed:07:81:00
Sep 16 23:39:02.827684 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=33:33:00:00:00:16:40:64:dc:38:ed:07:81:00
Sep 16 23:39:02.839676 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth5 MAC=33:33:00:00:00:16:40:64:dc:38:ed:07:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.594 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.594/0.594/0.594/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 16 14:31:04.115248 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:8b:00:96:81:00
Sep 16 14:31:04.115369 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:8b:00:96:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.696 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.696/0.696/0.696/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 00:32:08.399560 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:00:00:00:16:00:a0:26:16:00:16:81:00
Sep 17 00:32:08.611554 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:ff:16:00:16:00:a0:26:16:00:16:81:00
Sep 17 00:32:08.967567 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:16:00:16:81:00
Sep 17 00:32:08.967693 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:16:00:16:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth2 mtu 1390
set interfaces ethernet eth2 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth2 vif 100 ethertype 802.1ad
set interfaces ethernet eth2 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.627 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.627/0.627/0.627/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth2.*
Show output
Sep 16 20:07:36.158413 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=33:33:00:00:00:16:00:a0:26:54:55:16:81:00
Sep 16 20:07:36.626398 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=33:33:ff:54:55:16:00:a0:26:54:55:16:81:00
Sep 16 20:07:36.658385 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=33:33:00:00:00:16:00:a0:26:54:55:16:81:00
Sep 16 20:07:37.650397 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=33:33:00:00:00:16:00:a0:26:54:55:16:81:00
Sep 16 20:07:37.666384 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=33:33:00:00:00:16:00:a0:26:54:55:16:81:00
Sep 16 20:07:38.026484 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:54:55:16:81:00
Sep 16 20:07:38.026606 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth2 MAC=de:ad:be:ef:6c:10:00:a0:26:54:55:16:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.798 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.798/0.798/0.798/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 17 10:10:39.766629 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:00:00:00:16:00:a0:26:18:00:ca:81:00
Sep 17 10:10:39.782607 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:00:00:00:16:00:a0:26:18:00:ca:81:00
Sep 17 10:10:40.290663 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:18:00:ca:81:00
Sep 17 10:10:40.290863 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:18:00:ca:81:00

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth1 mtu 1390
set interfaces ethernet eth1 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth1 vif 100 ethertype 802.1ad
set interfaces ethernet eth1 vif 100 vif-c 201 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-id 200
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 201 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.735 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.735/0.735/0.735/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth1.*
Show output
Sep 16 23:56:09.004631 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:00:00:00:16:00:a0:26:12:00:3b:81:00
Sep 16 23:56:09.132608 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:00:00:00:16:00:a0:26:12:00:3b:81:00
Sep 16 23:56:09.648641 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=ff:ff:ff:ff:ff:ff:00:a0:26:12:00:3b:81:00
Sep 16 23:56:09.648865 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=de:ad:be:ef:6c:10:00:a0:26:12:00:3b:81:00
Sep 16 23:56:09.728651 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth1 MAC=33:33:ff:12:00:3b:00:a0:26:12:00:3b:81:00

Test VLAN Selector (QinQ) With Not Vlan Inner-pcp

Description

The traffic selector VLAN uses vlan id 100, vlan protocol 8021q, vlan inner-id 200 and not vlan inner-pcp 5. A traffic policy INNER_COS configured on the inner VLAN sub-interface sets the inner PCP value to 3, so the negated condition matches (the packet’s inner PCP differs from 5), causing rule 1 to match and log with prefix MATCH_VLAN.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set interfaces ethernet eth0 vif 100 vif-c 200 traffic policy local-out INNER_COS
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy INNER_COS rule 1 set cos-mark 3
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-pcp 5
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Ping the IP address 10.0.0.2 from DUT0:

admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1
Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data.
64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.355 ms

--- 10.0.0.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.355/0.355/0.355/0.000 ms

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

(?i).*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 18:11:56.295550 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:00:81:00
Sep 16 18:11:56.295599 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=de:ad:be:ef:6c:10:de:ad:be:ef:6c:00:81:00

Test VLAN Selector (802.1Q) With Not Vlan Protocol

Description

The traffic selector VLAN uses not vlan protocol ip. An arping (ARP) is sent: since ARP is not IP, the negated condition matches and rule 1 logs with prefix MATCH_VLAN.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021q
set traffic selector VLAN rule 1 not vlan protocol ip
set traffic selector VLAN rule 1 vlan id 100

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Send an ARP ping from DUT0 to IP address 10.0.0.2:

admin@DUT0$ arping 10.0.0.2 interface eth0.100 timeout 5 count 1
Show output
ARPING 10.0.0.2 from 10.0.0.1 eth0.100
Unicast reply from 10.0.0.2 [DE:AD:BE:EF:6C:10]  0.751ms
Sent 1 probes (1 broadcast(s))
Received 1 response(s)

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 18:12:05.689477 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 ARP HTYPE=1 PTYPE=0x0800 OPCODE=1 MACSRC=de:ad:be:ef:6c:00 IPSRC=10.0.0.1 MACDST=ff:ff:ff:ff:ff:ff IPDST=10.0.0.2

Test VLAN Selector (QinQ) With Not Vlan Inner-protocol

Description

The traffic selector VLAN uses not vlan inner-protocol ip. An arping (ARP) is sent: since ARP is not IP, the negated condition matches and rule 1 logs with prefix MATCH_VLAN.

Scenario

Step 1: Set the following configuration in DUT0 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 traffic policy link-out MATCH_VLAN
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.1/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
set traffic policy MATCH_VLAN rule 1 log prefix MATCH_VLAN
set traffic policy MATCH_VLAN rule 1 selector VLAN
set traffic selector VLAN rule 1 ether-type 8021ad
set traffic selector VLAN rule 1 not vlan inner-protocol ip
set traffic selector VLAN rule 1 vlan id 100
set traffic selector VLAN rule 1 vlan inner-id 200
set traffic selector VLAN rule 1 vlan protocol 8021q

Step 2: Set the following configuration in DUT1 :

set interfaces ethernet eth0 mtu 1390
set interfaces ethernet eth0 vif 100 ethertype 802.1ad
set interfaces ethernet eth0 vif 100 vif-c 200 address 10.0.0.2/24
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'

Step 3: Send an ARP ping from DUT0 to IP address 10.0.0.2:

admin@DUT0$ arping 10.0.0.2 interface eth0.100.200 timeout 5 count 1
Show output
ARPING 10.0.0.2 from 10.0.0.1 eth0.100.200
Unicast reply from 10.0.0.2 [DE:AD:BE:EF:6C:10]  0.760ms
Sent 1 probes (1 broadcast(s))
Received 1 response(s)

Step 4: Run the command system journal show | grep MATCH_VLAN on DUT0 and check whether the output matches the following regular expressions:

.*MATCH_VLAN-1.*eth0.*
Show output
Sep 16 18:12:15.123479 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=ff:ff:ff:ff:ff:ff:de:ad:be:ef:6c:00:81:00
Sep 16 18:12:15.131477 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=33:33:00:00:00:16:de:ad:be:ef:6c:00:81:00
Sep 16 18:12:15.147475 osdx kernel: [MATCH_VLAN-1] ACCEPT IN= OUT=eth0 MAC=33:33:00:00:00:16:de:ad:be:ef:6c:00:81:00

Previous Next

© Copyright 2026, Teldat.

Built with Sphinx using a theme provided by Read the Docs.