2 # SPDX-License-Identifier: BSD-3-Clause
4 CRYPTO_DEV=${CRYPTO_DEV:-'--vdev="crypto_null0"'}
6 #generate cfg file for ipsec-secgw
9 cat <<EOF > ${SGW_CFG_FILE}
11 sp ipv4 in esp bypass pri 1 sport 0:65535 dport 0:65535
12 sp ipv6 in esp bypass pri 1 sport 0:65535 dport 0:65535
14 sp ipv4 out esp bypass pri 1 sport 0:65535 dport 0:65535
15 sp ipv6 out esp bypass pri 1 sport 0:65535 dport 0:65535
18 rt ipv4 dst ${REMOTE_IPV4}/32 port 0
19 rt ipv4 dst ${LOCAL_IPV4}/32 port 1
21 rt ipv6 dst ${REMOTE_IPV6}/128 port 0
22 rt ipv6 dst ${LOCAL_IPV6}/128 port 1
25 neigh port 0 ${REMOTE_MAC}
26 neigh port 1 ${LOCAL_MAC}
32 SGW_CMD_XPRM='-w 300 -l'
36 ssh ${REMOTE_HOST} ip xfrm policy flush
37 ssh ${REMOTE_HOST} ip xfrm state flush
39 ssh ${REMOTE_HOST} ip xfrm policy list
40 ssh ${REMOTE_HOST} ip xfrm state list