if (status->status < 0)
return;
fb = ipsec_get_fallback_session(rule);
- if (strcmp(tokens[ti], "lookaside-none") == 0) {
+ if (strcmp(tokens[ti], "lookaside-none") == 0)
fb->type = RTE_SECURITY_ACTION_TYPE_NONE;
- } else {
+ else if (strcmp(tokens[ti], "cpu-crypto") == 0)
+ fb->type = RTE_SECURITY_ACTION_TYPE_CPU_CRYPTO;
+ else {
APP_CHECK(0, status, "unrecognized fallback "
"type %s.", tokens[ti]);
return;
SGW_CFG_XPRM="${SGW_CFG_XPRM} ${CRYPTO_PRIM_TYPE}"
fi
+ # check if fallback type is needed
+ if [[ "${MODE}" == *fallback* ]]; then
+ if [[ -n "${CRYPTO_FLBK_TYPE}" ]]; then
+ echo "${CRYPTO_FLBK_TYPE} is enabled"
+ fi
+ fi
+
#make linux to generate fragmented packets
if [[ -n "${MULTI_SEG_TEST}" && -n "${SGW_CMD_XPRM}" ]]; then
echo "multi-segment test is enabled"
PING_LEN=5000
MTU_LEN=1500
else
+ if [[ -z "${MULTI_SEG_TEST}" && "${MODE}" == *fallback* ]]; then
+ echo "MULTI_SEG_TEST environment variable needs to be \
+set for ${MODE} test"
+ exit 127
+ fi
PING_LEN=${DEF_PING_LEN}
MTU_LEN=${DEF_MTU_LEN}
fi
. ${DIR}/trs_aesgcm_defs.sh
-SGW_CFG_XPRM_IN='port_id 0 type inline-crypto-offload fallback lookaside-none'
+if [[ -z "${CRYPTO_FLBK_TYPE}" ]]; then
+ CRYPTO_FLBK_TYPE="fallback lookaside-none"
+fi
+
+SGW_CFG_XPRM_IN="port_id 0 type inline-crypto-offload ${CRYPTO_FLBK_TYPE}"
. ${DIR}/tun_aesgcm_defs.sh
-SGW_CFG_XPRM_IN='port_id 0 type inline-crypto-offload fallback lookaside-none'
+if [[ -z "${CRYPTO_FLBK_TYPE}" ]]; then
+ CRYPTO_FLBK_TYPE="fallback lookaside-none"
+fi
+
+SGW_CFG_XPRM_IN="port_id 0 type inline-crypto-offload ${CRYPTO_FLBK_TYPE}"