#------------------------------------------------- # IPsec configuration for MN TAHI tests # # MN : 3ffe:501:ffff:100:207:e9ff:fe3f:c123 # HA0: 3ffe:501:ffff:100:200:ff:fe00:a0a0 # HA1: 3ffe:501:ffff:100:200:ff:fe00:a1a1 #------------------------------------------------- #------------------------------------------------- # IPsec MN -> HA0 Transport mode MH SA1 (BU) #------------------------------------------------- add 3ffe:501:ffff:100:207:e9ff:fe3f:c123 3ffe:501:ffff:100:200:ff:fe00:a0a0 135 esp 2001 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec HA0 -> MN Transport mode MH SA2 (BA) #------------------------------------------------- add 3ffe:501:ffff:100:200:ff:fe00:a0a0 3ffe:501:ffff:100:207:e9ff:fe3f:c123 135 esp 2002 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec MN -> HA1 Transport mode MH SA1 (BU) #------------------------------------------------- add 3ffe:501:ffff:100:207:e9ff:fe3f:c123 3ffe:501:ffff:100:200:ff:fe00:a1a1 135 esp 2101 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec HA1 -> MN Transport mode MH SA2 (BA) #------------------------------------------------- add 3ffe:501:ffff:100:200:ff:fe00:a1a1 3ffe:501:ffff:100:207:e9ff:fe3f:c123 135 esp 2102 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec MN -> HA0 Transport mode ICMP SA5 (MPS) #------------------------------------------------- add 3ffe:501:ffff:100:207:e9ff:fe3f:c123 3ffe:501:ffff:100:200:ff:fe00:a0a0 58 esp 2005 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec HA0 -> MN Transport mode ICMP SA6 (MPA) #------------------------------------------------- add 3ffe:501:ffff:100:200:ff:fe00:a0a0 3ffe:501:ffff:100:207:e9ff:fe3f:c123 58 esp 2006 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec MN -> HA1 Transport mode ICMP SA5 (MPS) #------------------------------------------------- add 3ffe:501:ffff:100:207:e9ff:fe3f:c123 3ffe:501:ffff:100:200:ff:fe00:a1a1 58 esp 2105 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec HA1 -> MN Transport mode ICMP SA6 (MPA) #------------------------------------------------- add 3ffe:501:ffff:100:200:ff:fe00:a1a1 3ffe:501:ffff:100:207:e9ff:fe3f:c123 58 esp 2106 -m transport -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec MN -> HA0 Tunnel mode SA3 (HoTI) #------------------------------------------------- add 3ffe:501:ffff:100:207:e9ff:fe3f:c123 3ffe:501:ffff:100:200:ff:fe00:a0a0 135 esp 2003 -m tunnel -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec HA0 -> MN Tunnel mode SA4 (HoT) #------------------------------------------------- add 3ffe:501:ffff:100:200:ff:fe00:a0a0 3ffe:501:ffff:100:207:e9ff:fe3f:c123 135 esp 2004 -m tunnel -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec MN -> HA1 Tunnel mode SA3 (HoTI) #------------------------------------------------- add 3ffe:501:ffff:100:207:e9ff:fe3f:c123 3ffe:501:ffff:100:200:ff:fe00:a1a1 135 esp 2103 -m tunnel -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ; #------------------------------------------------- # IPsec HA1 -> MN Tunnel mode SA4 (HoT) #------------------------------------------------- add 3ffe:501:ffff:100:200:ff:fe00:a1a1 3ffe:501:ffff:100:207:e9ff:fe3f:c123 135 esp 2104 -m tunnel -E 3des-cbc "V6LC-000--12345678901234" -A hmac-sha1 "V6LC-000--1234567890" ;