summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--interface-definitions/interfaces-l2tpv3.xml.in151
-rw-r--r--python/vyos/ifconfig.py76
-rwxr-xr-xsrc/conf_mode/interfaces-l2tpv3.py228
3 files changed, 455 insertions, 0 deletions
diff --git a/interface-definitions/interfaces-l2tpv3.xml.in b/interface-definitions/interfaces-l2tpv3.xml.in
new file mode 100644
index 000000000..520cce283
--- /dev/null
+++ b/interface-definitions/interfaces-l2tpv3.xml.in
@@ -0,0 +1,151 @@
+<?xml version="1.0"?>
+<interfaceDefinition>
+ <node name="interfaces">
+ <children>
+ <tagNode name="l2tpv3" owner="${vyos_conf_scripts_dir}/interfaces-l2tpv3.py">
+ <properties>
+ <help>Layer 2 Tunnel Protocol Version 3 (L2TPv3) interface</help>
+ <priority>800</priority>
+ <constraint>
+ <regex>l2tpeth[0-9]+$</regex>
+ </constraint>
+ <constraintErrorMessage>L2TPv3 interface must be named l2tpethN</constraintErrorMessage>
+ <valueHelp>
+ <format>l2tpethN</format>
+ <description>L2TPv3 interface name</description>
+ </valueHelp>
+ </properties>
+ <children>
+ #include <include/address-ipv4-ipv6.xml.i>
+ #include <include/interface-description.xml.i>
+ <leafNode name="destination-port">
+ <properties>
+ <help>UDP destination port for L2TPv3 tunnel (default: 5000)</help>
+ <valueHelp>
+ <format>1-65535</format>
+ <description>Numeric IP port</description>
+ </valueHelp>
+ <constraint>
+ <validator name="numeric" argument="--range 1-65535"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ #include <include/interface-disable.xml.i>
+ <leafNode name="encapsulation">
+ <properties>
+ <help>Encapsulation type (defualt: UDP)</help>
+ <completionHelp>
+ <list>udp ip</list>
+ </completionHelp>
+ <valueHelp>
+ <format>udp</format>
+ <description>UDP encapsulation</description>
+ </valueHelp>
+ <valueHelp>
+ <format>ip</format>
+ <description>IP encapsulation</description>
+ </valueHelp>
+ <constraint>
+ <regex>(udp|ip)</regex>
+ </constraint>
+ <constraintErrorMessage>Encapsulation must be UDP or IP</constraintErrorMessage>
+ </properties>
+ </leafNode>
+ <leafNode name="local-ip">
+ <properties>
+ <help>Local IP address for L2TPv3 tunnel</help>
+ <valueHelp>
+ <format>ipv4</format>
+ <description>Local IPv4 address of tunnel</description>
+ </valueHelp>
+ <valueHelp>
+ <format>ipv6</format>
+ <description>Local IPv6 address of tunnel</description>
+ </valueHelp>
+ <constraint>
+ <validator name="ip-address"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ #include <include/interface-mtu-68-9000.xml.i>
+ <leafNode name="peer-session-id">
+ <properties>
+ <help>Peer session identifier</help>
+ <valueHelp>
+ <format>1-429496729</format>
+ <description>L2TPv3 peer session identifier</description>
+ </valueHelp>
+ <constraint>
+ <validator name="numeric" argument="--range 1-429496729"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ <leafNode name="peer-tunnel-id">
+ <properties>
+ <help>Peer tunnel identifier</help>
+ <valueHelp>
+ <format>1-429496729</format>
+ <description>L2TPv3 peer tunnel identifier</description>
+ </valueHelp>
+ <constraint>
+ <validator name="numeric" argument="--range 1-429496729"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ <leafNode name="remote-ip">
+ <properties>
+ <help>Remote IP address for L2TPv3 tunnel</help>
+ <valueHelp>
+ <format>ipv4</format>
+ <description>Remote IPv4 address of tunnel</description>
+ </valueHelp>
+ <valueHelp>
+ <format>ipv6</format>
+ <description>Remote IPv6 address of tunnel</description>
+ </valueHelp>
+ <constraint>
+ <validator name="ip-address"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ <leafNode name="session-id">
+ <properties>
+ <help>Session identifier</help>
+ <valueHelp>
+ <format>1-429496729</format>
+ <description>L2TPv3 session identifier</description>
+ </valueHelp>
+ <constraint>
+ <validator name="numeric" argument="--range 1-429496729"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ <leafNode name="source-port">
+ <properties>
+ <help>UDP source port for L2TPv3 tunnel (default: 5000)</help>
+ <valueHelp>
+ <format>1-65535</format>
+ <description>Numeric IP port</description>
+ </valueHelp>
+ <constraint>
+ <validator name="numeric" argument="--range 1-65535"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ <leafNode name="tunnel-id">
+ <properties>
+ <help>Local tunnel identifier</help>
+ <valueHelp>
+ <format>1-429496729</format>
+ <description>L2TPv3 local tunnel identifier</description>
+ </valueHelp>
+ <constraint>
+ <validator name="numeric" argument="--range 1-429496729"/>
+ </constraint>
+ </properties>
+ </leafNode>
+ </children>
+ </tagNode>
+ </children>
+ </node>
+</interfaceDefinition>
diff --git a/python/vyos/ifconfig.py b/python/vyos/ifconfig.py
index 79e52eb38..1c5a7cd14 100644
--- a/python/vyos/ifconfig.py
+++ b/python/vyos/ifconfig.py
@@ -1704,3 +1704,79 @@ class GeneveIf(Interface):
'remote': ''
}
return config
+
+class L2TPv3If(Interface):
+ """
+ The Linux bonding driver provides a method for aggregating multiple network
+ interfaces into a single logical "bonded" interface. The behavior of the
+ bonded interfaces depends upon the mode; generally speaking, modes provide
+ either hot standby or load balancing services. Additionally, link integrity
+ monitoring may be performed.
+ """
+ def __init__(self, ifname, config=''):
+ if config:
+ self._ifname = ifname
+ if not os.path.exists('/sys/class/net/{}'.format(self._ifname)):
+ # create tunnel interface
+ cmd = 'ip l2tp add tunnel tunnel_id {} '.format(config['tunnel_id'])
+ cmd += 'peer_tunnel_id {} '.format(config['peer_tunnel_id'])
+ cmd += 'udp_sport {} '.format(config['local_port'])
+ cmd += 'udp_dport {} '.format(config['remote_port'])
+ cmd += 'encap {} '.format(config['encapsulation'])
+ cmd += 'local {} '.format(config['local_address'])
+ cmd += 'remote {} '.format(config['remote_address'])
+ self._cmd(cmd)
+
+ # setup session
+ cmd = 'ip l2tp add session name {} '.format(self._ifname)
+ cmd += 'tunnel_id {} '.format(config['tunnel_id'])
+ cmd += 'session_id {} '.format(config['session_id'])
+ cmd += 'peer_session_id {} '.format(config['peer_session_id'])
+ self._cmd(cmd)
+
+ # interface is always A/D down. It needs to be enabled explicitly
+ self.set_state('down')
+
+ super().__init__(ifname, type='l2tp')
+
+ def remove(self):
+ """
+ Remove interface from operating system. Removing the interface
+ deconfigures all assigned IP addresses.
+ Example:
+ >>> from vyos.ifconfig import L2TPv3If
+ >>> i = L2TPv3If('l2tpeth0')
+ >>> i.remove()
+ """
+
+ if os.path.exists('/sys/class/net/{}'.format(self._ifname)):
+ # interface is always A/D down. It needs to be enabled explicitly
+ self.set_state('down')
+
+ #cmd = 'ip l2tp add tunnel tunnel_id {} '.format(config['tunnel_id'])
+
+ # call remove of parent class
+ super().remove()
+
+ @staticmethod
+ def get_config():
+ """
+ L2TPv3 interfaces require a configuration when they are added using
+ iproute2. This static method will provide the configuration dictionary
+ used by this class.
+
+ Example:
+ >> dict = L2TPv3If().get_config()
+ """
+ config = {
+ 'peer_tunnel_id': '',
+ 'local_port': 0,
+ 'remote_port': 0,
+ 'encapsulation': 'udp',
+ 'local_address': '',
+ 'remote_address': '',
+ 'session_id': '',
+ 'tunnel_id': '',
+ 'peer_session_id': ''
+ }
+ return config
diff --git a/src/conf_mode/interfaces-l2tpv3.py b/src/conf_mode/interfaces-l2tpv3.py
new file mode 100755
index 000000000..62d802b39
--- /dev/null
+++ b/src/conf_mode/interfaces-l2tpv3.py
@@ -0,0 +1,228 @@
+#!/usr/bin/env python3
+#
+# Copyright (C) 2019 VyOS maintainers and contributors
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2 or later as
+# published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
+
+import os
+
+from sys import exit
+from copy import deepcopy
+
+from vyos.config import Config
+from vyos.ifconfig import L2TPv3If, Interface
+from vyos import ConfigError
+from netifaces import interfaces
+
+default_config_data = {
+ 'address': [],
+ 'deleted': False,
+ 'description': '',
+ 'disable': False,
+ 'encapsulation': 'udp',
+ 'local_address': '',
+ 'local_port': 5000,
+ 'intf': '',
+ 'mtu': 1488,
+ 'peer_session_id': '',
+ 'peer_tunnel_id': '',
+ 'remote_address': '',
+ 'remote_port': 5000,
+ 'session_id': '',
+ 'tunnel_id': ''
+}
+
+def get_config():
+ l2tpv3 = deepcopy(default_config_data)
+ conf = Config()
+
+ # determine tagNode instance
+ try:
+ l2tpv3['intf'] = os.environ['VYOS_TAGNODE_VALUE']
+ except KeyError as E:
+ print("Interface not specified")
+
+ # Check if interface has been removed
+ if not conf.exists('interfaces l2tpv3 ' + l2tpv3['intf']):
+ l2tpv3['deleted'] = True
+ return l2tpv3
+
+ # set new configuration level
+ conf.set_level('interfaces l2tpv3 ' + l2tpv3['intf'])
+
+ # retrieve configured interface addresses
+ if conf.exists('address'):
+ l2tpv3['address'] = conf.return_values('address')
+
+ # retrieve interface description
+ if conf.exists('description'):
+ l2tpv3['description'] = conf.return_value('description')
+
+ # get tunnel destination port
+ if conf.exists('destination-port'):
+ l2tpv3['remote_port'] = int(conf.return_value('destination-port'))
+
+ # Disable this interface
+ if conf.exists('disable'):
+ l2tpv3['disable'] = True
+
+ # get tunnel encapsulation type
+ if conf.exists('encapsulation'):
+ l2tpv3['encapsulation'] = conf.return_value('encapsulation')
+
+ # get tunnel local ip address
+ if conf.exists('local-ip'):
+ l2tpv3['local_address'] = conf.return_value('local-ip')
+
+ # Maximum Transmission Unit (MTU)
+ if conf.exists('mtu'):
+ l2tpv3['mtu'] = int(conf.return_value('mtu'))
+
+ # Remote session id
+ if conf.exists('peer-session-id'):
+ l2tpv3['peer_session_id'] = conf.return_value('peer-session-id')
+
+ # Remote tunnel id
+ if conf.exists('peer-tunnel-id'):
+ l2tpv3['peer_tunnel_id'] = conf.return_value('peer-tunnel-id')
+
+ # Remote address of L2TPv3 tunnel
+ if conf.exists('remote-ip'):
+ l2tpv3['remote_address'] = conf.return_value('remote-ip')
+
+ # Local session id
+ if conf.exists('session-id'):
+ l2tpv3['session_id'] = conf.return_value('session-id')
+
+ # get local tunnel port
+ if conf.exists('source-port'):
+ l2tpv3['local_port'] = conf.return_value('source-port')
+
+ # get local tunnel id
+ if conf.exists('tunnel-id'):
+ l2tpv3['tunnel_id'] = conf.return_value('tunnel-id')
+
+ return l2tpv3
+
+
+def verify(l2tpv3):
+ if l2tpv3['deleted']:
+ # bail out early
+ return None
+
+ if not l2tpv3['local_address']:
+ raise ConfigError('Must configure the l2tpv3 local-ip for {}'.format(l2tpv3['intf']))
+
+ if not l2tpv3['remote_address']:
+ raise ConfigError('Must configure the l2tpv3 remote-ip for {}'.format(l2tpv3['intf']))
+
+ if not l2tpv3['tunnel_id']:
+ raise ConfigError('Must configure the l2tpv3 tunnel-id for {}'.format(l2tpv3['intf']))
+
+ if not l2tpv3['peer_tunnel_id']:
+ raise ConfigError('Must configure the l2tpv3 peer-tunnel-id for {}'.format(l2tpv3['intf']))
+
+ if not l2tpv3['session_id']:
+ raise ConfigError('Must configure the l2tpv3 session-id for {}'.format(l2tpv3['intf']))
+
+ if not l2tpv3['peer_session_id']:
+ raise ConfigError('Must configure the l2tpv3 peer-session-id for {}'.format(l2tpv3['intf']))
+
+ return None
+
+
+def generate(l2tpv3):
+ if l2tpv3['deleted']:
+ # bail out early
+ return None
+
+ # initialize kernel module if not loaded
+ if not os.path.isdir('/sys/module/l2tp_eth'):
+ if os.system('modprobe l2tp_eth') != 0:
+ raise ConfigError("failed loading l2tp_eth kernel module")
+
+ if not os.path.isdir('/sys/module/l2tp_netlink'):
+ if os.system('modprobe l2tp_netlink') != 0:
+ raise ConfigError("failed loading l2tp_netlink kernel module")
+
+ if not os.path.isdir('/sys/module/l2tp_ip'):
+ if os.system('modprobe l2tp_ip') != 0:
+ raise ConfigError("failed loading l2tp_ip kernel module")
+
+ if l2tpv3['encapsulation'] == 'ip':
+ if not os.path.isdir('/sys/module/l2tp_ip'):
+ if os.system('modprobe l2tp_ip') != 0:
+ raise ConfigError("failed loading l2tp_ip kernel module")
+
+ if not os.path.isdir('/sys/module/l2tp_ip6 '):
+ if os.system('modprobe l2tp_ip6 ') != 0:
+ raise ConfigError("failed loading l2tp_ip6 kernel module")
+
+ return None
+
+
+def apply(l2tpv3):
+ # Check if L2TPv3 interface already exists
+ if l2tpv3['intf'] in interfaces():
+ l = L2TPv3If(l2tpv3['intf'])
+ # L2TPv3 is super picky and the tunnel always needs to be recreated,
+ # thus we can simply always delete it first.
+ l.remove()
+
+
+ if not l2tpv3['deleted']:
+ # L2TPv3 interface needs to be created on-block
+ # instead of passing a ton of arguments, I just use a dict
+ # that is managed by vyos.ifconfig
+ conf = deepcopy(L2TPv3If.get_config())
+
+ conf['peer_tunnel_id'] = l2tpv3['peer_tunnel_id']
+ conf['local_port'] = l2tpv3['local_port']
+ conf['remote_port'] = l2tpv3['remote_port']
+ conf['encapsulation'] = l2tpv3['encapsulation']
+ conf['local_address'] = l2tpv3['local_address']
+ conf['remote_address'] = l2tpv3['remote_address']
+ conf['session_id'] = l2tpv3['session_id']
+ conf['tunnel_id'] = l2tpv3['tunnel_id']
+ conf['peer_session_id'] = l2tpv3['peer_session_id']
+
+ # Finally create the new interface
+ l = L2TPv3If(l2tpv3['intf'], config=conf)
+ # update interface description used e.g. by SNMP
+ l.set_alias(l2tpv3['description'])
+ # Maximum Transfer Unit (MTU)
+ l.set_mtu(l2tpv3['mtu'])
+
+ # Configure interface address(es) - no need to implicitly delete the
+ # old addresses as they have already been removed by deleting the
+ # interface above
+ for addr in l2tpv3['address']:
+ l.add_addr(addr)
+
+ # As the interface is always disabled first when changing parameters
+ # we will only re-enable the interface if it is not administratively
+ # disabled
+ if not l2tpv3['disable']:
+ l.set_state('up')
+
+ return None
+
+if __name__ == '__main__':
+ try:
+ c = get_config()
+ verify(c)
+ generate(c)
+ apply(c)
+ except ConfigError as e:
+ print(e)
+ exit(1)