NAME

  HTR_C_In_ah_esp - Host Transport Mode AH-ESP Inbound, AH (HMAC-MD5), ESP (DES-CBC) 


TARGET

  Host


SYNOPSIS

  HTR_C_In_ah_esp.seq [-tooloption ...] -pkt HTR_C_ah_esp.def
    -tooloption : v6eval tool option
  See also HTR_E_common.def and HTR_common.def


INITIALIZATION

For details of Network Topology, see 00README

Set NUT's SAD and SPD as following:

              NET5      NET3
    HOST1_NET5 -- Router -- NUT
         -----transport----->

Security Association Database (SAD) for AH

source address HOST1_NET5
destination address NUT_NET3
SPI 0x1000
mode transport
protocol AH
AH algorithm HMAC-MD5
AH algorithm key TAHITEST89ABCDEF

Security Association Database (SAD) for ESP

source address HOST1_NET5
destination address NUT_NET3
SPI 0x1000
mode transport
protocol ESP
ESP algorithm DES-CBC
ESP algorithm key TAHITEST

Security Policy Database (SPD)

source address HOST1_NET5
destination address NUT_NET3
upper spec any
direction in
protocol AH-ESP
mode transport


TEST PROCEDURE

 Tester                      Target
   |                           |
   |-------------------------->|
   |      ICMP Echo Request    |
   |        (with ESP)         |
   |                           |
   |<--------------------------|
   |      ICMP Echo Reply      |
   |                           |
   v                           v
  1. Send ICMP Echo Request with AH-ESP
  2. Receive ICMP Echo Reply

ICMP Echo Request with AH-ESP

IP Header Source Address HOST1_NET5
Destination Address NUT_NET3
AH SPI 0x1000
Algorithm HMAC-MD5
Key TAHITEST89ABCDEF
ESP SPI 0x1000
Algorithm DES-CBC
Key TAHITEST
ICMP Type 128 (Echo Request)

ICMP Echo Reply

IP Header Source Address NUT_NET3
Destination Address HOST1_NET5
ICMP Type 129 (Echo Reply)


JUDGMENT

  PASS: ICMP Echo Reply received


SEE ALSO

  perldoc V6evalTool
  IPSEC.html IPsec Test Common Utility