NAME

  HTR_E_Out_LifetimeSATime - Lifetime of SA using time, Host Transport Mode Outboud ESP (NULL), ESP Authentication HMAC-MD5


TARGET

  Host


SYNOPSIS

  HTR_E_Out_LifetimeSATime.seq [-tooloption ...] -pkt HTR_E_LifetimeSA.def
    -tooloption : v6eval tool option
  See also HTR_E_common.def and HTR_common.def


INITIALIZATION

For details of Network Topology, see 00README

Set NUT's SAD and SPD as following:

              NET5      NET3
    HOST1_NET5 -- Router -- NUT
         -----transport----->

Security Association Database (SAD)

source address NUT_NET3
destination address HOST1_NET5
SPI 0x1000
mode transport
lifetime hard = 35 sec
soft = 35 sec
protocol ESP
ESP algorithm NULL
ESP authentication HMAC-MD5
ESP authentication key TAHITEST89ABCDEF

Security Policy Database (SPD)

source address NUT_NET3
destination address HOST1_NET5
upper spec any
direction out
protocol ESP
mode transport


TEST PROCEDURE

 Tester                      Target
   |                           |
   |-------------------------->|
   |      ICMP Echo Request    |
   |                           |
   |<--------------------------|
   |      ICMP Echo Reply      |
   |        (with ESP)         |
   |                           |
   |           :               |
   |   Expire Lifetime of SA   |
   |           :               |
   |                           |
   |-------------------------->|
   |      ICMP Echo Request    |
   |                           |
   |<--------------------------|
   |     No ICMP Echo Reply    |
   |        (with ESP)         |
   |                           |
   v                           v
  1. Send ICMP Echo Request
  2. Receive ICMP Echo Reply with ESP
  3. Continue until expire lifetime of SA
  4. Send ICMP Echo Request
  5. No Receive ICMP Echo Reply with ESP

ICMP Echo Request with ESP

IP Header Source Address HOST1_NET5
Destination Address NUT_NET3
ESP SPI 0x1000
Algorithm DES-CBC
Key TAHITEST
ICMP Type 128 (Echo Request)

ICMP Echo Reply

IP Header Source Address NUT_NET3
Destination Address HOST1_NET5
ICMP Type 129 (Echo Reply)


JUDGMENT

  PASS: When lifetime of SA was expired, TN didn't receive ICMP Echo Reply from NUT.
  FAIL: When lifetime of SA was expired, TN received ICMP Echo Reply from NUT.


SEE ALSO

  perldoc V6evalTool
  IPSEC.html IPsec Test Common Utility