[vpp-dev] Future of IKEv2 implementation, and rsa-sig authentication

2018-05-24 Thread berengerf via Lists.Fd.Io
Hello, I discovered VPP few weeks ago, and I am quite interested in the IPsec/IKEv2 part. First, I saw that rsa-sig authentication was developped for IKEv2, however I did not find any tutorial or working config about this authentication method. I tried to build a configuration on my own but al

[vpp-dev] First packet is lost when ARP resolution occurs

2018-06-21 Thread berengerf via Lists.Fd.Io
Hello, I noticed that some packets were lost during IKEv2 negotiation with VPP. After investigation it seems that it is related to ARP resolution. When the ARP cache is empty and a packetX needs to be sent, VPP will send an ARP request (which is right), but the packetX won't be sent afterwards.

[vpp-dev] IKEv2 integration, ipsecX interface and related SPD

2018-06-21 Thread berengerf via Lists.Fd.Io
Hello, I have some questions regarding the integration of IKEv2 within VPP. When an IKEv2 negotiation succeeds, an ipsecX interface is created. Then in order to encrypt the outgoing traffic, the interface has to be set up manually, an address needs to be assigned to this interface (the address