mbox series

[v1,0/2] examples/ipsec-secgw: add fallback session

Message ID 20190814204847.15600-1-marcinx.smoczynski@intel.com (mailing list archive)
Headers
Series examples/ipsec-secgw: add fallback session |

Message

Marcin Smoczynski Aug. 14, 2019, 8:48 p.m. UTC
  Inline processing is limited to a specified subset of traffic. It is
often unable to handle more complicated situations, such as fragmented
traffic. When using inline processing such traffic is dropped.

Introduce multiple sessions per SA allowing to configure a fallback
lookaside session for packets that normally would be dropped.
A fallback session type in the SA configuration by adding 'fallback'
with 'lookaside-none' or 'lookaside-protocol' parameter to determine
type of session.

Fallback session feature is available only when using librte_ipsec.

Marcin Smoczynski (2):
  examples/ipsec-secgw: ipsec_sa structure cleanup
  examples/ipsec-secgw: add fallback session feature

 doc/guides/sample_app_ug/ipsec_secgw.rst |  17 ++-
 examples/ipsec-secgw/esp.c               |  35 ++++--
 examples/ipsec-secgw/ipsec-secgw.c       |  16 ++-
 examples/ipsec-secgw/ipsec.c             |  99 ++++++++-------
 examples/ipsec-secgw/ipsec.h             |  61 +++++++--
 examples/ipsec-secgw/ipsec_process.c     | 113 ++++++++++-------
 examples/ipsec-secgw/sa.c                | 153 +++++++++++++++++------
 7 files changed, 334 insertions(+), 160 deletions(-)

--
2.17.1