blob: 1594364474818a17bfab223d2ff2271b4f54473e [file] [log] [blame]
sangho80f11cb2015-04-01 13:05:26 -07001/*
Brian O'Connor43b53542016-04-09 01:19:45 -07002 * Copyright 2015-present Open Networking Laboratory
sangho80f11cb2015-04-01 13:05:26 -07003 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16package org.onosproject.segmentrouting;
17
sangho80f11cb2015-04-01 13:05:26 -070018import org.onlab.packet.Ethernet;
19import org.onlab.packet.ICMP;
Pier Ventreb6b81d52016-12-02 08:16:05 -080020import org.onlab.packet.ICMP6;
sangho80f11cb2015-04-01 13:05:26 -070021import org.onlab.packet.IPv4;
Pier Ventreb6b81d52016-12-02 08:16:05 -080022import org.onlab.packet.IPv6;
sangho80f11cb2015-04-01 13:05:26 -070023import org.onlab.packet.Ip4Address;
Pier Ventre1a655962016-11-28 16:48:06 -080024import org.onlab.packet.Ip6Address;
Pier Ventreadb4ae62016-11-23 09:57:42 -080025import org.onlab.packet.IpAddress;
sangho80f11cb2015-04-01 13:05:26 -070026import org.onlab.packet.IpPrefix;
27import org.onlab.packet.MPLS;
Pier Ventre1a655962016-11-28 16:48:06 -080028import org.onlab.packet.MacAddress;
29import org.onlab.packet.VlanId;
Pier Ventreb6b81d52016-12-02 08:16:05 -080030import org.onlab.packet.ndp.NeighborSolicitation;
Pier Ventreb6a7f342016-11-26 21:05:22 -080031import org.onosproject.incubator.net.neighbour.NeighbourMessageContext;
Pier Ventre1a655962016-11-28 16:48:06 -080032import org.onosproject.incubator.net.neighbour.NeighbourMessageType;
sangho80f11cb2015-04-01 13:05:26 -070033import org.onosproject.net.ConnectPoint;
34import org.onosproject.net.DeviceId;
Pier Ventre1a655962016-11-28 16:48:06 -080035import org.onosproject.net.Host;
36import org.onosproject.net.HostId;
sangho80f11cb2015-04-01 13:05:26 -070037import org.onosproject.net.flow.DefaultTrafficTreatment;
38import org.onosproject.net.flow.TrafficTreatment;
Pier Ventre1a655962016-11-28 16:48:06 -080039import org.onosproject.net.host.HostService;
sangho80f11cb2015-04-01 13:05:26 -070040import org.onosproject.net.packet.DefaultOutboundPacket;
sangho80f11cb2015-04-01 13:05:26 -070041import org.onosproject.net.packet.OutboundPacket;
Charles Chan319d1a22015-11-03 10:42:14 -080042import org.onosproject.segmentrouting.config.DeviceConfigNotFoundException;
Pier Ventre1a655962016-11-28 16:48:06 -080043import org.onosproject.segmentrouting.config.SegmentRoutingAppConfig;
sangho80f11cb2015-04-01 13:05:26 -070044import org.slf4j.Logger;
45import org.slf4j.LoggerFactory;
46
Jonathan Hartd53ebc42015-04-07 16:46:33 -070047import java.nio.ByteBuffer;
Saurav Dasc28b3432015-10-30 17:45:38 -070048import java.util.Set;
Jonathan Hartd53ebc42015-04-07 16:46:33 -070049
Charles Chanb7f75ac2016-01-11 18:28:54 -080050/**
51 * Handler of ICMP packets that responses or forwards ICMP packets that
52 * are sent to the controller.
53 */
Pier Ventreb6b81d52016-12-02 08:16:05 -080054public class IcmpHandler extends SegmentRoutingNeighbourHandler {
sangho80f11cb2015-04-01 13:05:26 -070055
56 private static Logger log = LoggerFactory.getLogger(IcmpHandler.class);
sangho80f11cb2015-04-01 13:05:26 -070057
58 /**
59 * Creates an IcmpHandler object.
60 *
61 * @param srManager SegmentRoutingManager object
62 */
63 public IcmpHandler(SegmentRoutingManager srManager) {
Pier Ventreb6b81d52016-12-02 08:16:05 -080064 super(srManager);
65 }
66
67 /**
68 * Utility function to send packet out.
69 *
70 * @param outport the output port
71 * @param payload the packet to send
72 * @param sid the segment id
73 * @param destIpAddress the destination ip address
74 * @param allowedHops the hop limit/ttl
75 */
76 private void sendPacketOut(ConnectPoint outport,
77 Ethernet payload,
78 int sid,
79 IpAddress destIpAddress,
80 byte allowedHops) {
81 int destSid;
82 if (destIpAddress.isIp4()) {
83 destSid = config.getIPv4SegmentId(payload.getDestinationMAC());
84 } else {
85 destSid = config.getIPv6SegmentId(payload.getDestinationMAC());
86 }
87
88 if (sid == -1 || destSid == sid ||
89 config.inSameSubnet(outport.deviceId(), destIpAddress)) {
90 TrafficTreatment treatment = DefaultTrafficTreatment.builder().
91 setOutput(outport.port()).build();
92 OutboundPacket packet = new DefaultOutboundPacket(outport.deviceId(),
93 treatment, ByteBuffer.wrap(payload.serialize()));
94 srManager.packetService.emit(packet);
95 } else {
96 log.debug("Send a MPLS packet as a ICMP response");
97 TrafficTreatment treatment = DefaultTrafficTreatment.builder()
98 .setOutput(outport.port())
99 .build();
100
101 payload.setEtherType(Ethernet.MPLS_UNICAST);
102 MPLS mplsPkt = new MPLS();
103 mplsPkt.setLabel(sid);
104 mplsPkt.setTtl(allowedHops);
105 mplsPkt.setPayload(payload.getPayload());
106 payload.setPayload(mplsPkt);
107
108 OutboundPacket packet = new DefaultOutboundPacket(outport.deviceId(),
109 treatment, ByteBuffer.wrap(payload.serialize()));
110
111 srManager.packetService.emit(packet);
112 }
sangho80f11cb2015-04-01 13:05:26 -0700113 }
114
Pier Ventre1a655962016-11-28 16:48:06 -0800115 //////////////////////////////////////
116 // ICMP Echo/Reply Protocol //
117 //////////////////////////////////////
118
sangho80f11cb2015-04-01 13:05:26 -0700119 /**
120 * Process incoming ICMP packet.
121 * If it is an ICMP request to router or known host, then sends an ICMP response.
122 * If it is an ICMP packet to known host and forward the packet to the host.
123 * If it is an ICMP packet to unknown host in a subnet, then sends an ARP request
124 * to the subnet.
125 *
Pier Ventreb6b81d52016-12-02 08:16:05 -0800126 * @param eth inbound ICMP packet
127 * @param inPort the input port
sangho80f11cb2015-04-01 13:05:26 -0700128 */
Pier Ventreb6b81d52016-12-02 08:16:05 -0800129 public void processIcmp(Ethernet eth, ConnectPoint inPort) {
130 DeviceId deviceId = inPort.deviceId();
131 IPv4 ipv4Packet = (IPv4) eth.getPayload();
132 Ip4Address destinationAddress = Ip4Address.valueOf(ipv4Packet.getDestinationAddress());
Pier Ventreb6a7f342016-11-26 21:05:22 -0800133 Set<IpAddress> gatewayIpAddresses = config.getPortIPs(deviceId);
Pier Ventreadb4ae62016-11-23 09:57:42 -0800134 IpAddress routerIp;
Charles Chan319d1a22015-11-03 10:42:14 -0800135 try {
Pier Ventreadb4ae62016-11-23 09:57:42 -0800136 routerIp = config.getRouterIpv4(deviceId);
Charles Chan319d1a22015-11-03 10:42:14 -0800137 } catch (DeviceConfigNotFoundException e) {
138 log.warn(e.getMessage() + " Aborting processPacketIn.");
139 return;
140 }
sangho80f11cb2015-04-01 13:05:26 -0700141 // ICMP to the router IP or gateway IP
Pier Ventreb6b81d52016-12-02 08:16:05 -0800142 if (((ICMP) ipv4Packet.getPayload()).getIcmpType() == ICMP.TYPE_ECHO_REQUEST &&
143 (destinationAddress.equals(routerIp.getIp4Address()) ||
Srikanth Vavilapalli37a461b2015-04-07 15:12:32 -0700144 gatewayIpAddresses.contains(destinationAddress))) {
Pier Ventreb6b81d52016-12-02 08:16:05 -0800145 sendIcmpResponse(eth, inPort);
146 // We remove the packet from the queue
147 srManager.ipHandler.dequeuePacket(ipv4Packet, destinationAddress);
sangho80f11cb2015-04-01 13:05:26 -0700148
149 // ICMP for any known host
150 } else if (!srManager.hostService.getHostsByIp(destinationAddress).isEmpty()) {
Saurav Das2d94d312015-11-24 23:21:05 -0800151 // TODO: known host packet should not be coming to controller - resend flows?
sangho80f11cb2015-04-01 13:05:26 -0700152 srManager.ipHandler.forwardPackets(deviceId, destinationAddress);
153
154 // ICMP for an unknown host in the subnet of the router
155 } else if (config.inSameSubnet(deviceId, destinationAddress)) {
Pier Ventreb6b81d52016-12-02 08:16:05 -0800156 srManager.arpHandler.sendArpRequest(deviceId, destinationAddress, inPort);
sangho80f11cb2015-04-01 13:05:26 -0700157
158 // ICMP for an unknown host
159 } else {
160 log.debug("ICMP request for unknown host {} ", destinationAddress);
Pier Ventreb6b81d52016-12-02 08:16:05 -0800161 // We remove the packet from the queue
162 srManager.ipHandler.dequeuePacket(ipv4Packet, destinationAddress);
sangho80f11cb2015-04-01 13:05:26 -0700163 }
164 }
165
Charles Chanf4586112015-11-09 16:37:23 -0800166 /**
167 * Sends an ICMP reply message.
168 *
169 * Note: we assume that packets sending from the edge switches to the hosts
170 * have untagged VLAN.
171 * @param icmpRequest the original ICMP request
172 * @param outport the output port where the ICMP reply should be sent to
173 */
Pier Ventreadb4ae62016-11-23 09:57:42 -0800174 private void sendIcmpResponse(Ethernet icmpRequest, ConnectPoint outport) {
Charles Chanf4586112015-11-09 16:37:23 -0800175 // Note: We assume that packets arrive at the edge switches have
176 // untagged VLAN.
Pier Ventreb6b81d52016-12-02 08:16:05 -0800177 Ethernet icmpReplyEth = ICMP.buildIcmpReply(icmpRequest);
sangho80f11cb2015-04-01 13:05:26 -0700178 IPv4 icmpRequestIpv4 = (IPv4) icmpRequest.getPayload();
Pier Ventreb6b81d52016-12-02 08:16:05 -0800179 IPv4 icmpReplyIpv4 = (IPv4) icmpReplyEth.getPayload();
180 Ip4Address destIpAddress = Ip4Address.valueOf(icmpRequestIpv4.getSourceAddress());
sangho9b169e32015-04-14 16:27:13 -0700181 Ip4Address destRouterAddress = config.getRouterIpAddressForASubnetHost(destIpAddress);
Pier Ventreadb4ae62016-11-23 09:57:42 -0800182 int destSid = config.getIPv4SegmentId(destRouterAddress);
Charles Chan70661362016-12-09 12:54:49 -0800183 if (destSid < 0) {
Pier Ventreb6b81d52016-12-02 08:16:05 -0800184 log.warn("Cannot find the Segment ID for {}", destIpAddress);
sangho80f11cb2015-04-01 13:05:26 -0700185 return;
186 }
Pier Ventreb6b81d52016-12-02 08:16:05 -0800187 sendPacketOut(outport, icmpReplyEth, destSid, destIpAddress, icmpReplyIpv4.getTtl());
sangho80f11cb2015-04-01 13:05:26 -0700188 }
189
Pier Ventreb6b81d52016-12-02 08:16:05 -0800190 ///////////////////////////////////////////
191 // ICMPv6 Echo/Reply Protocol //
192 ///////////////////////////////////////////
sangho80f11cb2015-04-01 13:05:26 -0700193
Pier Ventreb6b81d52016-12-02 08:16:05 -0800194 /**
195 * Process incoming ICMPv6 packet.
196 * If it is an ICMP request to router or known host, then sends an ICMP response.
197 * If it is an ICMP packet to known host and forward the packet to the host.
198 * If it is an ICMP packet to unknown host in a subnet, then sends an ARP request
199 * to the subnet.
200 *
201 * @param eth the incoming ICMPv6 packet
202 * @param inPort the input port
203 */
204 public void processIcmpv6(Ethernet eth, ConnectPoint inPort) {
205 DeviceId deviceId = inPort.deviceId();
206 IPv6 ipv6Packet = (IPv6) eth.getPayload();
207 Ip6Address destinationAddress = Ip6Address.valueOf(ipv6Packet.getDestinationAddress());
208 Set<IpAddress> gatewayIpAddresses = config.getPortIPs(deviceId);
209 IpAddress routerIp;
210 try {
211 routerIp = config.getRouterIpv6(deviceId);
212 } catch (DeviceConfigNotFoundException e) {
213 log.warn(e.getMessage() + " Aborting processPacketIn.");
214 return;
sangho80f11cb2015-04-01 13:05:26 -0700215 }
Pier Ventreb6b81d52016-12-02 08:16:05 -0800216 ICMP6 icmp6 = (ICMP6) ipv6Packet.getPayload();
217 // ICMP to the router IP or gateway IP
218 if (icmp6.getIcmpType() == ICMP6.ECHO_REQUEST &&
219 (destinationAddress.equals(routerIp.getIp6Address()) ||
220 gatewayIpAddresses.contains(destinationAddress))) {
221 sendIcmpv6Response(eth, inPort);
222 // We remove the packet from the queue
223 srManager.ipHandler.dequeuePacket(ipv6Packet, destinationAddress);
224 // ICMP for any known host
225 } else if (!srManager.hostService.getHostsByIp(destinationAddress).isEmpty()) {
226 // TODO: known host packet should not be coming to controller - resend flows?
227 srManager.ipHandler.forwardPackets(deviceId, destinationAddress);
228 // ICMP for an unknown host in the subnet of the router
229 } else if (config.inSameSubnet(deviceId, destinationAddress)) {
230 sendNdpRequest(deviceId, destinationAddress, inPort);
231 // ICMP for an unknown host or not configured host
232 } else {
233 log.debug("ICMPv6 request for unknown host or not configured host {} ", destinationAddress);
234 // We remove the packet from the queue
235 srManager.ipHandler.dequeuePacket(ipv6Packet, destinationAddress);
236 }
237 }
238
239 /**
240 * Sends an ICMPv6 reply message.
241 *
242 * Note: we assume that packets sending from the edge switches to the hosts
243 * have untagged VLAN.
244 * @param ethRequest the original ICMP request
245 * @param outport the output port where the ICMP reply should be sent to
246 */
247 private void sendIcmpv6Response(Ethernet ethRequest, ConnectPoint outport) {
248 // Note: We assume that packets arrive at the edge switches have
249 // untagged VLAN.
250 Ethernet ethReply = ICMP6.buildIcmp6Reply(ethRequest);
251 IPv6 icmpRequestIpv6 = (IPv6) ethRequest.getPayload();
252 IPv6 icmpReplyIpv6 = (IPv6) ethRequest.getPayload();
253 Ip6Address destIpAddress = Ip6Address.valueOf(icmpRequestIpv6.getSourceAddress());
254 Ip6Address destRouterAddress = config.getRouterIpAddressForASubnetHost(destIpAddress);
255 int sid = config.getIPv6SegmentId(destRouterAddress);
256 if (sid < 0) {
257 log.warn("Cannot find the Segment ID for {}", destIpAddress);
258 return;
259 }
260 sendPacketOut(outport, ethReply, sid, destIpAddress, icmpReplyIpv6.getHopLimit());
sangho80f11cb2015-04-01 13:05:26 -0700261 }
sangho9b169e32015-04-14 16:27:13 -0700262
Pier Ventre1a655962016-11-28 16:48:06 -0800263 ///////////////////////////////////////////
264 // ICMPv6 Neighbour Discovery Protocol //
265 ///////////////////////////////////////////
sangho9b169e32015-04-14 16:27:13 -0700266
Pier Ventre1a655962016-11-28 16:48:06 -0800267 /**
268 * Process incoming NDP packet.
269 *
270 * If it is an NDP request for the router or for the gateway, then sends a NDP reply.
271 * If it is an NDP request to unknown host flood in the subnet.
272 * If it is an NDP packet to known host forward the packet to the host.
273 *
274 * FIXME If the NDP packets use link local addresses we fail.
275 *
276 * @param pkt inbound packet
277 * @param hostService the host service
278 */
279 public void processPacketIn(NeighbourMessageContext pkt, HostService hostService) {
280 /*
281 * First we validate the ndp packet
282 */
283 SegmentRoutingAppConfig appConfig = srManager.cfgService
284 .getConfig(srManager.appId, SegmentRoutingAppConfig.class);
285 if (appConfig != null && appConfig.suppressSubnet().contains(pkt.inPort())) {
286 // Ignore NDP packets come from suppressed ports
287 pkt.drop();
288 return;
289 }
290 if (!validateSrcIp(pkt)) {
291 log.debug("Ignore NDP packet discovered on {} with unexpected src ip address {}.",
292 pkt.inPort(), pkt.sender());
293 pkt.drop();
294 return;
295 }
296
297 if (pkt.type() == NeighbourMessageType.REQUEST) {
298 handleNdpRequest(pkt, hostService);
299 } else {
300 handleNdpReply(pkt, hostService);
301 }
302
303 }
304
305 /**
306 * Utility function to verify if the src ip belongs to the same
307 * subnet configured on the port it is seen.
308 *
309 * @param pkt the ndp packet and context information
310 * @return true if the src ip is a valid address for the subnet configured
311 * for the connect point
312 */
313 private boolean validateSrcIp(NeighbourMessageContext pkt) {
314 ConnectPoint connectPoint = pkt.inPort();
315 IpPrefix subnet = config.getPortIPv6Subnet(
316 connectPoint.deviceId(),
317 connectPoint.port()
318 ).getIp6Prefix();
319 return subnet != null && subnet.contains(pkt.sender());
320 }
321
322 /**
323 * Helper method to handle the ndp requests.
324 *
325 * @param pkt the ndp packet request and context information
326 * @param hostService the host service
327 */
328 private void handleNdpRequest(NeighbourMessageContext pkt, HostService hostService) {
329 /*
330 * ND request for the gateway. We have to reply on behalf
331 * of the gateway.
332 */
333 if (isNdpForGateway(pkt)) {
334 log.debug("Sending NDP reply on behalf of the router");
Pier Ventreb6b81d52016-12-02 08:16:05 -0800335 sendResponse(pkt, config.getRouterMacForAGatewayIp(pkt.target()), hostService);
Pier Ventre1a655962016-11-28 16:48:06 -0800336 } else {
337 /*
338 * ND request for an host. We do a search by Ip.
339 */
340 Set<Host> hosts = hostService.getHostsByIp(pkt.target());
341 /*
342 * Possible misconfiguration ? In future this case
343 * should be handled we can have same hosts in different
344 * vlans.
345 */
346 if (hosts.size() > 1) {
347 log.warn("More than one host with IP {}", pkt.target());
348 }
349 Host targetHost = hosts.stream().findFirst().orElse(null);
350 /*
351 * If we know the host forward to its attachment
352 * point.
353 */
354 if (targetHost != null) {
355 log.debug("Forward NDP request to the target host");
356 pkt.forward(targetHost.location());
357 } else {
358 /*
359 * Flood otherwise.
360 */
361 log.debug("Flood NDP request to the target subnet");
362 flood(pkt);
363 }
364 }
365 }
366
367 /**
368 * Helper method to handle the ndp replies.
369 *
370 * @param pkt the ndp packet reply and context information
371 * @param hostService the host service
372 */
373 private void handleNdpReply(NeighbourMessageContext pkt, HostService hostService) {
374 if (isNdpForGateway(pkt)) {
375 log.debug("Forwarding all the ip packets we stored");
376 Ip6Address hostIpAddress = pkt.sender().getIp6Address();
377 srManager.ipHandler.forwardPackets(pkt.inPort().deviceId(), hostIpAddress);
378 } else {
379 HostId hostId = HostId.hostId(pkt.dstMac(), pkt.vlan());
380 Host targetHost = hostService.getHost(hostId);
381 if (targetHost != null) {
382 log.debug("Forwarding the reply to the host");
383 pkt.forward(targetHost.location());
384 } else {
385 /*
386 * We don't have to flood towards spine facing ports.
387 */
388 if (pkt.vlan().equals(VlanId.vlanId(SegmentRoutingManager.ASSIGNED_VLAN_NO_SUBNET))) {
389 return;
390 }
391 log.debug("Flooding the reply to the subnet");
392 flood(pkt);
393 }
394 }
395 }
396
397 /**
398 * Utility to verify if the ND are for the gateway.
399 *
400 * @param pkt the ndp packet
401 * @return true if the ndp is for the gateway. False otherwise
402 */
403 private boolean isNdpForGateway(NeighbourMessageContext pkt) {
404 DeviceId deviceId = pkt.inPort().deviceId();
405 Set<IpAddress> gatewayIpAddresses = null;
406 try {
407 if (pkt.target().equals(config.getRouterIpv6(deviceId))) {
408 return true;
409 }
410 gatewayIpAddresses = config.getPortIPs(deviceId);
411 } catch (DeviceConfigNotFoundException e) {
412 log.warn(e.getMessage() + " Aborting check for router IP in processing ndp");
413 }
414 if (gatewayIpAddresses != null &&
415 gatewayIpAddresses.contains(pkt.target())) {
416 return true;
417 }
418 return false;
419 }
420
421 /**
Pier Ventreb6b81d52016-12-02 08:16:05 -0800422 * Sends a NDP request for the target IP address to all ports except in-port.
Pier Ventre1a655962016-11-28 16:48:06 -0800423 *
Pier Ventreb6b81d52016-12-02 08:16:05 -0800424 * @param deviceId Switch device ID
425 * @param targetAddress target IP address for ARP
426 * @param inPort in-port
Pier Ventre1a655962016-11-28 16:48:06 -0800427 */
Pier Ventreb6b81d52016-12-02 08:16:05 -0800428 public void sendNdpRequest(DeviceId deviceId, IpAddress targetAddress, ConnectPoint inPort) {
429 byte[] senderMacAddress = new byte[MacAddress.MAC_ADDRESS_LENGTH];
430 byte[] senderIpAddress = new byte[Ip6Address.BYTE_LENGTH];
431 /*
432 * Retrieves device info.
433 */
434 getSenderInfo(senderMacAddress, senderIpAddress, deviceId, targetAddress);
435 /*
436 * We have to compute the dst mac address and dst
437 * ip address.
438 */
439 byte[] dstIp = IPv6.getSolicitNodeAddress(targetAddress.toOctets());
440 byte[] dstMac = IPv6.getMCastMacAddress(dstIp);
441 /*
442 * Creates the request.
443 */
444 Ethernet ndpRequest = NeighborSolicitation.buildNdpSolicit(
445 targetAddress.toOctets(),
446 senderIpAddress,
447 dstIp,
448 senderMacAddress,
449 dstMac,
450 VlanId.NONE
451 );
452 flood(ndpRequest, inPort, targetAddress);
Pier Ventre1a655962016-11-28 16:48:06 -0800453 }
454
sangho80f11cb2015-04-01 13:05:26 -0700455}