From ce5449687801bb941d6b77c2622e6e5fb0e29ce5 Mon Sep 17 00:00:00 2001 From: Victor Julien Date: Thu, 27 Jun 2019 15:14:26 +0200 Subject: [PATCH] tests: icmp over vxlan test --- tests/vxlan-decoder-02/README.md | 7 +++++++ tests/vxlan-decoder-02/test.yaml | 23 +++++++++++++++++++++++ tests/vxlan-decoder-02/vxlan.pcap | Bin 0 -> 1552 bytes 3 files changed, 30 insertions(+) create mode 100644 tests/vxlan-decoder-02/README.md create mode 100644 tests/vxlan-decoder-02/test.yaml create mode 100644 tests/vxlan-decoder-02/vxlan.pcap diff --git a/tests/vxlan-decoder-02/README.md b/tests/vxlan-decoder-02/README.md new file mode 100644 index 000000000..342ca79ab --- /dev/null +++ b/tests/vxlan-decoder-02/README.md @@ -0,0 +1,7 @@ +# Description + +Test basic VXLAN decoding + +# PCAP + +https://github.com/the-tcpdump-group/tcpdump/blob/master/tests/vxlan.pcap diff --git a/tests/vxlan-decoder-02/test.yaml b/tests/vxlan-decoder-02/test.yaml new file mode 100644 index 000000000..eb0e7e61c --- /dev/null +++ b/tests/vxlan-decoder-02/test.yaml @@ -0,0 +1,23 @@ +requires: + min-version: 5.0.0 + features: + - HAVE_LIBJANSSON + +checks: + - filter: + count: 1 + match: + event_type: flow + proto: "ICMP" + flow.pkts_toserver: 4 + flow.pkts_toclient: 4 + - filter: + count: 4 + match: + event_type: flow + dest_port: 4789 + - filter: + count: 4 + match: + event_type: alert + tunnel.dest_port: 4789 diff --git a/tests/vxlan-decoder-02/vxlan.pcap b/tests/vxlan-decoder-02/vxlan.pcap new file mode 100644 index 0000000000000000000000000000000000000000..04f0c2f9045d91017db4025df20e195b182bd1d6 GIT binary patch literal 1552 zc-p0sIY!^LedCU@xW5W!XlNTg;t6P2JOYO(Ix~d@gils z5VR12h({{5wXq06H2UUc4y=@)@h_8?cz~T4qX|?a-T!v-* zXB+ID(!_O3Xd!psDM1&2Cm3*o)7IA?@Lh2M-zB#@lynG_0219Z3gB4efX7^GSfIoJ z04BJi9!!{UixPz2L>agb>|z;jgr{txEh#xA)t;7~k(rg9lbe@cP*_x4Qd(ACQCU@8 zQ(Nb#Z)j|4ZfRwV_9+VtVutM)U5u0(U4GsPowl)V#>Y6lx5(I`GJesDkxFLZBrpp& zKAjn1%n9RVUG8bM>z@x-@R)oo#eH0Pes}%y5${sYtU+yMT~dMd$Nj&#Jbn|+l@On6 zZuXCRx>cEr-23;@KDV>U?x!}08ghS+Ir&oaeVmYwUL)^Ad__k7Q(;{B)Xx~5uxNP{ z$fH$<#{=@Xp?b6!Vtl|{TTs*EDS7NM;_>|%8BI}zaZ5DmW*nZ;^eB=?iw=*6