Coverage for vpn/choices.py: 100%
111 statements
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-10 18:35 +0000
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-10 18:35 +0000
1from django.utils.translation import gettext_lazy as _
3from utilities.choices import Choice, ChoiceSet
5#
6# Tunnels
7#
10class TunnelStatusChoices(ChoiceSet):
11 key = 'Tunnel.status'
13 STATUS_PLANNED = 'planned'
14 STATUS_ACTIVE = 'active'
15 STATUS_DISABLED = 'disabled'
17 CHOICES = [
18 Choice(
19 STATUS_PLANNED,
20 _('Planned'),
21 color='cyan',
22 description=_('Designated for future use but not yet in service')
23 ),
24 Choice(STATUS_ACTIVE, _('Active'), color='green', description=_('Established and carrying traffic')),
25 Choice(STATUS_DISABLED, _('Disabled'), color='red', description=_('Administratively disabled')),
26 ]
29class TunnelEncapsulationChoices(ChoiceSet):
30 ENCAP_GRE = 'gre'
31 ENCAP_IPSEC_TRANSPORT = 'ipsec-transport'
32 ENCAP_IPSEC_TUNNEL = 'ipsec-tunnel'
33 ENCAP_IP_IP = 'ip-ip'
34 ENCAP_L2TP = 'l2tp'
35 ENCAP_OPENVPN = 'openvpn'
36 ENCAP_PPTP = 'pptp'
37 ENCAP_WIREGUARD = 'wireguard'
39 CHOICES = [
40 Choice(
41 ENCAP_IPSEC_TRANSPORT,
42 _('IPsec - Transport'),
43 description=_('IPsec encrypting only the packet payload between endpoints')
44 ),
45 Choice(
46 ENCAP_IPSEC_TUNNEL,
47 _('IPsec - Tunnel'),
48 description=_('IPsec encrypting the entire original IP packet')
49 ),
50 Choice(ENCAP_IP_IP, _('IP-in-IP'), description=_('Encapsulation of one IP packet within another')),
51 Choice(ENCAP_GRE, _('GRE'), description=_('Generic Routing Encapsulation')),
52 Choice(ENCAP_WIREGUARD, _('WireGuard')),
53 Choice(ENCAP_OPENVPN, _('OpenVPN')),
54 Choice(ENCAP_L2TP, _('L2TP'), description=_('Layer 2 Tunneling Protocol')),
55 Choice(ENCAP_PPTP, _('PPTP'), description=_('Point-to-Point Tunneling Protocol')),
56 ]
59class TunnelTerminationTypeChoices(ChoiceSet):
60 # For TunnelCreateForm
61 TYPE_DEVICE = 'dcim.device'
62 TYPE_VIRTUALMACHINE = 'virtualization.virtualmachine'
64 CHOICES = (
65 Choice(TYPE_DEVICE, _('Device')),
66 Choice(TYPE_VIRTUALMACHINE, _('Virtual Machine')),
67 )
70class TunnelTerminationRoleChoices(ChoiceSet):
71 ROLE_PEER = 'peer'
72 ROLE_HUB = 'hub'
73 ROLE_SPOKE = 'spoke'
75 CHOICES = [
76 Choice(ROLE_PEER, _('Peer'), color='green', description=_('Symmetric endpoint in a point-to-point tunnel')),
77 Choice(ROLE_HUB, _('Hub'), color='blue', description=_('Central endpoint in a hub-and-spoke topology')),
78 Choice(ROLE_SPOKE, _('Spoke'), color='orange', description=_('Remote endpoint connecting to a hub')),
79 ]
82#
83# Crypto
84#
86class IKEVersionChoices(ChoiceSet):
87 VERSION_1 = 1
88 VERSION_2 = 2
90 CHOICES = (
91 Choice(VERSION_1, 'IKEv1'),
92 Choice(VERSION_2, 'IKEv2'),
93 )
96class IKEModeChoices(ChoiceSet):
97 AGGRESSIVE = 'aggressive'
98 MAIN = 'main'
100 CHOICES = (
101 Choice(AGGRESSIVE, _('Aggressive')),
102 Choice(MAIN, _('Main')),
103 )
106class AuthenticationMethodChoices(ChoiceSet):
107 PRESHARED_KEYS = 'preshared-keys'
108 CERTIFICATES = 'certificates'
109 RSA_SIGNATURES = 'rsa-signatures'
110 DSA_SIGNATURES = 'dsa-signatures'
112 CHOICES = (
113 Choice(PRESHARED_KEYS, _('Pre-shared keys')),
114 Choice(CERTIFICATES, _('Certificates')),
115 Choice(RSA_SIGNATURES, _('RSA signatures')),
116 Choice(DSA_SIGNATURES, _('DSA signatures')),
117 )
120class IPSecModeChoices(ChoiceSet):
121 ESP = 'esp'
122 AH = 'ah'
124 CHOICES = (
125 Choice(ESP, 'ESP'),
126 Choice(AH, 'AH'),
127 )
130class EncryptionAlgorithmChoices(ChoiceSet):
131 ENCRYPTION_AES128_CBC = 'aes-128-cbc'
132 ENCRYPTION_AES128_GCM = 'aes-128-gcm'
133 ENCRYPTION_AES192_CBC = 'aes-192-cbc'
134 ENCRYPTION_AES192_GCM = 'aes-192-gcm'
135 ENCRYPTION_AES256_CBC = 'aes-256-cbc'
136 ENCRYPTION_AES256_GCM = 'aes-256-gcm'
137 ENCRYPTION_3DES = '3des-cbc'
138 ENCRYPTION_DES = 'des-cbc'
140 CHOICES = (
141 Choice(ENCRYPTION_AES128_CBC, '128-bit AES (CBC)'),
142 Choice(ENCRYPTION_AES128_GCM, '128-bit AES (GCM)'),
143 Choice(ENCRYPTION_AES192_CBC, '192-bit AES (CBC)'),
144 Choice(ENCRYPTION_AES192_GCM, '192-bit AES (GCM)'),
145 Choice(ENCRYPTION_AES256_CBC, '256-bit AES (CBC)'),
146 Choice(ENCRYPTION_AES256_GCM, '256-bit AES (GCM)'),
147 Choice(ENCRYPTION_3DES, '3DES'),
148 Choice(ENCRYPTION_DES, 'DES'),
149 )
152class AuthenticationAlgorithmChoices(ChoiceSet):
153 AUTH_HMAC_SHA1 = 'hmac-sha1'
154 AUTH_HMAC_SHA256 = 'hmac-sha256'
155 AUTH_HMAC_SHA384 = 'hmac-sha384'
156 AUTH_HMAC_SHA512 = 'hmac-sha512'
157 AUTH_HMAC_MD5 = 'hmac-md5'
159 CHOICES = (
160 Choice(AUTH_HMAC_SHA1, 'SHA-1 HMAC'),
161 Choice(AUTH_HMAC_SHA256, 'SHA-256 HMAC'),
162 Choice(AUTH_HMAC_SHA384, 'SHA-384 HMAC'),
163 Choice(AUTH_HMAC_SHA512, 'SHA-512 HMAC'),
164 Choice(AUTH_HMAC_MD5, 'MD5 HMAC'),
165 )
168class DHGroupChoices(ChoiceSet):
169 # https://www.iana.org/assignments/ikev2-parameters/ikev2-parameters.xhtml#ikev2-parameters-8
170 GROUP_1 = 1 # 768-bit MODP
171 GROUP_2 = 2 # 1024-but MODP
172 # Groups 3-4 reserved
173 GROUP_5 = 5 # 1536-bit MODP
174 # Groups 6-13 unassigned
175 GROUP_14 = 14 # 2048-bit MODP
176 GROUP_15 = 15 # 3072-bit MODP
177 GROUP_16 = 16 # 4096-bit MODP
178 GROUP_17 = 17 # 6144-bit MODP
179 GROUP_18 = 18 # 8192-bit MODP
180 GROUP_19 = 19 # 256-bit random ECP
181 GROUP_20 = 20 # 384-bit random ECP
182 GROUP_21 = 21 # 521-bit random ECP (521 is not a typo)
183 GROUP_22 = 22 # 1024-bit MODP w/160-bit prime
184 GROUP_23 = 23 # 2048-bit MODP w/224-bit prime
185 GROUP_24 = 24 # 2048-bit MODP w/256-bit prime
186 GROUP_25 = 25 # 192-bit ECP
187 GROUP_26 = 26 # 224-bit ECP
188 GROUP_27 = 27 # brainpoolP224r1
189 GROUP_28 = 28 # brainpoolP256r1
190 GROUP_29 = 29 # brainpoolP384r1
191 GROUP_30 = 30 # brainpoolP512r1
192 GROUP_31 = 31 # Curve25519
193 GROUP_32 = 32 # Curve448
194 GROUP_33 = 33 # GOST3410_2012_256
195 GROUP_34 = 34 # GOST3410_2012_512
197 CHOICES = (
198 # Strings are formatted in this manner to optimize translations
199 Choice(GROUP_1, _('Group {n}').format(n=1)),
200 Choice(GROUP_2, _('Group {n}').format(n=2)),
201 Choice(GROUP_5, _('Group {n}').format(n=5)),
202 Choice(GROUP_14, _('Group {n}').format(n=14)),
203 Choice(GROUP_15, _('Group {n}').format(n=15)),
204 Choice(GROUP_16, _('Group {n}').format(n=16)),
205 Choice(GROUP_17, _('Group {n}').format(n=17)),
206 Choice(GROUP_18, _('Group {n}').format(n=18)),
207 Choice(GROUP_19, _('Group {n}').format(n=19)),
208 Choice(GROUP_20, _('Group {n}').format(n=20)),
209 Choice(GROUP_21, _('Group {n}').format(n=21)),
210 Choice(GROUP_22, _('Group {n}').format(n=22)),
211 Choice(GROUP_23, _('Group {n}').format(n=23)),
212 Choice(GROUP_24, _('Group {n}').format(n=24)),
213 Choice(GROUP_25, _('Group {n}').format(n=25)),
214 Choice(GROUP_26, _('Group {n}').format(n=26)),
215 Choice(GROUP_27, _('Group {n}').format(n=27)),
216 Choice(GROUP_28, _('Group {n}').format(n=28)),
217 Choice(GROUP_29, _('Group {n}').format(n=29)),
218 Choice(GROUP_30, _('Group {n}').format(n=30)),
219 Choice(GROUP_31, _('Group {n}').format(n=31)),
220 Choice(GROUP_32, _('Group {n}').format(n=32)),
221 Choice(GROUP_33, _('Group {n}').format(n=33)),
222 Choice(GROUP_34, _('Group {n}').format(n=34)),
223 )
226#
227# L2VPN
228#
230class L2VPNTypeChoices(ChoiceSet):
231 TYPE_VPLS = 'vpls'
232 TYPE_VPWS = 'vpws'
233 TYPE_EPL = 'epl'
234 TYPE_EVPL = 'evpl'
235 TYPE_EPLAN = 'ep-lan'
236 TYPE_EVPLAN = 'evp-lan'
237 TYPE_EPTREE = 'ep-tree'
238 TYPE_EVPTREE = 'evp-tree'
239 TYPE_VXLAN = 'vxlan'
240 TYPE_VXLAN_EVPN = 'vxlan-evpn'
241 TYPE_MPLS_EVPN = 'mpls-evpn'
242 TYPE_PBB_EVPN = 'pbb-evpn'
243 TYPE_EVPN_VPWS = 'evpn-vpws'
244 TYPE_SPB = 'spb'
246 CHOICES = (
247 ('VPLS', (
248 Choice(
249 TYPE_VPWS,
250 'VPWS',
251 description=_('Virtual Private Wire Service: point-to-point Layer 2 connectivity')
252 ),
253 Choice(
254 TYPE_VPLS,
255 'VPLS',
256 description=_('Virtual Private LAN Service: multipoint Layer 2 connectivity')
257 ),
258 )),
259 ('VXLAN', (
260 Choice(TYPE_VXLAN, 'VXLAN', description=_('Virtual Extensible LAN overlay')),
261 Choice(TYPE_VXLAN_EVPN, 'VXLAN-EVPN', description=_('VXLAN with EVPN control plane')),
262 )),
263 ('L2VPN E-VPN', (
264 Choice(TYPE_MPLS_EVPN, 'MPLS EVPN', description=_('Ethernet VPN over an MPLS transport')),
265 Choice(TYPE_PBB_EVPN, 'PBB EVPN', description=_('Provider Backbone Bridging with EVPN')),
266 Choice(TYPE_EVPN_VPWS, 'EVPN VPWS', description=_('Point-to-point service using an EVPN control plane'))
267 )),
268 ('E-Line', (
269 Choice(TYPE_EPL, 'EPL', description=_('Ethernet Private Line: dedicated point-to-point service')),
270 Choice(
271 TYPE_EVPL,
272 'EVPL',
273 description=_('Ethernet Virtual Private Line: multiplexed point-to-point service')
274 ),
275 )),
276 ('E-LAN', (
277 Choice(TYPE_EPLAN, _('Ethernet Private LAN'), description=_('Dedicated multipoint-to-multipoint service')),
278 Choice(
279 TYPE_EVPLAN,
280 _('Ethernet Virtual Private LAN'),
281 description=_('Multiplexed multipoint-to-multipoint service')
282 ),
283 )),
284 ('E-Tree', (
285 Choice(TYPE_EPTREE, _('Ethernet Private Tree'), description=_('Dedicated rooted multipoint service')),
286 Choice(
287 TYPE_EVPTREE,
288 _('Ethernet Virtual Private Tree'),
289 description=_('Multiplexed rooted multipoint service')
290 ),
291 )),
292 ('Other', (
293 Choice(TYPE_SPB, _('SPB'), description=_('Shortest Path Bridging')),
294 )),
295 )
297 P2P = (
298 TYPE_VPWS,
299 TYPE_EPL,
300 TYPE_EPLAN,
301 TYPE_EPTREE
302 )
305class L2VPNStatusChoices(ChoiceSet):
306 key = 'L2VPN.status'
308 STATUS_ACTIVE = 'active'
309 STATUS_PLANNED = 'planned'
310 STATUS_DECOMMISSIONING = 'decommissioning'
312 CHOICES = [
313 Choice(STATUS_ACTIVE, _('Active'), color='green', description=_('Established and carrying traffic')),
314 Choice(
315 STATUS_PLANNED,
316 _('Planned'),
317 color='cyan',
318 description=_('Designated for future use but not yet in service')
319 ),
320 Choice(STATUS_DECOMMISSIONING, _('Decommissioning'), color='red', description=_('Being retired from service')),
321 ]