ipsectypes.h 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589
  1. /**
  2. * This file has no copyright assigned and is placed in the Public Domain.
  3. * This file is part of the mingw-w64 runtime package.
  4. * No warranty is given; refer to the file DISCLAIMER.PD within this package.
  5. */
  6. #ifndef _INC_IPSECTYPES
  7. #define _INC_IPSECTYPES
  8. #include <iketypes.h>
  9. #ifdef __cplusplus
  10. extern "C" {
  11. #endif
  12. #if (_WIN32_WINNT >= 0x0600)
  13. typedef UINT8 IPSEC_AUTH_CONFIG;
  14. typedef UINT8 IPSEC_CIPHER_CONFIG;
  15. typedef UINT32 IPSEC_SA_SPI;
  16. typedef UINT64 IPSEC_TOKEN_HANDLE;
  17. typedef GUID IPSEC_CRYPTO_MODULE_ID;
  18. #ifndef __IPSEC_SA_TRANSFORM0_FWD_DECLARED
  19. #define __IPSEC_SA_TRANSFORM0_FWD_DECLARED
  20. typedef struct IPSEC_SA_TRANSFORM0_ IPSEC_SA_TRANSFORM0;
  21. #endif /* __IPSEC_SA_TRANSFORM0_FWD_DECLARED */
  22. #ifndef __FWPM_FILTER0_FWD_DECLARED
  23. #define __FWPM_FILTER0_FWD_DECLARED
  24. typedef struct FWPM_FILTER0_ FWPM_FILTER0;
  25. #endif /* __FWPM_FILTER0_FWD_DECLARED */
  26. typedef enum IPSEC_FAILURE_POINT_ {
  27. IPSEC_FAILURE_NONE,
  28. IPSEC_FAILURE_ME,
  29. IPSEC_FAILURE_PEER,
  30. IPSEC_FAILURE_POINT_MAX
  31. } IPSEC_FAILURE_POINT;
  32. typedef enum IPSEC_TRAFFIC_TYPE_ {
  33. IPSEC_TRAFFIC_TYPE_TRANSPORT,
  34. IPSEC_TRAFFIC_TYPE_TUNNEL,
  35. IPSEC_TRAFFIC_TYPE_MAX
  36. } IPSEC_TRAFFIC_TYPE;
  37. typedef enum IPSEC_PFS_GROUP_ {
  38. IPSEC_PFS_NONE,
  39. IPSEC_PFS_1,
  40. IPSEC_PFS_2,
  41. IPSEC_PFS_2048,
  42. IPSEC_PFS_ECP_256,
  43. IPSEC_PFS_ECP_384,
  44. IPSEC_PFS_MM,
  45. IPSEC_PFS_MAX
  46. } IPSEC_PFS_GROUP;
  47. typedef enum IPSEC_TRANSFORM_TYPE_ {
  48. IPSEC_TRANSFORM_AH = 1,
  49. IPSEC_TRANSFORM_ESP_AUTH,
  50. IPSEC_TRANSFORM_ESP_CIPHER,
  51. IPSEC_TRANSFORM_ESP_AUTH_AND_CIPHER,
  52. IPSEC_TRANSFORM_ESP_AUTH_FW,
  53. IPSEC_TRANSFORM_TYPE_MAX
  54. } IPSEC_TRANSFORM_TYPE;
  55. typedef enum IPSEC_AUTH_TYPE_ {
  56. IPSEC_AUTH_MD5,
  57. IPSEC_AUTH_SHA_1,
  58. IPSEC_AUTH_SHA_256,
  59. IPSEC_AUTH_AES_128,
  60. IPSEC_AUTH_AES_192,
  61. IPSEC_AUTH_AES_256,
  62. IPSEC_AUTH_MAX
  63. } IPSEC_AUTH_TYPE;
  64. typedef enum IPSEC_CIPHER_TYPE_ {
  65. IPSEC_CIPHER_TYPE_DES = 1,
  66. IPSEC_CIPHER_TYPE_3DES,
  67. IPSEC_CIPHER_TYPE_AES_128,
  68. IPSEC_CIPHER_TYPE_AES_192,
  69. IPSEC_CIPHER_TYPE_AES_256,
  70. IPSEC_CIPHER_TYPE_MAX
  71. } IPSEC_CIPHER_TYPE;
  72. typedef enum IPSEC_TOKEN_MODE_ {
  73. IPSEC_TOKEN_MODE_MAIN,
  74. IPSEC_TOKEN_MODE_EXTENDED,
  75. IPSEC_TOKEN_MODE_MAX
  76. } IPSEC_TOKEN_MODE;
  77. typedef enum IPSEC_TOKEN_PRINCIPAL_ {
  78. IPSEC_TOKEN_PRINCIPAL_LOCAL,
  79. IPSEC_TOKEN_PRINCIPAL_PEER,
  80. IPSEC_TOKEN_PRINCIPAL_MAX
  81. } IPSEC_TOKEN_PRINCIPAL;
  82. typedef enum IPSEC_TOKEN_TYPE_ {
  83. IPSEC_TOKEN_TYPE_MACHINE,
  84. IPSEC_TOKEN_TYPE_IMPERSONATION,
  85. IPSEC_TOKEN_TYPE_MAX
  86. } IPSEC_TOKEN_TYPE;
  87. typedef struct IPSEC_SA_LIFETIME0_ {
  88. UINT32 lifetimeSeconds;
  89. UINT32 lifetimeKilobytes;
  90. UINT32 lifetimePackets;
  91. } IPSEC_SA_LIFETIME0;
  92. typedef struct IPSEC_KEYING_POLICY0_ {
  93. UINT32 numKeyMods;
  94. GUID *keyModKeys;
  95. } IPSEC_KEYING_POLICY0;
  96. typedef struct IPSEC_SA_IDLE_TIMEOUT0_ {
  97. UINT32 idleTimeoutSeconds;
  98. UINT32 idleTimeoutSecondsFailOver;
  99. } IPSEC_SA_IDLE_TIMEOUT0;
  100. typedef struct IPSEC_PROPOSAL0_ {
  101. IPSEC_SA_LIFETIME0 lifetime;
  102. UINT32 numSaTransforms;
  103. IPSEC_SA_TRANSFORM0 *saTransforms;
  104. IPSEC_PFS_GROUP pfsGroup;
  105. } IPSEC_PROPOSAL0;
  106. typedef struct IPSEC_TRANSPORT_POLICY0_ {
  107. UINT32 numIpsecProposals;
  108. IPSEC_PROPOSAL0 *ipsecProposals;
  109. UINT32 flags;
  110. UINT32 ndAllowClearTimeoutSeconds;
  111. IPSEC_SA_IDLE_TIMEOUT0 saIdleTimeout;
  112. IKEEXT_EM_POLICY0 *emPolicy;
  113. } IPSEC_TRANSPORT_POLICY0;
  114. typedef struct IPSEC_AUTH_TRANSFORM_ID0_ {
  115. IPSEC_AUTH_TYPE authType;
  116. IPSEC_AUTH_CONFIG authConfig;
  117. } IPSEC_AUTH_TRANSFORM_ID0;
  118. typedef struct IPSEC_AUTH_TRANSFORM0_ {
  119. IPSEC_AUTH_TRANSFORM_ID0 authTransformId;
  120. IPSEC_CRYPTO_MODULE_ID *cryptoModuleId;
  121. } IPSEC_AUTH_TRANSFORM0;
  122. typedef struct IPSEC_CIPHER_TRANSFORM_ID0_ {
  123. IPSEC_CIPHER_TYPE cipherType;
  124. IPSEC_CIPHER_CONFIG cipherConfig;
  125. } IPSEC_CIPHER_TRANSFORM_ID0;
  126. typedef struct IPSEC_CIPHER_TRANSFORM0_ {
  127. IPSEC_CIPHER_TRANSFORM_ID0 cipherTransformId;
  128. IPSEC_CRYPTO_MODULE_ID *cryptoModuleId;
  129. } IPSEC_CIPHER_TRANSFORM0;
  130. typedef struct IPSEC_AUTH_AND_CIPHER_TRANSFORM0_ {
  131. IPSEC_AUTH_TRANSFORM0 authTransform;
  132. IPSEC_CIPHER_TRANSFORM0 cipherTransform;
  133. } IPSEC_AUTH_AND_CIPHER_TRANSFORM0;
  134. typedef struct IPSEC_SA_TRANSFORM0_ {
  135. IPSEC_TRANSFORM_TYPE ipsecTransformType;
  136. __C89_NAMELESS union {
  137. IPSEC_AUTH_TRANSFORM0 *ahTransform;
  138. IPSEC_AUTH_TRANSFORM0 *espAuthTransform;
  139. IPSEC_CIPHER_TRANSFORM0 *espCipherTransform;
  140. IPSEC_AUTH_AND_CIPHER_TRANSFORM0 *espAuthAndCipherTransform;
  141. IPSEC_AUTH_TRANSFORM0 *espAuthFwTransform;
  142. };
  143. } IPSEC_SA_TRANSFORM0;
  144. typedef struct IPSEC_TUNNEL_ENDPOINTS0_ {
  145. FWP_IP_VERSION ipVersion;
  146. __C89_NAMELESS union {
  147. UINT32 localV4Address;
  148. UINT8 localV6Address[16];
  149. };
  150. __C89_NAMELESS union {
  151. UINT32 remoteV4Address;
  152. UINT8 remoteV6Address[16];
  153. };
  154. } IPSEC_TUNNEL_ENDPOINTS0;
  155. typedef struct IPSEC_TUNNEL_POLICY0_ {
  156. UINT32 flags;
  157. UINT32 numIpsecProposals;
  158. IPSEC_PROPOSAL0 *ipsecProposals;
  159. IPSEC_TUNNEL_ENDPOINTS0 tunnelEndpoints;
  160. IPSEC_SA_IDLE_TIMEOUT0 saIdleTimeout;
  161. IKEEXT_EM_POLICY0 *emPolicy;
  162. } IPSEC_TUNNEL_POLICY0;
  163. typedef struct IPSEC_V4_UDP_ENCAPSULATION0_ {
  164. UINT16 localUdpEncapPort;
  165. UINT16 remoteUdpEncapPort;
  166. } IPSEC_V4_UDP_ENCAPSULATION0;
  167. typedef struct IPSEC_AGGREGATE_SA_STATISTICS0_ {
  168. UINT32 activeSas;
  169. UINT32 pendingSaNegotiations;
  170. UINT32 totalSasAdded;
  171. UINT32 totalSasDeleted;
  172. UINT32 successfulRekeys;
  173. UINT32 activeTunnels;
  174. UINT32 offloadedSas;
  175. } IPSEC_AGGREGATE_SA_STATISTICS0;
  176. typedef struct IPSEC_ESP_DROP_PACKET_STATISTICS0_ {
  177. UINT32 invalidSpisOnInbound;
  178. UINT32 decryptionFailuresOnInbound;
  179. UINT32 authenticationFailuresOnInbound;
  180. UINT32 replayCheckFailuresOnInbound;
  181. UINT32 saNotInitializedOnInbound;
  182. } IPSEC_ESP_DROP_PACKET_STATISTICS0;
  183. typedef struct IPSEC_AH_DROP_PACKET_STATISTICS0_ {
  184. UINT32 invalidSpisOnInbound;
  185. UINT32 authenticationFailuresOnInbound;
  186. UINT32 replayCheckFailuresOnInbound;
  187. UINT32 saNotInitializedOnInbound;
  188. } IPSEC_AH_DROP_PACKET_STATISTICS0;
  189. typedef struct IPSEC_AGGREGATE_DROP_PACKET_STATISTICS0_ {
  190. UINT32 invalidSpisOnInbound;
  191. UINT32 decryptionFailuresOnInbound;
  192. UINT32 authenticationFailuresOnInbound;
  193. UINT32 udpEspValidationFailuresOnInbound;
  194. UINT32 replayCheckFailuresOnInbound;
  195. UINT32 invalidClearTextInbound;
  196. UINT32 saNotInitializedOnInbound;
  197. UINT32 receiveOverIncorrectSaInbound;
  198. UINT32 secureReceivesNotMatchingFilters;
  199. } IPSEC_AGGREGATE_DROP_PACKET_STATISTICS0;
  200. typedef struct IPSEC_TRAFFIC_STATISTICS0_ {
  201. UINT64 encryptedByteCount;
  202. UINT64 authenticatedAHByteCount;
  203. UINT64 authenticatedESPByteCount;
  204. UINT64 transportByteCount;
  205. UINT64 tunnelByteCount;
  206. UINT64 offloadByteCount;
  207. } IPSEC_TRAFFIC_STATISTICS0;
  208. typedef struct IPSEC_STATISTICS0_ {
  209. IPSEC_AGGREGATE_SA_STATISTICS0 aggregateSaStatistics;
  210. IPSEC_ESP_DROP_PACKET_STATISTICS0 espDropPacketStatistics;
  211. IPSEC_AH_DROP_PACKET_STATISTICS0 ahDropPacketStatistics;
  212. IPSEC_AGGREGATE_DROP_PACKET_STATISTICS0 aggregateDropPacketStatistics;
  213. IPSEC_TRAFFIC_STATISTICS0 inboundTrafficStatistics;
  214. IPSEC_TRAFFIC_STATISTICS0 outboundTrafficStatistics;
  215. } IPSEC_STATISTICS0;
  216. typedef struct IPSEC_TOKEN0_ {
  217. IPSEC_TOKEN_TYPE type;
  218. IPSEC_TOKEN_PRINCIPAL principal;
  219. IPSEC_TOKEN_MODE mode;
  220. IPSEC_TOKEN_HANDLE token;
  221. } IPSEC_TOKEN0;
  222. typedef struct IPSEC_ID0_ {
  223. wchar_t *mmTargetName;
  224. wchar_t *emTargetName;
  225. UINT32 numTokens;
  226. IPSEC_TOKEN0 *tokens;
  227. UINT64 explicitCredentials;
  228. UINT64 logonId;
  229. } IPSEC_ID0;
  230. typedef struct IPSEC_SA_AUTH_INFORMATION0_ {
  231. IPSEC_AUTH_TRANSFORM0 authTransform;
  232. FWP_BYTE_BLOB authKey;
  233. } IPSEC_SA_AUTH_INFORMATION0;
  234. typedef struct IPSEC_SA_CIPHER_INFORMATION0_ {
  235. IPSEC_CIPHER_TRANSFORM0 cipherTransform;
  236. FWP_BYTE_BLOB cipherKey;
  237. } IPSEC_SA_CIPHER_INFORMATION0;
  238. typedef struct IPSEC_SA_AUTH_AND_CIPHER_INFORMATION0_ {
  239. IPSEC_SA_CIPHER_INFORMATION0 saCipherInformation;
  240. IPSEC_SA_AUTH_INFORMATION0 saAuthInformation;
  241. } IPSEC_SA_AUTH_AND_CIPHER_INFORMATION0;
  242. typedef struct IPSEC_SA0_ {
  243. IPSEC_SA_SPI spi;
  244. IPSEC_TRANSFORM_TYPE saTransformType;
  245. __C89_NAMELESS union {
  246. IPSEC_SA_AUTH_INFORMATION0 *ahInformation;
  247. IPSEC_SA_AUTH_INFORMATION0 *espAuthInformation;
  248. IPSEC_SA_CIPHER_INFORMATION0 *espCipherInformation;
  249. IPSEC_SA_AUTH_AND_CIPHER_INFORMATION0 *espAuthAndCipherInformation;
  250. IPSEC_SA_AUTH_INFORMATION0 *espAuthFwInformation;
  251. };
  252. } IPSEC_SA0;
  253. typedef struct IPSEC_KEYMODULE_STATE0_ {
  254. GUID keyModuleKey;
  255. FWP_BYTE_BLOB stateBlob;
  256. } IPSEC_KEYMODULE_STATE0;
  257. typedef struct IPSEC_SA_BUNDLE0_ {
  258. UINT32 flags;
  259. IPSEC_SA_LIFETIME0 lifetime;
  260. UINT32 idleTimeoutSeconds;
  261. UINT32 ndAllowClearTimeoutSeconds;
  262. IPSEC_ID0 *ipsecId;
  263. UINT32 napContext;
  264. UINT32 qmSaId;
  265. UINT32 numSAs;
  266. IPSEC_SA0 *saList;
  267. IPSEC_KEYMODULE_STATE0 *keyModuleState;
  268. FWP_IP_VERSION ipVersion;
  269. __C89_NAMELESS union {
  270. UINT32 peerV4PrivateAddress;
  271. ; // case(FWP_IP_VERSION_V6)
  272. };
  273. UINT64 mmSaId;
  274. IPSEC_PFS_GROUP pfsGroup;
  275. } IPSEC_SA_BUNDLE0;
  276. typedef struct IPSEC_TRAFFIC0_ {
  277. FWP_IP_VERSION ipVersion;
  278. __C89_NAMELESS union {
  279. UINT32 localV4Address;
  280. UINT8 localV6Address[16];
  281. };
  282. __C89_NAMELESS union {
  283. UINT32 remoteV4Address;
  284. UINT8 remoteV6Address[16];
  285. };
  286. IPSEC_TRAFFIC_TYPE trafficType;
  287. __C89_NAMELESS union {
  288. UINT64 ipsecFilterId;
  289. UINT64 tunnelPolicyId;
  290. };
  291. UINT16 remotePort;
  292. } IPSEC_TRAFFIC0;
  293. typedef struct IPSEC_SA_DETAILS0_ {
  294. FWP_IP_VERSION ipVersion;
  295. FWP_DIRECTION saDirection;
  296. IPSEC_TRAFFIC0 traffic;
  297. IPSEC_SA_BUNDLE0 saBundle;
  298. __C89_NAMELESS union {
  299. IPSEC_V4_UDP_ENCAPSULATION0 *udpEncapsulation;
  300. ; // case(FWP_IP_VERSION_V6)
  301. };
  302. FWPM_FILTER0 *transportFilter;
  303. } IPSEC_SA_DETAILS0;
  304. typedef struct IPSEC_SA_CONTEXT0_ {
  305. UINT64 saContextId;
  306. IPSEC_SA_DETAILS0 *inboundSa;
  307. IPSEC_SA_DETAILS0 *outboundSa;
  308. } IPSEC_SA_CONTEXT0;
  309. typedef struct IPSEC_GETSPI0_ {
  310. IPSEC_TRAFFIC0 inboundIpsecTraffic;
  311. FWP_IP_VERSION ipVersion;
  312. __C89_NAMELESS union {
  313. IPSEC_V4_UDP_ENCAPSULATION0 *inboundUdpEncapsulation;
  314. ; // case(FWP_IP_VERSION_V6)
  315. };
  316. IPSEC_CRYPTO_MODULE_ID *rngCryptoModuleID;
  317. } IPSEC_GETSPI0;
  318. typedef struct IPSEC_SA_ENUM_TEMPLATE0_ {
  319. FWP_DIRECTION saDirection;
  320. } IPSEC_SA_ENUM_TEMPLATE0;
  321. typedef struct IPSEC_SA_CONTEXT_ENUM_TEMPLATE0_ {
  322. FWP_CONDITION_VALUE0 localSubNet;
  323. FWP_CONDITION_VALUE0 remoteSubNet;
  324. } IPSEC_SA_CONTEXT_ENUM_TEMPLATE0;
  325. #endif /*(_WIN32_WINNT >= 0x0600)*/
  326. #if (_WIN32_WINNT >= 0x0601)
  327. typedef struct IPSEC_TUNNEL_ENDPOINTS1_ {
  328. FWP_IP_VERSION ipVersion;
  329. __C89_NAMELESS union {
  330. UINT32 localV4Address;
  331. UINT8 localV6Address[16];
  332. };
  333. __C89_NAMELESS union {
  334. UINT32 remoteV4Address;
  335. UINT8 remoteV6Address[16];
  336. };
  337. UINT64 localIfLuid;
  338. } IPSEC_TUNNEL_ENDPOINTS1;
  339. typedef struct IPSEC_TUNNEL_POLICY1_ {
  340. UINT32 flags;
  341. UINT32 numIpsecProposals;
  342. IPSEC_PROPOSAL0 *ipsecProposals;
  343. IPSEC_TUNNEL_ENDPOINTS1 tunnelEndpoints;
  344. IPSEC_SA_IDLE_TIMEOUT0 saIdleTimeout;
  345. IKEEXT_EM_POLICY1 *emPolicy;
  346. } IPSEC_TUNNEL_POLICY1;
  347. typedef struct IPSEC_TRANSPORT_POLICY1_ {
  348. UINT32 numIpsecProposals;
  349. IPSEC_PROPOSAL0 *ipsecProposals;
  350. UINT32 flags;
  351. UINT32 ndAllowClearTimeoutSeconds;
  352. IPSEC_SA_IDLE_TIMEOUT0 saIdleTimeout;
  353. IKEEXT_EM_POLICY1 *emPolicy;
  354. } IPSEC_TRANSPORT_POLICY1;
  355. typedef struct _IPSEC_DOSP_OPTIONS0 {
  356. UINT32 stateIdleTimeoutSeconds;
  357. UINT32 perIPRateLimitQueueIdleTimeoutSeconds;
  358. UINT8 ipV6IPsecUnauthDscp;
  359. UINT32 ipV6IPsecUnauthRateLimitBytesPerSec;
  360. UINT32 ipV6IPsecUnauthPerIPRateLimitBytesPerSec;
  361. UINT8 ipV6IPsecAuthDscp;
  362. UINT32 ipV6IPsecAuthRateLimitBytesPerSec;
  363. UINT8 icmpV6Dscp;
  364. UINT32 icmpV6RateLimitBytesPerSec;
  365. UINT8 ipV6FilterExemptDscp;
  366. UINT32 ipV6FilterExemptRateLimitBytesPerSec;
  367. UINT8 defBlockExemptDscp;
  368. UINT32 defBlockExemptRateLimitBytesPerSec;
  369. UINT32 maxStateEntries;
  370. UINT32 maxPerIPRateLimitQueues;
  371. UINT32 flags;
  372. UINT32 numPublicIFLuids;
  373. UINT64 *publicIFLuids;
  374. UINT32 numInternalIFLuids;
  375. UINT64 *internalIFLuids;
  376. FWP_V6_ADDR_AND_MASK publicV6AddrMask;
  377. FWP_V6_ADDR_AND_MASK internalV6AddrMask;
  378. } IPSEC_DOSP_OPTIONS0;
  379. typedef struct _IPSEC_DOSP_STATISTICS0 {
  380. UINT64 totalStateEntriesCreated;
  381. UINT64 currentStateEntries;
  382. UINT64 totalInboundAllowedIPv6IPsecUnauthPkts;
  383. UINT64 totalInboundRatelimitDiscardedIPv6IPsecUnauthPkts;
  384. UINT64 totalInboundPerIPRatelimitDiscardedIPv6IPsecUnauthPkts;
  385. UINT64 totalInboundOtherDiscardedIPv6IPsecUnauthPkts;
  386. UINT64 totalInboundAllowedIPv6IPsecAuthPkts;
  387. UINT64 totalInboundRatelimitDiscardedIPv6IPsecAuthPkts;
  388. UINT64 totalInboundOtherDiscardedIPv6IPsecAuthPkts;
  389. UINT64 totalInboundAllowedICMPv6Pkts;
  390. UINT64 totalInboundRatelimitDiscardedICMPv6Pkts;
  391. UINT64 totalInboundAllowedIPv6FilterExemptPkts;
  392. UINT64 totalInboundRatelimitDiscardedIPv6FilterExemptPkts;
  393. UINT64 totalInboundDiscardedIPv6FilterBlockPkts;
  394. UINT64 totalInboundAllowedDefBlockExemptPkts;
  395. UINT64 totalInboundRatelimitDiscardedDefBlockExemptPkts;
  396. UINT64 totalInboundDiscardedDefBlockPkts;
  397. UINT64 currentInboundIPv6IPsecUnauthPerIPRateLimitQueues;
  398. } IPSEC_DOSP_STATISTICS0;
  399. typedef struct _IPSEC_DOSP_STATE_ENUM_TEMPLATE0 {
  400. FWP_V6_ADDR_AND_MASK publicV6AddrMask;
  401. FWP_V6_ADDR_AND_MASK internalV6AddrMask;
  402. } IPSEC_DOSP_STATE_ENUM_TEMPLATE0;
  403. typedef struct _IPSEC_DOSP_STATE0 {
  404. UINT8 publicHostV6Addr[16];
  405. UINT8 internalHostV6Addr[16];
  406. UINT64 totalInboundIPv6IPsecAuthPackets;
  407. UINT64 totalOutboundIPv6IPsecAuthPackets;
  408. UINT32 durationSecs;
  409. } IPSEC_DOSP_STATE0;
  410. typedef struct IPSEC_TRAFFIC_STATISTICS1_ {
  411. UINT64 encryptedByteCount;
  412. UINT64 authenticatedAHByteCount;
  413. UINT64 authenticatedESPByteCount;
  414. UINT64 transportByteCount;
  415. UINT64 tunnelByteCount;
  416. UINT64 offloadByteCount;
  417. UINT64 totalSuccessfulPackets;
  418. } IPSEC_TRAFFIC_STATISTICS1;
  419. typedef struct IPSEC_AGGREGATE_DROP_PACKET_STATISTICS1_ {
  420. UINT32 invalidSpisOnInbound;
  421. UINT32 decryptionFailuresOnInbound;
  422. UINT32 authenticationFailuresOnInbound;
  423. UINT32 udpEspValidationFailuresOnInbound;
  424. UINT32 replayCheckFailuresOnInbound;
  425. UINT32 invalidClearTextInbound;
  426. UINT32 saNotInitializedOnInbound;
  427. UINT32 receiveOverIncorrectSaInbound;
  428. UINT32 secureReceivesNotMatchingFilters;
  429. UINT32 totalDropPacketsInbound;
  430. } IPSEC_AGGREGATE_DROP_PACKET_STATISTICS1;
  431. typedef struct IPSEC_STATISTICS1_ {
  432. IPSEC_AGGREGATE_SA_STATISTICS0 aggregateSaStatistics;
  433. IPSEC_ESP_DROP_PACKET_STATISTICS0 espDropPacketStatistics;
  434. IPSEC_AH_DROP_PACKET_STATISTICS0 ahDropPacketStatistics;
  435. IPSEC_AGGREGATE_DROP_PACKET_STATISTICS1 aggregateDropPacketStatistics;
  436. IPSEC_TRAFFIC_STATISTICS1 inboundTrafficStatistics;
  437. IPSEC_TRAFFIC_STATISTICS1 outboundTrafficStatistics;
  438. } IPSEC_STATISTICS1;
  439. typedef struct IPSEC_SA_BUNDLE1_ {
  440. UINT32 flags;
  441. IPSEC_SA_LIFETIME0 lifetime;
  442. UINT32 idleTimeoutSeconds;
  443. UINT32 ndAllowClearTimeoutSeconds;
  444. IPSEC_ID0 *ipsecId;
  445. UINT32 napContext;
  446. UINT32 qmSaId;
  447. UINT32 numSAs;
  448. IPSEC_SA0 *saList;
  449. IPSEC_KEYMODULE_STATE0 *keyModuleState;
  450. FWP_IP_VERSION ipVersion;
  451. __C89_NAMELESS union {
  452. UINT32 peerV4PrivateAddress;
  453. ; // case(FWP_IP_VERSION_V6)
  454. };
  455. UINT64 mmSaId;
  456. IPSEC_PFS_GROUP pfsGroup;
  457. GUID saLookupContext;
  458. UINT64 qmFilterId;
  459. } IPSEC_SA_BUNDLE1;
  460. typedef struct _IPSEC_VIRTUAL_IF_TUNNEL_INFO0 {
  461. UINT64 virtualIfTunnelId;
  462. UINT64 trafficSelectorId;
  463. } IPSEC_VIRTUAL_IF_TUNNEL_INFO0;
  464. typedef struct IPSEC_TRAFFIC1_ {
  465. FWP_IP_VERSION ipVersion;
  466. __C89_NAMELESS union {
  467. UINT32 localV4Address;
  468. UINT8 localV6Address[16];
  469. };
  470. __C89_NAMELESS union {
  471. UINT32 remoteV4Address;
  472. UINT8 remoteV6Address[16];
  473. };
  474. IPSEC_TRAFFIC_TYPE trafficType;
  475. __C89_NAMELESS union {
  476. UINT64 ipsecFilterId;
  477. UINT64 tunnelPolicyId;
  478. };
  479. UINT16 remotePort;
  480. UINT16 localPort;
  481. UINT8 ipProtocol;
  482. UINT64 localIfLuid;
  483. UINT32 realIfProfileId;
  484. } IPSEC_TRAFFIC1;
  485. typedef struct IPSEC_SA_DETAILS1_ {
  486. FWP_IP_VERSION ipVersion;
  487. FWP_DIRECTION saDirection;
  488. IPSEC_TRAFFIC1 traffic;
  489. IPSEC_SA_BUNDLE1 saBundle;
  490. __C89_NAMELESS union {
  491. IPSEC_V4_UDP_ENCAPSULATION0 *udpEncapsulation;
  492. ; // case(FWP_IP_VERSION_V6)
  493. };
  494. FWPM_FILTER0 *transportFilter;
  495. IPSEC_VIRTUAL_IF_TUNNEL_INFO0 *virtualIfTunnelInfo;
  496. } IPSEC_SA_DETAILS1;
  497. typedef struct IPSEC_SA_CONTEXT1_ {
  498. UINT64 saContextId;
  499. IPSEC_SA_DETAILS1 *inboundSa;
  500. IPSEC_SA_DETAILS1 *outboundSa;
  501. } IPSEC_SA_CONTEXT1;
  502. typedef struct IPSEC_GETSPI1_ {
  503. IPSEC_TRAFFIC1 inboundIpsecTraffic;
  504. FWP_IP_VERSION ipVersion;
  505. __C89_NAMELESS union {
  506. IPSEC_V4_UDP_ENCAPSULATION0 *inboundUdpEncapsulation;
  507. ; // case(FWP_IP_VERSION_V6)
  508. };
  509. IPSEC_CRYPTO_MODULE_ID *rngCryptoModuleID;
  510. } IPSEC_GETSPI1;
  511. typedef struct _IPSEC_ADDRESS_INFO0 {
  512. UINT32 numV4Addresses;
  513. UINT32 *v4Addresses;
  514. UINT32 numV6Addresses;
  515. FWP_BYTE_ARRAY16 *v6Addresses;
  516. } IPSEC_ADDRESS_INFO0;
  517. #endif /*(_WIN32_WINNT >= 0x0601)*/
  518. #ifdef __cplusplus
  519. }
  520. #endif
  521. #endif /*_INC_IPSECTYPES*/