summaryrefslogtreecommitdiff
path: root/interface-definitions/include/firewall/global-options.xml.i
diff options
context:
space:
mode:
authorNicolas Fort <nicolasfort1988@gmail.com>2024-08-26 18:10:01 +0000
committerNicolas Fort <nicolasfort1988@gmail.com>2024-08-28 12:19:19 +0000
commit8e0e1a99e5510c7575ab8a09145d6b4354692d55 (patch)
tree12c4d27314384f84b67a5e370e9d8f181ea15742 /interface-definitions/include/firewall/global-options.xml.i
parent003209eeab231675e82abb8cf6eab7ca0384bc3f (diff)
downloadvyos-1x-8e0e1a99e5510c7575ab8a09145d6b4354692d55.tar.gz
vyos-1x-8e0e1a99e5510c7575ab8a09145d6b4354692d55.zip
T6647: firewall. Introduce patch for accepting ARP and DHCP replies on stateful bridge firewall. This patch is needed because ARP and DHCP are marked as invalid connections. Also, add ehternet-type matcher in bridge firewall.
Diffstat (limited to 'interface-definitions/include/firewall/global-options.xml.i')
-rwxr-xr-x[-rw-r--r--]interface-definitions/include/firewall/global-options.xml.i6
1 files changed, 6 insertions, 0 deletions
diff --git a/interface-definitions/include/firewall/global-options.xml.i b/interface-definitions/include/firewall/global-options.xml.i
index cee8f1854..05fdd75cb 100644..100755
--- a/interface-definitions/include/firewall/global-options.xml.i
+++ b/interface-definitions/include/firewall/global-options.xml.i
@@ -49,6 +49,12 @@
<help>Apply configured firewall rules to traffic switched by bridges</help>
</properties>
<children>
+ <leafNode name="invalid-connections">
+ <properties>
+ <help>Accept ARP and DHCP despite they are marked as invalid connection</help>
+ <valueless/>
+ </properties>
+ </leafNode>
<leafNode name="ipv4">
<properties>
<help>Apply configured IPv4 firewall rules</help>