summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--templates/policy/route/node.tag/rule/node.tag/destination/group/address-group/node.def2
-rw-r--r--templates/policy/route/node.tag/rule/node.tag/destination/group/network-group/node.def2
-rw-r--r--templates/policy/route/node.tag/rule/node.tag/destination/group/port-group/node.def2
-rw-r--r--templates/policy/route/node.tag/rule/node.tag/set/table/node.def1
-rw-r--r--templates/policy/route/node.tag/rule/node.tag/source/group/address-group/node.def2
-rw-r--r--templates/policy/route/node.tag/rule/node.tag/source/group/network-group/node.def2
-rw-r--r--templates/policy/route/node.tag/rule/node.tag/source/group/port-group/node.def2
7 files changed, 7 insertions, 6 deletions
diff --git a/templates/policy/route/node.tag/rule/node.tag/destination/group/address-group/node.def b/templates/policy/route/node.tag/rule/node.tag/destination/group/address-group/node.def
index 07e791c..272149b 100644
--- a/templates/policy/route/node.tag/rule/node.tag/destination/group/address-group/node.def
+++ b/templates/policy/route/node.tag/rule/node.tag/destination/group/address-group/node.def
@@ -6,4 +6,4 @@ commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \
--set-name=$VAR(@) \
--set-type=address;"
-allowed: cli-shell-api listActiveNodes firewall group address-group
+allowed: cli-shell-api listNodes firewall group address-group
diff --git a/templates/policy/route/node.tag/rule/node.tag/destination/group/network-group/node.def b/templates/policy/route/node.tag/rule/node.tag/destination/group/network-group/node.def
index bf018a0..54604da 100644
--- a/templates/policy/route/node.tag/rule/node.tag/destination/group/network-group/node.def
+++ b/templates/policy/route/node.tag/rule/node.tag/destination/group/network-group/node.def
@@ -5,4 +5,4 @@ commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \
--action=check-set-type \
--set-name=$VAR(@) \
--set-type=network;"
-allowed: cli-shell-api listActiveNodes firewall group network-group
+allowed: cli-shell-api listNodes firewall group network-group
diff --git a/templates/policy/route/node.tag/rule/node.tag/destination/group/port-group/node.def b/templates/policy/route/node.tag/rule/node.tag/destination/group/port-group/node.def
index 865d2c5..985302b 100644
--- a/templates/policy/route/node.tag/rule/node.tag/destination/group/port-group/node.def
+++ b/templates/policy/route/node.tag/rule/node.tag/destination/group/port-group/node.def
@@ -5,4 +5,4 @@ commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \
--action=check-set-type \
--set-name=$VAR(@) \
--set-type=port;"
-allowed: cli-shell-api listActiveNodes firewall group port-group
+allowed: cli-shell-api listNodes firewall group port-group
diff --git a/templates/policy/route/node.tag/rule/node.tag/set/table/node.def b/templates/policy/route/node.tag/rule/node.tag/set/table/node.def
index bb97649..632ed54 100644
--- a/templates/policy/route/node.tag/rule/node.tag/set/table/node.def
+++ b/templates/policy/route/node.tag/rule/node.tag/set/table/node.def
@@ -2,6 +2,7 @@ type: txt
help: Routing table to forward packet with
val_help: u32:1-200 ; Table number
val_help: main ; Main table
+allowed: echo main `cli-shell-api listNodes protocols static table`
syntax:expression: exec "
if [[ $VAR(@) =~ ^-?[0-9]+$ ]] ; then
if [ $VAR(@) -lt 1 -o $VAR(@) -gt 200 ] ; then
diff --git a/templates/policy/route/node.tag/rule/node.tag/source/group/address-group/node.def b/templates/policy/route/node.tag/rule/node.tag/source/group/address-group/node.def
index 97c748d..8506b28 100644
--- a/templates/policy/route/node.tag/rule/node.tag/source/group/address-group/node.def
+++ b/templates/policy/route/node.tag/rule/node.tag/source/group/address-group/node.def
@@ -5,4 +5,4 @@ commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \
--action=check-set-type \
--set-name=$VAR(@) \
--set-type=address;"
-allowed: cli-shell-api listActiveNodes firewall group address-group
+allowed: cli-shell-api listNodes firewall group address-group
diff --git a/templates/policy/route/node.tag/rule/node.tag/source/group/network-group/node.def b/templates/policy/route/node.tag/rule/node.tag/source/group/network-group/node.def
index bf018a0..54604da 100644
--- a/templates/policy/route/node.tag/rule/node.tag/source/group/network-group/node.def
+++ b/templates/policy/route/node.tag/rule/node.tag/source/group/network-group/node.def
@@ -5,4 +5,4 @@ commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \
--action=check-set-type \
--set-name=$VAR(@) \
--set-type=network;"
-allowed: cli-shell-api listActiveNodes firewall group network-group
+allowed: cli-shell-api listNodes firewall group network-group
diff --git a/templates/policy/route/node.tag/rule/node.tag/source/group/port-group/node.def b/templates/policy/route/node.tag/rule/node.tag/source/group/port-group/node.def
index 865d2c5..985302b 100644
--- a/templates/policy/route/node.tag/rule/node.tag/source/group/port-group/node.def
+++ b/templates/policy/route/node.tag/rule/node.tag/source/group/port-group/node.def
@@ -5,4 +5,4 @@ commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \
--action=check-set-type \
--set-name=$VAR(@) \
--set-type=port;"
-allowed: cli-shell-api listActiveNodes firewall group port-group
+allowed: cli-shell-api listNodes firewall group port-group