diff options
author | Daniil Baturin <daniil@vyos.io> | 2024-08-14 17:33:55 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-08-14 17:33:55 +0100 |
commit | 4806d8755314f0ea3d21a1198e85b6d7ab0d0000 (patch) | |
tree | 1784725c73a0f47f833d6da0d754412e7e25fb0b | |
parent | e0ce3f0e5a979e678d20a77f37fb6626806c28a5 (diff) | |
parent | 2d953bedd0e416ead924f77ec612c997f950535a (diff) | |
download | vyos-1x-4806d8755314f0ea3d21a1198e85b6d7ab0d0000.tar.gz vyos-1x-4806d8755314f0ea3d21a1198e85b6d7ab0d0000.zip |
Merge pull request #3981 from nicolas-fort/T6646
T6646: conntrack: in ignore rules, if protocols=all, do not append it to the rule
-rwxr-xr-x[-rw-r--r--] | python/vyos/template.py | 3 | ||||
-rwxr-xr-x | smoketest/scripts/cli/test_system_conntrack.py | 1 |
2 files changed, 3 insertions, 1 deletions
diff --git a/python/vyos/template.py b/python/vyos/template.py index aa99bed5a..be9f781a6 100644..100755 --- a/python/vyos/template.py +++ b/python/vyos/template.py @@ -694,7 +694,8 @@ def conntrack_rule(rule_conf, rule_id, action, ipv6=False): else: for protocol, protocol_config in rule_conf['protocol'].items(): proto = protocol - output.append(f'meta l4proto {proto}') + if proto != 'all': + output.append(f'meta l4proto {proto}') tcp_flags = dict_search_args(rule_conf, 'tcp', 'flags') if tcp_flags and action != 'timeout': diff --git a/smoketest/scripts/cli/test_system_conntrack.py b/smoketest/scripts/cli/test_system_conntrack.py index c07fdce77..72deb7525 100755 --- a/smoketest/scripts/cli/test_system_conntrack.py +++ b/smoketest/scripts/cli/test_system_conntrack.py @@ -209,6 +209,7 @@ class TestSystemConntrack(VyOSUnitTestSHIM.TestCase): self.cli_set(base_path + ['ignore', 'ipv4', 'rule', '2', 'source', 'address', '192.0.2.1']) self.cli_set(base_path + ['ignore', 'ipv4', 'rule', '2', 'destination', 'group', 'address-group', address_group]) + self.cli_set(base_path + ['ignore', 'ipv4', 'rule', '2', 'protocol', 'all']) self.cli_set(base_path + ['ignore', 'ipv6', 'rule', '11', 'source', 'address', 'fe80::1']) self.cli_set(base_path + ['ignore', 'ipv6', 'rule', '11', 'destination', 'address', 'fe80::2']) |