diff options
| author | Nataliia Solomko <natalirs1985@gmail.com> | 2026-03-13 14:13:37 +0200 |
|---|---|---|
| committer | Nataliia Solomko <natalirs1985@gmail.com> | 2026-03-13 14:26:42 +0200 |
| commit | 87d9d1e801f7306439dcd79d3c9876225f983111 (patch) | |
| tree | ccc62e9345c3f3bebbb17890a34ac58ca8f651fd | |
| parent | 44e5e9f0b26ce496b04f603bb68c82ecf01dc54a (diff) | |
| download | vyos-1x-87d9d1e801f7306439dcd79d3c9876225f983111.tar.gz vyos-1x-87d9d1e801f7306439dcd79d3c9876225f983111.zip | |
vpp: T8368: Features nat44 and cgnat should not use the same interfaces
| -rw-r--r-- | python/vyos/vpp/config_verify.py | 24 | ||||
| -rw-r--r-- | src/conf_mode/vpp_nat_cgnat.py | 10 | ||||
| -rw-r--r-- | src/conf_mode/vpp_nat_nat44.py | 10 |
3 files changed, 44 insertions, 0 deletions
diff --git a/python/vyos/vpp/config_verify.py b/python/vyos/vpp/config_verify.py index 5c8953392..7b90b37db 100644 --- a/python/vyos/vpp/config_verify.py +++ b/python/vyos/vpp/config_verify.py @@ -341,3 +341,27 @@ def verify_vpp_buffers(settings: dict): 'Not enough buffers to initialize RX/TX queues for interfaces. ' f'Set "vpp settings resource-allocation buffers buffers-per-numa" to {buffers_required} or higher' ) + + +def verify_nat_interfaces(config: dict, feature_name: str): + """ + Verify that interfaces are not already used in the selected NAT feature. + Example: + verify_nat_interfaces(config, 'nat44') + verify_nat_interfaces(config, 'cgnat') + """ + directions = ['inside', 'outside'] + interfaces = config.get('interface', {}) + nat_interfaces = config.get(f'{feature_name}_config', {}).get('interface', {}) + + for direction in directions: + for iface in interfaces.get(direction, []): + # Check if iface is used in any nat44/cgnat direction + nat_dir = next( + (d for d in directions if iface in nat_interfaces.get(d, [])), None + ) + if nat_dir: + raise ConfigError( + f'Cannot use {iface} as {direction} interface: ' + f'it is already configured as {nat_dir} interface in {feature_name.upper()}' + ) diff --git a/src/conf_mode/vpp_nat_cgnat.py b/src/conf_mode/vpp_nat_cgnat.py index 48d0339b1..2044a07b9 100644 --- a/src/conf_mode/vpp_nat_cgnat.py +++ b/src/conf_mode/vpp_nat_cgnat.py @@ -25,6 +25,7 @@ from vyos.vpp.utils import vpp_iface_name_transform from vyos.vpp.nat.det44 import Det44 from vyos.vpp.control_vpp import VPPControl +from vyos.vpp.config_verify import verify_nat_interfaces protocol_map = { 'all': 0, @@ -107,6 +108,13 @@ def get_config(config=None) -> dict: } ) + config['nat44_config'] = conf.get_config_dict( + ['vpp', 'nat', 'nat44'], + key_mangling=('-', '_'), + get_first_key=True, + no_tag_node_value_mangle=True, + ) + if effective_config: config.update({'effective': effective_config}) @@ -139,6 +147,8 @@ def verify(config): f'Please choose a side for: {", ".join(conflict_ifaces)} ' ) + verify_nat_interfaces(config, 'nat44') + vpp = VPPControl() for direction in ['inside', 'outside']: for interface in config['interface'][direction]: diff --git a/src/conf_mode/vpp_nat_nat44.py b/src/conf_mode/vpp_nat_nat44.py index 30111bf40..7f0b27541 100644 --- a/src/conf_mode/vpp_nat_nat44.py +++ b/src/conf_mode/vpp_nat_nat44.py @@ -29,6 +29,7 @@ from vyos.vpp.utils import cli_ifaces_list from vyos.vpp.utils import vpp_iface_name_transform from vyos.vpp.nat.nat44 import Nat44 from vyos.vpp.control_vpp import VPPControl +from vyos.vpp.config_verify import verify_nat_interfaces protocol_map = { @@ -113,6 +114,13 @@ def get_config(config=None) -> dict: } ) + config['cgnat_config'] = conf.get_config_dict( + ['vpp', 'nat', 'cgnat'], + key_mangling=('-', '_'), + get_first_key=True, + no_tag_node_value_mangle=True, + ) + if effective_config: config.update({'effective': effective_config}) @@ -153,6 +161,8 @@ def verify(config): f'Both inside and outside interfaces must be configured. Please add: {", ".join(missing_keys)}' ) + verify_nat_interfaces(config, 'cgnat') + vpp = VPPControl() for direction in ['inside', 'outside']: for interface in config['interface'][direction]: |
