summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorNataliia Solomko <natalirs1985@gmail.com>2026-03-13 14:13:37 +0200
committerNataliia Solomko <natalirs1985@gmail.com>2026-03-13 14:26:42 +0200
commit87d9d1e801f7306439dcd79d3c9876225f983111 (patch)
treeccc62e9345c3f3bebbb17890a34ac58ca8f651fd
parent44e5e9f0b26ce496b04f603bb68c82ecf01dc54a (diff)
downloadvyos-1x-87d9d1e801f7306439dcd79d3c9876225f983111.tar.gz
vyos-1x-87d9d1e801f7306439dcd79d3c9876225f983111.zip
vpp: T8368: Features nat44 and cgnat should not use the same interfaces
-rw-r--r--python/vyos/vpp/config_verify.py24
-rw-r--r--src/conf_mode/vpp_nat_cgnat.py10
-rw-r--r--src/conf_mode/vpp_nat_nat44.py10
3 files changed, 44 insertions, 0 deletions
diff --git a/python/vyos/vpp/config_verify.py b/python/vyos/vpp/config_verify.py
index 5c8953392..7b90b37db 100644
--- a/python/vyos/vpp/config_verify.py
+++ b/python/vyos/vpp/config_verify.py
@@ -341,3 +341,27 @@ def verify_vpp_buffers(settings: dict):
'Not enough buffers to initialize RX/TX queues for interfaces. '
f'Set "vpp settings resource-allocation buffers buffers-per-numa" to {buffers_required} or higher'
)
+
+
+def verify_nat_interfaces(config: dict, feature_name: str):
+ """
+ Verify that interfaces are not already used in the selected NAT feature.
+ Example:
+ verify_nat_interfaces(config, 'nat44')
+ verify_nat_interfaces(config, 'cgnat')
+ """
+ directions = ['inside', 'outside']
+ interfaces = config.get('interface', {})
+ nat_interfaces = config.get(f'{feature_name}_config', {}).get('interface', {})
+
+ for direction in directions:
+ for iface in interfaces.get(direction, []):
+ # Check if iface is used in any nat44/cgnat direction
+ nat_dir = next(
+ (d for d in directions if iface in nat_interfaces.get(d, [])), None
+ )
+ if nat_dir:
+ raise ConfigError(
+ f'Cannot use {iface} as {direction} interface: '
+ f'it is already configured as {nat_dir} interface in {feature_name.upper()}'
+ )
diff --git a/src/conf_mode/vpp_nat_cgnat.py b/src/conf_mode/vpp_nat_cgnat.py
index 48d0339b1..2044a07b9 100644
--- a/src/conf_mode/vpp_nat_cgnat.py
+++ b/src/conf_mode/vpp_nat_cgnat.py
@@ -25,6 +25,7 @@ from vyos.vpp.utils import vpp_iface_name_transform
from vyos.vpp.nat.det44 import Det44
from vyos.vpp.control_vpp import VPPControl
+from vyos.vpp.config_verify import verify_nat_interfaces
protocol_map = {
'all': 0,
@@ -107,6 +108,13 @@ def get_config(config=None) -> dict:
}
)
+ config['nat44_config'] = conf.get_config_dict(
+ ['vpp', 'nat', 'nat44'],
+ key_mangling=('-', '_'),
+ get_first_key=True,
+ no_tag_node_value_mangle=True,
+ )
+
if effective_config:
config.update({'effective': effective_config})
@@ -139,6 +147,8 @@ def verify(config):
f'Please choose a side for: {", ".join(conflict_ifaces)} '
)
+ verify_nat_interfaces(config, 'nat44')
+
vpp = VPPControl()
for direction in ['inside', 'outside']:
for interface in config['interface'][direction]:
diff --git a/src/conf_mode/vpp_nat_nat44.py b/src/conf_mode/vpp_nat_nat44.py
index 30111bf40..7f0b27541 100644
--- a/src/conf_mode/vpp_nat_nat44.py
+++ b/src/conf_mode/vpp_nat_nat44.py
@@ -29,6 +29,7 @@ from vyos.vpp.utils import cli_ifaces_list
from vyos.vpp.utils import vpp_iface_name_transform
from vyos.vpp.nat.nat44 import Nat44
from vyos.vpp.control_vpp import VPPControl
+from vyos.vpp.config_verify import verify_nat_interfaces
protocol_map = {
@@ -113,6 +114,13 @@ def get_config(config=None) -> dict:
}
)
+ config['cgnat_config'] = conf.get_config_dict(
+ ['vpp', 'nat', 'cgnat'],
+ key_mangling=('-', '_'),
+ get_first_key=True,
+ no_tag_node_value_mangle=True,
+ )
+
if effective_config:
config.update({'effective': effective_config})
@@ -153,6 +161,8 @@ def verify(config):
f'Both inside and outside interfaces must be configured. Please add: {", ".join(missing_keys)}'
)
+ verify_nat_interfaces(config, 'cgnat')
+
vpp = VPPControl()
for direction in ['inside', 'outside']:
for interface in config['interface'][direction]: