summaryrefslogtreecommitdiff
path: root/data/vyos-firewall-init.conf
diff options
context:
space:
mode:
authorChristian Breunig <christian@breunig.cc>2024-01-30 11:24:28 +0000
committerGitHub <noreply@github.com>2024-01-30 11:24:28 +0000
commit02f7f91e3937f1622ba055847aa96b207d5ba754 (patch)
tree3765cb9f5359186791a772d294dbc12cef4edcca /data/vyos-firewall-init.conf
parent29045dff3845dbc26d8a0e16f44dcabc4a96bc53 (diff)
parent9eb129400dd57fc6c41c810fa5aa2c455b908322 (diff)
downloadvyos-1x-02f7f91e3937f1622ba055847aa96b207d5ba754.tar.gz
vyos-1x-02f7f91e3937f1622ba055847aa96b207d5ba754.zip
Merge pull request #2905 from vyos/mergify/bp/sagitta/pr-2877
vrf: T5973: multiple bugfixes and improvements (backport #2877)
Diffstat (limited to 'data/vyos-firewall-init.conf')
-rw-r--r--data/vyos-firewall-init.conf19
1 files changed, 19 insertions, 0 deletions
diff --git a/data/vyos-firewall-init.conf b/data/vyos-firewall-init.conf
index cd7d5011f..5a4e03015 100644
--- a/data/vyos-firewall-init.conf
+++ b/data/vyos-firewall-init.conf
@@ -54,3 +54,22 @@ table ip6 raw {
type filter hook prerouting priority -300; policy accept;
}
}
+
+# Required by VRF
+table inet vrf_zones {
+ # Map of interfaces and connections tracking zones
+ map ct_iface_map {
+ typeof iifname : ct zone
+ }
+ # Assign unique zones for each VRF
+ # Chain for inbound traffic
+ chain vrf_zones_ct_in {
+ type filter hook prerouting priority raw; policy accept;
+ counter ct original zone set iifname map @ct_iface_map
+ }
+ # Chain for locally-generated traffic
+ chain vrf_zones_ct_out {
+ type filter hook output priority raw; policy accept;
+ counter ct original zone set oifname map @ct_iface_map
+ }
+}