diff options
author | Christian Breunig <christian@breunig.cc> | 2024-01-30 11:24:28 +0000 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-01-30 11:24:28 +0000 |
commit | 02f7f91e3937f1622ba055847aa96b207d5ba754 (patch) | |
tree | 3765cb9f5359186791a772d294dbc12cef4edcca /data/vyos-firewall-init.conf | |
parent | 29045dff3845dbc26d8a0e16f44dcabc4a96bc53 (diff) | |
parent | 9eb129400dd57fc6c41c810fa5aa2c455b908322 (diff) | |
download | vyos-1x-02f7f91e3937f1622ba055847aa96b207d5ba754.tar.gz vyos-1x-02f7f91e3937f1622ba055847aa96b207d5ba754.zip |
Merge pull request #2905 from vyos/mergify/bp/sagitta/pr-2877
vrf: T5973: multiple bugfixes and improvements (backport #2877)
Diffstat (limited to 'data/vyos-firewall-init.conf')
-rw-r--r-- | data/vyos-firewall-init.conf | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/data/vyos-firewall-init.conf b/data/vyos-firewall-init.conf index cd7d5011f..5a4e03015 100644 --- a/data/vyos-firewall-init.conf +++ b/data/vyos-firewall-init.conf @@ -54,3 +54,22 @@ table ip6 raw { type filter hook prerouting priority -300; policy accept; } } + +# Required by VRF +table inet vrf_zones { + # Map of interfaces and connections tracking zones + map ct_iface_map { + typeof iifname : ct zone + } + # Assign unique zones for each VRF + # Chain for inbound traffic + chain vrf_zones_ct_in { + type filter hook prerouting priority raw; policy accept; + counter ct original zone set iifname map @ct_iface_map + } + # Chain for locally-generated traffic + chain vrf_zones_ct_out { + type filter hook output priority raw; policy accept; + counter ct original zone set oifname map @ct_iface_map + } +} |