diff options
author | Indrajit Raychaudhuri <irc@indrajit.com> | 2023-12-26 19:19:10 -0600 |
---|---|---|
committer | Christian Breunig <christian@breunig.cc> | 2023-12-30 20:32:36 +0100 |
commit | 468984d7cde4039143d3fc90bffc3eac2f2e05d1 (patch) | |
tree | cfbacf5d1ea1fbd89748ed8ebf285878ba9c9e05 /data | |
parent | 201501ace13020e187dfbba4b125eb3f8664046d (diff) | |
download | vyos-1x-468984d7cde4039143d3fc90bffc3eac2f2e05d1.tar.gz vyos-1x-468984d7cde4039143d3fc90bffc3eac2f2e05d1.zip |
firewall: T5834: Add support for default log for route policy
One can now do `set policy route foo default-log` which will add log
to the policy route chain.
(cherry picked from commit 6278ce9b7cb2060c8226a60ccbdb580a0d8a3fb5)
Diffstat (limited to 'data')
-rw-r--r-- | data/templates/firewall/nftables-policy.j2 | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/data/templates/firewall/nftables-policy.j2 b/data/templates/firewall/nftables-policy.j2 index d77e3f6e9..9e28899b0 100644 --- a/data/templates/firewall/nftables-policy.j2 +++ b/data/templates/firewall/nftables-policy.j2 @@ -28,6 +28,9 @@ table ip vyos_mangle { {{ rule_conf | nft_rule('route', route_text, rule_id, 'ip') }} {% endfor %} {% endif %} +{% if conf.default_log is vyos_defined %} + counter log prefix "[ipv4-{{ (route_text)[:19] }}-default]" +{% endif %} } {% endfor %} {% endif %} @@ -57,6 +60,9 @@ table ip6 vyos_mangle { {{ rule_conf | nft_rule('route6', route_text, rule_id, 'ip6') }} {% endfor %} {% endif %} +{% if conf.default_log is vyos_defined %} + counter log prefix "[ipv6-{{ (route_text)[:19] }}-default]" +{% endif %} } {% endfor %} {% endif %} |