diff options
author | Nicolas Fort <nicolasfort1988@gmail.com> | 2022-05-12 09:37:47 -0300 |
---|---|---|
committer | Nicolas Fort <nicolasfort1988@gmail.com> | 2022-05-27 14:46:58 +0000 |
commit | 2f3fdb9e96a14abf89a32391b44e24b02c3a96f2 (patch) | |
tree | 352fe8b0fa88bfd8bd145489d57e1cec1cf4592f /interface-definitions | |
parent | 44326619582f52f5439e301271f728e206e18f8b (diff) | |
download | vyos-1x-2f3fdb9e96a14abf89a32391b44e24b02c3a96f2.tar.gz vyos-1x-2f3fdb9e96a14abf89a32391b44e24b02c3a96f2.zip |
Firewall: T3907: Revert migration script 6-to-7 and add new 7-to-8
Diffstat (limited to 'interface-definitions')
4 files changed, 26 insertions, 44 deletions
diff --git a/interface-definitions/firewall.xml.in b/interface-definitions/firewall.xml.in index ff8d92a24..94450d808 100644 --- a/interface-definitions/firewall.xml.in +++ b/interface-definitions/firewall.xml.in @@ -599,7 +599,7 @@ </properties> <children> #include <include/firewall/action-accept-drop-reject.xml.i> - #include <include/firewall/log.xml.i> + #include <include/firewall/rule-log-level.xml.i> </children> </node> <node name="invalid"> @@ -608,7 +608,7 @@ </properties> <children> #include <include/firewall/action-accept-drop-reject.xml.i> - #include <include/firewall/log.xml.i> + #include <include/firewall/rule-log-level.xml.i> </children> </node> <node name="related"> @@ -617,7 +617,7 @@ </properties> <children> #include <include/firewall/action-accept-drop-reject.xml.i> - #include <include/firewall/log.xml.i> + #include <include/firewall/rule-log-level.xml.i> </children> </node> </children> diff --git a/interface-definitions/include/firewall/common-rule.xml.i b/interface-definitions/include/firewall/common-rule.xml.i index 0b8838872..079864122 100644 --- a/interface-definitions/include/firewall/common-rule.xml.i +++ b/interface-definitions/include/firewall/common-rule.xml.i @@ -76,6 +76,25 @@ </leafNode> </children> </node> +<leafNode name="log"> + <properties> + <help>Option to log packets matching rule</help> + <completionHelp> + <list>enable disable</list> + </completionHelp> + <valueHelp> + <format>enable</format> + <description>Enable log</description> + </valueHelp> + <valueHelp> + <format>disable</format> + <description>Disable log</description> + </valueHelp> + <constraint> + <regex>(enable|disable)</regex> + </constraint> + </properties> +</leafNode> #include <include/firewall/rule-log-level.xml.i> <node name="connection-status"> <properties> diff --git a/interface-definitions/include/firewall/name-default-log.xml.i b/interface-definitions/include/firewall/name-default-log.xml.i index c3f6f0171..1d0ff9497 100644 --- a/interface-definitions/include/firewall/name-default-log.xml.i +++ b/interface-definitions/include/firewall/name-default-log.xml.i @@ -1,45 +1,8 @@ <!-- include start from firewall/name-default-log.xml.i --> <leafNode name="enable-default-log"> <properties> - <help>Option to log packets matching default-action</help> - <completionHelp> - <list>emerg alert crit err warn notice info debug</list> - </completionHelp> - <valueHelp> - <format>emerg</format> - <description>Emerg log level</description> - </valueHelp> - <valueHelp> - <format>alert</format> - <description>Alert log level</description> - </valueHelp> - <valueHelp> - <format>crit</format> - <description>Critical log level</description> - </valueHelp> - <valueHelp> - <format>err</format> - <description>Error log level</description> - </valueHelp> - <valueHelp> - <format>warn</format> - <description>Warning log level</description> - </valueHelp> - <valueHelp> - <format>notice</format> - <description>Notice log level</description> - </valueHelp> - <valueHelp> - <format>info</format> - <description>Info log level</description> - </valueHelp> - <valueHelp> - <format>debug</format> - <description>Debug log level</description> - </valueHelp> - <constraint> - <regex>(emerg|alert|crit|err|warn|notice|info|debug)</regex> - </constraint> + <help>Option to log packets hitting default-action</help> + <valueless/> </properties> </leafNode> <!-- include end -->
\ No newline at end of file diff --git a/interface-definitions/include/firewall/rule-log-level.xml.i b/interface-definitions/include/firewall/rule-log-level.xml.i index 4842b73ca..10c8de5e3 100644 --- a/interface-definitions/include/firewall/rule-log-level.xml.i +++ b/interface-definitions/include/firewall/rule-log-level.xml.i @@ -1,7 +1,7 @@ <!-- include start from firewall/common-rule.xml.i --> -<leafNode name="log"> +<leafNode name="log-level"> <properties> - <help>Option to log packets matching rule</help> + <help>Set log-level. Log must be enable.</help> <completionHelp> <list>emerg alert crit err warn notice info debug</list> </completionHelp> |