diff options
| author | Marius Lindvall <marius@varden.info> | 2026-01-01 22:42:10 +0100 |
|---|---|---|
| committer | Marius Lindvall <marius@varden.info> | 2026-01-01 22:42:10 +0100 |
| commit | 95f40d8b30f03a47b022042ed8b3c179b0e7abdf (patch) | |
| tree | cf4f451c23bbe59179d7ca01199ab3ab3ad31e97 /smoketest/scripts/cli | |
| parent | 76830afc8703a3f9f6be7500cb92aa9b6e255425 (diff) | |
| download | vyos-1x-95f40d8b30f03a47b022042ed8b3c179b0e7abdf.tar.gz vyos-1x-95f40d8b30f03a47b022042ed8b3c179b0e7abdf.zip | |
nat66: T8139: add support for NAT66 source groups
Copy the support for NAT66 destination groups (commit f96733dd and
commit 43554efc) over to NAT66 source groups as well.
Change the existing smoketest for NAT66 groups to also cover a source
group use-case example.
Diffstat (limited to 'smoketest/scripts/cli')
| -rwxr-xr-x | smoketest/scripts/cli/test_nat66.py | 18 |
1 files changed, 16 insertions, 2 deletions
diff --git a/smoketest/scripts/cli/test_nat66.py b/smoketest/scripts/cli/test_nat66.py index 5e5e4829a..d5b137c70 100755 --- a/smoketest/scripts/cli/test_nat66.py +++ b/smoketest/scripts/cli/test_nat66.py @@ -148,10 +148,13 @@ class TestNAT66(VyOSUnitTestSHIM.TestCase): address_group_member = 'fc00::1' network_group = 'smoketest_net' network_group_member = 'fc00::/64' + mac_group = 'smoketest_mac' + mac_group_member = '00:01:02:03:04:05' translation_prefix = 'fc01::/64' self.cli_set(['firewall', 'group', 'ipv6-address-group', address_group, 'address', address_group_member]) self.cli_set(['firewall', 'group', 'ipv6-network-group', network_group, 'network', network_group_member]) + self.cli_set(['firewall', 'group', 'mac-group', mac_group, 'mac-address', mac_group_member]) self.cli_set(dst_path + ['rule', '1', 'destination', 'group', 'address-group', address_group]) self.cli_set(dst_path + ['rule', '1', 'translation', 'address', translation_prefix]) @@ -159,6 +162,9 @@ class TestNAT66(VyOSUnitTestSHIM.TestCase): self.cli_set(dst_path + ['rule', '2', 'destination', 'group', 'network-group', network_group]) self.cli_set(dst_path + ['rule', '2', 'translation', 'address', translation_prefix]) + self.cli_set(dst_path + ['rule', '3', 'source', 'group', 'mac-group', mac_group]) + self.cli_set(dst_path + ['rule', '3', 'translation', 'address', translation_prefix]) + self.cli_commit() nftables_search = [ @@ -167,7 +173,8 @@ class TestNAT66(VyOSUnitTestSHIM.TestCase): [f'set N6_{network_group}'], [f'elements = {{ {network_group_member} }}'], ['ip6 daddr', f'@A6_{address_group}', 'dnat prefix to fc01::/64'], - ['ip6 daddr', f'@N6_{network_group}', 'dnat prefix to fc01::/64'] + ['ip6 daddr', f'@N6_{network_group}', 'dnat prefix to fc01::/64'], + ['ether saddr', f'@M_{mac_group}', 'dnat prefix to fc01::/64'], ] self.verify_nftables(nftables_search, 'ip6 vyos_nat') @@ -234,10 +241,13 @@ class TestNAT66(VyOSUnitTestSHIM.TestCase): address_group_member = 'fc00::1' network_group = 'smoketest_net' network_group_member = 'fc00::/64' + mac_group = 'smoketest_mac' + mac_group_member = '00:01:02:03:04:05' translation_prefix = 'fc01::/64' self.cli_set(['firewall', 'group', 'ipv6-address-group', address_group, 'address', address_group_member]) self.cli_set(['firewall', 'group', 'ipv6-network-group', network_group, 'network', network_group_member]) + self.cli_set(['firewall', 'group', 'mac-group', mac_group, 'mac-address', mac_group_member]) self.cli_set(src_path + ['rule', '1', 'destination', 'group', 'address-group', address_group]) self.cli_set(src_path + ['rule', '1', 'translation', 'address', translation_prefix]) @@ -245,6 +255,9 @@ class TestNAT66(VyOSUnitTestSHIM.TestCase): self.cli_set(src_path + ['rule', '2', 'destination', 'group', 'network-group', network_group]) self.cli_set(src_path + ['rule', '2', 'translation', 'address', translation_prefix]) + self.cli_set(src_path + ['rule', '3', 'source', 'group', 'mac-group', mac_group]) + self.cli_set(src_path + ['rule', '3', 'translation', 'address', translation_prefix]) + self.cli_commit() nftables_search = [ @@ -253,7 +266,8 @@ class TestNAT66(VyOSUnitTestSHIM.TestCase): [f'set N6_{network_group}'], [f'elements = {{ {network_group_member} }}'], ['ip6 daddr', f'@A6_{address_group}', 'snat prefix to fc01::/64'], - ['ip6 daddr', f'@N6_{network_group}', 'snat prefix to fc01::/64'] + ['ip6 daddr', f'@N6_{network_group}', 'snat prefix to fc01::/64'], + ['ether saddr', f'@M_{mac_group}', 'snat prefix to fc01::/64'], ] self.verify_nftables(nftables_search, 'ip6 vyos_nat') |
