summaryrefslogtreecommitdiff
path: root/smoketest/scripts/cli
diff options
context:
space:
mode:
authorsarthurdev <965089+sarthurdev@users.noreply.github.com>2025-02-20 19:33:16 +0100
committersarthurdev <965089+sarthurdev@users.noreply.github.com>2025-02-20 19:33:16 +0100
commitac890f5e3ff7d0bb4853199204e4db7c4f1dcc3e (patch)
tree68ccbbfb117d41382ba7c8a3dfa3bf88165255ec /smoketest/scripts/cli
parent4d9d45a45acaa506b9cc99dbb86e12b9cb692dd1 (diff)
downloadvyos-1x-ac890f5e3ff7d0bb4853199204e4db7c4f1dcc3e.tar.gz
vyos-1x-ac890f5e3ff7d0bb4853199204e4db7c4f1dcc3e.zip
firewall: T7148: Bridge state-policy uses drop in place of reject
Diffstat (limited to 'smoketest/scripts/cli')
-rwxr-xr-xsmoketest/scripts/cli/test_firewall.py7
1 files changed, 7 insertions, 0 deletions
diff --git a/smoketest/scripts/cli/test_firewall.py b/smoketest/scripts/cli/test_firewall.py
index 93d41a7f7..33144c7fa 100755
--- a/smoketest/scripts/cli/test_firewall.py
+++ b/smoketest/scripts/cli/test_firewall.py
@@ -658,6 +658,13 @@ class TestFirewall(VyOSUnitTestSHIM.TestCase):
self.verify_nftables(nftables_search, 'ip vyos_filter')
+ # T7148 - Ensure bridge rule reject -> drop
+ self.cli_set(['firewall', 'global-options', 'state-policy', 'invalid', 'action', 'reject'])
+ self.cli_commit()
+
+ self.verify_nftables([['ct state invalid', 'reject']], 'ip vyos_filter')
+ self.verify_nftables([['ct state invalid', 'drop']], 'bridge vyos_filter')
+
# Check conntrack is enabled from state-policy
self.verify_nftables_chain([['accept']], 'ip vyos_conntrack', 'FW_CONNTRACK')
self.verify_nftables_chain([['accept']], 'ip6 vyos_conntrack', 'FW_CONNTRACK')