diff options
| author | David Vølker <david@voelker.dk> | 2026-06-01 08:09:06 +0200 |
|---|---|---|
| committer | Christian Breunig <christian@breunig.cc> | 2026-07-01 21:51:21 +0200 |
| commit | 0d3ac22b95cef90e7c54ef823c00bb59b935c158 (patch) | |
| tree | d4655b06e0c9976a5ecdeae87205e944e098c7b9 /src/conf_mode/interfaces_vxlan.py | |
| parent | 063e007a5a8eac3bb9ad101206dc94734eeaa595 (diff) | |
| download | vyos-1x-0d3ac22b95cef90e7c54ef823c00bb59b935c158.tar.gz vyos-1x-0d3ac22b95cef90e7c54ef823c00bb59b935c158.zip | |
firewall: T8761: re-introduce VRF interface names in generated firewall config
This change re-implements the intended behaviour from T4180 aswell as from
T4506, it ensures that both the vrf-member interface aswell as the vrf itself
is added as an oifname -> meaning that traffic traversing and originating from
withing VyOS is matches outbound.
Changes done by c-po:
* re-sort dependency list to keep diff low
* vyos.configdict.is_vrf_changed() should return early and not carry
over the to-be return value
* keep common coding style (dict by . separation) in nftables-zone.j2
Co-authored-by: Christian Breunig <christian@breunig.cc>
Diffstat (limited to 'src/conf_mode/interfaces_vxlan.py')
| -rwxr-xr-x | src/conf_mode/interfaces_vxlan.py | 9 |
1 files changed, 7 insertions, 2 deletions
diff --git a/src/conf_mode/interfaces_vxlan.py b/src/conf_mode/interfaces_vxlan.py index 86e885807..1dab47b4a 100755 --- a/src/conf_mode/interfaces_vxlan.py +++ b/src/conf_mode/interfaces_vxlan.py @@ -23,6 +23,7 @@ from vyos.configdep import call_dependents from vyos.configdict import get_interface_dict from vyos.configdict import leaf_node_changed from vyos.configdict import is_node_changed +from vyos.configdict import is_vrf_changed from vyos.configdict import node_changed from vyos.configverify import verify_address from vyos.configverify import verify_bridge_delete @@ -89,6 +90,10 @@ def get_config(config=None): if 'static_arp' in vxlan: set_dependents('static_arp', conf) + # Check vrf membership, to ensure firewall is updated + if is_vrf_changed(conf, ifname): + set_dependents('firewall', conf) + return vxlan def verify(vxlan): @@ -257,8 +262,8 @@ def apply(vxlan): v = VXLANIf(**vxlan) v.update(vxlan) - if 'static_arp' in vxlan: - call_dependents() + # run the dependents + call_dependents() return None |
