summaryrefslogtreecommitdiff
path: root/src/conf_mode/interfaces_wwan.py
diff options
context:
space:
mode:
authorDavid Vølker <david@voelker.dk>2026-06-01 08:09:06 +0200
committerChristian Breunig <christian@breunig.cc>2026-07-01 21:51:21 +0200
commit0d3ac22b95cef90e7c54ef823c00bb59b935c158 (patch)
treed4655b06e0c9976a5ecdeae87205e944e098c7b9 /src/conf_mode/interfaces_wwan.py
parent063e007a5a8eac3bb9ad101206dc94734eeaa595 (diff)
downloadvyos-1x-0d3ac22b95cef90e7c54ef823c00bb59b935c158.tar.gz
vyos-1x-0d3ac22b95cef90e7c54ef823c00bb59b935c158.zip
firewall: T8761: re-introduce VRF interface names in generated firewall config
This change re-implements the intended behaviour from T4180 aswell as from T4506, it ensures that both the vrf-member interface aswell as the vrf itself is added as an oifname -> meaning that traffic traversing and originating from withing VyOS is matches outbound. Changes done by c-po: * re-sort dependency list to keep diff low * vyos.configdict.is_vrf_changed() should return early and not carry over the to-be return value * keep common coding style (dict by . separation) in nftables-zone.j2 Co-authored-by: Christian Breunig <christian@breunig.cc>
Diffstat (limited to 'src/conf_mode/interfaces_wwan.py')
-rwxr-xr-xsrc/conf_mode/interfaces_wwan.py12
1 files changed, 10 insertions, 2 deletions
diff --git a/src/conf_mode/interfaces_wwan.py b/src/conf_mode/interfaces_wwan.py
index ad6c806ad..0fe67508a 100755
--- a/src/conf_mode/interfaces_wwan.py
+++ b/src/conf_mode/interfaces_wwan.py
@@ -24,6 +24,7 @@ from vyos.configdep import set_dependents
from vyos.configdep import call_dependents
from vyos.configdict import get_interface_dict
from vyos.configdict import is_node_changed
+from vyos.configdict import is_vrf_changed
from vyos.configverify import verify_authentication
from vyos.configverify import verify_interface_exists
from vyos.configverify import verify_mirror_redirect
@@ -93,6 +94,10 @@ def get_config(config=None):
if 'static_arp' in wwan:
set_dependents('static_arp', conf)
+ # Check vrf membership, to ensure firewall is updated
+ if is_vrf_changed(conf, ifname):
+ set_dependents('firewall', conf)
+
return wwan
def verify(wwan):
@@ -170,6 +175,9 @@ def apply(wwan):
if os.path.exists(cron_script):
os.unlink(cron_script)
+ # run the dependents
+ call_dependents()
+
return None
if 'shutdown_required' in wwan or (not is_wwan_connected(wwan['ifname'])):
@@ -192,8 +200,8 @@ def apply(wwan):
w.update(wwan)
- if 'static_arp' in wwan:
- call_dependents()
+ # run the dependents
+ call_dependents()
return None