summaryrefslogtreecommitdiff
path: root/src/conf_mode
diff options
context:
space:
mode:
authorDaniil Baturin <daniil@vyos.io>2024-06-03 15:12:31 +0200
committerGitHub <noreply@github.com>2024-06-03 15:12:31 +0200
commite74970c8b1a5663c06c1071b9b4f360dbfb666a9 (patch)
tree304f49e6ba45432f70afbbdd7c46aec0fa43164a /src/conf_mode
parent38fd6b2c4964a7385b2b366a15af4676075b045e (diff)
parent3ad333fc62807f5816f826d7bc0c4c8e0ac96167 (diff)
downloadvyos-1x-e74970c8b1a5663c06c1071b9b4f360dbfb666a9.tar.gz
vyos-1x-e74970c8b1a5663c06c1071b9b4f360dbfb666a9.zip
Merge pull request #3572 from talmakion/bugfix/T6403
nat64: T6403: validate source prefix for RFC compliance
Diffstat (limited to 'src/conf_mode')
-rwxr-xr-xsrc/conf_mode/nat64.py10
1 files changed, 8 insertions, 2 deletions
diff --git a/src/conf_mode/nat64.py b/src/conf_mode/nat64.py
index c1e7ebf85..32a1c47d1 100755
--- a/src/conf_mode/nat64.py
+++ b/src/conf_mode/nat64.py
@@ -20,7 +20,7 @@ import csv
import os
import re
-from ipaddress import IPv6Network
+from ipaddress import IPv6Network, IPv6Address
from json import dumps as json_write
from vyos import ConfigError
@@ -103,8 +103,14 @@ def verify(nat64) -> None:
# Verify that source.prefix is set and is a /96
if not dict_search("source.prefix", instance):
raise ConfigError(f"Source NAT64 rule {rule} missing source prefix")
- if IPv6Network(instance["source"]["prefix"]).prefixlen != 96:
+ src_prefix = IPv6Network(instance["source"]["prefix"])
+ if src_prefix.prefixlen != 96:
raise ConfigError(f"Source NAT64 rule {rule} source prefix must be /96")
+ if (int(src_prefix[0]) & int(IPv6Address('0:0:0:0:ff00::'))) != 0:
+ raise ConfigError(
+ f'Source NAT64 rule {rule} source prefix is not RFC6052-compliant: '
+ 'bits 64 to 71 (9th octet) must be zeroed'
+ )
pools = dict_search("translation.pool", instance)
if pools: