diff options
author | Daniil Baturin <daniil@vyos.io> | 2024-05-23 11:23:49 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-05-23 11:23:49 +0200 |
commit | 5678e37fd0b37b266330cf2d1fde79071a96bf2b (patch) | |
tree | 0d379e30773b37848bbdc533ce95edb4526d68ef /src | |
parent | 0f551d2a1d58f46c8135f7e18becc8267222580d (diff) | |
parent | 7fe568ca1672f1dfbd2b56ee3ef7a6ab48b03070 (diff) | |
download | vyos-1x-5678e37fd0b37b266330cf2d1fde79071a96bf2b.tar.gz vyos-1x-5678e37fd0b37b266330cf2d1fde79071a96bf2b.zip |
Merge pull request #3507 from c-po/nat-T6345
nat: T6345: source NAT port mapping "fully-random" is superfluous in Kernel >=5.0
Diffstat (limited to 'src')
-rwxr-xr-x | src/migration-scripts/nat/7-to-8 | 62 |
1 files changed, 62 insertions, 0 deletions
diff --git a/src/migration-scripts/nat/7-to-8 b/src/migration-scripts/nat/7-to-8 new file mode 100755 index 000000000..ab2ffa6d3 --- /dev/null +++ b/src/migration-scripts/nat/7-to-8 @@ -0,0 +1,62 @@ +#!/usr/bin/env python3 +# +# Copyright (C) 2024 VyOS maintainers and contributors +# +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License version 2 or later as +# published by the Free Software Foundation. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see <http://www.gnu.org/licenses/>. + +# T6345: random - In kernel 5.0 and newer this is the same as fully-random. +# In earlier kernels the port mapping will be randomized using a seeded +# MD5 hash mix using source and destination address and destination port. +# drop fully-random from CLI + +from sys import argv,exit +from vyos.configtree import ConfigTree + +if len(argv) < 2: + print("Must specify file name!") + exit(1) + +file_name = argv[1] + +with open(file_name, 'r') as f: + config_file = f.read() + +config = ConfigTree(config_file) + +if not config.exists(['nat']): + # Nothing to do + exit(0) + +for direction in ['source', 'destination']: + # If a node doesn't exist, we obviously have nothing to do. + if not config.exists(['nat', direction]): + continue + + # However, we also need to handle the case when a 'source' or 'destination' sub-node does exist, + # but there are no rules under it. + if not config.list_nodes(['nat', direction]): + continue + + for rule in config.list_nodes(['nat', direction, 'rule']): + port_mapping = ['nat', direction, 'rule', rule, 'translation', 'options', 'port-mapping'] + if config.exists(port_mapping): + tmp = config.return_value(port_mapping) + if tmp == 'fully-random': + config.set(port_mapping, value='random') + +try: + with open(file_name, 'w') as f: + f.write(config.to_string()) +except OSError as e: + print(f'Failed to save the modified config: {e}') + exit(1) |