diff options
Diffstat (limited to 'interface-definitions')
6 files changed, 232 insertions, 65 deletions
| diff --git a/interface-definitions/high-availability.xml.in b/interface-definitions/high-availability.xml.in index 4f55916fa..47a772d04 100644 --- a/interface-definitions/high-availability.xml.in +++ b/interface-definitions/high-availability.xml.in @@ -12,6 +12,12 @@            <help>Virtual Router Redundancy Protocol settings</help>          </properties>          <children> +          <leafNode name="disable-snmp"> +            <properties> +              <valueless/> +              <help>Disable SNMP</help> +            </properties> +          </leafNode>            <node name="global-parameters">              <properties>                <help>VRRP global parameters</help> diff --git a/interface-definitions/include/firewall/global-options.xml.i b/interface-definitions/include/firewall/global-options.xml.i index a63874cb0..e655cd6ac 100644 --- a/interface-definitions/include/firewall/global-options.xml.i +++ b/interface-definitions/include/firewall/global-options.xml.i @@ -145,21 +145,21 @@      </leafNode>      <leafNode name="source-validation">        <properties> -        <help>Policy for source validation by reversed path, as specified in RFC3704</help> +        <help>Policy for IPv4 source validation by reversed path, as specified in RFC3704</help>          <completionHelp>            <list>strict loose disable</list>          </completionHelp>          <valueHelp>            <format>strict</format> -          <description>Enable Strict Reverse Path Forwarding as defined in RFC3704</description> +          <description>Enable IPv4 Strict Reverse Path Forwarding as defined in RFC3704</description>          </valueHelp>          <valueHelp>            <format>loose</format> -          <description>Enable Loose Reverse Path Forwarding as defined in RFC3704</description> +          <description>Enable IPv4 Loose Reverse Path Forwarding as defined in RFC3704</description>          </valueHelp>          <valueHelp>            <format>disable</format> -          <description>No source validation</description> +          <description>No IPv4 source validation</description>          </valueHelp>          <constraint>            <regex>(strict|loose|disable)</regex> @@ -227,6 +227,30 @@        </properties>        <defaultValue>disable</defaultValue>      </leafNode> +    <leafNode name="ipv6-source-validation"> +      <properties> +        <help>Policy for IPv6 source validation by reversed path, as specified in RFC3704</help> +        <completionHelp> +          <list>strict loose disable</list> +        </completionHelp> +        <valueHelp> +          <format>strict</format> +          <description>Enable IPv6 Strict Reverse Path Forwarding as defined in RFC3704</description> +        </valueHelp> +        <valueHelp> +          <format>loose</format> +          <description>Enable IPv6 Loose Reverse Path Forwarding as defined in RFC3704</description> +        </valueHelp> +        <valueHelp> +          <format>disable</format> +          <description>No IPv6 source validation</description> +        </valueHelp> +        <constraint> +          <regex>(strict|loose|disable)</regex> +        </constraint> +      </properties> +      <defaultValue>disable</defaultValue> +    </leafNode>      <leafNode name="ipv6-src-route">        <properties>          <help>Policy for handling IPv6 packets with routing extension header</help> diff --git a/interface-definitions/include/firewall/source-destination-group-ipv4.xml.i b/interface-definitions/include/firewall/source-destination-group-ipv4.xml.i new file mode 100644 index 000000000..8c34fb933 --- /dev/null +++ b/interface-definitions/include/firewall/source-destination-group-ipv4.xml.i @@ -0,0 +1,41 @@ +<!-- include start from firewall/source-destination-group-ipv4.xml.i --> +<node name="group"> +  <properties> +    <help>Group</help> +  </properties> +  <children> +    <leafNode name="address-group"> +      <properties> +        <help>Group of addresses</help> +        <completionHelp> +          <path>firewall group address-group</path> +        </completionHelp> +      </properties> +    </leafNode> +    <leafNode name="domain-group"> +      <properties> +        <help>Group of domains</help> +        <completionHelp> +          <path>firewall group domain-group</path> +        </completionHelp> +      </properties> +    </leafNode> +    <leafNode name="network-group"> +      <properties> +        <help>Group of networks</help> +        <completionHelp> +          <path>firewall group network-group</path> +        </completionHelp> +      </properties> +    </leafNode> +    <leafNode name="port-group"> +      <properties> +        <help>Group of ports</help> +        <completionHelp> +          <path>firewall group port-group</path> +        </completionHelp> +      </properties> +    </leafNode> +  </children> +</node> +<!-- include end --> diff --git a/interface-definitions/include/version/conntrack-version.xml.i b/interface-definitions/include/version/conntrack-version.xml.i index 696f76362..c0f632c70 100644 --- a/interface-definitions/include/version/conntrack-version.xml.i +++ b/interface-definitions/include/version/conntrack-version.xml.i @@ -1,3 +1,3 @@  <!-- include start from include/version/conntrack-version.xml.i --> -<syntaxVersion component='conntrack' version='3'></syntaxVersion> +<syntaxVersion component='conntrack' version='4'></syntaxVersion>  <!-- include end --> diff --git a/interface-definitions/interfaces-virtual-ethernet.xml.in b/interface-definitions/interfaces-virtual-ethernet.xml.in index 1daa764d4..5f205f354 100644 --- a/interface-definitions/interfaces-virtual-ethernet.xml.in +++ b/interface-definitions/interfaces-virtual-ethernet.xml.in @@ -21,6 +21,7 @@            #include <include/interface/dhcp-options.xml.i>            #include <include/interface/dhcpv6-options.xml.i>            #include <include/interface/disable.xml.i> +          #include <include/interface/netns.xml.i>            #include <include/interface/vif-s.xml.i>            #include <include/interface/vif.xml.i>            #include <include/interface/vrf.xml.i> diff --git a/interface-definitions/system-conntrack.xml.in b/interface-definitions/system-conntrack.xml.in index 8dad048b8..3abf9bbf0 100644 --- a/interface-definitions/system-conntrack.xml.in +++ b/interface-definitions/system-conntrack.xml.in @@ -40,82 +40,177 @@                <help>Customized rules to ignore selective connection tracking</help>              </properties>              <children> -              <tagNode name="rule"> +              <node name="ipv4">                  <properties> -                  <help>Rule number</help> -                  <valueHelp> -                    <format>u32:1-999999</format> -                    <description>Number of conntrack ignore rule</description> -                  </valueHelp> -                  <constraint> -                    <validator name="numeric" argument="--range 1-999999"/> -                  </constraint> -                  <constraintErrorMessage>Ignore rule number must be between 1 and 999999</constraintErrorMessage> +                  <help>IPv4 rules</help>                  </properties>                  <children> -                  #include <include/generic-description.xml.i> -                  <node name="destination"> +                  <tagNode name="rule">                      <properties> -                      <help>Destination parameters</help> +                      <help>Rule number</help> +                      <valueHelp> +                        <format>u32:1-999999</format> +                        <description>Number of conntrack ignore rule</description> +                      </valueHelp> +                      <constraint> +                        <validator name="numeric" argument="--range 1-999999"/> +                      </constraint> +                      <constraintErrorMessage>Ignore rule number must be between 1 and 999999</constraintErrorMessage>                      </properties>                      <children> -                      #include <include/nat-address.xml.i> -                      #include <include/nat-port.xml.i> +                      #include <include/generic-description.xml.i> +                      <node name="destination"> +                        <properties> +                          <help>Destination parameters</help> +                        </properties> +                        <children> +                          #include <include/firewall/source-destination-group-ipv4.xml.i> +                          #include <include/nat-address.xml.i> +                          #include <include/nat-port.xml.i> +                        </children> +                      </node> +                      <leafNode name="inbound-interface"> +                        <properties> +                          <help>Interface to ignore connections tracking on</help> +                          <completionHelp> +                            <list>any</list> +                            <script>${vyos_completion_dir}/list_interfaces</script> +                          </completionHelp> +                        </properties> +                      </leafNode> +                      #include <include/ip-protocol.xml.i> +                      <leafNode name="protocol"> +                        <properties> +                          <help>Protocol to match (protocol name, number, or "all")</help> +                          <completionHelp> +                            <script>${vyos_completion_dir}/list_protocols.sh</script> +                            <list>all tcp_udp</list> +                          </completionHelp> +                          <valueHelp> +                            <format>all</format> +                            <description>All IP protocols</description> +                          </valueHelp> +                          <valueHelp> +                            <format>tcp_udp</format> +                            <description>Both TCP and UDP</description> +                          </valueHelp> +                          <valueHelp> +                            <format>u32:0-255</format> +                            <description>IP protocol number</description> +                          </valueHelp> +                          <valueHelp> +                            <format><protocol></format> +                            <description>IP protocol name</description> +                          </valueHelp> +                          <valueHelp> +                            <format>!<protocol></format> +                            <description>IP protocol name</description> +                          </valueHelp> +                          <constraint> +                            <validator name="ip-protocol"/> +                          </constraint> +                        </properties> +                      </leafNode> +                      <node name="source"> +                        <properties> +                          <help>Source parameters</help> +                        </properties> +                        <children> +                          #include <include/firewall/source-destination-group-ipv4.xml.i> +                          #include <include/nat-address.xml.i> +                          #include <include/nat-port.xml.i> +                        </children> +                      </node>                      </children> -                  </node> -                  <leafNode name="inbound-interface"> -                    <properties> -                      <help>Interface to ignore connections tracking on</help> -                      <completionHelp> -                        <list>any</list> -                        <script>${vyos_completion_dir}/list_interfaces</script> -                      </completionHelp> -                    </properties> -                  </leafNode> -                  #include <include/ip-protocol.xml.i> -                  <leafNode name="protocol"> +                  </tagNode> +                </children> +              </node> +              <node name="ipv6"> +                <properties> +                  <help>IPv6 rules</help> +                </properties> +                <children> +                  <tagNode name="rule">                      <properties> -                      <help>Protocol to match (protocol name, number, or "all")</help> -                      <completionHelp> -                        <script>${vyos_completion_dir}/list_protocols.sh</script> -                        <list>all tcp_udp</list> -                      </completionHelp> -                      <valueHelp> -                        <format>all</format> -                        <description>All IP protocols</description> -                      </valueHelp> -                      <valueHelp> -                        <format>tcp_udp</format> -                        <description>Both TCP and UDP</description> -                      </valueHelp> -                      <valueHelp> -                        <format>u32:0-255</format> -                        <description>IP protocol number</description> -                      </valueHelp> -                      <valueHelp> -                        <format><protocol></format> -                        <description>IP protocol name</description> -                      </valueHelp> +                      <help>Rule number</help>                        <valueHelp> -                        <format>!<protocol></format> -                        <description>IP protocol name</description> +                        <format>u32:1-999999</format> +                        <description>Number of conntrack ignore rule</description>                        </valueHelp>                        <constraint> -                        <validator name="ip-protocol"/> +                        <validator name="numeric" argument="--range 1-999999"/>                        </constraint> -                    </properties> -                  </leafNode> -                  <node name="source"> -                    <properties> -                      <help>Source parameters</help> +                      <constraintErrorMessage>Ignore rule number must be between 1 and 999999</constraintErrorMessage>                      </properties>                      <children> -                      #include <include/nat-address.xml.i> -                      #include <include/nat-port.xml.i> +                      #include <include/generic-description.xml.i> +                      <node name="destination"> +                        <properties> +                          <help>Destination parameters</help> +                        </properties> +                        <children> +                          #include <include/firewall/address-ipv6.xml.i> +                          #include <include/firewall/source-destination-group-ipv6.xml.i> +                          #include <include/nat-port.xml.i> +                        </children> +                      </node> +                      <leafNode name="inbound-interface"> +                        <properties> +                          <help>Interface to ignore connections tracking on</help> +                          <completionHelp> +                            <list>any</list> +                            <script>${vyos_completion_dir}/list_interfaces</script> +                          </completionHelp> +                        </properties> +                      </leafNode> +                      #include <include/ip-protocol.xml.i> +                      <leafNode name="protocol"> +                        <properties> +                          <help>Protocol to match (protocol name, number, or "all")</help> +                          <completionHelp> +                            <script>${vyos_completion_dir}/list_protocols.sh</script> +                            <list>all tcp_udp</list> +                          </completionHelp> +                          <valueHelp> +                            <format>all</format> +                            <description>All IP protocols</description> +                          </valueHelp> +                          <valueHelp> +                            <format>tcp_udp</format> +                            <description>Both TCP and UDP</description> +                          </valueHelp> +                          <valueHelp> +                            <format>u32:0-255</format> +                            <description>IP protocol number</description> +                          </valueHelp> +                          <valueHelp> +                            <format><protocol></format> +                            <description>IP protocol name</description> +                          </valueHelp> +                          <valueHelp> +                            <format>!<protocol></format> +                            <description>IP protocol name</description> +                          </valueHelp> +                          <constraint> +                            <validator name="ip-protocol"/> +                          </constraint> +                        </properties> +                      </leafNode> +                      <node name="source"> +                        <properties> +                          <help>Source parameters</help> +                        </properties> +                        <children> +                          #include <include/firewall/address-ipv6.xml.i> +                          #include <include/firewall/source-destination-group-ipv6.xml.i> +                          #include <include/nat-port.xml.i> +                        </children> +                      </node>                      </children> -                  </node> +                  </tagNode>                  </children> -              </tagNode> +              </node> +                            </children>            </node>            <node name="log"> | 
