From 0d3ac22b95cef90e7c54ef823c00bb59b935c158 Mon Sep 17 00:00:00 2001 From: David Vølker Date: Mon, 1 Jun 2026 08:09:06 +0200 Subject: firewall: T8761: re-introduce VRF interface names in generated firewall config This change re-implements the intended behaviour from T4180 aswell as from T4506, it ensures that both the vrf-member interface aswell as the vrf itself is added as an oifname -> meaning that traffic traversing and originating from withing VyOS is matches outbound. Changes done by c-po: * re-sort dependency list to keep diff low * vyos.configdict.is_vrf_changed() should return early and not carry over the to-be return value * keep common coding style (dict by . separation) in nftables-zone.j2 Co-authored-by: Christian Breunig --- src/conf_mode/interfaces_sstpc.py | 13 +++++++++++++ 1 file changed, 13 insertions(+) (limited to 'src/conf_mode/interfaces_sstpc.py') diff --git a/src/conf_mode/interfaces_sstpc.py b/src/conf_mode/interfaces_sstpc.py index 50d3d1cb3..0231b9952 100755 --- a/src/conf_mode/interfaces_sstpc.py +++ b/src/conf_mode/interfaces_sstpc.py @@ -20,6 +20,9 @@ from sys import exit from vyos.config import Config from vyos.configdict import get_interface_dict from vyos.configdict import is_node_changed +from vyos.configdict import is_vrf_changed +from vyos.configdep import set_dependents +from vyos.configdep import call_dependents from vyos.configverify import verify_authentication from vyos.configverify import verify_vrf from vyos.ifconfig import SSTPCIf @@ -57,6 +60,10 @@ def get_config(config=None): # bail out early - no need to further process other nodes break + # Check vrf membership, to ensure firewall is updated + if is_vrf_changed(conf, ifname): + set_dependents('firewall', conf) + return sstpc def verify(sstpc): @@ -107,6 +114,9 @@ def apply(sstpc): p = SSTPCIf(ifname) p.remove() call(f'systemctl stop ppp@{ifname}.service') + + # run the dependents and return + call_dependents() return None # reconnect should only be necessary when specific options change, @@ -128,6 +138,9 @@ def apply(sstpc): p = SSTPCIf(ifname) p.update(sstpc) + # run the dependents + call_dependents() + return None if __name__ == '__main__': -- cgit v1.2.3