summaryrefslogtreecommitdiff
path: root/docs
diff options
context:
space:
mode:
authorRuben Herold <ruben@puettmann.net>2026-09-25 15:37:27 +0200
committerGitHub <noreply@github.com>2026-09-25 14:37:27 +0100
commit75d44591ed7cd7b6246f5d5f48722d70d11f7b98 (patch)
tree8962445cbf1362c88c831fbf53711789b8d6775a /docs
parent93f84b050c90cb2d21d5216fc9d54fbcd118f407 (diff)
downloadvyos-documentation-75d44591ed7cd7b6246f5d5f48722d70d11f7b98.tar.gz
vyos-documentation-75d44591ed7cd7b6246f5d5f48722d70d11f7b98.zip
docs: T9157: document firewall fib-type match (#2186)
* docs: T9157: document firewall fib-type match Companion doc entry for vyos/vyos-1x#5372, which adds "fib-type" as a source/destination match option (nftables' fib daddr/saddr type expression) for forward/input/output/name rule sets, ipv4 and ipv6. * docs: T9157: update fib match docs for fib-type -> fib type rename Companion vyos-1x PR #5372 restructured the "fib-type" leaf into a "fib" node with a "type" child (following feedback from l0crian1 and sarthurdev to reserve the "fib" namespace for a possible future lookup/match concatenation feature, tracked separately under T5119). Update the CLI paths and examples here to match, and fix "prohibited" to "prohibit" to match nftables' actual fib_addrtype token. * docs: T9157: add prerouting raw fib type reference, fix backtick style CodeRabbit feedback on #2186: - the prose showed a "prerouting raw" example but the command reference only listed forward/input/output/name filter forms, even though fib.xml.i is also included from common-rule-ipv{4,6}-raw.xml.i for that hook. Add the missing source/destination cfgcmd entries. - MyST pages use single backticks for inline code, not double (that's for embedded RST); fix the fib type prose accordingly. * docs: T9157: update fib docs for rule-level lookup/match split Companion vyos-1x PR #5372 moved "fib" from a leaf nested under destination/source to a rule-level node with separate "lookup" (source-address/destination-address) and "match route-type" children, per l0crian1's review feedback - reserving room for mark/iif/oif lookup keys and oif/oifname match results later (tracked under T5119) without ever renaming what ships now. Update the CLI paths and examples here to match.
Diffstat (limited to 'docs')
-rw-r--r--docs/configuration/firewall/ipv4.md51
-rw-r--r--docs/configuration/firewall/ipv6.md51
2 files changed, 102 insertions, 0 deletions
diff --git a/docs/configuration/firewall/ipv4.md b/docs/configuration/firewall/ipv4.md
index 35d51c4e..767a22f3 100644
--- a/docs/configuration/firewall/ipv4.md
+++ b/docs/configuration/firewall/ipv4.md
@@ -491,6 +491,57 @@ set firewall ipv4 name FOO rule 100 destination address-mask 0.255.0.255
:::
```
+```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv4 input filter rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv4 output filter rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv4 name \<name\> rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv4 prerouting raw rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv4 input filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv4 output filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv4 name \<name\> rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv4 prerouting raw rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+
+Match based on the result of a Forwarding Information Base (FIB) lookup
+instead of the packet's literal address. `lookup` selects which address to
+look up: `source-address` performs a reverse-path lookup, `destination-address`
+a normal route lookup. `match route-type` compares the resulting address
+type; both `lookup` and `match route-type` must be configured together.
+`type` is one of `local`, `unicast`, `broadcast`, `multicast`, `anycast`,
+`blackhole`, `unreachable` or `prohibit`. The `!` character negates the
+match.
+
+This is particularly useful in `prerouting raw` to distinguish traffic
+destined to the router itself from traffic being forwarded through it,
+without needing to enumerate every locally configured address in a
+network-group by hand:
+
+:::{code-block} none
+set firewall ipv4 prerouting raw rule 1 fib lookup destination-address
+set firewall ipv4 prerouting raw rule 1 fib match route-type local
+set firewall ipv4 prerouting raw rule 1 action accept
+set firewall ipv4 prerouting raw rule 2 action notrack
+:::
+```
+
```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> source fqdn \<fqdn\>
```
diff --git a/docs/configuration/firewall/ipv6.md b/docs/configuration/firewall/ipv6.md
index 8347511f..a705e1e0 100644
--- a/docs/configuration/firewall/ipv6.md
+++ b/docs/configuration/firewall/ipv6.md
@@ -492,6 +492,57 @@ set firewall ipv6 forward filter rule 200 source address-mask ::ffff:ffff:ffff:f
:::
```
+```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> fib lookup [source-address | destination-address]
+```
+
+```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+```
+
+```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> fib match route-type [\<type\> | !\<type\>]
+
+Match based on the result of a Forwarding Information Base (FIB) lookup
+instead of the packet's literal address. `lookup` selects which address to
+look up: `source-address` performs a reverse-path lookup, `destination-address`
+a normal route lookup. `match route-type` compares the resulting address
+type; both `lookup` and `match route-type` must be configured together.
+`type` is one of `local`, `unicast`, `broadcast`, `multicast`, `anycast`,
+`blackhole`, `unreachable` or `prohibit`. The `!` character negates the
+match.
+
+This is particularly useful in `prerouting raw` to distinguish traffic
+destined to the router itself from traffic being forwarded through it,
+without needing to enumerate every locally configured address in a
+network-group by hand:
+
+:::{code-block} none
+set firewall ipv6 prerouting raw rule 1 fib lookup destination-address
+set firewall ipv6 prerouting raw rule 1 fib match route-type local
+set firewall ipv6 prerouting raw rule 1 action accept
+set firewall ipv6 prerouting raw rule 2 action notrack
+:::
+```
+
```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source fqdn \<fqdn\>
```