diff options
| author | Ruben Herold <ruben@puettmann.net> | 2026-09-25 15:37:27 +0200 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2026-09-25 14:37:27 +0100 |
| commit | 75d44591ed7cd7b6246f5d5f48722d70d11f7b98 (patch) | |
| tree | 8962445cbf1362c88c831fbf53711789b8d6775a /docs | |
| parent | 93f84b050c90cb2d21d5216fc9d54fbcd118f407 (diff) | |
| download | vyos-documentation-75d44591ed7cd7b6246f5d5f48722d70d11f7b98.tar.gz vyos-documentation-75d44591ed7cd7b6246f5d5f48722d70d11f7b98.zip | |
docs: T9157: document firewall fib-type match (#2186)
* docs: T9157: document firewall fib-type match
Companion doc entry for vyos/vyos-1x#5372, which adds
"fib-type" as a source/destination match option
(nftables' fib daddr/saddr type expression) for
forward/input/output/name rule sets, ipv4 and ipv6.
* docs: T9157: update fib match docs for fib-type -> fib type rename
Companion vyos-1x PR #5372 restructured the "fib-type" leaf into a
"fib" node with a "type" child (following feedback from l0crian1 and
sarthurdev to reserve the "fib" namespace for a possible future
lookup/match concatenation feature, tracked separately under T5119).
Update the CLI paths and examples here to match, and fix "prohibited"
to "prohibit" to match nftables' actual fib_addrtype token.
* docs: T9157: add prerouting raw fib type reference, fix backtick style
CodeRabbit feedback on #2186:
- the prose showed a "prerouting raw" example but the command
reference only listed forward/input/output/name filter forms, even
though fib.xml.i is also included from common-rule-ipv{4,6}-raw.xml.i
for that hook. Add the missing source/destination cfgcmd entries.
- MyST pages use single backticks for inline code, not double
(that's for embedded RST); fix the fib type prose accordingly.
* docs: T9157: update fib docs for rule-level lookup/match split
Companion vyos-1x PR #5372 moved "fib" from a leaf nested under
destination/source to a rule-level node with separate "lookup"
(source-address/destination-address) and "match route-type" children,
per l0crian1's review feedback - reserving room for mark/iif/oif
lookup keys and oif/oifname match results later (tracked under T5119)
without ever renaming what ships now. Update the CLI paths and
examples here to match.
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/configuration/firewall/ipv4.md | 51 | ||||
| -rw-r--r-- | docs/configuration/firewall/ipv6.md | 51 |
2 files changed, 102 insertions, 0 deletions
diff --git a/docs/configuration/firewall/ipv4.md b/docs/configuration/firewall/ipv4.md index 35d51c4e..767a22f3 100644 --- a/docs/configuration/firewall/ipv4.md +++ b/docs/configuration/firewall/ipv4.md @@ -491,6 +491,57 @@ set firewall ipv4 name FOO rule 100 destination address-mask 0.255.0.255 ::: ``` +```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 input filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 output filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 name \<name\> rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 prerouting raw rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv4 input filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv4 output filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv4 name \<name\> rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv4 prerouting raw rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] + +Match based on the result of a Forwarding Information Base (FIB) lookup +instead of the packet's literal address. `lookup` selects which address to +look up: `source-address` performs a reverse-path lookup, `destination-address` +a normal route lookup. `match route-type` compares the resulting address +type; both `lookup` and `match route-type` must be configured together. +`type` is one of `local`, `unicast`, `broadcast`, `multicast`, `anycast`, +`blackhole`, `unreachable` or `prohibit`. The `!` character negates the +match. + +This is particularly useful in `prerouting raw` to distinguish traffic +destined to the router itself from traffic being forwarded through it, +without needing to enumerate every locally configured address in a +network-group by hand: + +:::{code-block} none +set firewall ipv4 prerouting raw rule 1 fib lookup destination-address +set firewall ipv4 prerouting raw rule 1 fib match route-type local +set firewall ipv4 prerouting raw rule 1 action accept +set firewall ipv4 prerouting raw rule 2 action notrack +::: +``` + ```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> source fqdn \<fqdn\> ``` diff --git a/docs/configuration/firewall/ipv6.md b/docs/configuration/firewall/ipv6.md index 8347511f..a705e1e0 100644 --- a/docs/configuration/firewall/ipv6.md +++ b/docs/configuration/firewall/ipv6.md @@ -492,6 +492,57 @@ set firewall ipv6 forward filter rule 200 source address-mask ::ffff:ffff:ffff:f ::: ``` +```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv6 name \<name\> rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] +``` + +```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> fib match route-type [\<type\> | !\<type\>] + +Match based on the result of a Forwarding Information Base (FIB) lookup +instead of the packet's literal address. `lookup` selects which address to +look up: `source-address` performs a reverse-path lookup, `destination-address` +a normal route lookup. `match route-type` compares the resulting address +type; both `lookup` and `match route-type` must be configured together. +`type` is one of `local`, `unicast`, `broadcast`, `multicast`, `anycast`, +`blackhole`, `unreachable` or `prohibit`. The `!` character negates the +match. + +This is particularly useful in `prerouting raw` to distinguish traffic +destined to the router itself from traffic being forwarded through it, +without needing to enumerate every locally configured address in a +network-group by hand: + +:::{code-block} none +set firewall ipv6 prerouting raw rule 1 fib lookup destination-address +set firewall ipv6 prerouting raw rule 1 fib match route-type local +set firewall ipv6 prerouting raw rule 1 action accept +set firewall ipv6 prerouting raw rule 2 action notrack +::: +``` + ```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source fqdn \<fqdn\> ``` |
