From 75d44591ed7cd7b6246f5d5f48722d70d11f7b98 Mon Sep 17 00:00:00 2001 From: Ruben Herold Date: Fri, 25 Sep 2026 15:37:27 +0200 Subject: docs: T9157: document firewall fib-type match (#2186) * docs: T9157: document firewall fib-type match Companion doc entry for vyos/vyos-1x#5372, which adds "fib-type" as a source/destination match option (nftables' fib daddr/saddr type expression) for forward/input/output/name rule sets, ipv4 and ipv6. * docs: T9157: update fib match docs for fib-type -> fib type rename Companion vyos-1x PR #5372 restructured the "fib-type" leaf into a "fib" node with a "type" child (following feedback from l0crian1 and sarthurdev to reserve the "fib" namespace for a possible future lookup/match concatenation feature, tracked separately under T5119). Update the CLI paths and examples here to match, and fix "prohibited" to "prohibit" to match nftables' actual fib_addrtype token. * docs: T9157: add prerouting raw fib type reference, fix backtick style CodeRabbit feedback on #2186: - the prose showed a "prerouting raw" example but the command reference only listed forward/input/output/name filter forms, even though fib.xml.i is also included from common-rule-ipv{4,6}-raw.xml.i for that hook. Add the missing source/destination cfgcmd entries. - MyST pages use single backticks for inline code, not double (that's for embedded RST); fix the fib type prose accordingly. * docs: T9157: update fib docs for rule-level lookup/match split Companion vyos-1x PR #5372 moved "fib" from a leaf nested under destination/source to a rule-level node with separate "lookup" (source-address/destination-address) and "match route-type" children, per l0crian1's review feedback - reserving room for mark/iif/oif lookup keys and oif/oifname match results later (tracked under T5119) without ever renaming what ships now. Update the CLI paths and examples here to match. --- docs/configuration/firewall/ipv4.md | 51 +++++++++++++++++++++++++++++++++++++ docs/configuration/firewall/ipv6.md | 51 +++++++++++++++++++++++++++++++++++++ 2 files changed, 102 insertions(+) (limited to 'docs') diff --git a/docs/configuration/firewall/ipv4.md b/docs/configuration/firewall/ipv4.md index 35d51c4e..767a22f3 100644 --- a/docs/configuration/firewall/ipv4.md +++ b/docs/configuration/firewall/ipv4.md @@ -491,6 +491,57 @@ set firewall ipv4 name FOO rule 100 destination address-mask 0.255.0.255 ::: ``` +```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 input filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 output filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 name \ rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 prerouting raw rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv4 input filter rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv4 output filter rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv4 name \ rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv4 prerouting raw rule \<1-999999\> fib match route-type [\ | !\] + +Match based on the result of a Forwarding Information Base (FIB) lookup +instead of the packet's literal address. `lookup` selects which address to +look up: `source-address` performs a reverse-path lookup, `destination-address` +a normal route lookup. `match route-type` compares the resulting address +type; both `lookup` and `match route-type` must be configured together. +`type` is one of `local`, `unicast`, `broadcast`, `multicast`, `anycast`, +`blackhole`, `unreachable` or `prohibit`. The `!` character negates the +match. + +This is particularly useful in `prerouting raw` to distinguish traffic +destined to the router itself from traffic being forwarded through it, +without needing to enumerate every locally configured address in a +network-group by hand: + +:::{code-block} none +set firewall ipv4 prerouting raw rule 1 fib lookup destination-address +set firewall ipv4 prerouting raw rule 1 fib match route-type local +set firewall ipv4 prerouting raw rule 1 action accept +set firewall ipv4 prerouting raw rule 2 action notrack +::: +``` + ```{cfgcmd} set firewall ipv4 forward filter rule \<1-999999\> source fqdn \ ``` diff --git a/docs/configuration/firewall/ipv6.md b/docs/configuration/firewall/ipv6.md index 8347511f..a705e1e0 100644 --- a/docs/configuration/firewall/ipv6.md +++ b/docs/configuration/firewall/ipv6.md @@ -492,6 +492,57 @@ set firewall ipv6 forward filter rule 200 source address-mask ::ffff:ffff:ffff:f ::: ``` +```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 name \ rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> fib lookup [source-address | destination-address] +``` + +```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv6 input filter rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv6 output filter rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv6 name \ rule \<1-999999\> fib match route-type [\ | !\] +``` + +```{cfgcmd} set firewall ipv6 prerouting raw rule \<1-999999\> fib match route-type [\ | !\] + +Match based on the result of a Forwarding Information Base (FIB) lookup +instead of the packet's literal address. `lookup` selects which address to +look up: `source-address` performs a reverse-path lookup, `destination-address` +a normal route lookup. `match route-type` compares the resulting address +type; both `lookup` and `match route-type` must be configured together. +`type` is one of `local`, `unicast`, `broadcast`, `multicast`, `anycast`, +`blackhole`, `unreachable` or `prohibit`. The `!` character negates the +match. + +This is particularly useful in `prerouting raw` to distinguish traffic +destined to the router itself from traffic being forwarded through it, +without needing to enumerate every locally configured address in a +network-group by hand: + +:::{code-block} none +set firewall ipv6 prerouting raw rule 1 fib lookup destination-address +set firewall ipv6 prerouting raw rule 1 fib match route-type local +set firewall ipv6 prerouting raw rule 1 action accept +set firewall ipv6 prerouting raw rule 2 action notrack +::: +``` + ```{cfgcmd} set firewall ipv6 forward filter rule \<1-999999\> source fqdn \ ``` -- cgit v1.2.3