summaryrefslogtreecommitdiff
path: root/tests/integration
diff options
context:
space:
mode:
authoromnom62 <75066712+omnom62@users.noreply.github.com>2026-08-27 04:00:17 +1000
committerGitHub <noreply@github.com>2026-08-26 21:00:17 +0300
commit433a274ce636573953f8a4be9c68743a2ed1d0a5 (patch)
treeda9e545f9ffdf50289c1b94580450a456177d74b /tests/integration
parent899a6bf7955592ec40670944a860a1bee97b432c (diff)
downloadvyos.vyos-433a274ce636573953f8a4be9c68743a2ed1d0a5.tar.gz
vyos.vyos-433a274ce636573953f8a4be9c68743a2ed1d0a5.zip
T8220: Firewall Zone Policy support (#447)
Add zone base policy firewall module
Diffstat (limited to 'tests/integration')
-rw-r--r--tests/integration/targets/vyos_firewall_global/tests/cli/_get_version.yaml17
-rw-r--r--tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg3
-rw-r--r--tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_5.cfg21
-rw-r--r--tests/integration/targets/vyos_firewall_global/vars/main.yaml65
-rw-r--r--tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml15
-rw-r--r--tests/integration/targets/vyos_firewall_global/vars/v1_5.yaml110
6 files changed, 227 insertions, 4 deletions
diff --git a/tests/integration/targets/vyos_firewall_global/tests/cli/_get_version.yaml b/tests/integration/targets/vyos_firewall_global/tests/cli/_get_version.yaml
index 2588b194..45bc2e18 100644
--- a/tests/integration/targets/vyos_firewall_global/tests/cli/_get_version.yaml
+++ b/tests/integration/targets/vyos_firewall_global/tests/cli/_get_version.yaml
@@ -8,6 +8,7 @@
- name: debug vyos_facts
debug:
var: vyos_facts
+ when: vyos_facts is not skipped
- name: pull version from facts
set_fact:
@@ -19,10 +20,20 @@
vyos_version: "{{ vyos_version }}.0"
when: vyos_version.count('.') == 1
-- name: include correct vars
+- name: report resolved VyOS version
+ debug:
+ msg: "Using VyOS version {{ vyos_version }} for this testcase"
+
+- name: include correct vars (pre-1.4.0)
include_vars: pre-v1_4.yaml
when: vyos_version is version('1.4.0', '<', version_type='semver')
-- name: include correct vars
+- name: include correct vars (1.4.x)
include_vars: v1_4.yaml
- when: vyos_version is version('1.4.0', '>=', version_type='semver')
+ when: >-
+ vyos_version is version('1.4.0', '>=', version_type='semver') and
+ vyos_version is version('1.5.0', '<', version_type='semver')
+
+- name: include correct vars (1.5.0+)
+ include_vars: v1_5.yaml
+ when: vyos_version is version('1.5.0', '>=', version_type='semver')
diff --git a/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg b/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg
index 41435780..882d9aaa 100644
--- a/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg
+++ b/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg
@@ -16,3 +16,6 @@ set firewall global-options state-policy established log 'enable'
set firewall global-options state-policy invalid action 'reject'
set firewall global-options syn-cookies 'enable'
set firewall global-options twa-hazards-protection 'enable'
+set firewall zone ZONE-TEST interface 'eth0.1234'
+set firewall zone ZONE-TEST description 'zone-test test description'
+set firewall zone ZONE-TEST default-action 'drop'
diff --git a/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_5.cfg b/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_5.cfg
new file mode 100644
index 00000000..88553c00
--- /dev/null
+++ b/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_5.cfg
@@ -0,0 +1,21 @@
+set firewall global-options all-ping 'enable'
+set firewall global-options broadcast-ping 'enable'
+set firewall group address-group MGMT-HOSTS address '192.0.1.1'
+set firewall group address-group MGMT-HOSTS address '192.0.1.3'
+set firewall group address-group MGMT-HOSTS address '192.0.1.5'
+set firewall group address-group MGMT-HOSTS description 'This group has the Management hosts address list'
+set firewall group network-group MGMT description 'This group has the Management network addresses'
+set firewall group network-group MGMT network '192.0.1.0/24'
+set firewall global-options ip-src-route 'enable'
+set firewall global-options log-martians 'enable'
+set firewall global-options receive-redirects 'disable'
+set firewall global-options send-redirects 'enable'
+set firewall global-options source-validation 'strict'
+set firewall global-options state-policy established action 'accept'
+set firewall global-options state-policy established log 'enable'
+set firewall global-options state-policy invalid action 'reject'
+set firewall global-options syn-cookies 'enable'
+set firewall global-options twa-hazards-protection 'enable'
+set firewall zone ZONE-TEST member interface 'eth0.1234'
+set firewall zone ZONE-TEST description 'zone-test test description'
+set firewall zone ZONE-TEST default-action 'drop'
diff --git a/tests/integration/targets/vyos_firewall_global/vars/main.yaml b/tests/integration/targets/vyos_firewall_global/vars/main.yaml
index 0f041b60..94bdca87 100644
--- a/tests/integration/targets/vyos_firewall_global/vars/main.yaml
+++ b/tests/integration/targets/vyos_firewall_global/vars/main.yaml
@@ -37,6 +37,12 @@ merged:
connection_type: invalid
twa_hazards_protection: true
validation: strict
+ zone:
+ - name: ZONE-TEST
+ default_action: drop
+ description: zone-test test description
+ interfaces:
+ - eth0.1234
config:
validation: strict
log_martians: true
@@ -70,6 +76,12 @@ merged:
description: This group has the Management network addresses
members:
- address: 192.0.1.0/24
+ zone:
+ - name: ZONE-TEST
+ description: zone-test test description
+ interfaces:
+ - eth0.1234
+
diff_config:
validation: strict
log_martians: true
@@ -139,7 +151,12 @@ populate:
members:
- address: 192.0.1.0/24
afi: ipv4
-
+ zone:
+ - name: ZONE-TEST
+ description: zone-test test description
+ interfaces:
+ - eth0.1234
+ default_action: drop
replaced:
commands: "{{ replaced_commands }}"
after:
@@ -183,6 +200,16 @@ replaced:
syn_cookies: true
twa_hazards_protection: true
validation: strict
+ zone:
+ - name: FZP-2
+ default_action: reject
+ default_log: true
+ description: This is the Firewall zone fzp2
+ interfaces:
+ - eth2
+ - lo
+ intra_zone_filtering:
+ action: accept
config:
validation: strict
log_martians: true
@@ -221,6 +248,16 @@ replaced:
description: This group has the Management network addresses
members:
- address: 192.0.1.0/24
+ zone:
+ - name: FZP-2
+ default_action: reject
+ default_log: true
+ description: This is the Firewall zone fzp2
+ interfaces:
+ - eth2
+ - lo
+ intra_zone_filtering:
+ action: accept
diff_config:
validation: strict
log_martians: true
@@ -300,6 +337,12 @@ rendered:
description: This group has the Management network addresses
members:
- address: 192.0.1.0/24
+ zone:
+ - name: ZONE-TEST
+ description: zone-test test description
+ interfaces:
+ - eth0.1234
+ default_action: drop
deleted:
commands: "{{ deleted_commands }}"
@@ -341,6 +384,16 @@ round_trip:
members:
- address: 192.0.1.0/24
afi: ipv4
+ zone:
+ - name: FZP-2
+ default_action: reject
+ default_log: true
+ description: This is the Firewall zone fzp2
+ interfaces:
+ - eth2
+ - lo
+ intra_zone_filtering:
+ action: accept
forward_config:
validation: strict
log_martians: true
@@ -374,6 +427,16 @@ round_trip:
description: This group has the Management network addresses
members:
- address: 192.0.1.0/24
+ zone:
+ - name: FZP-2
+ default_action: reject
+ default_log: true
+ description: This is the Firewall zone fzp2
+ interfaces:
+ - eth2
+ - lo
+ intra_zone_filtering:
+ action: accept
revert_config:
validation: strict
log_martians: false
diff --git a/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml b/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml
index 68773b2c..fffa93d8 100644
--- a/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml
+++ b/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml
@@ -20,6 +20,9 @@ merged_commands:
- set firewall global-options twa-hazards-protection 'enable'
- set firewall global-options syn-cookies 'enable'
- set firewall global-options source-validation 'strict'
+ - set firewall zone ZONE-TEST description 'zone-test test description'
+ - set firewall zone ZONE-TEST interface eth0.1234
+ - set firewall zone ZONE-TEST default-action 'drop'
populate_commands:
- set firewall global-options all-ping 'enable'
@@ -40,9 +43,12 @@ populate_commands:
- set firewall global-options state-policy invalid action 'reject'
- set firewall global-options syn-cookies 'enable'
- set firewall global-options twa-hazards-protection 'enable'
+ - set firewall zone ZONE-TEST interface 'eth0.1234'
+ - set firewall zone ZONE-TEST description 'zone-test test description'
replaced_commands:
- delete firewall group address-group MGMT-HOSTS
+ - delete firewall zone ZONE-TEST
- set firewall group address-group SALES-HOSTS address 192.0.2.1
- set firewall group address-group SALES-HOSTS address 192.0.2.2
- set firewall group address-group SALES-HOSTS address 192.0.2.3
@@ -52,6 +58,12 @@ replaced_commands:
- set firewall group address-group ENG-HOSTS address 192.0.3.2
- set firewall group address-group ENG-HOSTS description 'Sales office hosts address list'
- set firewall group address-group ENG-HOSTS
+ - set firewall zone FZP-2 default-action 'reject'
+ - set firewall zone FZP-2 default-log
+ - set firewall zone FZP-2 description 'This is the Firewall zone fzp2'
+ - set firewall zone FZP-2 interface eth2
+ - set firewall zone FZP-2 interface lo
+ - set firewall zone FZP-2 intra-zone-filtering action accept
rendered_commands:
- set firewall group address-group SALES-HOSTS address 192.0.2.1
@@ -78,6 +90,9 @@ rendered_commands:
- set firewall global-options twa-hazards-protection 'enable'
- set firewall global-options syn-cookies 'enable'
- set firewall global-options source-validation 'strict'
+ - set firewall zone ZONE-TEST interface eth0.1234
+ - set firewall zone ZONE-TEST description 'zone-test test description'
+ - set firewall zone ZONE-TEST default-action 'drop'
deleted_commands:
- "delete firewall"
diff --git a/tests/integration/targets/vyos_firewall_global/vars/v1_5.yaml b/tests/integration/targets/vyos_firewall_global/vars/v1_5.yaml
new file mode 100644
index 00000000..d32eacc7
--- /dev/null
+++ b/tests/integration/targets/vyos_firewall_global/vars/v1_5.yaml
@@ -0,0 +1,110 @@
+---
+merged_commands:
+ - set firewall group address-group MGMT-HOSTS address 192.0.1.1
+ - set firewall group address-group MGMT-HOSTS address 192.0.1.3
+ - set firewall group address-group MGMT-HOSTS address 192.0.1.5
+ - set firewall group address-group MGMT-HOSTS description 'This group has the Management hosts address list'
+ - set firewall group address-group MGMT-HOSTS
+ - set firewall group network-group MGMT network 192.0.1.0/24
+ - set firewall group network-group MGMT description 'This group has the Management network addresses'
+ - set firewall group network-group MGMT
+ - set firewall global-options ip-src-route 'enable'
+ - set firewall global-options receive-redirects 'disable'
+ - set firewall global-options send-redirects 'enable'
+ - set firewall global-options state-policy established action 'accept'
+ - set firewall global-options state-policy established log
+ - set firewall global-options state-policy invalid action 'reject'
+ - set firewall global-options broadcast-ping 'enable'
+ - set firewall global-options all-ping 'enable'
+ - set firewall global-options log-martians 'enable'
+ - set firewall global-options twa-hazards-protection 'enable'
+ - set firewall global-options syn-cookies 'enable'
+ - set firewall global-options source-validation 'strict'
+ - set firewall zone ZONE-TEST description 'zone-test test description'
+ - set firewall zone ZONE-TEST member interface eth0.1234
+ - set firewall zone ZONE-TEST default-action 'drop'
+
+populate_commands:
+ - set firewall global-options all-ping 'enable'
+ - set firewall global-options broadcast-ping 'enable'
+ - set firewall group address-group MGMT-HOSTS address '192.0.1.1'
+ - set firewall group address-group MGMT-HOSTS address '192.0.1.3'
+ - set firewall group address-group MGMT-HOSTS address '192.0.1.5'
+ - set firewall group address-group MGMT-HOSTS description 'This group has the Management hosts address list'
+ - set firewall group network-group MGMT description 'This group has the Management network addresses'
+ - set firewall group network-group MGMT network '192.0.1.0/24'
+ - set firewall global-options ip-src-route 'enable'
+ - set firewall global-options log-martians 'enable'
+ - set firewall global-options receive-redirects 'disable'
+ - set firewall global-options send-redirects 'enable'
+ - set firewall global-options source-validation 'strict'
+ - set firewall global-options state-policy established action 'accept'
+ - set firewall global-options state-policy established log
+ - set firewall global-options state-policy invalid action 'reject'
+ - set firewall global-options syn-cookies 'enable'
+ - set firewall global-options twa-hazards-protection 'enable'
+ - set firewall zone ZONE-TEST member interface 'eth0.1234'
+ - set firewall zone ZONE-TEST description 'zone-test test description'
+
+replaced_commands:
+ - delete firewall group address-group MGMT-HOSTS
+ - delete firewall zone ZONE-TEST
+ - set firewall group address-group SALES-HOSTS address 192.0.2.1
+ - set firewall group address-group SALES-HOSTS address 192.0.2.2
+ - set firewall group address-group SALES-HOSTS address 192.0.2.3
+ - set firewall group address-group SALES-HOSTS description 'Sales office hosts address list'
+ - set firewall group address-group SALES-HOSTS
+ - set firewall group address-group ENG-HOSTS address 192.0.3.1
+ - set firewall group address-group ENG-HOSTS address 192.0.3.2
+ - set firewall group address-group ENG-HOSTS description 'Sales office hosts address list'
+ - set firewall group address-group ENG-HOSTS
+ - set firewall zone FZP-2 default-action 'reject'
+ - set firewall zone FZP-2 default-log
+ - set firewall zone FZP-2 description 'This is the Firewall zone fzp2'
+ - set firewall zone FZP-2 member interface eth2
+ - set firewall zone FZP-2 member interface lo
+ - set firewall zone FZP-2 intra-zone-filtering action accept
+
+rendered_commands:
+ - set firewall group address-group SALES-HOSTS address 192.0.2.1
+ - set firewall group address-group SALES-HOSTS address 192.0.2.2
+ - set firewall group address-group SALES-HOSTS address 192.0.2.3
+ - set firewall group address-group SALES-HOSTS description 'Sales office hosts address list'
+ - set firewall group address-group SALES-HOSTS
+ - set firewall group address-group ENG-HOSTS address 192.0.3.1
+ - set firewall group address-group ENG-HOSTS address 192.0.3.2
+ - set firewall group address-group ENG-HOSTS description 'Sales office hosts address list'
+ - set firewall group address-group ENG-HOSTS
+ - set firewall group network-group MGMT network 192.0.1.0/24
+ - set firewall group network-group MGMT description 'This group has the Management network addresses'
+ - set firewall group network-group MGMT
+ - set firewall global-options ip-src-route 'enable'
+ - set firewall global-options receive-redirects 'disable'
+ - set firewall global-options send-redirects 'enable'
+ - set firewall global-options state-policy established action 'accept'
+ - set firewall global-options state-policy established log
+ - set firewall global-options state-policy invalid action 'reject'
+ - set firewall global-options broadcast-ping 'enable'
+ - set firewall global-options all-ping 'enable'
+ - set firewall global-options log-martians 'enable'
+ - set firewall global-options twa-hazards-protection 'enable'
+ - set firewall global-options syn-cookies 'enable'
+ - set firewall global-options source-validation 'strict'
+ - set firewall zone ZONE-TEST member interface eth0.1234
+ - set firewall zone ZONE-TEST description 'zone-test test description'
+ - set firewall zone ZONE-TEST default-action 'drop'
+
+deleted_commands:
+ - "delete firewall"
+
+parsed_config_file: "_parsed_config_1_5.cfg"
+
+replaced_diff:
+ - '+ network "1.1.1.1/32"'
+ - '- network "192.0.1.0/24"'
+
+merged_diff:
+ - '+ network "1.1.1.1/32"'
+
+deleted_diff:
+ - '- network "192.0.1.0/24"'