feat(firewall): report the gateway a filter rule policy-routes to
CI / test (3.10) (push) Successful in 57s
CI / test (3.11) (push) Successful in 35s
CI / test (3.12) (push) Successful in 33s
CI / test (3.10) (pull_request) Successful in 33s
CI / test (3.11) (pull_request) Successful in 31s
CI / test (3.12) (pull_request) Successful in 35s
CI / test (3.10) (push) Successful in 57s
CI / test (3.11) (push) Successful in 35s
CI / test (3.12) (push) Successful in 33s
CI / test (3.10) (pull_request) Successful in 33s
CI / test (3.11) (pull_request) Successful in 31s
CI / test (3.12) (pull_request) Successful in 35s
get_firewall_rules read searchRule but dropped the rule's gateway. A pass rule with a gateway hands what it matches to that gateway, local destinations included, so it does not reach a host on another internal network. Without the field a caller judging reachability reads a rule meant for internet traffic as a hole into every server: on the first real box, "pass UDP IOT -> any" via WAN_GW made 61 hosts look reachable from the IoT segment (netOrk #575). The rule dict gains "gateway", the gateway's name or "". It is an extra field like floating and interface_label; the generic diff compares a fixed field list and ignores it.
This commit is contained in:
@@ -2444,6 +2444,10 @@ class OPNsenseDriver(OPNsensePingMixin, FirewallDriver):
|
||||
* ``floating`` — bool, rule applies across all interfaces
|
||||
* ``interface_label`` — human-readable interface description
|
||||
* ``is_group`` — bool, interface is an interface group
|
||||
* ``gateway`` — the gateway a pass rule policy-routes to, or
|
||||
``""``. Such a rule sends what it matches to that gateway, local
|
||||
destinations included, so it does not reach a host on another
|
||||
internal network.
|
||||
"""
|
||||
try:
|
||||
resp = self._get("/api/firewall/filter/searchRule?current=1&rowCount=-1")
|
||||
@@ -2508,6 +2512,7 @@ class OPNsenseDriver(OPNsensePingMixin, FirewallDriver):
|
||||
"log": str(row.get("log", "0")) == "1",
|
||||
"enabled": str(row.get("enabled", "1")) == "1",
|
||||
"category": category,
|
||||
"gateway": row.get("gateway", "") or "",
|
||||
})
|
||||
|
||||
return sorted(result, key=lambda x: (x["floating"], x["is_group"], x["interface"], x["sequence"]))
|
||||
|
||||
Reference in New Issue
Block a user