feat(firewall): report the gateway a filter rule policy-routes to #7

Merged
christianmanivong merged 1 commits from feat/firewall-rule-gateway into master 2026-10-05 04:47:56 +00:00
Owner

get_firewall_rules now reports gateway: the gateway a filter rule policy-routes to, or "".

A pass rule with a gateway hands what it matches to that gateway, local destinations included. netOrk's segmentation evaluation needs this to tell "internet only via WAN_GW" from "reachable from the IoT segment". On the first real box, pass UDP IOT -> any via WAN_GW made 61 hosts look reachable (NetOrk/netork#575).

  • It's an extra field, like floating and interface_label. diff_firewall_rules compares a fixed field list, so it doesn't change any diff.
  • Tests: tests/unit/test_firewall_rules.py covers a gateway, an empty one, and a row without the field (290 passed).

napalm-opnsense is unpinned in netOrk's vendor-drivers.txt, so the next engine image picks this up once it is merged.

`get_firewall_rules` now reports `gateway`: the gateway a filter rule policy-routes to, or `""`. A pass rule with a gateway hands what it matches to that gateway, local destinations included. netOrk's segmentation evaluation needs this to tell "internet only via WAN_GW" from "reachable from the IoT segment". On the first real box, `pass UDP IOT -> any` via `WAN_GW` made 61 hosts look reachable (NetOrk/netork#575). - It's an extra field, like `floating` and `interface_label`. `diff_firewall_rules` compares a fixed field list, so it doesn't change any diff. - Tests: `tests/unit/test_firewall_rules.py` covers a gateway, an empty one, and a row without the field (290 passed). napalm-opnsense is unpinned in netOrk's `vendor-drivers.txt`, so the next engine image picks this up once it is merged.
christianmanivong added 1 commit 2026-10-05 04:34:58 +00:00
feat(firewall): report the gateway a filter rule policy-routes to
CI / test (3.10) (push) Successful in 57s
CI / test (3.11) (push) Successful in 35s
CI / test (3.12) (push) Successful in 33s
CI / test (3.10) (pull_request) Successful in 33s
CI / test (3.11) (pull_request) Successful in 31s
CI / test (3.12) (pull_request) Successful in 35s
fffdd95e6a
get_firewall_rules read searchRule but dropped the rule's gateway. A pass
rule with a gateway hands what it matches to that gateway, local
destinations included, so it does not reach a host on another internal
network. Without the field a caller judging reachability reads a rule meant
for internet traffic as a hole into every server: on the first real box,
"pass UDP IOT -> any" via WAN_GW made 61 hosts look reachable from the IoT
segment (netOrk #575).

The rule dict gains "gateway", the gateway's name or "". It is an extra
field like floating and interface_label; the generic diff compares a fixed
field list and ignores it.
christianmanivong merged commit 0f172f02c0 into master 2026-10-05 04:47:56 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: NAPALM/napalm-opnsense#7