get_firewall_rules now reports gateway: the gateway a filter rule policy-routes to, or "".
A pass rule with a gateway hands what it matches to that gateway, local destinations included. netOrk's segmentation evaluation needs this to tell "internet only via WAN_GW" from "reachable from the IoT segment". On the first real box, pass UDP IOT -> any via WAN_GW made 61 hosts look reachable (NetOrk/netork#575).
It's an extra field, like floating and interface_label. diff_firewall_rules compares a fixed field list, so it doesn't change any diff.
Tests: tests/unit/test_firewall_rules.py covers a gateway, an empty one, and a row without the field (290 passed).
napalm-opnsense is unpinned in netOrk's vendor-drivers.txt, so the next engine image picks this up once it is merged.
`get_firewall_rules` now reports `gateway`: the gateway a filter rule policy-routes to, or `""`.
A pass rule with a gateway hands what it matches to that gateway, local destinations included. netOrk's segmentation evaluation needs this to tell "internet only via WAN_GW" from "reachable from the IoT segment". On the first real box, `pass UDP IOT -> any` via `WAN_GW` made 61 hosts look reachable (NetOrk/netork#575).
- It's an extra field, like `floating` and `interface_label`. `diff_firewall_rules` compares a fixed field list, so it doesn't change any diff.
- Tests: `tests/unit/test_firewall_rules.py` covers a gateway, an empty one, and a row without the field (290 passed).
napalm-opnsense is unpinned in netOrk's `vendor-drivers.txt`, so the next engine image picks this up once it is merged.
get_firewall_rules read searchRule but dropped the rule's gateway. A pass
rule with a gateway hands what it matches to that gateway, local
destinations included, so it does not reach a host on another internal
network. Without the field a caller judging reachability reads a rule meant
for internet traffic as a hole into every server: on the first real box,
"pass UDP IOT -> any" via WAN_GW made 61 hosts look reachable from the IoT
segment (netOrk #575).
The rule dict gains "gateway", the gateway's name or "". It is an extra
field like floating and interface_label; the generic diff compares a fixed
field list and ignores it.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
get_firewall_rulesnow reportsgateway: the gateway a filter rule policy-routes to, or"".A pass rule with a gateway hands what it matches to that gateway, local destinations included. netOrk's segmentation evaluation needs this to tell "internet only via WAN_GW" from "reachable from the IoT segment". On the first real box,
pass UDP IOT -> anyviaWAN_GWmade 61 hosts look reachable (NetOrk/netork#575).floatingandinterface_label.diff_firewall_rulescompares a fixed field list, so it doesn't change any diff.tests/unit/test_firewall_rules.pycovers a gateway, an empty one, and a row without the field (290 passed).napalm-opnsense is unpinned in netOrk's
vendor-drivers.txt, so the next engine image picks this up once it is merged.