File tree 3 files changed +32
-0
lines changed
interface-definitions/include/firewall
3 files changed +32
-0
lines changed Original file line number Diff line number Diff line change @@ -13,6 +13,14 @@ net.ipv4.conf.*.send_redirects = {{ 1 if global_options.send_redirects == 'enabl
13
13
net.ipv4.tcp_syncookies = {{ 1 if global_options.syn_cookies == 'enable' else 0 }}
14
14
net.ipv4.tcp_rfc1337 = {{ 1 if global_options.twa_hazards_protection == 'enable' else 0 }}
15
15
16
+ {% if global_options .apply_for_bridge is vyos_defined %}
17
+ net.bridge.bridge-nf-call-iptables = {{ 1 if global_options.apply_for_bridge.ipv4 is vyos_defined else 0 }}
18
+ net.bridge.bridge-nf-call-ip6tables = {{ 1 if global_options.apply_for_bridge.ipv6 is vyos_defined else 0 }}
19
+ {% else %}
20
+ net.bridge.bridge-nf-call-iptables =0
21
+ net.bridge.bridge-nf-call-ip6tables = 0
22
+ {% endif %}
23
+
16
24
## Timeout values:
17
25
net.netfilter.nf_conntrack_icmp_timeout = {{ global_options.timeout.icmp }}
18
26
net.netfilter.nf_conntrack_generic_timeout = {{ global_options.timeout.other }}
Original file line number Diff line number Diff line change 44
44
</properties>
45
45
<defaultValue>disable</defaultValue>
46
46
</leafNode>
47
+ <node name=" apply-for-bridge" >
48
+ <properties>
49
+ <help>Apply configured firewall rules to traffic switched by bridges</help>
50
+ </properties>
51
+ <children>
52
+ <leafNode name=" ipv4" >
53
+ <properties>
54
+ <help>Apply configured IPv4 firewall rules</help>
55
+ <valueless/>
56
+ </properties>
57
+ </leafNode>
58
+ <leafNode name=" ipv6" >
59
+ <properties>
60
+ <help>Apply configured IPv6 firewall rules</help>
61
+ <valueless/>
62
+ </properties>
63
+ </leafNode>
64
+ </children>
65
+ </node>
47
66
<leafNode name=" directed-broadcast" >
48
67
<properties>
49
68
<help>Policy for handling IPv4 directed broadcast forwarding on all interfaces</help>
Original file line number Diff line number Diff line change @@ -110,3 +110,8 @@ net.ipv6.conf.all.seg6_enabled = 0
110
110
net.ipv6.conf.default.seg6_enabled = 0
111
111
112
112
net.vrf.strict_mode = 1
113
+
114
+ # https://vyos.dev/T6570
115
+ # By default, do not forward traffic from bridge to IPvX layer
116
+ net.bridge.bridge-nf-call-iptables = 0
117
+ net.bridge.bridge-nf-call-ip6tables = 0
You can’t perform that action at this time.
0 commit comments