diff --git a/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg b/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg index e9a3c7d9..13237bd8 100644 --- a/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg +++ b/tests/integration/targets/vyos_firewall_global/tests/cli/_parsed_config_1_4.cfg @@ -1,18 +1,22 @@ set firewall global-options all-ping 'enable' set firewall global-options broadcast-ping 'enable' set firewall group address-group MGMT-HOSTS address '192.0.1.1' set firewall group address-group MGMT-HOSTS address '192.0.1.3' set firewall group address-group MGMT-HOSTS address '192.0.1.5' set firewall group address-group MGMT-HOSTS description 'This group has the Management hosts address list' set firewall group network-group MGMT description 'This group has the Management network addresses' set firewall group network-group MGMT network '192.0.1.0/24' set firewall global-options ip-src-route 'enable' set firewall global-options log-martians 'enable' set firewall global-options receive-redirects 'disable' set firewall global-options send-redirects 'enable' set firewall global-options source-validation 'strict' set firewall global-options state-policy established action 'accept' set firewall global-options state-policy established log 'enable' # set firewall global-options state-policy invalid acti. .on 'reject' set firewall global-options syn-cookies 'enable' set firewall global-options twa-hazards-protection 'enable' +set firewall global-options twa-hazards-protection 'enable' +set firewall zone ZONE-TEST interface 'eth0.1234' +set firewall zone ZONE-TEST description 'zone-test test description' +set firewall zone ZONE-TEST default-action 'drop' diff --git a/tests/integration/targets/vyos_firewall_global/vars/main.yaml b/tests/integration/targets/vyos_firewall_global/vars/main.yaml index 5908083d..a035ae0a 100644 --- a/tests/integration/targets/vyos_firewall_global/vars/main.yaml +++ b/tests/integration/targets/vyos_firewall_global/vars/main.yaml @@ -1,384 +1,447 @@ --- merged: before: [] commands: "{{ merged_commands }}" after: group: address_group: - members: - address: 192.0.1.1 - address: 192.0.1.3 - address: 192.0.1.5 description: This group has the Management hosts address list name: MGMT-HOSTS afi: ipv4 network_group: - members: - address: 192.0.1.0/24 description: This group has the Management network addresses name: MGMT afi: ipv4 log_martians: true ping: all: true broadcast: true route_redirects: - afi: ipv4 icmp_redirects: receive: false send: true ip_src_route: true syn_cookies: true state_policy: - action: accept connection_type: established log: true - # - action: reject - # connection_type: invalid + - action: reject + connection_type: invalid twa_hazards_protection: true validation: strict + zone: + - name: ZONE-TEST + default_action: drop + description: zone-test test description + interfaces: + - eth0.1234 config: validation: strict log_martians: true syn_cookies: true twa_hazards_protection: true ping: all: true broadcast: true state_policy: - connection_type: established action: accept log: true - # - connection_type: invalid - # action: reject + - connection_type: invalid + action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: MGMT-HOSTS description: This group has the Management hosts address list members: - address: 192.0.1.1 - address: 192.0.1.3 - address: 192.0.1.5 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 192.0.1.0/24 + zone: + - name: ZONE-TEST + description: zone-test test description + interfaces: + - eth0.1234 + diff_config: validation: strict log_martians: true syn_cookies: true twa_hazards_protection: true ping: all: true broadcast: true state_policy: - connection_type: established action: accept log: true - # - connection_type: invalid - # action: reject + - connection_type: invalid + action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: MGMT-HOSTS description: This group has the Management hosts address list members: - address: 192.0.1.1 - address: 192.0.1.3 - address: 192.0.1.5 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 1.1.1.1/32 populate: validation: strict log_martians: true syn_cookies: true twa_hazards_protection: true ping: all: true broadcast: true state_policy: - connection_type: established action: accept log: true - # - connection_type: invalid - # action: reject + - connection_type: invalid + action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: MGMT-HOSTS description: This group has the Management hosts address list members: - address: 192.0.1.1 - address: 192.0.1.3 - address: 192.0.1.5 afi: ipv4 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 192.0.1.0/24 afi: ipv4 - + zone: + - name: ZONE-TEST + description: zone-test test description + interfaces: + - eth0.1234 + default_action: drop replaced: commands: "{{ replaced_commands }}" after: group: address_group: - members: - address: 192.0.3.1 - address: 192.0.3.2 description: Sales office hosts address list name: ENG-HOSTS afi: ipv4 - members: - address: 192.0.2.1 - address: 192.0.2.2 - address: 192.0.2.3 description: Sales office hosts address list name: SALES-HOSTS afi: ipv4 network_group: - members: - address: 192.0.1.0/24 description: This group has the Management network addresses name: MGMT afi: ipv4 log_martians: true ping: all: true broadcast: true route_redirects: - afi: ipv4 icmp_redirects: receive: false send: true ip_src_route: true state_policy: - action: accept connection_type: established log: true - # - action: reject - # connection_type: invalid + - action: reject + connection_type: invalid syn_cookies: true twa_hazards_protection: true validation: strict + zone: + - name: FZP-2 + default_action: reject + default_log: true + description: This is the Firewall zone fzp2 + interfaces: + - eth2 + - lo0 + intra_zone_filtering: + action: accept config: validation: strict log_martians: true syn_cookies: true twa_hazards_protection: true ping: all: true broadcast: true state_policy: - connection_type: established action: accept log: true - # - connection_type: invalid - # action: reject + - connection_type: invalid + action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: SALES-HOSTS description: Sales office hosts address list members: - address: 192.0.2.1 - address: 192.0.2.2 - address: 192.0.2.3 - name: ENG-HOSTS description: Sales office hosts address list members: - address: 192.0.3.1 - address: 192.0.3.2 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 192.0.1.0/24 + zone: + - name: FZP-2 + default_action: reject + default_log: true + description: This is the Firewall zone fzp2 + interfaces: + - eth2 + - lo0 + intra_zone_filtering: + action: accept diff_config: validation: strict log_martians: true syn_cookies: true twa_hazards_protection: true ping: all: true broadcast: true state_policy: - connection_type: established action: accept log: true - # - connection_type: invalid - # action: reject + - connection_type: invalid + action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: SALES-HOSTS description: Sales office hosts address list members: - address: 192.0.2.1 - address: 192.0.2.2 - address: 192.0.2.3 - name: ENG-HOSTS description: Sales office hosts address list members: - address: 192.0.3.1 - address: 192.0.3.2 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 1.1.1.1/32 rendered: commands: "{{ rendered_commands }}" config: validation: strict log_martians: true syn_cookies: true twa_hazards_protection: true ping: all: true broadcast: true state_policy: - connection_type: established action: accept log: true - connection_type: invalid action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: SALES-HOSTS description: Sales office hosts address list members: - address: 192.0.2.1 - address: 192.0.2.2 - address: 192.0.2.3 - name: ENG-HOSTS description: Sales office hosts address list members: - address: 192.0.3.1 - address: 192.0.3.2 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 192.0.1.0/24 + zone: + - name: ZONE-TEST + description: zone-test test description + interfaces: + - eth0.1234 + default_action: drop deleted: commands: "{{ deleted_commands }}" after: [] round_trip: after: validation: strict log_martians: false syn_cookies: false twa_hazards_protection: false ping: all: false broadcast: false state_policy: - connection_type: established action: accept log: true - # - connection_type: invalid - # action: reject + - connection_type: invalid + action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: MGMT-HOSTS description: This group has the Management hosts address list members: - address: 192.0.1.1 - address: 192.0.1.3 - address: 192.0.1.5 afi: ipv4 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 192.0.1.0/24 afi: ipv4 + zone: + - name: FZP-2 + default_action: reject + default_log: true + description: This is the Firewall zone fzp2 + interfaces: + - eth2 + - lo0 + intra_zone_filtering: + action: accept forward_config: validation: strict log_martians: true syn_cookies: true twa_hazards_protection: true ping: all: true broadcast: true state_policy: - connection_type: established action: accept log: true - # - connection_type: invalid - # action: reject + - connection_type: invalid + action: reject route_redirects: - afi: ipv4 ip_src_route: true icmp_redirects: send: true receive: false group: address_group: - name: MGMT-HOSTS description: This group has the Management hosts address list members: - address: 192.0.1.1 - address: 192.0.1.3 - address: 192.0.1.5 network_group: - name: MGMT description: This group has the Management network addresses members: - address: 192.0.1.0/24 + zone: + - name: FZP-2 + default_action: reject + default_log: true + description: This is the Firewall zone fzp2 + interfaces: + - eth2 + - lo0 + intra_zone_filtering: + action: accept revert_config: validation: strict log_martians: false syn_cookies: false twa_hazards_protection: false ping: all: false broadcast: false diff --git a/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml b/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml index dbbb2065..0833c200 100644 --- a/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml +++ b/tests/integration/targets/vyos_firewall_global/vars/v1_4.yaml @@ -1,95 +1,110 @@ --- merged_commands: - set firewall group address-group MGMT-HOSTS address 192.0.1.1 - set firewall group address-group MGMT-HOSTS address 192.0.1.3 - set firewall group address-group MGMT-HOSTS address 192.0.1.5 - set firewall group address-group MGMT-HOSTS description 'This group has the Management hosts address list' - set firewall group address-group MGMT-HOSTS - set firewall group network-group MGMT network 192.0.1.0/24 - set firewall group network-group MGMT description 'This group has the Management network addresses' - set firewall group network-group MGMT - set firewall global-options ip-src-route 'enable' - set firewall global-options receive-redirects 'disable' - set firewall global-options send-redirects 'enable' - set firewall global-options state-policy established action 'accept' - set firewall global-options state-policy established log - # - set firewall global-options state-policy invalid action 'reject' + - set firewall global-options state-policy invalid action 'reject' - set firewall global-options broadcast-ping 'enable' - set firewall global-options all-ping 'enable' - set firewall global-options log-martians 'enable' - set firewall global-options twa-hazards-protection 'enable' - set firewall global-options syn-cookies 'enable' - set firewall global-options source-validation 'strict' + - set firewall zone ZONE-TEST description 'zone-test test description' + - set firewall zone ZONE-TEST interface eth0.1234 + - set firewall zone ZONE-TEST default-action 'drop' populate_commands: - set firewall global-options all-ping 'enable' - set firewall global-options broadcast-ping 'enable' - set firewall group address-group MGMT-HOSTS address '192.0.1.1' - set firewall group address-group MGMT-HOSTS address '192.0.1.3' - set firewall group address-group MGMT-HOSTS address '192.0.1.5' - set firewall group address-group MGMT-HOSTS description 'This group has the Management hosts address list' - set firewall group network-group MGMT description 'This group has the Management network addresses' - set firewall group network-group MGMT network '192.0.1.0/24' - set firewall global-options ip-src-route 'enable' - set firewall global-options log-martians 'enable' - set firewall global-options receive-redirects 'disable' - set firewall global-options send-redirects 'enable' - set firewall global-options source-validation 'strict' - set firewall global-options state-policy established action 'accept' - set firewall global-options state-policy established log - # - set firewall global-options state-policy invalid action 'reject' + - set firewall global-options state-policy invalid action 'reject' - set firewall global-options syn-cookies 'enable' - set firewall global-options twa-hazards-protection 'enable' + - set firewall zone ZONE-TEST interface 'eth0.1234' + - set firewall zone ZONE-TEST description 'zone-test test description' replaced_commands: - delete firewall group address-group MGMT-HOSTS + - delete firewall zone ZONE-TEST - set firewall group address-group SALES-HOSTS address 192.0.2.1 - set firewall group address-group SALES-HOSTS address 192.0.2.2 - set firewall group address-group SALES-HOSTS address 192.0.2.3 - set firewall group address-group SALES-HOSTS description 'Sales office hosts address list' - set firewall group address-group SALES-HOSTS - set firewall group address-group ENG-HOSTS address 192.0.3.1 - set firewall group address-group ENG-HOSTS address 192.0.3.2 - set firewall group address-group ENG-HOSTS description 'Sales office hosts address list' - set firewall group address-group ENG-HOSTS + - set firewall zone FZP-2 default-action 'reject' + - set firewall zone FZP-2 default-log + - set firewall zone FZP-2 description 'This is the Firewall zone fzp2' + - set firewall zone FZP-2 interface eth2 + - set firewall zone FZP-2 interface lo0 + - set firewall zone FZP-2 intra-zone-filtering action accept rendered_commands: - set firewall group address-group SALES-HOSTS address 192.0.2.1 - set firewall group address-group SALES-HOSTS address 192.0.2.2 - set firewall group address-group SALES-HOSTS address 192.0.2.3 - set firewall group address-group SALES-HOSTS description 'Sales office hosts address list' - set firewall group address-group SALES-HOSTS - set firewall group address-group ENG-HOSTS address 192.0.3.1 - set firewall group address-group ENG-HOSTS address 192.0.3.2 - set firewall group address-group ENG-HOSTS description 'Sales office hosts address list' - set firewall group address-group ENG-HOSTS - set firewall group network-group MGMT network 192.0.1.0/24 - set firewall group network-group MGMT description 'This group has the Management network addresses' - set firewall group network-group MGMT - set firewall global-options ip-src-route 'enable' - set firewall global-options receive-redirects 'disable' - set firewall global-options send-redirects 'enable' - set firewall global-options state-policy established action 'accept' - set firewall global-options state-policy established log - set firewall global-options state-policy invalid action 'reject' - set firewall global-options broadcast-ping 'enable' - set firewall global-options all-ping 'enable' - set firewall global-options log-martians 'enable' - set firewall global-options twa-hazards-protection 'enable' - set firewall global-options syn-cookies 'enable' - set firewall global-options source-validation 'strict' + - set firewall zone ZONE-TEST interface eth0.1234 + - set firewall zone ZONE-TEST description 'zone-test test description' + - set firewall zone ZONE-TEST default-action 'drop' deleted_commands: - "delete firewall" parsed_config_file: "_parsed_config_1_4.cfg" replaced_diff: - '+ network "1.1.1.1/32"' - '- network "192.0.1.0/24"' merged_diff: - '+ network "1.1.1.1/32"' deleted_diff: - '- network "192.0.1.0/24"'