Page MenuHomeVyOS Platform

firewall: Allow both protocol names and numbers consistently
Closed, ResolvedPublic

Description

I would like to submit the following PR and need a Task ID. Could you please approve this?
https://github.com/Amiya-Corp/vyos-1x_fork/pull/1

The summary below is copied from my PR:

Change summary

Fixes inconsistent handling of protocol specification in firewall configuration. When users specify protocol by IANA number (e.g., 6 for TCP), certain options like port specifications, TCP flags, and GRE settings would fail validation because the checks compare against string names.

This PR normalizes protocol numbers to their string names early in verify_rule() so all subsequent validations work consistently.

Example of the bug:

# This works
set firewall ipv4 name RULE rule 1 protocol 6

# This fails with "Protocol must be tcp, udp, or tcp_udp when specifying a port"
set firewall ipv4 name RULE rule 2 protocol 6
set firewall ipv4 name RULE rule 2 destination port 443

Types of changes

  • Bug fix (non-breaking change which fixes an issue)

Related Task(s)

<!-- N/A -->

Related PR(s)

<!-- N/A -->

Component(s) name

src/conf_mode/firewall.py

How to test / Smoketest result

After this fix, all combinations work correctly. Each test case includes both Protocol Number and Protocol Name variants.

1. Port specification (TCP)

# Numeric protocol (6 = TCP)
set firewall ipv4 name RULE rule 1 action accept
set firewall ipv4 name RULE rule 1 protocol 6
set firewall ipv4 name RULE rule 1 destination port 443

# String protocol
set firewall ipv4 name RULE rule 2 action accept
set firewall ipv4 name RULE rule 2 protocol tcp
set firewall ipv4 name RULE rule 2 destination port 443

2. Port specification (UDP)

# Numeric protocol (17 = UDP)
set firewall ipv4 name RULE rule 3 action accept
set firewall ipv4 name RULE rule 3 protocol 17
set firewall ipv4 name RULE rule 3 destination port 53

# String protocol
set firewall ipv4 name RULE rule 4 action accept
set firewall ipv4 name RULE rule 4 protocol udp
set firewall ipv4 name RULE rule 4 destination port 53

3. TCP flags

# Numeric protocol (6 = TCP)
set firewall ipv4 name RULE rule 5 action accept
set firewall ipv4 name RULE rule 5 protocol 6
set firewall ipv4 name RULE rule 5 tcp flags syn

# String protocol
set firewall ipv4 name RULE rule 6 action accept
set firewall ipv4 name RULE rule 6 protocol tcp
set firewall ipv4 name RULE rule 6 tcp flags syn

4. GRE matching

# Numeric protocol (47 = GRE)
set firewall ipv4 name RULE rule 7 action accept
set firewall ipv4 name RULE rule 7 protocol 47
set firewall ipv4 name RULE rule 7 gre flags checksum unset
set firewall ipv4 name RULE rule 7 gre key 100

# String protocol
set firewall ipv4 name RULE rule 8 action accept
set firewall ipv4 name RULE rule 8 protocol gre
set firewall ipv4 name RULE rule 8 gre flags checksum unset
set firewall ipv4 name RULE rule 8 gre key 100

5. synproxy action

# Numeric protocol (6 = TCP)
set firewall ipv4 name RULE rule 9 action synproxy
set firewall ipv4 name RULE rule 9 protocol 6
set firewall ipv4 name RULE rule 9 synproxy tcp mss 1460

# String protocol
set firewall ipv4 name RULE rule 10 action synproxy
set firewall ipv4 name RULE rule 10 protocol tcp
set firewall ipv4 name RULE rule 10 synproxy tcp mss 1460

6. ICMP protocol (IPv4)

# Numeric protocol (1 = ICMP)
set firewall ipv4 name RULE rule 11 action accept
set firewall ipv4 name RULE rule 11 protocol 1
set firewall ipv4 name RULE rule 11 icmp type-name echo-request

# String protocol
set firewall ipv4 name RULE rule 12 action accept
set firewall ipv4 name RULE rule 12 protocol icmp
set firewall ipv4 name RULE rule 12 icmp type-name echo-request

7. ICMPv6 protocol (IPv6)

# Numeric protocol (58 = ICMPv6)
set firewall ipv6 name RULE6 rule 1 action accept
set firewall ipv6 name RULE6 rule 1 protocol 58
set firewall ipv6 name RULE6 rule 1 icmpv6 type-name echo-request

# String protocol
set firewall ipv6 name RULE6 rule 2 action accept
set firewall ipv6 name RULE6 rule 2 protocol ipv6-icmp
set firewall ipv6 name RULE6 rule 2 icmpv6 type-name echo-request

Link to Devin run: https://app.devin.ai/sessions/5a7eed8e95a944fdb70ed1183be15929
Requested by: @Nyandorew

Details

Version
vyos-1x: 1.5.0
Is it a breaking change?
Stricter validation
Issue type
Bug (incorrect behavior)

Event Timeline

Y-ANDOU triaged this task as Normal priority.
Y-ANDOU created this object in space S1 VyOS Public.

Hi, this PR implements T8247. Merging is blocked by branch protection and requires 2 approving reviews from reviewers with write access.
Could a maintainer please review and approve? Thanks!
PR: https://github.com/vyos/vyos-1x/pull/4978

Viacheslav changed the task status from Open to In progress.Feb 10 2026, 9:42 AM
Viacheslav assigned this task to Y-ANDOU.
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.