Skip to content

[caclmgrd] Heuristically determine whether ACL is IPv4 or IPv6, use iptables/ip6tables accordingly#1767

Merged
lguohan merged 2 commits intosonic-net:masterfrom
jleveque:cacl_v6
Jun 5, 2018
Merged

[caclmgrd] Heuristically determine whether ACL is IPv4 or IPv6, use iptables/ip6tables accordingly#1767
lguohan merged 2 commits intosonic-net:masterfrom
jleveque:cacl_v6

Conversation

@jleveque
Copy link
Contributor

@jleveque jleveque commented Jun 5, 2018

No description provided.

@jleveque jleveque self-assigned this Jun 5, 2018
@jleveque jleveque requested a review from lguohan June 5, 2018 01:58
# do it now. We determine heuristically based on whether the
# src IP is a v4 or v6 address.
if not table_ip_version:
if "SRC_IP" in rule_props and rule_props["SRC_IP"]:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if SRC_IP is not specified, does the ACL need to be applied to both iptables AND ip6tables?

Copy link
Contributor Author

@jleveque jleveque Jun 5, 2018

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No. We assume that with regard to service ACLS, IPv4 and IPv6 ACLs will be stored in separate tables. If a rule needs to be applied to both IPv4 and IPv6, it needs to be specified twice, one in a v4 table and once in a v6 table.

However, I realize that this implementation also assumes that the first rule in the table will always have a SRC_IP defined. If not, then the table will be assumed to be v4, whether or not subsequent rules have v6 SRC_IPs. This may not always be true. #Fixed in commit 250155c

@lguohan lguohan merged commit 711be8f into sonic-net:master Jun 5, 2018
lguohan pushed a commit that referenced this pull request Jun 5, 2018
…ptables/ip6tables accordingly (#1767)

* [caclmgrd] Heuristically determine whether ACL is IPv4 or IPv6, use iptables/ip6tables accordingly

* Check all rules in table until we find one with a SRC_IP
@jleveque jleveque deleted the cacl_v6 branch June 5, 2018 16:33
theasianpianist pushed a commit to theasianpianist/sonic-buildimage that referenced this pull request Feb 5, 2022
…t cleanup fix (sonic-net#1767)

* Clean up: Remove rif in test_portchannel.py

Signed-off-by: Wenda Ni <wonda.ni@gmail.com>
noaOrMlnx pushed a commit to noaOrMlnx/sonic-buildimage that referenced this pull request Nov 24, 2025
…C448O16, Arista-7060X6-64PE-B-C512S2 (sonic-net#1767)

<!--
 Please make sure you've read and understood our contributing guidelines:
 https://github.com/Azure/SONiC/blob/gh-pages/CONTRIBUTING.md

 failure_prs.log Make sure all your commits include a signature generated with `git commit -s` **

 If this is a bug fix, make sure your description includes "fixes #xxxx", or
 "closes #xxxx" or "resolves #xxxx"

 Please provide the following information:
-->

#### Why I did it
The convention for buffer profiles is that they're lower case, which some test cases expect.

##### Work item tracking
- Microsoft ADO **(number only)**:

#### How I did it

#### How to verify it

<!--
If PR needs to be backported, then the PR must be tested against the base branch and the earliest backport release branch and provide tested image version on these two branches. For example, if the PR is requested for master, 202211 and 202012, then the requester needs to provide test results on master and 202012.
-->

#### Which release branch to backport (provide reason below if selected)

<!--
- Note we only backport fixes to a release branch, *not* features!
- Please also provide a reason for the backporting below.
- e.g.
- [x] 202006
-->

- [ ] 202205
- [ ] 202211
- [ ] 202305
- [ ] 202311
- [ ] 202405
- [ ] 202411
- [ ] 202505

#### Tested branch (Please provide the tested image version)

<!--
- Please provide tested image version
- e.g.
- [x] 20201231.100
-->

- [ ] <!-- image version 1 -->
- [ ] <!-- image version 2 -->

#### Description for the changelog
<!--
Write a short (one line) summary that describes the changes in this
pull request for inclusion in the changelog:
-->

<!--
 Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU.
-->

#### Link to config_db schema for YANG module changes
<!--
Provide a link to config_db schema for the table for which YANG model
is defined
Link should point to correct section on https://github.com/Azure/sonic-buildimage/blob/master/src/sonic-yang-models/doc/Configuration.md
-->

#### A picture of a cute animal (not mandatory but encouraged)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants