[caclmgrd] Heuristically determine whether ACL is IPv4 or IPv6, use iptables/ip6tables accordingly#1767
Merged
lguohan merged 2 commits intosonic-net:masterfrom Jun 5, 2018
jleveque:cacl_v6
Merged
[caclmgrd] Heuristically determine whether ACL is IPv4 or IPv6, use iptables/ip6tables accordingly#1767lguohan merged 2 commits intosonic-net:masterfrom jleveque:cacl_v6
lguohan merged 2 commits intosonic-net:masterfrom
jleveque:cacl_v6
Conversation
…ptables/ip6tables accordingly
prsunny
reviewed
Jun 5, 2018
files/image_config/caclmgrd/caclmgrd
Outdated
| # do it now. We determine heuristically based on whether the | ||
| # src IP is a v4 or v6 address. | ||
| if not table_ip_version: | ||
| if "SRC_IP" in rule_props and rule_props["SRC_IP"]: |
Contributor
There was a problem hiding this comment.
if SRC_IP is not specified, does the ACL need to be applied to both iptables AND ip6tables?
Contributor
Author
There was a problem hiding this comment.
No. We assume that with regard to service ACLS, IPv4 and IPv6 ACLs will be stored in separate tables. If a rule needs to be applied to both IPv4 and IPv6, it needs to be specified twice, one in a v4 table and once in a v6 table.
However, I realize that this implementation also assumes that the first rule in the table will always have a SRC_IP defined. If not, then the table will be assumed to be v4, whether or not subsequent rules have v6 SRC_IPs. This may not always be true. #Fixed in commit 250155c
lguohan
approved these changes
Jun 5, 2018
lguohan
pushed a commit
that referenced
this pull request
Jun 5, 2018
…ptables/ip6tables accordingly (#1767) * [caclmgrd] Heuristically determine whether ACL is IPv4 or IPv6, use iptables/ip6tables accordingly * Check all rules in table until we find one with a SRC_IP
theasianpianist
pushed a commit
to theasianpianist/sonic-buildimage
that referenced
this pull request
Feb 5, 2022
…t cleanup fix (sonic-net#1767) * Clean up: Remove rif in test_portchannel.py Signed-off-by: Wenda Ni <wonda.ni@gmail.com>
noaOrMlnx
pushed a commit
to noaOrMlnx/sonic-buildimage
that referenced
this pull request
Nov 24, 2025
…C448O16, Arista-7060X6-64PE-B-C512S2 (sonic-net#1767) <!-- Please make sure you've read and understood our contributing guidelines: https://github.com/Azure/SONiC/blob/gh-pages/CONTRIBUTING.md failure_prs.log Make sure all your commits include a signature generated with `git commit -s` ** If this is a bug fix, make sure your description includes "fixes #xxxx", or "closes #xxxx" or "resolves #xxxx" Please provide the following information: --> #### Why I did it The convention for buffer profiles is that they're lower case, which some test cases expect. ##### Work item tracking - Microsoft ADO **(number only)**: #### How I did it #### How to verify it <!-- If PR needs to be backported, then the PR must be tested against the base branch and the earliest backport release branch and provide tested image version on these two branches. For example, if the PR is requested for master, 202211 and 202012, then the requester needs to provide test results on master and 202012. --> #### Which release branch to backport (provide reason below if selected) <!-- - Note we only backport fixes to a release branch, *not* features! - Please also provide a reason for the backporting below. - e.g. - [x] 202006 --> - [ ] 202205 - [ ] 202211 - [ ] 202305 - [ ] 202311 - [ ] 202405 - [ ] 202411 - [ ] 202505 #### Tested branch (Please provide the tested image version) <!-- - Please provide tested image version - e.g. - [x] 20201231.100 --> - [ ] <!-- image version 1 --> - [ ] <!-- image version 2 --> #### Description for the changelog <!-- Write a short (one line) summary that describes the changes in this pull request for inclusion in the changelog: --> <!-- Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU. --> #### Link to config_db schema for YANG module changes <!-- Provide a link to config_db schema for the table for which YANG model is defined Link should point to correct section on https://github.com/Azure/sonic-buildimage/blob/master/src/sonic-yang-models/doc/Configuration.md --> #### A picture of a cute animal (not mandatory but encouraged)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.