proxmox-fw : les types ICMP au vocabulaire de Proxmox (fragmentation-needed)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Daniel Allaire 2026-09-29 14:05:22 -04:00
parent e68f315625
commit 2695013b32

View file

@ -121,6 +121,12 @@ def _ports(fl: dict) -> list[str]:
return fixes
# LE REGISTRE PARLE NFTABLES, PROXMOX PARLE IPTABLES (2026-09-29). `frag-needed` est le
# nom nftables ; l'API Proxmox le refuse (« invalid icmp-type value ») et attend
# `fragmentation-needed`. Mesure a la premiere application des flux `externe`.
ICMP_PROXMOX = {"frag-needed": "fragmentation-needed"}
def _cibles(fl: dict) -> list[dict]:
"""Ce qu'une regle vise : un port TCP/UDP, ou un TYPE ICMP.
@ -132,7 +138,8 @@ def _cibles(fl: dict) -> list[dict]:
"""
if str(fl.get("protocole", "tcp")).lower() == "icmp":
p = fl["port"]
return [{"proto": "icmp", "icmp_type": str(t)} for t in (p if isinstance(p, list) else [p])]
return [{"proto": "icmp", "icmp_type": ICMP_PROXMOX.get(str(t), str(t))}
for t in (p if isinstance(p, list) else [p])]
return [{"proto": fl.get("protocole", "tcp"), "dport": port} for port in _ports(fl)]