proxmox-fw : les types ICMP au vocabulaire de Proxmox (fragmentation-needed)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
parent
e68f315625
commit
2695013b32
1 changed files with 8 additions and 1 deletions
|
|
@ -121,6 +121,12 @@ def _ports(fl: dict) -> list[str]:
|
|||
return fixes
|
||||
|
||||
|
||||
# LE REGISTRE PARLE NFTABLES, PROXMOX PARLE IPTABLES (2026-09-29). `frag-needed` est le
|
||||
# nom nftables ; l'API Proxmox le refuse (« invalid icmp-type value ») et attend
|
||||
# `fragmentation-needed`. Mesure a la premiere application des flux `externe`.
|
||||
ICMP_PROXMOX = {"frag-needed": "fragmentation-needed"}
|
||||
|
||||
|
||||
def _cibles(fl: dict) -> list[dict]:
|
||||
"""Ce qu'une regle vise : un port TCP/UDP, ou un TYPE ICMP.
|
||||
|
||||
|
|
@ -132,7 +138,8 @@ def _cibles(fl: dict) -> list[dict]:
|
|||
"""
|
||||
if str(fl.get("protocole", "tcp")).lower() == "icmp":
|
||||
p = fl["port"]
|
||||
return [{"proto": "icmp", "icmp_type": str(t)} for t in (p if isinstance(p, list) else [p])]
|
||||
return [{"proto": "icmp", "icmp_type": ICMP_PROXMOX.get(str(t), str(t))}
|
||||
for t in (p if isinstance(p, list) else [p])]
|
||||
return [{"proto": fl.get("protocole", "tcp"), "dport": port} for port in _ports(fl)]
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue