File manager - Edit - /opt/saltstack/salt/lib/python3.10/site-packages/salt/modules/__pycache__/napalm_netacl.cpython-310.pyc
Back
o ;j\r � @ s d Z ddlZddlZddlmZ e�e�ZzddlZddl Zddl ZddlZdZW n e y4 dZY nw dZdgZdd � Zd d� Ze ddd��Ze ddd��Ze ddd��Zddd�Z ddd�ZdS )a� NAPALM ACL ========== Generate and load ACL (firewall) configuration on network devices. .. versionadded:: 2017.7.0 :codeauthor: Mircea Ulinic <ping@mirceaulinic.net> :maturity: new :depends: capirca, napalm :platform: unix Dependencies ------------ The firewall configuration is generated by Capirca_. .. _Capirca: https://github.com/google/capirca To install Capirca, execute: ``pip install capirca``. To be able to load configuration on network devices, it requires NAPALM_ library to be installed: ``pip install napalm``. Please check Installation_ for complete details. .. _NAPALM: https://napalm.readthedocs.io .. _Installation: https://napalm.readthedocs.io/en/latest/installation/index.html � N)�proxy_napalm_wrapTFZnetacl�*c C s t r tjj�ttt�r tS dS )z7 This module requires both NAPALM and Capirca. )FzSThe netacl (napalm_acl) module cannot be loaded. Please install capirca and napalm.)�HAS_CAPIRCA�salt�utilsZnapalmZvirtualZ__opts__�__virtualname__�__file__� r r �N/opt/saltstack/salt/lib/python3.10/site-packages/salt/modules/napalm_netacl.py�__virtual__A s r c C s� t d �� } t d �� }t d �� }| dkrd|v rdS | dkr&|dkr&dS | dkr0|d kr0d S | dkr:|dkr:dS |d kr@dS | dkrFdS | S )z� Given the following NAPALM grains, we can determine the Capirca platform name: - vendor - device model - operating system Not the most optimal. �vendor�os�modelZjuniperZsrxZ junipersrxZciscoZiosZiosxrZciscoxrZasaZciscoasa�linuxZiptableszpalo alto networksZ paloaltofw)Z __grains__�lower)r Zos_r r r r �_get_capirca_platformS s r �acl�%Y/%m/%dc K sT |sg }t � }td || |f|||||||| | ||d�|��}td |||| td�S )a�# Generate and load the configuration of a policy term. filter_name The name of the policy filter. term_name The name of the term. filter_options Additional filter options. These options are platform-specific. See the complete list of options_. .. _options: https://github.com/google/capirca/wiki/Policy-format#header-section pillar_key: ``acl`` The key in the pillar containing the default attributes values. Default: ``acl``. If the pillar contains the following structure: .. code-block:: yaml firewall: - my-filter: terms: - my-term: source_port: 1234 source_address: - 1.2.3.4/32 - 5.6.7.8/32 The ``pillar_key`` field would be specified as ``firewall``. pillarenv Query the master to generate fresh pillar data on the fly, specifically from the requested pillar environment. saltenv Included only for compatibility with :conf_minion:`pillarenv_from_saltenv`, and is otherwise ignored. merge_pillar: ``True`` Merge the CLI variables with the pillar. Default: ``True``. The properties specified through the CLI have higher priority than the pillar. revision_id Add a comment in the term config having the description for the changes applied. revision_no The revision count. revision_date: ``True`` Boolean flag: display the date when the term configuration was generated. Default: ``True``. revision_date_format: ``%Y/%m/%d`` The date format to be used when generating the perforce data. Default: ``%Y/%m/%d`` (<year>/<month>/<day>). test: ``False`` Dry run? If set as ``True``, will apply the config, discard and return the changes. Default: ``False`` and will commit the changes on the device. commit: ``True`` Commit? Default: ``True``. debug: ``False`` Debug mode. Will insert a new key under the output dictionary, as ``loaded_config`` containing the raw configuration loaded on the device. source_service A special service to choose from. This is a helper so the user is able to select a source just using the name, instead of specifying a source_port and protocol. As this module is available on Unix platforms only, it reads the IANA_ port assignment from /etc/services. If the user requires additional shortcuts to be referenced, they can add entries under /etc/services, which can be managed using the :mod:`file state <salt.states.file>`. .. _IANA: http://www.iana.org/assignments/port-numbers destination_service A special service to choose from. This is a helper so the user is able to select a source just using the name, instead of specifying a destination_port and protocol. Allows the same options as ``source_service``. term_fields Term attributes. To see what fields are supported, please consult the list of supported keywords_. Some platforms have a few other optional_ keywords. .. _keywords: https://github.com/google/capirca/wiki/Policy-format#keywords .. _optional: https://github.com/google/capirca/wiki/Policy-format#optionally-supported-keywords .. note:: The following fields are accepted (some being platform-specific): - action - address - address_exclude - comment - counter - expiration - destination_address - destination_address_exclude - destination_port - destination_prefix - forwarding_class - forwarding_class_except - logging - log_name - loss_priority - option - policer - port - precedence - principals - protocol - protocol_except - qos - pan_application - routing_instance - source_address - source_address_exclude - source_port - source_prefix - verbatim - packet_length - fragment_offset - hop_limit - icmp_type - ether_type - traffic_class_count - traffic_type - translated - dscp_set - dscp_match - dscp_except - next_ip - flexible_match_range - source_prefix_except - destination_prefix_except - vpn - source_tag - destination_tag - source_interface - destination_interface - flattened - flattened_addr - flattened_saddr - flattened_daddr - priority .. note:: The following fields can be also a single value and a list of values: - action - address - address_exclude - comment - destination_address - destination_address_exclude - destination_port - destination_prefix - forwarding_class - forwarding_class_except - logging - option - port - precedence - principals - protocol - protocol_except - pan_application - source_address - source_address_exclude - source_port - source_prefix - verbatim - icmp_type - ether_type - traffic_type - dscp_match - dscp_except - flexible_match_range - source_prefix_except - destination_prefix_except - source_tag - destination_tag - source_service - destination_service Example: ``destination_address`` can be either defined as: .. code-block:: yaml destination_address: 172.17.17.1/24 or as a list of destination IP addresses: .. code-block:: yaml destination_address: - 172.17.17.1/24 - 172.17.19.1/24 or a list of services to be matched: .. code-block:: yaml source_service: - ntp - snmp - ldap - bgpd .. note:: The port fields ``source_port`` and ``destination_port`` can be used as above to select either a single value, either a list of values, but also they can select port ranges. Example: .. code-block:: yaml source_port: - - 1000 - 2000 - - 3000 - 4000 With the configuration above, the user is able to select the 1000-2000 and 3000-4000 source port ranges. The output is a dictionary having the same form as :mod:`net.load_config <salt.modules.napalm_network.load_config>`. CLI Example: .. code-block:: bash salt 'edge01.bjm01' netacl.load_term_config filter-name term-name source_address=1.2.3.4 destination_address=5.6.7.8 action=accept test=True debug=True Output Example: .. code-block:: jinja edge01.bjm01: ---------- already_configured: False comment: Configuration discarded. diff: [edit firewall] + family inet { + /* + ** $Date: 2017/03/22 $ + ** + */ + filter filter-name { + interface-specific; + term term-name { + from { + source-address { + 1.2.3.4/32; + } + destination-address { + 5.6.7.8/32; + } + } + then accept; + } + } + } loaded_config: firewall { family inet { replace: /* ** $Date: 2017/03/22 $ ** */ filter filter-name { interface-specific; term term-name { from { source-address { 1.2.3.4/32; } destination-address { 5.6.7.8/32; } } then accept; } } } } result: True zcapirca.get_term_config)�filter_options� pillar_key� pillarenv�saltenv�merge_pillar�revision_id�revision_no� revision_date�revision_date_format�source_service�destination_service�net.load_config��text�test�commit�debugZinherit_napalm_device�r �__salt__Z napalm_device)�filter_name� term_namer r r r r r r r r r"