mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-08 06:29:08 +02:00
[management] Fix invalid port range sync (#3571)
We should not send port range when a port is set or when protocol is all or icmp
This commit is contained in:
@@ -255,15 +255,24 @@ func toProtocolFirewallRules(rules []*types.FirewallRule) []*proto.FirewallRule
|
|||||||
for i := range rules {
|
for i := range rules {
|
||||||
rule := rules[i]
|
rule := rules[i]
|
||||||
|
|
||||||
result[i] = &proto.FirewallRule{
|
fwRule := &proto.FirewallRule{
|
||||||
PolicyID: []byte(rule.PolicyID),
|
PolicyID: []byte(rule.PolicyID),
|
||||||
PeerIP: rule.PeerIP,
|
PeerIP: rule.PeerIP,
|
||||||
Direction: getProtoDirection(rule.Direction),
|
Direction: getProtoDirection(rule.Direction),
|
||||||
Action: getProtoAction(rule.Action),
|
Action: getProtoAction(rule.Action),
|
||||||
Protocol: getProtoProtocol(rule.Protocol),
|
Protocol: getProtoProtocol(rule.Protocol),
|
||||||
Port: rule.Port,
|
Port: rule.Port,
|
||||||
PortInfo: rule.PortRange.ToProto(),
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if shouldUsePortRange(fwRule) {
|
||||||
|
fwRule.PortInfo = rule.PortRange.ToProto()
|
||||||
|
}
|
||||||
|
|
||||||
|
result[i] = fwRule
|
||||||
}
|
}
|
||||||
return result
|
return result
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func shouldUsePortRange(rule *proto.FirewallRule) bool {
|
||||||
|
return rule.Port == "" && (rule.Protocol == proto.RuleProtocol_UDP || rule.Protocol == proto.RuleProtocol_TCP)
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user