|
18 | 18 | from nethsec import utils, objects |
19 | 19 |
|
20 | 20 | PROTOCOLS = ['tcp', 'udp', 'udplite', 'icmp', 'esp', 'ah', 'sctp'] |
21 | | -TARGETS = ['ACCEPT', 'DROP', 'REJECT'] |
| 21 | +TARGETS = ['ACCEPT', 'DROP', 'REJECT', 'NOTRACK'] |
22 | 22 |
|
23 | 23 | def add_device_to_zone(uci, device, zone): |
24 | 24 | ''' |
@@ -1464,7 +1464,7 @@ def validate_rule(uci, src: str, src_ip: list[str], dest: str, dest_ip: list[str |
1464 | 1464 | dest_ip: a list of destination ip |
1465 | 1465 | proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp" |
1466 | 1466 | dest_port: a list of destination ports, each element cna be be a port number, a comma-separated list of port numbers or a range with `-` (eg. 80-90) |
1467 | | - target: target, must be one of 'ACCEPT', 'REJECT', 'DROP' |
| 1467 | + target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK' |
1468 | 1468 | service: service name |
1469 | 1469 | ns_src: an object in the form `<database>/<id>` |
1470 | 1470 | ns_dst: an object in the form `<database>/<id>` |
@@ -1533,7 +1533,7 @@ def setup_rule(uci, id: str, name: str, src: str, src_ip: list[str], dest: str, |
1533 | 1533 | dest_ip: a list of destination IP addresses |
1534 | 1534 | proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp" |
1535 | 1535 | dest_port: a list of destination ports, each element can be a port number, a comma-separated list of port numbers, or a range with `-` (e.g., 80-90) |
1536 | | - target: target, must be one of 'ACCEPT', 'REJECT', 'DROP' |
| 1536 | + target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK' |
1537 | 1537 | service: service name |
1538 | 1538 | enabled: if True, rule is enabled; if False, rule is disabled |
1539 | 1539 | log: if True, log traffic |
@@ -1680,7 +1680,7 @@ def add_rule(uci, name: str, src: str, src_ip: list[str], dest: str, dest_ip: li |
1680 | 1680 | dest_ip: a list of destination ip |
1681 | 1681 | proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp" |
1682 | 1682 | dest_port: a list of destination ports, each element cna be be a port number, a comma-separated list of port numbers or a range with `-` (eg. 80-90) |
1683 | | - target: target, must be one of 'ACCEPT', 'REJECT', 'DROP' |
| 1683 | + target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK' |
1684 | 1684 | service: service name |
1685 | 1685 | enabled: if True, rule is enabled, if False, rule is disabled |
1686 | 1686 | log: if True, log traffic |
@@ -1728,7 +1728,7 @@ def edit_rule(uci, id: str, name: str, src: str, src_ip: list[str], dest: str, d |
1728 | 1728 | dest_ip: a list of destination ip |
1729 | 1729 | proto: protocol, must be a list of protocols in "tcp", "udp", "udplite", "icmp", "esp", "ah", "sctp" |
1730 | 1730 | dest_port: a list of destination ports, each element cna be be a port number, a comma-separated list of port numbers or a range with `-` (eg. 80-90) |
1731 | | - target: target, must be one of 'ACCEPT', 'REJECT', 'DROP' |
| 1731 | + target: target, must be one of 'ACCEPT', 'REJECT', 'DROP', 'NOTRACK' |
1732 | 1732 | service: service name |
1733 | 1733 | enabled: if True, rule is enabled, if False, rule is disabled |
1734 | 1734 | log: if True, log traffic |
|
0 commit comments