Updates caclmgrd to add MATCH service#131
Open
ashish12pant wants to merge 1 commit intosonic-net:masterfrom
Open
Updates caclmgrd to add MATCH service#131ashish12pant wants to merge 1 commit intosonic-net:masterfrom
ashish12pant wants to merge 1 commit intosonic-net:masterfrom
Conversation
|
|
44e2d7b to
b2bc671
Compare
Member
|
@qiluo-msft Appreciate if you can review this PR. |
Contributor
|
@ashish12pant what's the difference between EXTERNAL_CLIENT and MATCH? Any particular reason to add a new service? |
Author
Limitations with EXTERNAL_CLIENT:
Suppose we have following rule using EXTERNAL_CLIENT These will translate to Correct translation will be. New service MATCH overcomes these limitations. It can accept any protocol and will work for multiple rule with different dst port. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A new service Type “MATCH” in caclmgrd daemon, which can be used to apply user given combination of IP_PROTOCOL, SRC_IP, DST_PORT.
Sample JSON input:
Translated Iptables rule from caclmgrd: