Commit Graph
5 Commits
Author SHA1 Message Date
christianmanivong 90b8e08789 feat(firewall): add generic diff/apply mechanism for firewall rules
FirewallRuleDict/FirewallRuleDiffDict (models.py) plus three abstract
methods (get_firewall_rules/apply_firewall_rule/commit_firewall_rules)
concrete drivers implement, and two concrete methods every driver gets
for free: diff_firewall_rules() matches desired vs. live rules by
description and reports add/update (never delete -- a firewall may carry
manually-created rules a caller's desired set was never meant to
describe); apply_firewall_ruleset() orchestrates applying the diff and
yields progress lines, meant for streaming to a caller.

This is the generic reconciliation engine NetOrk's Firewall Profile
feature needs against OPNsense -- kept here instead of in
napalm-opnsense since the matching/comparison/orchestration logic is
identical for any firewall vendor that implements the three abstract
methods.
2026-07-20 15:01:13 +02:00
christianmanivong 478c7b434a feat(firewall): add send_wake_on_lan() capability to FirewallDriver
Abstract method for sending a Wake-on-LAN magic packet through a
firewall's driver connection, following the same contract style as
get_nat_translations/get_security_zones. Raises NotImplementedError
by default; concrete drivers implement it per their own API.
2026-07-12 11:17:26 +02:00
christianmanivongandClaude Sonnet 4.6 51e677492a feat: OUI_PREFIXES auf DeviceTypeDriver für MAC-basiertes Fingerprinting
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 15:41:45 +02:00
christianmanivongandClaude Sonnet 4.6 0f6734e6da feat: DeviceTypeDriver base class mit FingerprintRule und PortSpec
Neue Zwischenschicht zwischen NetworkDriver und den typ-spezifischen
Basisklassen (FirewallDriver, SwitchDriver, …). Definiert das
Fingerprinting-Interface für den Discovery-Subsystem:

- FingerprintRule (NamedTuple): pattern, weight, mandatory, negative
- PortSpec (NamedTuple): scheme, port, paths, weight, mandatory
- DeviceTypeDriver: VENDOR, DRIVER_NAME, PORT_SPECS, SNMP_OBJECT_ID_PREFIX,
  SNMP_FINGERPRINT, SSH_FINGERPRINT, HTTP_FINGERPRINT

Alle *Driver-Klassen erben jetzt von DeviceTypeDriver statt NetworkDriver.
Transitiv ist NetworkDriver weiterhin in der MRO (keine Breaking Change).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 14:29:41 +02:00
christianmanivongandClaude Sonnet 4.6 95f8771824 feat: add TYPE_LABEL class attribute to all base driver classes
Each abstract base class now carries a TYPE_LABEL: str attribute that
describes the device category in human-readable form:

  AccessPointDriver  → "Access Point"
  FirewallDriver     → "Firewall"
  HypervisorDriver   → "Hypervisor"
  OSDriver           → "OS"
  ResidentialGatewayDriver → "Gateway"
  StorageDriver      → "Storage"
  SwitchDriver       → "Switch"

Concrete drivers can override TYPE_LABEL to express a more specific
category (e.g. LinuxDriver sets "Linux"). The backend reads this
attribute to expose a type_label in the DriverInfo API response,
replacing the hardcoded DRIVER_TYPE map in the frontend.

23 tests covering presence, value, inheritance, and override.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-24 11:36:41 +02:00