feat: port forwards are a firewall reader too, and only the WAN's #2

Merged
christianmanivong merged 1 commits from feature/port-forwards-shared into main 2026-10-03 14:31:01 +00:00
Owner

get_port_forwards moves from ResidentialGatewayDriver to NatVpnMixin, which firewalls and home gateways already share, and PortForwardDict moves next to NATTranslationDict.

The contract now says what counts:

  • Only forwards from the WAN. Destination NAT between internal networks is left out, and so are rules that only exempt traffic from redirection.
  • "ANY" means every protocol.
  • External port 0 means every port, i.e. a whole host forwarded.

This is a declaration under TYPE_CHECKING only; nothing changes at runtime.

Related: NetOrk/netork#504

`get_port_forwards` moves from `ResidentialGatewayDriver` to `NatVpnMixin`, which firewalls and home gateways already share, and `PortForwardDict` moves next to `NATTranslationDict`. The contract now says what counts: - **Only forwards from the WAN.** Destination NAT between internal networks is left out, and so are rules that only exempt traffic from redirection. - **`"ANY"`** means every protocol. - **External port `0`** means every port, i.e. a whole host forwarded. This is a declaration under `TYPE_CHECKING` only; nothing changes at runtime. Related: NetOrk/netork#504
christianmanivong added 1 commit 2026-10-03 14:30:53 +00:00
get_port_forwards was declared on ResidentialGatewayDriver alone, as if a
port forward were a home-router feature. A firewall forwards ports just the
same (OPNsense calls it destination NAT), and netOrk asks both: is this host
reachable from the internet, which CVEs are exposed. The declaration moves to
NatVpnMixin, where the two roles already overlap, and PortForwardDict next to
NATTranslationDict.

The contract now says what counts. Destination NAT between internal networks
and rules that only exempt traffic are not port forwards: callers read every
entry as "reachable from outside". "ANY" forwards every protocol and an
external port of 0 every port -- a whole host forwarded is the most exposed
case and must not fall out for lack of a port number.

Declaration only, under TYPE_CHECKING: nothing changes at runtime.
christianmanivong merged commit 36b7852bce into main 2026-10-03 14:31:01 +00:00
christianmanivong deleted branch feature/port-forwards-shared 2026-10-03 14:31:02 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: NAPALM/napalm-device-types#2