diff --git a/doc/userguide/firewall/firewall-design.rst b/doc/userguide/firewall/firewall-design.rst index b2eb9d38c721..351cd19f25d5 100644 --- a/doc/userguide/firewall/firewall-design.rst +++ b/doc/userguide/firewall/firewall-design.rst @@ -122,6 +122,14 @@ alert action in firewall rules. The effect will be the creation of an alert event when the firewall rule matches. +config +~~~~~~ + +``config`` is a primary firewall action used to apply the setting of the ``config`` +rule keyword when the rule matches, see :doc:`../rules/config`. +The ``config`` action does not issue a verdict for the packet or the flow, so the +other tables are still evaluated. It is not available as a secondary action. + Multi action rules ~~~~~~~~~~~~~~~~~~ diff --git a/src/detect-parse.c b/src/detect-parse.c index 44d546984c19..6a7c9d768465 100644 --- a/src/detect-parse.c +++ b/src/detect-parse.c @@ -1822,6 +1822,10 @@ static int SigParseActionDo(const char *action_in, const int idx, const bool fw_ "rules"); return -1; } + if (idx > 0 && (flags & ACTION_PASS) && !(*action_out & ACTION_ACCEPT)) { + SCLogError("'pass' is only supported as a secondary action for 'accept'"); + return -1; + } } /* parse scope, if any */ @@ -1873,6 +1877,14 @@ static int SigParseActionDo(const char *action_in, const int idx, const bool fw_ return -1; } *scope_out = scope_flags; + } else if (*scope_out != 0 && (flags & ACTION_PASS)) { + /* No scope given, this action inherits the scope set by the preceding + * actions of a multi-action rule. */ + if (*scope_out != ACTION_SCOPE_PACKET && *scope_out != ACTION_SCOPE_FLOW) { + SCLogError("invalid action scope '%s' in action '%s': only 'packet' and 'flow' allowed", + ActionScopeToString((enum ActionScope) * scope_out), action_in); + return -1; + } } /* require explicit action scope for fw rules */ @@ -4201,6 +4213,11 @@ static int DoParsePolicy(const char *policy_name, struct DetectFirewallPolicy *p return -1; idx++; } + + if (action & ACTION_CONFIG) { + SCLogError("%s: 'config' is not a valid default policy action", policy_name); + return -1; + } pol->action = action; pol->action_scope = action_scope; return 1;