From b70f452e8b2d10fa18c7c4ac7a49da8454cf7e67 Mon Sep 17 00:00:00 2001 From: fumingwei Date: Thu, 28 Dec 2023 15:04:27 +0800 Subject: [PATCH] =?UTF-8?q?feature:TSG-18248:=E5=88=A0=E9=99=A4firewall=20?= =?UTF-8?q?Decoders.RADIUS=E7=9B=B8=E5=85=B3=E9=85=8D=E7=BD=AE=E9=A1=B9?= =?UTF-8?q?=E5=8F=8A=E5=85=B6=E4=BB=A3=E7=A0=81?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../install_config/group_vars/rpm_version.yml | 3 --- .../roles/firewall/templates/main.conf.j2.j2 | 22 ------------------- .../roles/sapp/templates/conflist.inf.j2.j2 | 4 ---- .../roles/sapp/templates/entrylist.conf.j2 | 1 - .../templates/necessary_plug_list.conf.j2 | 2 -- .../files/helm/conf/conflist.inf | 6 ----- .../traffic-engine/files/helm/conf/main.conf | 7 ------ .../files/helm/conf/necessary_plug_list.conf | 2 -- .../traffic-engine/files/helm/values.yaml | 4 ---- .../provision.default.yml.7400MCN0P01R01 | 3 --- .../provision.yml.sample.7400MCN0P01R01 | 3 --- 11 files changed, 57 deletions(-) diff --git a/ansible/install_config/group_vars/rpm_version.yml b/ansible/install_config/group_vars/rpm_version.yml index 9b6b8136..92a44f26 100644 --- a/ansible/install_config/group_vars/rpm_version.yml +++ b/ansible/install_config/group_vars/rpm_version.yml @@ -4,8 +4,6 @@ certstore_rpm_version: firewall_rpm_version: conn_telemetry: conn_telemetry-1.0.3.4ef6df6 firewall: firewall-3.0.25.d1db696 - #gtp_signaling_plug: gtp_signaling_plug-2.0.0.3f233d7 - #radius_collect_plug: radius_collect_plug-2.0.11.47a51f3 glimpse_detector: glimpse_detector-3.0.0.7240884 qdpi_detector: qdpi_detector-4.0.3.9f81ea0 tsg_ddos_sketch: tsg_ddos_sketch-2.0.1.918b16e @@ -19,7 +17,6 @@ firewall_rpm_version: gtp: gtp-1.0.7.e1041b2 ssh: ssh-2.1.7.b053e65 dtls: dtls-2.0.3.51e8096 - radius: radius-1.0.7.54b70b2 mesa_sip: mesa_sip-2.0.2.11024e4 deal_socks: deal_socks-1.0.4.329bba3 stratum: stratum-1.1.0.29a2cff diff --git a/ansible/roles/firewall/templates/main.conf.j2.j2 b/ansible/roles/firewall/templates/main.conf.j2.j2 index 861c4310..bba69def 100644 --- a/ansible/roles/firewall/templates/main.conf.j2.j2 +++ b/ansible/roles/firewall/templates/main.conf.j2.j2 @@ -145,28 +145,6 @@ TRAFFIC_MIRROR_ENABLE=1 NIC_NAME="{{ dp_traffic_mirror.nic_name }}" DEFAULT_VLAN_ID={{ dp_traffic_mirror.traffic_mirror_vlan_id }} {% endif %} -[RADIUS_PLUG] -{% raw %}{% set tags_list = [] %} -{% if data_center.name is defined %} -{% set tag_json = "{\"tag\":\"" ~ "data_center" ~ "\",\"value\":\"" ~ data_center.name ~ "\"}" %} -{{tags_list.append(tag_json)}}{% endif %} -{% if device.tags is defined %} -{% for device_tag in device.tags %} -{% for key,value in device_tag.items() %} -{% set tag_json = "{\"tag\":\"" ~ key ~ "\",\"value\":\"" ~ value ~ "\"}" %} -{{tags_list.append(tag_json)}}{% endfor %} -{% endfor %} -{% endif %} -{% if data_center.name is not defined and device.tags is not defined %} -{{ device.tags }} -{% endif %} -DEVICE_TAGS={"tags":[{{ tags_list | join(",") }}]} -{% endraw %} -PACKET_TYPE_FLAG=16 -COLLECT_TOPIC="RADIUS-RECORD" -SERVICE_ID=162 -LOG_PATH="log/radius_collect" -LOG_LEVEL=30 [GTP_SIGNALING] {% raw %}{% if gtp.enable_gtp_c_record == 1 %} diff --git a/ansible/roles/sapp/templates/conflist.inf.j2.j2 b/ansible/roles/sapp/templates/conflist.inf.j2.j2 index 25186dc6..d07822d9 100644 --- a/ansible/roles/sapp/templates/conflist.inf.j2.j2 +++ b/ansible/roles/sapp/templates/conflist.inf.j2.j2 @@ -21,7 +21,6 @@ ./plug/protocol/quic/quic.inf ./plug/protocol/l2tp_protocol_plug/l2tp_protocol_plug.inf ./plug/protocol/gtp/gtp.inf -./plug/protocol/radius/radius.inf ./plug/protocol/ssh/ssh.inf ./plug/protocol/stratum/stratum.inf ./plug/protocol/rdp/rdp.inf @@ -43,9 +42,6 @@ ./plug/business/kni/kni.inf {% endif %} ./plug/business/conn_telemetry/conn_telemetry.inf -{% if radius.enable == 1 %} -#./plug/business/radius_collect_plug/radius_collect_plug.inf -{% endif %} {% endraw %} {% if runtime_env == 'TSG-7400-mcn0' %} {% raw %}{% if npb_device == 'tera' %} diff --git a/ansible/roles/sapp/templates/entrylist.conf.j2 b/ansible/roles/sapp/templates/entrylist.conf.j2 index 54f344d2..b9340759 100644 --- a/ansible/roles/sapp/templates/entrylist.conf.j2 +++ b/ansible/roles/sapp/templates/entrylist.conf.j2 @@ -19,7 +19,6 @@ RTP SIP GTP SSH -RADIUS SOCKS STRATUM RDP diff --git a/ansible/roles/sapp/templates/necessary_plug_list.conf.j2 b/ansible/roles/sapp/templates/necessary_plug_list.conf.j2 index 9bac8332..81a502e3 100644 --- a/ansible/roles/sapp/templates/necessary_plug_list.conf.j2 +++ b/ansible/roles/sapp/templates/necessary_plug_list.conf.j2 @@ -12,7 +12,6 @@ ./plug/protocol/mail/mail.inf ./plug/protocol/ftp/ftp.inf ./plug/protocol/quic/quic.inf -./plug/protocol/radius/radius.inf ./plug/protocol/rdp/rdp.inf ./plug/protocol/bgp/bgp.inf ./plug/protocol/l2tp_protocol_plug/l2tp_protocol_plug.inf @@ -22,7 +21,6 @@ #./plug/business/gtp_signaling_plug/gtp_signaling_plug.inf ./plug/business/http_healthcheck/http_healthcheck.inf ./plug/platform/tsg_ddos_sketch/tsg_ddos_sketch.inf 1 -#./plug/business/radius_collect_plug/radius_collect_plug.inf ./plug/business/firewall/firewall.inf ./plug/stellar_on_sapp/start_loader.inf ./plug/stellar_on_sapp/defer_loader.inf \ No newline at end of file diff --git a/ansible/roles/traffic-engine/files/helm/conf/conflist.inf b/ansible/roles/traffic-engine/files/helm/conf/conflist.inf index 117fa726..a8d1f4d2 100644 --- a/ansible/roles/traffic-engine/files/helm/conf/conflist.inf +++ b/ansible/roles/traffic-engine/files/helm/conf/conflist.inf @@ -36,9 +36,6 @@ {{- if eq .Values.decoders.GTPC .Values.define_enable_val_yes }} ./plug/protocol/gtp/gtp.inf {{- end }} -{{- if eq .Values.decoders.RADIUS .Values.define_enable_val_yes }} -./plug/protocol/radius/radius.inf -{{- end }} {{- if eq .Values.decoders.SSH .Values.define_enable_val_yes }} ./plug/protocol/ssh/ssh.inf {{- end }} @@ -62,7 +59,4 @@ {{- if eq .Values.decoders.GTPC .Values.define_enable_val_yes }} #./plug/business/gtp_signaling_plug/gtp_signaling_plug.inf {{- end }} -{{- if and (eq .Values.radius_record.enable .Values.define_enable_val_yes) (eq .Values.decoders.RADIUS .Values.define_enable_val_yes) }} -#./plug/business/radius_collect_plug/radius_collect_plug.inf -{{- end }} ./plug/stellar_on_sapp/defer_loader.inf \ No newline at end of file diff --git a/ansible/roles/traffic-engine/files/helm/conf/main.conf b/ansible/roles/traffic-engine/files/helm/conf/main.conf index 5e3f3396..87656e50 100644 --- a/ansible/roles/traffic-engine/files/helm/conf/main.conf +++ b/ansible/roles/traffic-engine/files/helm/conf/main.conf @@ -170,13 +170,6 @@ NIC_NAME="{{ .Values.nic_mirror_name.firewall }}" {{- end }} APP_NAME="sapp-mirror-{{ .Values.app_symbol_index }}" DEFAULT_VLAN_ID=0 -[RADIUS_PLUG] -DEVICE_TAGS={"tags":[{{- include "traffic-engine.device-tag-list" . }}]} -PACKET_TYPE_FLAG=16 -COLLECT_TOPIC="RADIUS-RECORD" -SERVICE_ID=162 -LOG_PATH="log/radius_collect" -LOG_LEVEL=30 {{- if eq .Values.decoders.GTPC .Values.define_enable_val_yes }} [GTP_SIGNALING] diff --git a/ansible/roles/traffic-engine/files/helm/conf/necessary_plug_list.conf b/ansible/roles/traffic-engine/files/helm/conf/necessary_plug_list.conf index dec22678..47277020 100644 --- a/ansible/roles/traffic-engine/files/helm/conf/necessary_plug_list.conf +++ b/ansible/roles/traffic-engine/files/helm/conf/necessary_plug_list.conf @@ -11,7 +11,6 @@ ./plug/protocol/mail/mail.inf ./plug/protocol/ftp/ftp.inf ./plug/protocol/quic/quic.inf -./plug/protocol/radius/radius.inf ./plug/protocol/rdp/rdp.inf ./plug/protocol/bgp/bgp.inf ./plug/protocol/l2tp_protocol_plug/l2tp_protocol_plug.inf @@ -21,7 +20,6 @@ #./plug/business/gtp_signaling_plug/gtp_signaling_plug.inf ./plug/business/http_healthcheck/http_healthcheck.inf ./plug/platform/tsg_ddos_sketch/tsg_ddos_sketch.inf 1 -#./plug/business/radius_collect_plug/radius_collect_plug.inf ./plug/business/firewall/firewall.inf ./plug/stellar_on_sapp/start_loader.inf ./plug/stellar_on_sapp/defer_loader.inf \ No newline at end of file diff --git a/ansible/roles/traffic-engine/files/helm/values.yaml b/ansible/roles/traffic-engine/files/helm/values.yaml index 5ac4c22c..cb4736fd 100644 --- a/ansible/roles/traffic-engine/files/helm/values.yaml +++ b/ansible/roles/traffic-engine/files/helm/values.yaml @@ -110,9 +110,6 @@ proxy: voip_record: enable_sip: yes enable_rtp: yes - -radius_record: - enable: yes bgp_record: enable: yes @@ -175,7 +172,6 @@ decoders: RTP: yes SIP: yes SSH: yes - RADIUS: yes SOCKS: yes STRATUM: yes RDP: yes diff --git a/ansible/roles/tsg-os-provision/files/config_sample/provision.default.yml.7400MCN0P01R01 b/ansible/roles/tsg-os-provision/files/config_sample/provision.default.yml.7400MCN0P01R01 index 0cdad492..986f960c 100644 --- a/ansible/roles/tsg-os-provision/files/config_sample/provision.default.yml.7400MCN0P01R01 +++ b/ansible/roles/tsg-os-provision/files/config_sample/provision.default.yml.7400MCN0P01R01 @@ -27,9 +27,6 @@ sessionrecord: capturepacket: enable: 1 -radius: - enable: 1 - app_behavior: enable: 0 diff --git a/ansible/roles/tsg-os-provision/files/config_sample/provision.yml.sample.7400MCN0P01R01 b/ansible/roles/tsg-os-provision/files/config_sample/provision.yml.sample.7400MCN0P01R01 index 3d1aedb9..bb9cc3ef 100644 --- a/ansible/roles/tsg-os-provision/files/config_sample/provision.yml.sample.7400MCN0P01R01 +++ b/ansible/roles/tsg-os-provision/files/config_sample/provision.yml.sample.7400MCN0P01R01 @@ -29,9 +29,6 @@ sessionrecord: capturepacket: enable: 0/1 -radius: - enable: 0/1 - gtp: enable_gtp_c_record: 0/1