|
| 1 | +--- |
| 2 | +title: Unified Routing behavior changes |
| 3 | +pcx_content_type: concept |
| 4 | +description: Rule behavior differences for Cloudflare Network Firewall accounts moving from Legacy Routing to Unified Routing. |
| 5 | +products: |
| 6 | + - cloudflare-network-firewall |
| 7 | +--- |
| 8 | + |
| 9 | +Cloudflare Network Firewall rules can behave differently depending on whether your account uses Legacy Routing or [Unified Routing](/magic-transit/reference/traffic-steering/#unified-routing-mode). Review the following changes before you upgrade to Unified Routing. |
| 10 | + |
| 11 | +## `ip.geoip.country` |
| 12 | + |
| 13 | +The `ip.geoip.country` field is no longer supported on Unified Routing. Rewrite any rule that uses `ip.geoip.country` with the [`ip.src.country` and `ip.dst.country`](/cloudflare-network-firewall/reference/network-firewall-fields/#ipsrccountry) fields instead. |
| 14 | + |
| 15 | +| Match type | Rule using `ip.geoip.country` | Equivalent rule | |
| 16 | +| --------------- | ------------------------------------------ | ------------------------------------------------------------------------- | |
| 17 | +| Equals | `ip.geoip.country eq "US"` | `ip.src.country eq "US" or ip.dst.country eq "US"` | |
| 18 | +| Does not equal | `ip.geoip.country ne "US"` | `ip.src.country ne "US" and ip.dst.country ne "US"` | |
| 19 | +| In a list | `ip.geoip.country in {"UK" "FR"}` | `ip.src.country in {"UK" "FR"} or ip.dst.country in {"UK" "FR"}` | |
| 20 | +| Not in a list | `not ip.geoip.country in {"UK" "FR"}` | `not ip.src.country in {"UK" "FR"} and not ip.dst.country in {"UK" "FR"}` | |
| 21 | + |
| 22 | +## Rule evaluation for L3 traffic |
| 23 | + |
| 24 | +Legacy Routing has limited support for L3 protocols. IPv6 support is limited to the `ip.src` and `ip.dst` fields. A rule is either exclusively applied to IPv4 packets or exclusively applied to IPv6 packets, based on the address family of the literal used in the rule. |
| 25 | + |
| 26 | +On Unified Routing, as a first step to supporting IPv6 more broadly, a rule like this is also evaluated against IPv4 traffic. |
| 27 | + |
| 28 | +| Rule | Routing mode | Behavior for IPv4 | Behavior for IPv6 | |
| 29 | +| --------------------- | ------------ | --------------------------- | -------------------------------------------------- | |
| 30 | +| `ip.src ne fe80::/64` | Legacy | IPv4 packets skip this rule | Matches for all traffic not sourced from fe80::/64 | |
| 31 | +| `ip.src ne fe80::/64` | Unified | Matches for all traffic | Matches for all traffic not sourced from fe80::/64 | |
| 32 | + |
| 33 | +To restrict the rule to only match IPv6 traffic, update the expression to `ip.src in {::/0} and ip.src ne fe80::/64`. |
| 34 | + |
| 35 | +IPv6 behavior is unchanged from Legacy Routing. |
| 36 | + |
| 37 | +## Rule evaluation for L4 traffic |
| 38 | + |
| 39 | +On Legacy Routing, the L4 protocol is inferred from the expression and only applied to packets of that protocol. `tcp.srcport eq 80` and `tcp.srcport ne 80` both apply only to TCP traffic. Packets of other protocols, for example UDP, will not match the expression. |
| 40 | + |
| 41 | +On Unified Routing, Cloudflare Network Firewall does not infer the protocol, and rules must specify a protocol in the expression explicitly. `tcp.srcport eq 80` still only applies to TCP traffic, but `tcp.srcport ne 80` now matches both TCP and UDP traffic. To restrict the rule to only match TCP traffic, update the expression to `ip.proto eq "tcp" and tcp.srcport eq 80`. |
0 commit comments