feat(ISP/firewall): forward filtering #231

Merged
thubrecht merged 1 commit from isp-firewall into main 2025-02-05 16:07:49 +01:00
Member

Il faut recheck que le checkReversePath est pas génant, et si on déploie on casse la co de test

Il faut recheck que le checkReversePath est pas génant, et si on déploie on casse la co de test
@ -322,0 +344,4 @@
ip daddr 10.0.0.0/27 accept;
# Not others nor CRI
ip daddr 10.0.0.0/8 jump forward_reject;
Owner

juste jump forward_reject par défaut ici, ne filtre pas par IP.

juste jump forward_reject par défaut ici, ne filtre pas par IP.
Author
Member

on veut quand même que les gens puissent accéder à internet

on veut quand même que les gens puissent accéder à internet
lbailly marked this conversation as resolved
lbailly force-pushed isp-firewall from 3d6bf02c7e
All checks were successful
Run pre-commit on all files / pre-commit (push) Successful in 23s
Check meta / check_meta (pull_request) Successful in 15s
Check meta / check_dns (pull_request) Successful in 16s
Check workflows / check_workflows (pull_request) Successful in 17s
Build all the nodes / netcore02 (pull_request) Successful in 21s
Build all the nodes / ap01 (pull_request) Successful in 1m4s
Build the shell / build-shell (pull_request) Successful in 32s
Build all the nodes / bridge01 (pull_request) Successful in 1m59s
Build all the nodes / hypervisor02 (pull_request) Successful in 2m1s
Build all the nodes / hypervisor01 (pull_request) Successful in 2m2s
Build all the nodes / storage01 (pull_request) Successful in 2m0s
Build all the nodes / geo01 (pull_request) Successful in 2m7s
Build all the nodes / geo02 (pull_request) Successful in 2m13s
Build all the nodes / rescue01 (pull_request) Successful in 2m13s
Run pre-commit on all files / pre-commit (pull_request) Successful in 39s
Build all the nodes / hypervisor03 (pull_request) Successful in 2m29s
Build all the nodes / web02 (pull_request) Successful in 2m13s
Build all the nodes / web03 (pull_request) Successful in 2m13s
Build all the nodes / tower01 (pull_request) Successful in 2m35s
Build all the nodes / compute01 (pull_request) Successful in 2m39s
Build all the nodes / web01 (pull_request) Successful in 2m47s
Build all the nodes / vault01 (pull_request) Successful in 3m54s
to c511376ac3
All checks were successful
Check meta / check_dns (push) Successful in 16s
Check meta / check_dns (pull_request) Successful in 15s
Check workflows / check_workflows (pull_request) Successful in 16s
Check meta / check_meta (pull_request) Successful in 19s
Check meta / check_meta (push) Successful in 20s
Build all the nodes / netcore02 (pull_request) Successful in 20s
Run pre-commit on all files / pre-commit (push) Successful in 25s
Build all the nodes / ap01 (pull_request) Successful in 32s
Build the shell / build-shell (pull_request) Successful in 27s
Run pre-commit on all files / pre-commit (pull_request) Successful in 23s
Build all the nodes / bridge01 (pull_request) Successful in 2m13s
Build all the nodes / geo02 (pull_request) Successful in 2m13s
Build all the nodes / hypervisor03 (pull_request) Successful in 2m12s
Build all the nodes / vault01 (pull_request) Successful in 2m28s
Build all the nodes / hypervisor01 (pull_request) Successful in 2m59s
Build all the nodes / hypervisor02 (pull_request) Successful in 3m2s
Build all the nodes / build01 (pull_request) Successful in 3m3s
Build all the nodes / storage01 (pull_request) Successful in 2m50s
Build all the nodes / web01 (pull_request) Successful in 2m49s
Build all the nodes / rescue01 (pull_request) Successful in 2m56s
Build all the nodes / tower01 (pull_request) Successful in 2m58s
Build all the nodes / geo01 (pull_request) Successful in 3m15s
Build all the nodes / web03 (pull_request) Successful in 2m54s
Build all the nodes / web02 (pull_request) Successful in 3m1s
Build all the nodes / compute01 (pull_request) Successful in 3m35s
2025-01-14 17:21:31 +01:00
Compare
lbailly force-pushed isp-firewall from c511376ac3
All checks were successful
Check meta / check_dns (push) Successful in 16s
Check meta / check_dns (pull_request) Successful in 15s
Check workflows / check_workflows (pull_request) Successful in 16s
Check meta / check_meta (pull_request) Successful in 19s
Check meta / check_meta (push) Successful in 20s
Build all the nodes / netcore02 (pull_request) Successful in 20s
Run pre-commit on all files / pre-commit (push) Successful in 25s
Build all the nodes / ap01 (pull_request) Successful in 32s
Build the shell / build-shell (pull_request) Successful in 27s
Run pre-commit on all files / pre-commit (pull_request) Successful in 23s
Build all the nodes / bridge01 (pull_request) Successful in 2m13s
Build all the nodes / geo02 (pull_request) Successful in 2m13s
Build all the nodes / hypervisor03 (pull_request) Successful in 2m12s
Build all the nodes / vault01 (pull_request) Successful in 2m28s
Build all the nodes / hypervisor01 (pull_request) Successful in 2m59s
Build all the nodes / hypervisor02 (pull_request) Successful in 3m2s
Build all the nodes / build01 (pull_request) Successful in 3m3s
Build all the nodes / storage01 (pull_request) Successful in 2m50s
Build all the nodes / web01 (pull_request) Successful in 2m49s
Build all the nodes / rescue01 (pull_request) Successful in 2m56s
Build all the nodes / tower01 (pull_request) Successful in 2m58s
Build all the nodes / geo01 (pull_request) Successful in 3m15s
Build all the nodes / web03 (pull_request) Successful in 2m54s
Build all the nodes / web02 (pull_request) Successful in 3m1s
Build all the nodes / compute01 (pull_request) Successful in 3m35s
to 58a27d8914
All checks were successful
Check meta / check_meta (push) Successful in 15s
Check meta / check_meta (pull_request) Successful in 15s
Check workflows / check_workflows (pull_request) Successful in 16s
Run pre-commit on all files / pre-commit (push) Successful in 24s
Check meta / check_dns (push) Successful in 29s
Check meta / check_dns (pull_request) Successful in 29s
Check workflows / check_workflows (push) Successful in 30s
Build all the nodes / ap01 (pull_request) Successful in 31s
Build all the nodes / netcore02 (pull_request) Successful in 19s
Build all the nodes / geo02 (pull_request) Successful in 1m44s
Build all the nodes / geo01 (pull_request) Successful in 1m45s
Build all the nodes / rescue01 (pull_request) Successful in 2m2s
Build all the nodes / build01 (pull_request) Successful in 2m20s
Build all the nodes / hypervisor01 (pull_request) Successful in 2m22s
Build all the nodes / hypervisor02 (pull_request) Successful in 2m25s
Run pre-commit on all files / pre-commit (pull_request) Successful in 37s
Build the shell / build-shell (pull_request) Successful in 43s
Build all the nodes / hypervisor03 (pull_request) Successful in 2m26s
Build all the nodes / bridge01 (pull_request) Successful in 2m30s
Build all the nodes / tower01 (pull_request) Successful in 2m17s
Build all the nodes / vault01 (pull_request) Successful in 2m15s
Build all the nodes / storage01 (pull_request) Successful in 2m35s
Build all the nodes / web02 (pull_request) Successful in 2m23s
Build all the nodes / compute01 (pull_request) Successful in 2m58s
Build all the nodes / web01 (pull_request) Successful in 2m31s
Build all the nodes / web03 (pull_request) Successful in 2m37s
2025-01-28 16:41:17 +01:00
Compare
lbailly changed title from WIP: feat(ISP/firewall): forward filtering to feat(ISP/firewall): forward filtering 2025-01-28 22:15:47 +01:00
lbailly force-pushed isp-firewall from 58a27d8914
All checks were successful
Check meta / check_meta (push) Successful in 15s
Check meta / check_meta (pull_request) Successful in 15s
Check workflows / check_workflows (pull_request) Successful in 16s
Run pre-commit on all files / pre-commit (push) Successful in 24s
Check meta / check_dns (push) Successful in 29s
Check meta / check_dns (pull_request) Successful in 29s
Check workflows / check_workflows (push) Successful in 30s
Build all the nodes / ap01 (pull_request) Successful in 31s
Build all the nodes / netcore02 (pull_request) Successful in 19s
Build all the nodes / geo02 (pull_request) Successful in 1m44s
Build all the nodes / geo01 (pull_request) Successful in 1m45s
Build all the nodes / rescue01 (pull_request) Successful in 2m2s
Build all the nodes / build01 (pull_request) Successful in 2m20s
Build all the nodes / hypervisor01 (pull_request) Successful in 2m22s
Build all the nodes / hypervisor02 (pull_request) Successful in 2m25s
Run pre-commit on all files / pre-commit (pull_request) Successful in 37s
Build the shell / build-shell (pull_request) Successful in 43s
Build all the nodes / hypervisor03 (pull_request) Successful in 2m26s
Build all the nodes / bridge01 (pull_request) Successful in 2m30s
Build all the nodes / tower01 (pull_request) Successful in 2m17s
Build all the nodes / vault01 (pull_request) Successful in 2m15s
Build all the nodes / storage01 (pull_request) Successful in 2m35s
Build all the nodes / web02 (pull_request) Successful in 2m23s
Build all the nodes / compute01 (pull_request) Successful in 2m58s
Build all the nodes / web01 (pull_request) Successful in 2m31s
Build all the nodes / web03 (pull_request) Successful in 2m37s
to e7033418e0
Some checks failed
Run pre-commit on all files / pre-commit (push) Has been cancelled
Check meta / check_meta (pull_request) Successful in 16s
Check meta / check_dns (pull_request) Successful in 16s
Check meta / check_meta (push) Successful in 17s
Check meta / check_dns (push) Successful in 19s
Build all the nodes / netaccess01 (pull_request) Successful in 20s
Check workflows / check_workflows (pull_request) Successful in 27s
Build all the nodes / ap01 (pull_request) Successful in 32s
Build all the nodes / netcore01 (pull_request) Successful in 38s
Build all the nodes / netcore02 (pull_request) Successful in 32s
Build the shell / build-shell (pull_request) Successful in 24s
Run pre-commit on all files / pre-commit (pull_request) Successful in 26s
Build all the nodes / hypervisor03 (pull_request) Successful in 1m29s
Build all the nodes / hypervisor01 (pull_request) Successful in 1m32s
Build all the nodes / hypervisor02 (pull_request) Successful in 1m37s
Build all the nodes / geo01 (pull_request) Successful in 1m41s
Build all the nodes / geo02 (pull_request) Successful in 1m45s
Build all the nodes / bridge01 (pull_request) Successful in 1m55s
Build all the nodes / tower01 (pull_request) Successful in 1m55s
Build all the nodes / build01 (pull_request) Successful in 2m4s
Build all the nodes / storage01 (pull_request) Successful in 1m59s
Build all the nodes / rescue01 (pull_request) Successful in 2m4s
Build all the nodes / web02 (pull_request) Successful in 2m10s
Build all the nodes / compute01 (pull_request) Successful in 2m27s
Build all the nodes / vault01 (pull_request) Successful in 2m19s
Build all the nodes / web03 (pull_request) Successful in 2m18s
Build all the nodes / web01 (pull_request) Successful in 2m40s
2025-02-05 00:16:03 +01:00
Compare
lbailly force-pushed isp-firewall from e7033418e0
Some checks failed
Run pre-commit on all files / pre-commit (push) Has been cancelled
Check meta / check_meta (pull_request) Successful in 16s
Check meta / check_dns (pull_request) Successful in 16s
Check meta / check_meta (push) Successful in 17s
Check meta / check_dns (push) Successful in 19s
Build all the nodes / netaccess01 (pull_request) Successful in 20s
Check workflows / check_workflows (pull_request) Successful in 27s
Build all the nodes / ap01 (pull_request) Successful in 32s
Build all the nodes / netcore01 (pull_request) Successful in 38s
Build all the nodes / netcore02 (pull_request) Successful in 32s
Build the shell / build-shell (pull_request) Successful in 24s
Run pre-commit on all files / pre-commit (pull_request) Successful in 26s
Build all the nodes / hypervisor03 (pull_request) Successful in 1m29s
Build all the nodes / hypervisor01 (pull_request) Successful in 1m32s
Build all the nodes / hypervisor02 (pull_request) Successful in 1m37s
Build all the nodes / geo01 (pull_request) Successful in 1m41s
Build all the nodes / geo02 (pull_request) Successful in 1m45s
Build all the nodes / bridge01 (pull_request) Successful in 1m55s
Build all the nodes / tower01 (pull_request) Successful in 1m55s
Build all the nodes / build01 (pull_request) Successful in 2m4s
Build all the nodes / storage01 (pull_request) Successful in 1m59s
Build all the nodes / rescue01 (pull_request) Successful in 2m4s
Build all the nodes / web02 (pull_request) Successful in 2m10s
Build all the nodes / compute01 (pull_request) Successful in 2m27s
Build all the nodes / vault01 (pull_request) Successful in 2m19s
Build all the nodes / web03 (pull_request) Successful in 2m18s
Build all the nodes / web01 (pull_request) Successful in 2m40s
to 1737583fbc
All checks were successful
Run pre-commit on all files / pre-commit (push) Successful in 25s
Check meta / check_meta (pull_request) Successful in 16s
Check meta / check_dns (pull_request) Successful in 34s
Check workflows / check_workflows (pull_request) Successful in 43s
Build all the nodes / ap01 (pull_request) Successful in 1m25s
Build all the nodes / bridge01 (pull_request) Successful in 1m33s
Build all the nodes / geo01 (pull_request) Successful in 1m30s
Build all the nodes / build01 (pull_request) Successful in 1m35s
Build all the nodes / netaccess01 (pull_request) Successful in 42s
Build all the nodes / netcore01 (pull_request) Successful in 38s
Build all the nodes / netcore02 (pull_request) Successful in 44s
Build all the nodes / geo02 (pull_request) Successful in 1m35s
Build all the nodes / compute01 (pull_request) Successful in 2m0s
Run pre-commit on all files / pre-commit (pull_request) Successful in 27s
Build the shell / build-shell (pull_request) Successful in 28s
Build all the nodes / hypervisor01 (pull_request) Successful in 1m42s
Build all the nodes / hypervisor03 (pull_request) Successful in 1m41s
Build all the nodes / hypervisor02 (pull_request) Successful in 1m45s
Build all the nodes / storage01 (pull_request) Successful in 1m24s
Build all the nodes / rescue01 (pull_request) Successful in 1m32s
Build all the nodes / web02 (pull_request) Successful in 1m27s
Build all the nodes / tower01 (pull_request) Successful in 1m42s
Build all the nodes / web03 (pull_request) Successful in 1m34s
Build all the nodes / vault01 (pull_request) Successful in 1m48s
Build all the nodes / web01 (pull_request) Successful in 2m13s
2025-02-05 00:16:12 +01:00
Compare
lbailly force-pushed isp-firewall from 1737583fbc
All checks were successful
Run pre-commit on all files / pre-commit (push) Successful in 25s
Check meta / check_meta (pull_request) Successful in 16s
Check meta / check_dns (pull_request) Successful in 34s
Check workflows / check_workflows (pull_request) Successful in 43s
Build all the nodes / ap01 (pull_request) Successful in 1m25s
Build all the nodes / bridge01 (pull_request) Successful in 1m33s
Build all the nodes / geo01 (pull_request) Successful in 1m30s
Build all the nodes / build01 (pull_request) Successful in 1m35s
Build all the nodes / netaccess01 (pull_request) Successful in 42s
Build all the nodes / netcore01 (pull_request) Successful in 38s
Build all the nodes / netcore02 (pull_request) Successful in 44s
Build all the nodes / geo02 (pull_request) Successful in 1m35s
Build all the nodes / compute01 (pull_request) Successful in 2m0s
Run pre-commit on all files / pre-commit (pull_request) Successful in 27s
Build the shell / build-shell (pull_request) Successful in 28s
Build all the nodes / hypervisor01 (pull_request) Successful in 1m42s
Build all the nodes / hypervisor03 (pull_request) Successful in 1m41s
Build all the nodes / hypervisor02 (pull_request) Successful in 1m45s
Build all the nodes / storage01 (pull_request) Successful in 1m24s
Build all the nodes / rescue01 (pull_request) Successful in 1m32s
Build all the nodes / web02 (pull_request) Successful in 1m27s
Build all the nodes / tower01 (pull_request) Successful in 1m42s
Build all the nodes / web03 (pull_request) Successful in 1m34s
Build all the nodes / vault01 (pull_request) Successful in 1m48s
Build all the nodes / web01 (pull_request) Successful in 2m13s
to b3eb86c0a1
All checks were successful
Build all the nodes / tower01 (pull_request) Successful in 2m39s
Build all the nodes / hypervisor01 (pull_request) Successful in 2m50s
Build all the nodes / web02 (pull_request) Successful in 2m54s
Build all the nodes / geo02 (pull_request) Successful in 3m2s
Build all the nodes / rescue01 (pull_request) Successful in 2m59s
Build all the nodes / hypervisor03 (pull_request) Successful in 3m6s
Build all the nodes / web03 (pull_request) Successful in 3m5s
Build all the nodes / web01 (pull_request) Successful in 3m32s
Build all the nodes / compute01 (pull_request) Successful in 3m47s
Build all the nodes / ap01 (push) Successful in 1m8s
Build all the nodes / netcore01 (push) Successful in 28s
Build all the nodes / netaccess01 (push) Successful in 49s
Build all the nodes / netcore02 (push) Successful in 39s
Build all the nodes / hypervisor01 (push) Successful in 1m40s
Build all the nodes / bridge01 (push) Successful in 2m17s
Build all the nodes / hypervisor02 (push) Successful in 1m39s
Build the shell / build-shell (push) Successful in 25s
Build all the nodes / geo02 (push) Successful in 2m3s
Build all the nodes / geo01 (push) Successful in 2m36s
Run pre-commit on all files / pre-commit (push) Successful in 45s
Build all the nodes / hypervisor03 (push) Successful in 1m54s
Build all the nodes / compute01 (push) Successful in 2m46s
Build all the nodes / build01 (push) Successful in 2m55s
Build all the nodes / tower01 (push) Successful in 2m7s
Build all the nodes / vault01 (push) Successful in 2m27s
Build all the nodes / rescue01 (push) Successful in 2m51s
Build all the nodes / web02 (push) Successful in 2m44s
Build all the nodes / web03 (push) Successful in 3m13s
Build all the nodes / web01 (push) Successful in 3m18s
Build all the nodes / storage01 (push) Successful in 3m40s
2025-02-05 15:52:12 +01:00
Compare
thubrecht deleted branch isp-firewall 2025-02-05 16:07:49 +01:00
dgnum-chores referenced this pull request from a commit 2025-06-12 14:35:39 +02:00
dgnum-chores referenced this pull request from a commit 2025-06-12 14:36:38 +02:00
dgnum-chores referenced this pull request from a commit 2025-06-12 14:57:57 +02:00
lbailly referenced this pull request from a commit 2025-06-12 16:21:20 +02:00
lbailly referenced this pull request from a commit 2025-06-12 16:25:50 +02:00
Sign in to join this conversation.
No description provided.