You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/util/linuxfw
Irbe Krumina 5fb721d4ad
util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546)
We have hosts that support IPv6, but not IPv6 firewall configuration
in iptables mode.
We also have hosts that have some support for IPv6 firewall
configuration in iptables mode, but do not have iptables filter table.
We should:
- configure ip rules for all hosts that support IPv6
- only configure firewall rules in iptables mode if the host
has iptables filter table.

Updates tailscale/tailscale#11540

Signed-off-by: Irbe Krumina <irbe@tailscale.com>
2 months ago
..
linuxfwtest util/linuxfw: initial implementation of package 1 year ago
detector.go linuxfw,wgengine/route,ipn: add c2n and nodeattrs to control linux netfilter 6 months ago
fake.go util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546) 2 months ago
helpers.go all: cleanup unused code, part 2 (#10670) 6 months ago
iptables.go util/linuxfw: move detection logic 8 months ago
iptables_runner.go util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546) 2 months ago
iptables_runner_test.go util/linuxfw: move fake runner into pkg 8 months ago
linuxfw.go util/linuxfw,wgengine/router: enable IPv6 configuration when netfilter is disabled 3 months ago
linuxfw_unsupported.go all: cleanup unused code, part 2 (#10670) 6 months ago
nftables.go util/cmpx: delete now that we're using Go 1.22 4 months ago
nftables_runner.go util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546) 2 months ago
nftables_runner_test.go util/linuxfw: add missing error checks in tests 7 months ago
nftables_types.go util/linuxfw: add new arch build constraints 11 months ago