You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/util/linuxfw
Andrew Lytvynov 728622665f
1.48 cherry-picks for nftables (#8989)
* wgengine/router: fall back and set iptables as default again

Due to the conflict between our nftables implementation and ufw, which is a common utility used
on linux. We now want to take a step back to prevent regression. This will give us more chance to
let users to test our nftables support and heuristic.

Updates: #391
Signed-off-by: KevinLiang10 <kevinliang@tailscale.com>
(cherry picked from commit 93cab56277)

* util/linuxfw: reorganize nftables rules to allow it to work with ufw

This commit tries to mimic the way iptables-nft work with the filewall rules. We
follow the convention of using tables like filter, nat and the conventional
chains, to make our nftables implementation work with ufw.

Updates: #391

Signed-off-by: KevinLiang10 <kevinliang@tailscale.com>
(cherry picked from commit b040094b90)

* tailcfg: update docs on NetInfo.FirewallMode

Updates #391

Change-Id: Ifef196b31dd145f424fb0c0d0bb04565cc22c717
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
(cherry picked from commit 282dad1b62)

---------

Co-authored-by: KevinLiang10 <kevinliang@tailscale.com>
Co-authored-by: Brad Fitzpatrick <bradfitz@tailscale.com>
2 years ago
..
linuxfwtest util/linuxfw: initial implementation of package 3 years ago
helpers.go util/linuxfw: initial implementation of package 3 years ago
iptables.go util/linuxfw: rename ErrorFWModeNotSupported 2 years ago
iptables_runner.go util/linuxfw: add nftables support 3 years ago
iptables_runner_test.go util/linuxfw: decoupling IPTables logic from linux router 3 years ago
linuxfw.go util/linuxfw: rename ErrorFWModeNotSupported 2 years ago
linuxfw_unsupported.go util/linuxfw: add new arch build constraints 3 years ago
nftables.go util/linuxfw: rename ErrorFWModeNotSupported 2 years ago
nftables_runner.go 1.48 cherry-picks for nftables (#8989) 2 years ago
nftables_runner_test.go 1.48 cherry-picks for nftables (#8989) 2 years ago
nftables_types.go util/linuxfw: add new arch build constraints 3 years ago