You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/util/linuxfw
James Tucker ba6ec42f6d util/linuxfw: add missing input rule to the tailscale tun
Add an explicit accept rule for input to the tun interface, as a mirror
to the explicit rule to accept output from the tun interface.

The rule matches any packet in to our tun interface and accepts it, and
the rule is positioned and prioritized such that it should be evaluated
prior to conventional ufw/iptables/nft rules.

Updates #391
Fixes #7332
Updates #9084

Signed-off-by: James Tucker <james@tailscale.com>
2 years ago
..
linuxfwtest util/linuxfw: initial implementation of package 3 years ago
helpers.go util/linuxfw: initial implementation of package 3 years ago
iptables.go util/linuxfw: rename ErrorFWModeNotSupported 2 years ago
iptables_runner.go util/linuxfw: add missing input rule to the tailscale tun 2 years ago
iptables_runner_test.go util/linuxfw: add missing input rule to the tailscale tun 2 years ago
linuxfw.go util/linuxfw: rename ErrorFWModeNotSupported 2 years ago
linuxfw_unsupported.go util/linuxfw: Fix comment which lists supported linux arches 2 years ago
nftables.go util/linuxfw: rename ErrorFWModeNotSupported 2 years ago
nftables_runner.go util/linuxfw: add missing input rule to the tailscale tun 2 years ago
nftables_runner_test.go util/linuxfw: add missing input rule to the tailscale tun 2 years ago
nftables_types.go util/linuxfw: add new arch build constraints 2 years ago