You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/util/linuxfw
Irbe Krumina 5fb721d4ad
util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546)
We have hosts that support IPv6, but not IPv6 firewall configuration
in iptables mode.
We also have hosts that have some support for IPv6 firewall
configuration in iptables mode, but do not have iptables filter table.
We should:
- configure ip rules for all hosts that support IPv6
- only configure firewall rules in iptables mode if the host
has iptables filter table.

Updates tailscale/tailscale#11540

Signed-off-by: Irbe Krumina <irbe@tailscale.com>
2 years ago
..
linuxfwtest util/linuxfw: initial implementation of package 3 years ago
detector.go linuxfw,wgengine/route,ipn: add c2n and nodeattrs to control linux netfilter 2 years ago
fake.go util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546) 2 years ago
helpers.go all: cleanup unused code, part 2 (#10670) 2 years ago
iptables.go util/linuxfw: move detection logic 2 years ago
iptables_runner.go util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546) 2 years ago
iptables_runner_test.go util/linuxfw: move fake runner into pkg 2 years ago
linuxfw.go util/linuxfw,wgengine/router: enable IPv6 configuration when netfilter is disabled 2 years ago
linuxfw_unsupported.go all: cleanup unused code, part 2 (#10670) 2 years ago
nftables.go util/cmpx: delete now that we're using Go 1.22 2 years ago
nftables_runner.go util/linuxfw,wgengine/router: skip IPv6 firewall configuration in partial iptables mode (#11546) 2 years ago
nftables_runner_test.go util/linuxfw: add missing error checks in tests 2 years ago
nftables_types.go util/linuxfw: add new arch build constraints 2 years ago