Anonymous | Login | 2024-11-21 01:29 MST |
Main | My View | View Issues | Change Log | Roadmap | Repositories |
View Issue Details [ Jump to Notes ] | [ Issue History ] [ Print ] | ||||||||
ID | Project | Category | View Status | Date Submitted | Last Update | ||||
0021091 | ClearOS | app-firewall - Firewall | public | 2018-08-14 11:37 | 2019-07-11 05:29 | ||||
Reporter | NickH | ||||||||
Assigned To | dsokoloski | ||||||||
Priority | normal | Severity | tweak | Reproducibility | always | ||||
Status | closed | Resolution | fixed | ||||||
Platform | OS | OS Version | |||||||
Product Version | 7.5.0 Updates | ||||||||
Target Version | 7.6.0 | Fixed in Version | 7.6.0 | ||||||
Summary | 0021091: Change to default incoming rule for 169.254.0.0/16 to block new packets only | ||||||||
Description | From forum post https://www.clearos.com/clearfoundation/social/community/outgoing-connection-to-one-specific-address-does-not-work-even-if-all-outgoing-connections-are-allowed#reply-228511 [^] it looks like various cloud providers are now using 169.254 addresses for instance metadata. See: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html [^] and https://docs.microsoft.com/en-us/azure/virtual-machines/windows/instance-metadata-service. [^] Can I suggest the default Incoming rule for 169.254.0.0/16 is changed just to block NEW packets by adding "-m state --state NEW" to the rule. | ||||||||
Tags | No tags attached. | ||||||||
Attached Files | |||||||||
Notes | |
(0008441) NickH (developer) 2018-11-01 06:47 |
Big dawning here. The firewall will block new packets anyway. Just remove the rule. |
Issue History | |||
Date Modified | Username | Field | Change |
2018-08-14 11:37 | NickH | New Issue | |
2018-08-14 11:39 | user2 | Target Version | => 7.5.0 Updates |
2018-08-14 11:40 | user2 | Assigned To | => dsokoloski |
2018-08-14 11:40 | user2 | Status | new => assigned |
2018-10-30 18:11 | user2 | Target Version | 7.5.0 Updates => 7.6.0 Updates |
2018-11-01 06:47 | NickH | Note Added: 0008441 | |
2018-11-20 11:52 | dsokoloski | Status | assigned => resolved |
2018-11-20 11:52 | dsokoloski | Resolution | open => fixed |
2018-11-20 11:52 | dsokoloski | Fixed in Version | => 7.6.0 |
2018-11-20 11:52 | dsokoloski | Target Version | 7.6.0 Updates => 7.6.0 |
2019-07-11 05:29 | NickH | Status | resolved => closed |