Emit the implied ACCEPT for DNAT and REDIRECT rules #29
Reference in New Issue
Block a user
Delete Branch "benvin/dnat-implied-accept"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Shorewall DNAT/REDIRECT imply a filter ACCEPT for the translated flow; tomswall emitted only the prerouting NAT, so DNATed services stayed dropped.
ct status dnat, taggedrule:N:accept.+.limit(verified:ratelimit 10/sec:5+ zone with eth2,eth3 → 2 limited forward rules, no error) → count dst interfaces/addrs for DNAT/REDIRECT in the guard (or reject).useryieldsmeta skuidin forward, which can never match, so the published service stays dropped → don't apply the user extra to the implied accept (or reject DNAT+user), and add a test for extras on the accept.all/anysource is not skipped for the target zone (zoneSpecs keeps it global, srcZone "all" != dstZone), so the accept is iif-less and also covers target→target hairpin; shorewall skips source==dest forallunlessall+→ treatall/anyas wild in dnatSkipsIntrazone and expand per zone.sportsbut compileDNATRule ignores SPORT, so a rule with SPORT NATs every source port but only accepts the listed one → drop sports from the accept, or apply it to the nat rule too.!ok || r.Chain != "prerouting" && r.Tag == "rule:3"is precedence-obscure and skips the input accept silently → parenthesise or keywantby chain+tag.No findings.
No findings.