Accept intra-zone traffic between different interfaces #37
Reference in New Issue
Block a user
Delete Branch "benvin/intrazone-multi-iface"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Shorewall accepts traffic between different interfaces of the same zone unless an explicit
zone zone(orall+) policy overrides it; routeback only governs same-interface traffic. tomswall emits only routeback accepts and skips explicitzone zonepolicies, so e.g. lxdbr0 to docker0 in zonelxdhits the forward drop.zone zonepolicies in place of the implicit acceptfw fw <action>now counts as explicitIntra; with sz==dz==fw, selectChain givesinputand both ifaces are "", so it emits an unconditional input rule (all input accepted or dropped, ahead of every laternet fwpolicy). Previously skipped → exclude the firewall zone from explicitIntra (and fromoverridden), and add a test withfw fw ACCEPT/DROP.No findings.