Match zones defined by hosts entries #38
Reference in New Issue
Block a user
Delete Branch "benvin/hosts-zones"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Zones defined only by
hostsentries (e.g.lan:netwithlan wlo1:192.0.2.0/24) resolve to no interfaces, so the compiler skips their rules and policies, and the parent zone captures their hosts.!exclusions and keep failing closed for zones with neither interfaces nor hosts!exclusions and[v6]brackets in hosts and-interface zones on migrateip saddr/daddr != exclon an IPv6 packet reads IPv6 header bytes, so a matching packet skips the zone match. That is stricter for ACCEPT but looser for DROP/REJECT rules, blrules and DROP/REJECT policies: the packet escapes the drop and can reach a later accept (the ponytail note at :1312 is wrong that it only skips the zone) → emit the exclusion as (nfproto != fam) OR (addr != excl) per exclusion family, or reject mixed-family exclusions in validateHosts; drop the false comment.No findings.
routeback(config.HostOptions.RouteBack, set by shorewall convert) are never read by the compiler, so two host groups of one zone on one interface get no intra accept/zone zonepolicy even with routeback; shorewall emits them → skip the pair only when neither host has Options.RouteBack (and the interface has no routeback), carry the flag on zoneMatchNo findings.