Match source/dest zones on conntrack rules #24
Reference in New Issue
Block a user
Delete Branch "benvin/conntrack-zones"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Conntrack rules ignored their SOURCE/DEST zones and addresses, so a notrack meant for one zone hit every interface.
chain: outputwith another source andchain: preroutingwith an fw source are compile errors,chain: bothemits prerouting only-= all), as in stockNOTRACK - - udp 53chain: output/bothwith a non-fw source (e.g.net->fw) emits raw_output with no iif/oif at all (src iface dropped, fw dest resolves to ""), i.e. bareudp dport 53 notrackon all fw egress, the exact bug this PR fixes → reject non-fw source on raw_output at compile (or skip that chain for it) instead of emitting an unscoped rule.src.Zone == fwZone;chain: outputwith an interface-less non-fw dest still fails closed, but a non-fw source in output silently ignores the source zone (and its fail-closed check) → validate/skip as above and cover with a test.chain: output,chain: both, negated address (!192.0.2.1), sport, or a dest-zone-only rule (dest zone ignored in raw_prerouting) → add them; thebothcase would currently expose the unscoped raw_output rule.net -> lan) is silently dropped (dstIfaces forced to ""), so the rule matches regardless of dest → return an error or document/skip; shorewall's DEST zone is not ignorable here.chain: preroutingwith an fw source falls through to raw_prerouting with no iif (fw sources have no interface), so the rule matches all inbound/forwarded traffic filtered only by DEST/proto, not fw traffic → rejectchain: preroutingwith SOURCE fw as a compile error (like the non-fwoutputcase) and add a test.fw/all(no address) in raw_output (chain: output, orboth) resolves to no iif/oif/addr, so it emits an unscoped notrack/drop on all locally generated traffic (and unscoped prerouting forboth) → require DEST to scope the rule (zone with interfaces, or an address) when SOURCE is omitted in raw_output, else error; add a test.nte) is not rejected:resolveZoneInterfacesreturns[""]for zones absent fromcfg.Zones, so the rule compiles global and a typo notracks/drops every interface (fail open, the opposite of what this PR is for) → error on zones not incfg.Zones(other thanfw/all/any), plus a test.all!net/all+exclusions are silently ignored:zoneSpecskeeps the whole string asZone, which is not incfg.Zones, so the rule is global and the!netexclusion is dropped → expand viaexpandZoneRef(or reject exclusions), plus a test.