18 ms·
Right now it's just an egress firewall. It bundles the "nft" userspace utility and creates its own isolated nftables table to block traffic in the forward chain
by jamilbk 5y ago
Right now it's just an egress firewall. It bundles the "nft" userspace utility and creates its own isolated nftables table to block traffic in the forward chain. See here for details:
https://github.com/firezone/firezone/blob/master/apps/fz_wall/lib/fz_wall/cli/live.ex#L18 https://github.com/firezone/firezone/blob/master/apps/fz_wal...
It wouldn't be too hard to add functionality to block ingress traffic as well, though. Is that something you'd find useful?
- mbreese 5y agoCan I ask -- what's the idea behind the egress firewall? Is it to make sure that all of the wireguard traffic is destined for the local network and not the internet at large?
- jamilbk 5y agoYeah that was one motivation behind it -- to provide some rudimentary controls to filter outbound traffic through the VPN server. The egress firewall will also be useful for upcoming 2FA features -- we can block traffic destined to the Internet until the user authenticates through the web portal (in addition to having the WireGuard config on their device). For now the egress firewall is more of just an MVP feature though :-)
- vegardx 5y agoI see that you mentioned LDAP/SSO integration, do you have any plans for doing role mappings to egress filters. It would be super handy for the use case you mentioned as your inspiration for the product, connecting to VPCs. We've been looking at AWS Client VPN for this reason alone. This would let us control what peered VPCs a user was able to talk with, or even what subnets on specific VPCs they could access.
- jamilbk 5y agoThis is great feedback. We are discussing features that should satisfy this workflow in this issue: https://github.com/firezone/firezone/issues/259 https://github.com/firezone/firezone/issues/259 It essentially boils down to having different firewall zones tied to user states (unauthenticated, authenticated, LDAP group, etc).