4 ms·
Yeah that was one motivation behind it -- to provide some rudimentary controls to filter outbound traffic through the VPN server. The egress firewall will also
by jamilbk 5y ago
Yeah that was one motivation behind it -- to provide some rudimentary controls to filter outbound traffic through the VPN server.
The egress firewall will also be useful for upcoming 2FA features -- we can block traffic destined to the Internet until the user authenticates through the web portal (in addition to having the WireGuard config on their device).
For now the egress firewall is more of just an MVP feature though :-)
- vegardx 5y agoI see that you mentioned LDAP/SSO integration, do you have any plans for doing role mappings to egress filters. It would be super handy for the use case you mentioned as your inspiration for the product, connecting to VPCs. We've been looking at AWS Client VPN for this reason alone. This would let us control what peered VPCs a user was able to talk with, or even what subnets on specific VPCs they could access.
- jamilbk 5y agoThis is great feedback. We are discussing features that should satisfy this workflow in this issue: https://github.com/firezone/firezone/issues/259 https://github.com/firezone/firezone/issues/259 It essentially boils down to having different firewall zones tied to user states (unauthenticated, authenticated, LDAP group, etc).