3 ms·
Tailscale engineer here. I confirm. Only cryptographically valid packets are accepted, and then we only return peer identity information for flows from said au
by bradfitz 4y ago
Tailscale engineer here. I confirm.
Only cryptographically valid packets are accepted, and then we only return peer identity information for flows from said authenticated & authorized packets.
- matthewaveryusa 4y agoFor services you run where you do ip <-> identity authentication you have to make sure that you're only listening on the tailscale interface right? ie, if your server is listen on 0.0.0.0 then you may be open to IP spoofing?
- codethief 4y agoIIUC the way the server (Graphana/Minecraft) and the proxy described in the OP interact is the following: All incoming packets pass through the proxy which is running WireGuard in user space and which then passes them on to the server (which only listens on 127.0.0.1): > By setting the whitelist setting to 127.0.0.1, you only allow connections from the Grafana authentication proxy to be able to bypass Grafana’s normal authentication mechanisms. Since the proxy runs WireGuard in user space it will take care of assigning the IP addresses itself (after successful authentication), meaning no IP address spoofing or network interface "confusion" is possible.
- dave_universetf 4y agoNot necessarily. On linux for example, you'll find netfilter firewall rules installed by tailscale that implement strict reverse path filtering, which will ensure that tailscale IPs can only reach your userspace process if they originated from the tailscale network interface. (you might ask why we don't use the rp_filter sysctl for this; unfortunately linux has a broken precedence order where loose filtering overrides strict filtering, so even if we ask for strict behavior for tailscale0, if the systemwide default is loose, we get the insufficient loose behavior - so we implement RPF by hand in netfilter instead, sigh)