3 ms·
Not necessarily. On linux for example, you'll find netfilter firewall rules installed by tailscale that implement strict reverse path filtering, which will ensu
by dave_universetf 4y ago
Not necessarily. On linux for example, you'll find netfilter firewall rules installed by tailscale that implement strict reverse path filtering, which will ensure that tailscale IPs can only reach your userspace process if they originated from the tailscale network interface.
(you might ask why we don't use the rp_filter sysctl for this; unfortunately linux has a broken precedence order where loose filtering overrides strict filtering, so even if we ask for strict behavior for tailscale0, if the systemwide default is loose, we get the insufficient loose behavior - so we implement RPF by hand in netfilter instead, sigh)