3 ms·
Yes. All you have to do is whitelist your clients' yggdrasil addresses in your firewall. in pf syntax: table <yggdrasil> persist file "/etc/yggdrasil-allowe
by realreality 6mo ago
Yes. All you have to do is whitelist your clients' yggdrasil addresses in your firewall.
in pf syntax:
table <yggdrasil> persist file "/etc/yggdrasil-allowed"
pass in quick on tun0 inet6 proto tcp from <yggdrasil> to port $services
- Karrot_Kream 6mo agoHave you had issues with bad actors flooding you? And how are your routes (when you're stationary?) Just curious
- MarsIronPI 6mo agoI actually don't have firewalls set up on my devices that run Yggdrasil yet (please don't crack me). I haven't noticed any brute-force attacks on my SSH servers yet. Though I really should set up firewalls. As for routing, I run my own node on a VPS, so all my edge devices are peered with that machine so routing is fine. Though when my machines are on the same network they automatically peer with each other directly.
- realreality 6mo agoI haven't noticed any bad actor traffic. Perhaps yggdrasil is still too obscure to bother attacking. The stationary nodes are connected to several public yggdrasil peers that are geographically close by. The routing "just works", though connecting to a peer can take a few seconds, at first.