ssh is never left without a rule
The floor allowed ssh from the mesh's addresses, and from everywhere on a machine that faces outward. On a machine the mesh knows no addresses for it emitted neither — so the chain dropped by default and ssh was simply shut. That is the first machine anybody adopts: reached over the network, with the port needed to fix it closed by the act of adopting it. Found by reading the rules off a live machine rather than trusting the generator.
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
package catalogue
|
||||
|
||||
import (
|
||||
"os"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestPrintRehearsalRuleset(t *testing.T) {
|
||||
if os.Getenv("PRINT_RULESET") == "" {
|
||||
t.Skip("set PRINT_RULESET")
|
||||
}
|
||||
rules := mustFilter(t, Resolution{Modules: []Manifest{
|
||||
{Module: "pub", Listens: []Listening{{Port: 8099, From: FromMesh, Why: "the thing it serves"}}},
|
||||
}}, nil)
|
||||
t.Log("\n" + AsNftables(rules, []string{"192.0.2.20"}, true))
|
||||
}
|
||||
Reference in New Issue
Block a user