9 Commits
Author SHA1 Message Date
jschoubben b4c21b4f67 Read a machine's iptables rules when it has no nft, instead of calling it unfiltered (hq ADR 0100) 2026-09-22 19:59:22 +02:00
jschoubben d3f2595968 Read a ufw rule's direction: an outgoing rule answers no opening, and incoming is the default ufw merges on (hq ADR 0103) 2026-09-22 19:51:35 +02:00
jschoubben 444ad8f3cf Record the forward policies before disabling ufw, so a retried retirement restores them (hq ADR 0100) 2026-09-22 18:33:09 +02:00
jschoubben b531c47486 Refuse an opening ufw would merge into a found rule that does other than a plain allow, and read log types in either place (hq ADR 0103) 2026-09-22 18:29:06 +02:00
jschoubben 52e139d96f Add no opening a found ufw rule already answers, since ufw takes rules differing only in comment for one, as captured on a lab machine (hq ADR 0103) 2026-09-22 18:06:47 +02:00
jschoubben da65f84c45 Read fail2ban's bans as no firewall, and an iptables-nft reject as a refusal, from rulesets captured on a lab machine (hq ADR 0100) 2026-09-22 18:04:48 +02:00
jschoubben 8e2f75454d Put back the forward policy ufw disable opens when the found firewall is retired, as measured on a lab machine (hq ADR 0100) 2026-09-22 18:03:30 +02:00
jschoubben 3e0e6e6b7e Delete a forwarded opening the way ufw accepts it, and read a fresh machine's resolver as not in use — both measured on a lab machine (hq ADR 0100) 2026-09-22 17:37:01 +02:00
jschoubben 3c90d155b3 Converge openings through the firewall an adopted node was found with, and retire it only when the node converges (hq ADR 0100) 2026-09-22 17:19:49 +02:00