Development issues regarding the cerowrt test router project
 help / color / mirror / Atom feed
* [Cerowrt-devel] Firewall configuration in 3.10.50-1
@ 2014-09-15 15:22 Norman Yarvin
  2014-09-15 15:32 ` Dave Taht
  0 siblings, 1 reply; 3+ messages in thread
From: Norman Yarvin @ 2014-09-15 15:22 UTC (permalink / raw)
  To: cerowrt-devel

I was just bringing up a router with 3.10.50-1, and noticed something
that seemed amiss in the default firewall configuration.  That is,
under the Network / Interfaces tab, most of the interfaces, under
"Firewall Settings", weren't assigned to any "firewall zone" ("guest",
"wan", or "lan"), but rather were left as "unspecified".

Maybe this is on purpose for some reason, but it seems worth
mentioning.


-- 
Norman Yarvin					http://yarchive.net/blog

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [Cerowrt-devel] Firewall configuration in 3.10.50-1
  2014-09-15 15:22 [Cerowrt-devel] Firewall configuration in 3.10.50-1 Norman Yarvin
@ 2014-09-15 15:32 ` Dave Taht
  2014-09-15 15:57   ` Norman Yarvin
  0 siblings, 1 reply; 3+ messages in thread
From: Dave Taht @ 2014-09-15 15:32 UTC (permalink / raw)
  To: Norman Yarvin; +Cc: cerowrt-devel

It is a bug in the gui. To get efficiency in the firewall rules cero
uses a pattern match
to blend together all the interfaces. So you see in
/etc/config/firewall file lines that use

s+ To pattern match the three secure interfaces (se00, sw00, sw10)
gw+ To pattern match the guest interfaces.



On Mon, Sep 15, 2014 at 6:22 PM, Norman Yarvin <yarvin@yarchive.net> wrote:
> I was just bringing up a router with 3.10.50-1, and noticed something
> that seemed amiss in the default firewall configuration.  That is,
> under the Network / Interfaces tab, most of the interfaces, under
> "Firewall Settings", weren't assigned to any "firewall zone" ("guest",
> "wan", or "lan"), but rather were left as "unspecified".
>
> Maybe this is on purpose for some reason, but it seems worth
> mentioning.
>
>
> --
> Norman Yarvin                                   http://yarchive.net/blog
> _______________________________________________
> Cerowrt-devel mailing list
> Cerowrt-devel@lists.bufferbloat.net
> https://lists.bufferbloat.net/listinfo/cerowrt-devel



-- 
Dave Täht

https://www.bufferbloat.net/projects/make-wifi-fast

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [Cerowrt-devel] Firewall configuration in 3.10.50-1
  2014-09-15 15:32 ` Dave Taht
@ 2014-09-15 15:57   ` Norman Yarvin
  0 siblings, 0 replies; 3+ messages in thread
From: Norman Yarvin @ 2014-09-15 15:57 UTC (permalink / raw)
  To: Dave Taht; +Cc: cerowrt-devel

Ah, okay.

It seems like the GUI could be fixed by just nuking the "firewall
settings" tab.  (Since if someone does try to use it, it'll interact
in some unspecified way with the existing "s+" and "gw+" rules.)


On Mon, Sep 15, 2014 at 06:32:09PM +0300, Dave Taht wrote:
>It is a bug in the gui. To get efficiency in the firewall rules cero
>uses a pattern match
>to blend together all the interfaces. So you see in
>/etc/config/firewall file lines that use
>
>s+ To pattern match the three secure interfaces (se00, sw00, sw10)
>gw+ To pattern match the guest interfaces.
>
>
>
>On Mon, Sep 15, 2014 at 6:22 PM, Norman Yarvin <yarvin@yarchive.net> wrote:
>> I was just bringing up a router with 3.10.50-1, and noticed something
>> that seemed amiss in the default firewall configuration.  That is,
>> under the Network / Interfaces tab, most of the interfaces, under
>> "Firewall Settings", weren't assigned to any "firewall zone" ("guest",
>> "wan", or "lan"), but rather were left as "unspecified".
>>
>> Maybe this is on purpose for some reason, but it seems worth
>> mentioning.
>>
>>
>> --
>> Norman Yarvin                                   http://yarchive.net/blog
>> _______________________________________________
>> Cerowrt-devel mailing list
>> Cerowrt-devel@lists.bufferbloat.net
>> https://lists.bufferbloat.net/listinfo/cerowrt-devel
>
>
>
>-- 
>Dave Täht
>
>https://www.bufferbloat.net/projects/make-wifi-fast

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2014-09-15 15:57 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-09-15 15:22 [Cerowrt-devel] Firewall configuration in 3.10.50-1 Norman Yarvin
2014-09-15 15:32 ` Dave Taht
2014-09-15 15:57   ` Norman Yarvin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox