Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upFix too relaxed firewall rules in proxyvm #136
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
|
Modified by smoku on 27 Mar 2011 15:25 UTC |
marmarek
added this to the Release 1 Beta 1 milestone
Mar 8, 2015
marmarek
added
bug
C: core
P: major
labels
Mar 8, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
marmarek
Mar 8, 2015
Member
Comment by smoku on 27 Mar 2011 16:45 UTC
Fixed in http://git.qubes-os.org/?p=smoku/core;a=commit;h=04a6b01b1b8992acd4712d697b80dba6b37d66bf
|
Comment by smoku on 27 Mar 2011 16:45 UTC |
marmarek
closed this
Mar 8, 2015
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
marmarek commentedMar 8, 2015
Reported by rafal on 25 Mar 2011 13:17 UTC
Just after creation of proxy and somevm behind it, there is a rule in proxy fw rules in FORWARD:
ACCEPT state NEW,ESTABLISHED,RELATED from any to any
it looks wrong (should be ESTABLISHED,RELATED ?), as a result netvm can connect to somevm open ports (if netvm guesses somevm IP).
Migrated-From: https://wiki.qubes-os.org/ticket/136