Project

General

Profile

Actions

Bug #4258

closed

DNS Resolver - auto-added access controls missing IPv6 subnets where "all" interfaces selected

Added by Kill Bill over 9 years ago. Updated over 9 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
DNS Resolver
Target version:
Start date:
01/21/2015
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.2
Affected Architecture:
All

Description

IPv4 subnets are automagically added to /var/unbound/access_lists.conf; however this is not done with any of the IPv6 subnets defined for internal interfaces.

Actions #1

Updated by Chris Buechler over 9 years ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100
Actions #3

Updated by Chris Buechler over 9 years ago

  • Subject changed from DNS Resolver - auto-added access controls missing IPv6 subnets to DNS Resolver - auto-added access controls missing IPv6 subnets where "all" interfaces selected
  • Status changed from Feedback to Resolved
  • Target version set to 2.2
  • % Done changed from 100 to 0

updated subject to specific issue. Fixed

Actions #4

Updated by Kill Bill over 9 years ago

Ok, this works mostly fine, except that it misses OpenVPN's IPv6 (and probably IPsec as well, don't have IPv6 IPsec tunnel configured though.)

Actions #5

Updated by Chris Buechler over 9 years ago

It only covers interfaces that are assigned and enabled plus static routes for IPv6. Manual entries will be required for other circumstances.

Actions #6

Updated by Kill Bill over 9 years ago

Kinda confused really what it covers now. It certainly is adding OpenVPN and IPSec IPv4 subnets to the ACL.

Actions #7

Updated by Chris Buechler over 9 years ago

for v4, it uses the same source networks as it uses for outbound NAT auto rule generation, which is a diff process.

Actions #8

Updated by Kill Bill over 9 years ago

OK, lets call this fixed then. Thanks. :)

(Kinda inconsistent results, perhaps the VPN stuff would be worth a separate checkbox instead, but it certainly is not good time for similar nontrivial changes now.)

Actions

Also available in: Atom PDF