Jump to content
Not connected, Your IP: 18.117.107.188
Sign in to follow this  
iwih2gk

Eddie Firewall improvement - Suggestion

Recommended Posts

I have thought about making this post a few times now. Today I am getting around to it. This will apply to members using Eddie with its ability to create a desired server list, which I use 100% of the time now. I decided to pull up the NFT firewall rules that Eddie sets when it is mounted and running. I know Eddie has a decent firewall running, BUT I feel there is an unnecessary risk by creating a firewall rule for every single server in Air’s system.

 

e.g. ----- > sudo nft list ruleset shows a rule created for hundreds/every server, and not ONLY firewall rules for the servers in my created list.

 

I don’t know how difficult it would be to have Eddie “SEE” the server IP’s in a user’s configured preference list and then only create a ruleset for those exclusively? With that configuration in place the remainder of Air’s servers would be BLOCKED from passing through tun0 in a linux instance. Similar in Windows I would think, but with different nomenclature. While only a very remote chance of a hacked server there is still at least some chance. I can’t imagine any weakness to removing firewall rules for servers not being used, but in fact would be allowed, if somehow a person got into one of those unused servers in a user's current Eddie configuration. My .02


The topic is a suggestion, but  maybe a Mod wants to move this to the Eddie forum.

Share this post


Link to post
12 hours ago, iwih2gk said:

The topic is a suggestion, but  maybe a Mod wants to move this to the Eddie forum.


Hello!

It's a suggestion to take into serious consideration and yes, we will move the topic into Eddie specific forum. In the AirVPN Suite for Linux the network lock design is different and was already optimized during the initial design, exactly in the way you suggest. Another bonus is a lighter firewall that needs to examine less rules.

Kind regards
 

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image
Sign in to follow this  

×
×
  • Create New...