Warp nACLs (network access control lists)

  • SzethFriendOfNimi@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    ·
    edit-2
    11 months ago

    Kirk: We need more packets!

    Scotty: I canna divert more packets. She’s gonna blow.

    Spock: Perhaps we could divert the packets via a patch cable.

    Scotty: Ya gotta be kiddin’ me. That’s a horrible plan.

    Kirk: Do it.

    Enterprise Computer: We’ve been trying to reach you about your ships extended warp bubble

    Scotty: Bloody idiots, the lot of ya

  • CyberEgg
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    11 months ago

    Ouf. Please close port 80. And if this is not a web server, close any ports for inbound traffic and implement a spi capable firewall.

    • lud@lemm.ee
      link
      fedilink
      arrow-up
      4
      ·
      11 months ago

      It looks like these are examples from some documentation and not someone actual config

      • AFallingAnvil@lemmy.caOP
        link
        fedilink
        arrow-up
        6
        ·
        11 months ago

        This, I just grabbed a random example. I shudder to think of actually posting the ACLs from any production environment

        • Ananace@lemmy.ananace.dev
          link
          fedilink
          arrow-up
          1
          ·
          11 months ago

          I think the file upload size limit could become a problem in my case, at least in terms of posting the complete ACLs.

          We’ve recently managed to come down to only ~1.4k VLANs though, and the network firewall pair for our server networks now only handles ~600 SPB services.

      • CyberEgg
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        11 months ago

        Yea, I guess. But this should only be an example for how not to ACL

    • funkajunk@lemm.ee
      link
      fedilink
      English
      arrow-up
      3
      ·
      11 months ago

      Port 80 is open so you can redirect to https, it’s not actually serving over http