Node: Only Allow Traffic to Router #117

Open
opened 2024-10-24 14:32:55 +00:00 by mik-tf · 13 comments
Owner

We need to secure the farmer's local network to avoid attacks.

Requirements

  • restrict outgoing network, only traffic to router is allowed (we get router info over DHCP, auto config)

References

Notes

  • First written for this issue: #98

Status

Live for zoslight nodes now

We need to secure the farmer's local network to avoid attacks. ## Requirements - restrict outgoing network, only traffic to router is allowed (we get router info over DHCP, auto config) ## References - GitHub Issue: https://github.com/threefoldtech/zos/issues/2455 ## Notes - First written for this issue: https://git.ourworld.tf/tfgrid/circle_engineering/issues/98 ## Status Live for zoslight nodes now
mik-tf added this to the tfgrid_3_15 project 2024-10-24 14:33:01 +00:00
delandtj was assigned by mik-tf 2024-10-24 14:33:16 +00:00
Owner
See https://github.com/threefoldtech/zos/issues/2399
Owner

@despiegk pls take a look at this issue, your input is needed

@despiegk pls take a look at this issue, your input is needed
Author
Owner

Update

  • There was a meeting on this and it is now well on its way (don't need Kristof's input anymore as it's been discussed in the meeting)
  • We will update the issue when it's done
  • The ongoing github issue on this is here: https://github.com/threefoldtech/zos/issues/2455
    • When this is done, we can close this gitea issue.
# Update - There was a meeting on this and it is now well on its way (don't need Kristof's input anymore as it's been discussed in the meeting) - We will update the issue when it's done - The ongoing github issue on this is here: https://github.com/threefoldtech/zos/issues/2455 - When this is done, we can close this gitea issue.
Owner
new ticket https://github.com/threefoldtech/zos/issues/2455
mik-tf added the
Story
label 2024-10-31 14:19:34 +00:00
mik-tf added the due date 2024-11-11 2024-11-05 03:11:30 +00:00
Author
Owner

Update

  • @delandtj please let us now how this is going when you have more info, thanks.
# Update - @delandtj please let us now how this is going when you have more info, thanks.
Author
Owner

Update

  • @delandtj is working on it, should be good for the 11th of November
# Update - @delandtj is working on it, should be good for the 11th of November
Author
Owner

Update

# Update - Jan proposed a solution: https://github.com/threefoldtech/zos/issues/2455#issuecomment-2465245950 - We just need to implement it
Author
Owner

Update

  • Updated the GH issue with all specs developed so far by the team (thanks everyone for input+work)
  • IMO, next step is to implement and test

Wdyt? @sabrinasadik @thabeta

# Update - Updated the GH issue with all specs developed so far by the team (thanks everyone for input+work) - IMO, next step is to implement and test Wdyt? @sabrinasadik @thabeta
Author
Owner

Update

  • Jan explained to devs what we want
  • Devs will work and update Jan if things come up
  • Devs: Ashra + Omar
# Update - Jan explained to devs what we want - Devs will work and update Jan if things come up - Devs: Ashra + Omar
mik-tf modified the project from tfgrid_3_15 to tfgrid_3_15_patch 2024-11-26 15:11:32 +00:00
Author
Owner

Update

  • Devs are working on this
  • Should be ok for 3.15 patch/additional release
# Update - Devs are working on this - Should be ok for 3.15 patch/additional release
delandtj was unassigned by despiegk 2024-12-30 15:10:32 +00:00
thabeta self-assigned this 2024-12-30 15:11:23 +00:00
despiegk modified the due date from 2024-11-11 to 2025-01-03 2024-12-30 15:12:28 +00:00
Author
Owner

Update

  • Thabet is owner of the issue
  • ETA for January 3 2025
# Update - Thabet is owner of the issue - ETA for January 3 2025
Author
Owner

@thabeta lmk if I can help in any way for this story.

@thabeta lmk if I can help in any way for this story.
Owner

this is patched for zoslight nodes on mainnet now, for zos nodes further assistance from azmy is required

this is patched for zoslight nodes on mainnet now, for zos nodes further assistance from azmy is required
Sign in to join this conversation.
No Milestone
No Assignees
3 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

2025-01-03

Dependencies

No dependencies set.

Reference: tfgrid/circle_engineering#117
No description provided.