Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Compatibility with Zone Based Firewalls? #6

Open
GNU-Plus-Windows-User opened this issue Jan 6, 2025 · 5 comments
Open

Compatibility with Zone Based Firewalls? #6

GNU-Plus-Windows-User opened this issue Jan 6, 2025 · 5 comments

Comments

@GNU-Plus-Windows-User
Copy link
Contributor

I have personally not tested this feature, but some other users in the CrowdSec Discord have reported that firewall rules and objects are not being created when using zone based firewalls. These rules are created via IPtables but they do not show up via the GUI.

By the way, I've just tested this bouncer out, I had some issues setting it up but other than that it's working great for me!

@PintjesB
Copy link

PintjesB commented Jan 6, 2025

I am one of those users, but the rules are not getting created in the iptables (nor in the GUI, as mentioned). It is however visible through the API.

The IP objects are getting created correctly. But the rules using said objects aren't visible (and thus, not deletable)

@Teifun2
Copy link
Owner

Teifun2 commented Jan 6, 2025

Is this the UNIFI_SITE? This would be a configurable Environment Variable.

The default is the "default" site as according to documentation this is present in any unifi router.

image

@PintjesB
Copy link

PintjesB commented Jan 6, 2025

I don't think so. Like mentioned the IP objects get created and are visible in the GUI. The rules using said objects however aren't visible in the GUI for people using the new Zone Based rules. People using the old firewall rules system can see the rules as intended...

@Teifun2
Copy link
Owner

Teifun2 commented Jan 20, 2025

FYI: I have opened a ticket with the maintainer of the unifi library to ask for guidance how to adapt.

I hope soemthing comes of it:
paultyng/go-unifi#242

@PintjesB
Copy link

Awesome!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants