You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Anyone can help out by sponsoring development of new features or contributing pull requests.
Please use this issue for discussions related to the feature.
Description
Umbrella task and brainstorming topic for advanced firewall features, including outstanding TODO's from #448
Support ipsets, with RPC support for dynamic blocking/allowing IPs in an ipset
Integrate fail2ban, see below design proposal
Investigate fail2ban integration with firewalld, for more info, see:
Firewalld ignoring rich-rule against port forwarding firewalld/firewalld#1466 (comment)
firewalld helpers -- possibly for conntrack, e.g., ftp
With
modprobe br_netfilterfirewalld would see all traffic, but there are issues,It is impossible to add a rule accepting bridge traffic with FirewallBackend=nftables firewalld/firewalld#1236,
and limits to what seem to be possible atm. You may also need to enable these callbacks:
Investigate filtering out firewall log messages from other log files
Podman published ports, https://firewalld.org/2024/11/strict-forward-ports
Software fastpath https://firewalld.org/2023/05/nftables-flowtable
Additional Information
No response
General Information
Anyone can help out by sponsoring development of new features or contributing pull requests.
Please use this issue for discussions related to the feature.