Skip to content

Commit b3253cd

Browse files
authored
NM-9: fix all rsrc static node rule (#3593)
* user policies fix * fix user acl rules for all resources tag * handle relayed comms via gateway with active acl policies * fix static node comms to all resources * add all resources src rule for static node
1 parent 32657dd commit b3253cd

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

logic/acls.go

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -59,6 +59,14 @@ func GetFwRulesOnIngressGateway(node models.Node) (rules []models.FwRule) {
5959
},
6060
Allow: true,
6161
})
62+
rules = append(rules, models.FwRule{
63+
SrcIP: node.NetworkRange,
64+
DstIP: net.IPNet{
65+
IP: nodeI.Address.IP,
66+
Mask: net.CIDRMask(32, 32),
67+
},
68+
Allow: true,
69+
})
6270
}
6371
if nodeI.Address6.IP != nil {
6472
rules = append(rules, models.FwRule{
@@ -68,6 +76,14 @@ func GetFwRulesOnIngressGateway(node models.Node) (rules []models.FwRule) {
6876
},
6977
Allow: true,
7078
})
79+
rules = append(rules, models.FwRule{
80+
SrcIP: node.NetworkRange6,
81+
DstIP: net.IPNet{
82+
IP: nodeI.Address.IP,
83+
Mask: net.CIDRMask(128, 128),
84+
},
85+
Allow: true,
86+
})
7187
}
7288
continue
7389
}

0 commit comments

Comments
 (0)