[Bug report] ABE blocking non-local website

Discussions about the Application Boundaries Enforcer (ABE) module
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: [Bug report] ABE blocking non-local website

Post by Giorgio Maone »

Ralf wrote:
However, since it seems this is gonna be quite common at least during the switch to IPv6 of hosting providers, and since web servers are very unlikely to be legitimately hosted on link-local IPs inside LANs, I'm gonna work-around for good by considering IPv6 link-local addresses (fe80:/10) as external for the purpose of cross-zone checks.
Doesn't this circumvent parts of the protection? I don't know which IPs, for example, (home) routers use for their LAN configuration interface.
Nope. link-local address are just a subset of LAN IPs and are not routable, therefore a device which hosts any valuable web service (like a router) is guaranteed to have at least another IP which is not link-local and can be used to identify the device as either LAN or WAN.

Done in latest development build 2.4.2rc7 and stable 2.4.2.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
User avatar
GµårÐïåñ
Lieutenant Colonel
Posts: 3369
Joined: Fri Mar 20, 2009 5:19 am
Location: PST - USA
Contact:

Re: [Bug report] ABE blocking non-local website

Post by GµårÐïåñ »

Ok, will do, just thinking out loud buddy, no worries. We'll figure it out.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.46 Safari/536.5 Comodo_Dragon/19.0.3.0
Post Reply