2 Commits
Author SHA1 Message Date
sysopsandClaude Sonnet 5 00d084a188 Fix nftables auto-merge syntax and block private/reserved ranges
auto-merge is a standalone set statement, not an nft "flags" value -
"flags interval, auto-merge;" is a syntax error; fixed to "flags
interval;" followed by "auto-merge" on its own line. Needed because large
public blocklists (FireHOL, Spamhaus) contain overlapping CIDRs that
nftables otherwise refuses as "conflicting intervals".

Also add a hard guard: reject any "block" entry that overlaps a private/
reserved/bogon range (RFC1918, CGNAT, loopback, link-local, etc.) in both
the single-entry and bulk-import paths. Public feeds like FireHOL level1
routinely include ranges like 10.0.0.0/8 and 172.16.0.0/12, meant for
WAN-only edge firewalls - applied host-wide here (where WireGuard/LAN
subnets legitimately live in that same private space), those entries
would silently block a server's own internal/VPN traffic instead of
actual bad actors.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 20:44:29 +02:00
sysopsandClaude Sonnet 5 eb1913d400 Add central host-wide firewall allow/block lists
New model.IPListEntry + jsondb CRUD, independent of any single WireGuard
server. firewall.GenerateGlobalRuleset builds an nftables table
(wireguard_ui_global) with allow/block sets evaluated at priority -10 -
before every per-server table - so it applies to all traffic on the host,
not just WireGuard. Allow entries always win over block entries.
firewall.ApplyGlobal loads it live via `nft -f`, scoped to that one table.

New "Global Firewall Lists" page (nav entry under Settings): add/delete
entries, ruleset preview, "Apply now (live)" with an explicit confirm()
warning since this affects the whole host's firewall, not just one server.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 17:45:53 +02:00