Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there anything among these that incorporates a basic configurable firewall policy?

In the more distant past, I used sshuttle to create “one way” poor man’s VPN; it is slow, but it was enough to saturate the remote connections I had at the time; and —- unlike many other systems at the time —- I knew I could trust the cryptography and key distribution, which piggybacks ssh.

At the minimum,I want to have connections going only one way between sine hosts, or no way in the case of two edge devices - and possibly also list specific ports and protocols. Sshuttle only provided directionality - and not intentionally either…

Sshuttle was conceived and written by Avery Pennarun, who later went to co-create … tailscale.



Tailscale has a pretty comprehensive ACL system


And it's fully supported by Headscale.


+1. I use the postup/postdown settings in wireguard to add/remove iptables configuration, but it would be nice to have a more user-friendly setup.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: