core-agent-linux/qubesagent
Pawel Marczewski bfe31cfec8
qubes-firewall: add anti-spoofing rules for connected machines
qubes-firewall will now blacklist IP addresses from all connected
machines on non-vif* interfaces. This prevents spoofing source or
target address on packets going over an upstream link, even if
a VM in question is powered off at the moment.

Depends on QubesOS/qubes-core-admin#303 which makes admin maintain
the list of IPs in qubesdb.

Fixes QubesOS/qubes-issues#5540.
2020-01-09 18:25:08 +01:00
..
__init__.py network: rewrite qubes-firewall daemon 2016-09-12 05:22:53 +02:00
firewall.py qubes-firewall: add anti-spoofing rules for connected machines 2020-01-09 18:25:08 +01:00
test_firewall.py Convert qubesagent module to python3 2019-09-19 04:57:55 +02:00
xdg.py Implement D-Bus Activation of desktop files manually 2019-03-20 05:04:58 +01:00