qubes-firewall will now blacklist IP addresses from all connected machines on non-vif* interfaces. This prevents spoofing source or target address on packets going over an upstream link, even if a VM in question is powered off at the moment. Depends on QubesOS/qubes-core-admin#303 which makes admin maintain the list of IPs in qubesdb. Fixes QubesOS/qubes-issues#5540. |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| firewall.py | ||
| test_firewall.py | ||
| xdg.py | ||