WaverleyLabs / fwknop

Client and Gateway Modules for Software Defined Perimeter (SDP)
GNU General Public License v2.0
88 stars 51 forks source link

Controller exposed ? since IPtables Drop all is on gateway only #8

Open CaMpeeerrr opened 2 years ago

CaMpeeerrr commented 2 years ago

Hi, im testing this sdp on a local environment, using 3 different vms on the same machine with seperate local ip adresses, with 3ports open on my Router one for Controller one for Gateway one for UDP transfer between client and gateway

the gateway on drop all policy ! so that port is filtered but the controller one is open and exposed, im i supposed to run the Ctrl and Gateway on the same VM ?

Thank you,

takahiro-ono commented 2 years ago

I am not a WaverleyLabs developer, and...

You can deploy a Gateway on the same host or in front of Controller to protect Controller traffic. When you deploy a Gateway and a Controller on the same host, you need additional configuration on Clients and Gateways so that they send SPA before Controller communication.

I am trying to implement such environments, but still working for Gateway configuration now.