freedomofpress / securedrop-docs

Documentation for the SecureDrop project
https://docs.securedrop.org/
Other
22 stars 26 forks source link

clarify anti-lockout rules in OPNSense firewall configuration #518

Open torinthiel opened 11 months ago

torinthiel commented 11 months ago

Expected behavior

The alias list in OPNSense setup instructions mentions only relevant aliases

Actual behavior

Last entry in the 'Firewall Aliases' table, namely _antilockoutports is not referenced later in the document.

Additional information

It's possible that the entry is referenced by the built-in anti lockout rule mentioned later in the documentation, but it's not visible on the screenshot above which is supposed to show initial configuration.

cfm commented 10 months ago

Thanks, @torinthiel. I've reviewed the OPNSense instructions, and I agree that the (multiple) "anti-lockout" aliases, rules, and settings are confusing. I think the right thing for us to do is to clarify our overall treatment of OPNSense's anti-lockout features, and I suspect we'll wind up updating both our instructions and the screenshots in the process.