OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Haproxy acl - Source IP matches IP or Alias
« previous next »
  • Print
Pages: [1]

Author Topic: Haproxy acl - Source IP matches IP or Alias  (Read 8097 times)

dragon2611

  • Jr. Member
  • **
  • Posts: 94
  • Karma: 4
    • View Profile
Haproxy acl - Source IP matches IP or Alias
« on: November 04, 2017, 04:56:03 pm »
How do you get it to work with alias?

I've tried tabbing the field but that doesn't seem to work (firefox) and if I don't put an actual IP then it seems ha proxy gets upset.

I wanted to use an negative match on a list if IP's (I.e the rule says deny access to /wp-admin/ on the backend server but if it's one of those IP's on the trusted list the rule shouldn't fire)
« Last Edit: November 04, 2017, 05:28:19 pm by dragon2611 »
Logged

fraenki

  • Full Member
  • ***
  • Posts: 171
  • Karma: 28
    • View Profile
    • GitHub
Re: Haproxy acl - Source IP matches IP or Alias
« Reply #1 on: November 05, 2017, 09:12:19 pm »
Quote from: dragon2611 on November 04, 2017, 04:56:03 pm
How do you get it to work with alias?

Firewall -> Aliases
...are currently not supported in the HAProxy plugin.

(I know, that text reads "Source IP matches IP or Alias", but this is wrong... I'll fix this text with the next release.)


Regards
- Frank
« Last Edit: November 05, 2017, 09:20:46 pm by fraenki »
Logged

dragon2611

  • Jr. Member
  • **
  • Posts: 94
  • Karma: 4
    • View Profile
Re: Haproxy acl - Source IP matches IP or Alias
« Reply #2 on: November 09, 2017, 05:12:14 pm »
Fair enough

It would be really nice if supported alias's but I suspect that's a fair bit of work  ;)
Logged

fraenki

  • Full Member
  • ***
  • Posts: 171
  • Karma: 28
    • View Profile
    • GitHub
Re: Haproxy acl - Source IP matches IP or Alias
« Reply #3 on: November 14, 2017, 11:59:15 pm »
Quote from: dragon2611 on November 09, 2017, 05:12:14 pm
It would be really nice if supported alias's but I suspect that's a fair bit of work  ;)

The main issue is that Aliases are still part of the legacy codebase. Once this part is rewritten, it's easy to add to the HAProxy plugin. Maybe as early as OPNsense 18.1, we'll have to wait. :)


Regards
- Frank
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Haproxy acl - Source IP matches IP or Alias
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2