Skip to content

Support additional egress protocol combinations #277

Description

Allow egress rules to select a protocol without requiring a specific port, and allow a port to apply to both TCP and UDP.

For a chosen destination, support these combinations:

Rule Expected behaviour
TCP, no port specified Match TCP traffic on all destination ports, but not UDP or ICMP.
UDP, no port specified Match UDP traffic on all destination ports, but not TCP or ICMP.
ICMP, no port specified Match ICMP traffic without also allowing TCP or UDP.
any, no port specified Preserve the existing all-protocol behaviour.
any, port 443 Match TCP and UDP on destination port 443, but not ICMP.

Apply these combinations to both allow and deny rules. Explicit deny must continue to take precedence over allow.

Verify allowed traffic and nearby cases that must remain blocked.

MXC schema requirement: network.egress.allow[].ports and network.egress.deny[].ports, where protocol supports tcp, udp, icmp and any, and port is optional.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions