Skip to content

Support CIDR exclusions within individual egress rules #279

Description

Allow a destination range to exclude smaller ranges within that rule, without turning those exclusions into global deny rules.

Example Expected behaviour
Allow 192.0.2.0/24, except 192.0.2.128/25 That rule allows the first half of the range, but does not match the excluded half.
Another rule explicitly allows 192.0.2.200/32 That address can still be allowed; the earlier exclusion must not globally block it.
An address is excluded from a deny rule Other rules and the egress default decide its outcome; exclusion does not automatically allow it.
An exclusion lies outside its parent CIDR Reject with a clear validation error.

Explicit deny rules must still take precedence over allow rules. Verify overlapping rules so that an exclusion affects only the rule containing it.

MXC schema requirement: to[].cidr and to[].except, for example:

{
  "to": [{
    "cidr": "192.0.2.0/24",
    "except": ["192.0.2.128/25"]
  }]
}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions