search for: newnetmaskgroup

Displaying 7 results from an estimated 7 matches for "newnetmaskgroup".

2017 Sep 27
2
Conditionally disabling auth policy
...; > > > Is there any way to disable auth policy, possibly inside a remote{}? > > > > auth_policy_server_url complains that it can't be used inside a remote > > block, so no dice there. Anything I'm missing? > > From my config: > ``` > allowed_subnets=newNetmaskGroup() > allowed_subnets:addMask('fe80::/64') > allowed_subnets:addMask('127.0.0.0/8') > [snip] > if (not(allowed_subnets.match(lt.remote))) > -- do GeoIP check > end > ``` > > of course could just skip all checks in that case if really wanted. but &g...
2017 Sep 27
2
Conditionally disabling auth policy
I've been digging into the auth policy stuff with weakforced lately. There are cases (IP ranges, so could be wrapped up in remote {} blocks) where it'd be nice to skip the auth policy (internal hosts that I can trust, but that are hitting the same servers as the outside world). Is there any way to disable auth policy, possibly inside a remote{}? auth_policy_server_url complains that it
2017 Sep 28
2
Conditionally disabling auth policy
...uth policy, possibly inside a remote{}? > >>> > >>> auth_policy_server_url complains that it can't be used inside a remote > >>> block, so no dice there. Anything I'm missing? > >> From my config: > >> ``` > >> allowed_subnets=newNetmaskGroup() > >> allowed_subnets:addMask('fe80::/64') > >> allowed_subnets:addMask('127.0.0.0/8') > >> [snip] > >> if (not(allowed_subnets.match(lt.remote))) > >> -- do GeoIP check > >> end > >> ``` > >> > &g...
2017 Sep 28
1
Conditionally disabling auth policy
...t; > > > >>> auth_policy_server_url complains that it can't be used inside a > remote > > > >>> block, so no dice there. Anything I'm missing? > > > >> From my config: > > > >> ``` > > > >> allowed_subnets=newNetmaskGroup() > > > >> allowed_subnets:addMask('fe80::/64') > > > >> allowed_subnets:addMask('127.0.0.0/8') > > > >> [snip] > > > >> if (not(allowed_subnets.match(lt.remote))) > > > >> -- do GeoIP check > >...
2017 Sep 27
0
Conditionally disabling auth policy
...ame servers as the outside world). > > Is there any way to disable auth policy, possibly inside a remote{}? > > auth_policy_server_url complains that it can't be used inside a remote > block, so no dice there. Anything I'm missing? >From my config: ``` allowed_subnets=newNetmaskGroup() allowed_subnets:addMask('fe80::/64') allowed_subnets:addMask('127.0.0.0/8') [snip] if (not(allowed_subnets.match(lt.remote))) -- do GeoIP check end ``` of course could just skip all checks in that case if really wanted. but you probably want to be careful not to skip to...
2017 Sep 28
0
Conditionally disabling auth policy
...Is there any way to disable auth policy, possibly inside a remote{}? >>> >>> auth_policy_server_url complains that it can't be used inside a remote >>> block, so no dice there. Anything I'm missing? >> From my config: >> ``` >> allowed_subnets=newNetmaskGroup() >> allowed_subnets:addMask('fe80::/64') >> allowed_subnets:addMask('127.0.0.0/8') >> [snip] >> if (not(allowed_subnets.match(lt.remote))) >> -- do GeoIP check >> end >> ``` >> >> of course could just skip all checks i...
2017 Sep 28
0
Conditionally disabling auth policy
...remote{}? > > >>> > > >>> auth_policy_server_url complains that it can't be used inside a remote > > >>> block, so no dice there. Anything I'm missing? > > >> From my config: > > >> ``` > > >> allowed_subnets=newNetmaskGroup() > > >> allowed_subnets:addMask('fe80::/64') > > >> allowed_subnets:addMask('127.0.0.0/8') > > >> [snip] > > >> if (not(allowed_subnets.match(lt.remote))) > > >> -- do GeoIP check > > >> end > >...