feat: port forwards are a firewall reader too, and only the WAN's
get_port_forwards was declared on ResidentialGatewayDriver alone, as if a port forward were a home-router feature. A firewall forwards ports just the same (OPNsense calls it destination NAT), and netOrk asks both: is this host reachable from the internet, which CVEs are exposed. The declaration moves to NatVpnMixin, where the two roles already overlap, and PortForwardDict next to NATTranslationDict. The contract now says what counts. Destination NAT between internal networks and rules that only exempt traffic are not port forwards: callers read every entry as "reachable from outside". "ANY" forwards every protocol and an external port of 0 every port -- a whole host forwarded is the most exposed case and must not fall out for lack of a port number. Declaration only, under TYPE_CHECKING: nothing changes at runtime.
This commit is contained in:
@@ -227,6 +227,11 @@ class PfSenseDriver(FirewallDriver):
|
||||
def get_vpn_tunnels(self):
|
||||
# return Dict[str, VPNTunnelDict]
|
||||
...
|
||||
|
||||
def get_port_forwards(self):
|
||||
# return List[PortForwardDict] — forwards from the WAN only, never a
|
||||
# redirect between internal networks (shared with home gateways)
|
||||
...
|
||||
```
|
||||
|
||||
### Hypervisor
|
||||
|
||||
Reference in New Issue
Block a user