Page MenuHomeVyOS Platform
Feed Advanced Search

Wed, May 15

Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

I guess the fate of upnp has already been decided https://vyos.dev/rVYOSONEX7c438caa2c21101cbefc2eec21935ab55af19c46
RIP

Wed, May 15, 8:17 AM

Tue, May 14

Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

If you are really that curious, I can attach a screenshot.

Tue, May 14, 4:04 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

A bunch to unpack here.
[...]

Tue, May 14, 3:41 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

Created a poll for maintainers on this topic, and we will go with the decision made.

Tue, May 14, 3:36 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

go learn how cheap cameras open firewalls via UPnP and make them available on the internet without people being aware of that

or how malware exfiltrates data via port 443 because enterprises can't reliably block outbound traffic on that port.

Tue, May 14, 2:48 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

If you know how to test it will be great to test it. If no one needs it even for tests, what are we talking about?

Tue, May 14, 2:29 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.
In T5835#187933, @simplysoft wrote:

A firewall is doing exactly this all the time when using NAT, autonomously opening ports via call from internal networks (aka internal originated traffic) to allow responses to reach the originator. Enterprises might have some strict outbound rules. For UPnP is exactly the same, an enterprise would have strict rules which services are allowed to open ports.

Not if it's not configured to do so.

Tue, May 14, 2:20 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

I'm not sure if that summary from you @Viacheslav is fully reflecting the current state.
I'm also not sure if the original implementation never worked, might very well have been broken while refactoring some vyos internals how the firewall is structured, but I guess you should have a better understanding of (the history of) your product. Otherwise I would be very surprised if a broken feature got into your product without every working / being tested.

Tue, May 14, 2:03 PM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

Does it work now?

Tue, May 14, 11:04 AM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

One reasons it is rarely seen is as most are not aware of it being used undercover and when not being present, nothing necessarily brakes (due to fallback to other mechanisms). For some home routers we saw this was an undocumented "feature" that you did not have any control over, more recent & reasonable implementation we have seen allow you to enable or disable it (but nothing much more like fine grained permissions)

Tue, May 14, 10:36 AM
Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

@aidan-gibson main use case is games typically, which is not in priority for us

Tue, May 14, 9:17 AM

Dec 18 2023

Unknown Object (User) added a comment to T5835: UPnP port mapping / rule installation fails.

The mentioned file that missing is located upstream in https://github.com/miniupnp/miniupnp/tree/miniupnpd_2_3_1/miniupnpd/netfilter_nft/scripts
and the upstream configuration options that we think are missing to match vyos chains is https://github.com/miniupnp/miniupnp/blob/miniupnpd_2_3_1/miniupnpd/miniupnpd.conf#L77

Dec 18 2023, 4:49 PM
Unknown Object (User) created T5835: UPnP port mapping / rule installation fails.
Dec 18 2023, 2:10 PM