Saturday, August 22, 2020

Had a firewall rule allowing private IP range on public interface.

So a sophos firewall I use auto created a firewall rule when I made a new IPsec tunnel. It was allowing source networks of 192.168.x.x and 10.x.x.x private IP range on all interfaces, including WAN. But since there was no NAT rule and private IP ranges aren’t routable on the Internet, could anything external have accessed something via this rule?



No comments:

Post a Comment