Open
Description
This may be user error so please tell me to stfu.
My static_overrides.yml is as follows:
(venv) root@host-92-204-168-17:~/validator-firewall# cat /etc/validator-firewall/static_overrides.yml
allow:
- name: "ashburn"
ip: 45.43.11.28
deny:
(It wouldn't work without the deny section)
But I'm seeing this in the logs:
(venv) root@host-92-204-168-17:~/validator-firewall# sudo journalctl -u validator-firewall.service -f
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.456256Z","level":"INFO","fields":{"message":"Loaded static overrides: StaticOverrides { allow: [NameAddressPair { name: \"ashburn\", ip: 45.43.11.
28/32 }], deny: [] }","log.target":"validator_firewall","log.module_path":"validator_firewall","log.file":"validator-firewall/src/main.rs","log.line":86},"target":"validator_firewall"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.456284Z","level":"WARN","fields":{"message":"No protected ports provided, defaulting to 8009 and 8010","log.target":"validator_firewall","log.modu
le_path":"validator_firewall","log.file":"validator-firewall/src/main.rs","log.line":92},"target":"validator_firewall"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.629799Z","level":"INFO","fields":{"message":"Filtering UDP ports: [8009, 8010]","log.target":"validator_firewall","log.module_path":"validator_fir
ewall","log.file":"validator-firewall/src/main.rs","log.line":130},"target":"validator_firewall"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.629837Z","level":"WARN","fields":{"message":"No deny list client specified, only using static overrides","log.target":"validator_firewall","log.mo
dule_path":"validator_firewall","log.file":"validator-firewall/src/main.rs","log.line":171},"target":"validator_firewall"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.646037Z","level":"INFO","fields":{"message":"Waiting for Ctrl-C...","log.target":"validator_firewall","log.module_path":"validator_firewall","log.
file":"validator-firewall/src/main.rs","log.line":212},"target":"validator_firewall"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.646114Z","level":"WARN","fields":{"message":"Entering close to leader mode due to missing leader status","log.target":"validator_firewall::leader_
tracker","log.module_path":"validator_firewall::leader_tracker","log.file":"validator-firewall/src/leader_tracker.rs","log.line":277},"target":"validator_firewall::leader_tracker"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.646142Z","level":"INFO","fields":{"message":"All traffic summary: 0 pkts last_interval 0 pkts 0 pkts/s","traffic_type":"All","rate":0,"delta":0,"t
otal":0},"target":"validator_firewall::stats_service"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.646178Z","level":"INFO","fields":{"message":"Blocked traffic summary: 0 pkts last_interval 0 pkts 0 pkts/s","traffic_type":"Blocked","rate":0,"del
ta":0,"total":0},"target":"validator_firewall::stats_service"}
Jul 30 02:11:09 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:09.703070Z","level":"INFO","fields":{"message":"New leader schedule loaded. Epoch 649 max slot 280800000","log.target":"validator_firewall::leader_tr
acker","log.module_path":"validator_firewall::leader_tracker","log.file":"validator-firewall/src/leader_tracker.rs","log.line":86},"target":"validator_firewall::leader_tracker"}
Jul 30 02:11:10 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:10.147163Z","level":"INFO","fields":{"message":"Exiting close to leader mode: Current 87461","log.target":"validator_firewall::leader_tracker","log.m
odule_path":"validator_firewall::leader_tracker","log.file":"validator-firewall/src/leader_tracker.rs","log.line":259},"target":"validator_firewall::leader_tracker"}
Jul 30 02:11:19 host-92-204-168-17.example.com validator-firewall[712972]: {"timestamp":"2024-07-30T02:11:19.648059Z","level":"INFO","fields":{"message":"total_packets: 162.19.222.240 = 38"},"target":"validator_firewall::stats_service"}
...snip...
Jul 30 01:53:11 host-92-204-168-17.example.com validator-firewall[711450]: {"timestamp":"2024-07-30T01:53:11.876920Z","level":"INFO","fields":{"message":"dropped_packets: 45.43.11.28 = 262"},"target":"validator_firewall::stats_service"}
why is it dropping packets from the allow override host? misconfiguration, or am I just missing something?
Metadata
Metadata
Assignees
Labels
No labels