cross-posted from: https://programming.dev/post/2768533

I have a vm for which I have s specific whitelist only firewall. It is supposed to only allow connections to the IPs an app connects to when syncing.

I first got the sync server IP’s listening to tcpdump, then when I had the IP’s I activated the whitelist.

This worked perfectly for some time, but now it appears that the IP’s have changed. I could do the same thing again but repeating the process regularly is annoying and defeats the whole purpose of only ever allowing network connections to specific whitelisted serves.

Alternatively, I could set up a process to only allow network traffic from that app somewhat.

Using debian-11 btw.

Any help is appreceated !!!

EDIT: I don’t own the sync servers, my app simply connects them, so I can get the updated state from my other devices

  • @[email protected]
    link
    fedilink
    4
    edit-2
    1 year ago

    IP white lists are, as you have found out, essentially dead. You should just do proper authorization.

    Alternatively, look into a wire guard vpn or something like tailscale.