Cornelius Diekmann

Results 15 issues of Cornelius Diekmann

Wouldn't it be great if this tool also supports the BSD pf firewall? We need: - a BSD pf semantics - a parser - a translation to a simplified firewall...

enhancement
help wanted

Over the last releases, the performance both of the Isabelle tests and the Haskell tool declined. My guess: this is related to the upcoming support of IPv6. In general, since...

enhancement
help wanted

The fffuu Haskell tool fails with the error message "undefined" if some precondition of the Isabelle-generated code does not hold. For example, Isabelle assumes that an ipassmt does not have...

enhancement

When talking about filtering behavior, the actions `ULOG`, `NFLOG`, and `LOG` all behave equally: They only log (somehow) and do not influence the filtering behavior. The parser (tokenizer) should recognize...

While being harder to administrate than stateful firewalls, stateless firewalls may be faster. This is in particular important if someone is trying to DOS a firewall. Can we translate a...

enhancement
help wanted

- Telnet, X11, NetBIOS from the Internet? - Outbound any? - Special-purpose IP addresses? - ... Checking for firewall best practices would be a nice enhancement. Pull requests welcome :-)...

enhancement
help wanted

This feature requires - Semantics for nftables - Verified translation of iptables nftables - A parser for nftables Will be implemented on by ongy.

enhancement

We can calculate the access control matrix for a fixed service. This answers for example the question "who is allowed to set up ssh connections with whom?". For this feature,...

enhancement
help wanted

We want a fully verified converter that translates rulestes from your proprietary firewall to an open source firewall. This needs: - A semantics for the proprietary firewall - A verified...

enhancement
help wanted

Currently, the service matrices (build_ip_partition_pretty) are just dumped as plain text. They could be perfectly visualized as graph. My idea: dump them as dot and run graphviz afterwards. Code can...

enhancement
help wanted