securedrop-docs icon indicating copy to clipboard operation
securedrop-docs copied to clipboard

clarify anti-lockout rules in OPNSense firewall configuration

Open torinthiel opened this issue 2 years ago • 1 comments

Expected behavior

The alias list in OPNSense setup instructions mentions only relevant aliases

Actual behavior

Last entry in the 'Firewall Aliases' table, namely antilockout_ports is not referenced later in the document.

Additional information

It's possible that the entry is referenced by the built-in anti lockout rule mentioned later in the documentation, but it's not visible on the screenshot above which is supposed to show initial configuration.

torinthiel avatar Nov 15 '23 21:11 torinthiel

Thanks, @torinthiel. I've reviewed the OPNSense instructions, and I agree that the (multiple) "anti-lockout" aliases, rules, and settings are confusing. I think the right thing for us to do is to clarify our overall treatment of OPNSense's anti-lockout features, and I suspect we'll wind up updating both our instructions and the screenshots in the process.

cfm avatar Jan 11 '24 20:01 cfm