innernet icon indicating copy to clipboard operation
innernet copied to clipboard

Don't send non-associated CIDRs to peers

Open afics opened this issue 3 years ago • 1 comments

Hi,

is there a reason all CIDRs are visible to all clients? My assumption is that in order to work a client only needs to see its associated CIDR and its own (+ any up to the root cidr) in order to work. Did I get that wrong?

If my assumption is true I would prefer to "hide" non-associated CIDRs from peers that don't need to see them. This cloud also be an optimization for networks with many CIDRs.

Regards, Armin

afics avatar Sep 20 '21 13:09 afics

Yeah! I can see how that makes more sense from a least-privilege perspective.

mcginty avatar Nov 05 '21 03:11 mcginty