Advanced PF Mode: Am I going to lock myself out with a typo?
Advanced PF Mode: Am I going to lock myself out with a typo?
I need to write some incredibly cursed NAT reflection rules that the Simple Firewall UI just isn't built for. I'm ready to switch to Advanced Mode and write the raw PF syntax, but I'm terrified of making a typo.
I'm managing this Karios node remotely, if I drop all packets by mistake, am I going to have to drive to the data center to plug in a crash cart?
Ian Evans @ianHey 23realm!
Karios uses a "Change Confirmation System" straight out of the enterprise networking playbook. When you commit your raw PF rules in the UI, it loads them into memory and starts a 60-second countdown clock. It will prompt you in the browser to confirm you didn't just nuke your own connection.
If you did make a typo and lock yourself out, the timer expires and Karios just quietly rolls back to the last known-good
pf.conf. No crash cart required!Pro-tip: This safety net only exists in the UI. If you SSH in and go full cowboy with
pfctl -f /etc/pf.conf, you are on your own.
