docs(access-control): correct policy direction claim across docs (#739)

Earlier docs asserted that policies using `ALL`, `ICMP`, or portless
`TCP`/`UDP` must be bidirectional. Data-plane testing on NetBird
0.59.10 shows the engine honors the direction flag for every
protocol — peer-d's iptables only installs the destination-side
`ACCEPT` rule, so reverse-initiated traffic is dropped at the source
even when the policy uses `ALL` or `ICMP`. The greyed-out direction
toggle in the dashboard is a UX guardrail, not an enforcement gap.

- manage-network-access.mdx: rewrite the Policies overview and
  Multiple Mesh Networks paragraphs; drop the outdated `Note`
  callout; trim Creating Policies guidance.
- access-control/index.mdx: rewrite Protocol-Specific Behavior;
  drop the "Always Bidirectional (regardless of UI setting)" list.
- implement-zero-trust.mdx: soften TCP/UDP+ports framing.
- troubleshooting-client.mdx: drop "always true for the protocol
  `ALL`" clause from the bidirectional-rule bullet.

Network-resource (routing peer) policies remain genuinely
unidirectional — that statement preserved.
This commit is contained in:
Jack Carter
2026-05-11 12:24:44 +02:00
committed by GitHub
parent e64d8012d7
commit 4449fb3e38
4 changed files with 7 additions and 22 deletions
+1 -1
View File
@@ -788,7 +788,7 @@ Just like with the previous section you can loosen the above example by:
- replacing `access:srv-c` _Group_ with `access:int-net1` _Group_,
- allowing `ALL` protocol, _Ports_ will become greyed out because all traffic will be allowed,
- creating a bidirectional rule (both arrows should be green), always true for the protocol `ALL`,
- creating a bidirectional rule (both arrows should be green),
- selecting a different source group from the pool assigned to `peer-a`,
- it could be built-in `All` group, but it is discouraged,
- selecting a different destination group from the pool assigned to `peer-b`,