From 5603d36165788084ebdc178945c89696b1e789ff Mon Sep 17 00:00:00 2001 From: crn4 Date: Mon, 17 Nov 2025 14:25:04 +0100 Subject: [PATCH] added exception on not appending route firewall rules if we have all wildcard --- management/server/types/networkmapbuilder.go | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/management/server/types/networkmapbuilder.go b/management/server/types/networkmapbuilder.go index 41aaa7fc8..6361e2e93 100644 --- a/management/server/types/networkmapbuilder.go +++ b/management/server/types/networkmapbuilder.go @@ -22,10 +22,11 @@ import ( ) const ( - allPeers = "0.0.0.0" - fw = "fw:" - rfw = "route-fw:" - nr = "network-resource-" + allPeers = "0.0.0.0" + allWildcard = "0.0.0.0/0" + v6AllWildcard = "::/0" + fw = "fw:" + rfw = "route-fw:" ) type NetworkMapCache struct { @@ -1640,6 +1641,10 @@ func (b *NetworkMapBuilder) updateRouteFirewallRules(routesView *PeerRoutesView, } if string(rule.RouteID) == update.RuleID { + if hasWildcard := slices.Contains(rule.SourceRanges, allWildcard) || slices.Contains(rule.SourceRanges, v6AllWildcard); hasWildcard { + break + } + sourceIP := update.AddSourceIP if strings.Contains(sourceIP, ":") {