[eduVPN-deploy] Fixed IP - ccd

Frank Weis Frank.Weis at cgie.lu
Wed Jul 27 14:48:57 CEST 2022

Hi François,

the firewall open/close code is yet to be done, but most of the required parts exist. There will be a DB that connects users to resources as well as current state info that can be used to see what needs to be done when (user, IP) disconnects.


On 27.07.22 11:24, François Kooman wrote:

On 26.07.22 18:40, Frank Weis wrote:

Hi Frank,

it would be preferable to have the IP on disconnect too. Otherwise, if a
user connects with several devices, I'd have to drop all the IPs
associated with the user from the tables. On disconnects, having just
the IP(s) (not the userID) would probably be fine, but I'm sure that
doesn't help at all.

I'll have a look at it, this is at least a bit of a challenge to do that
cleanly in the server ;-)

I could work around this by setting maxActiveConfigurations to 1, I guess.


The firewall has states, so I will need to remove IPs from tables AND
kill states on disconnects.

I meant state as in that it for example has an "ID" for a firewall
modification "event" that you can use later in the next request
(/disconnect) to "undo" the change.



