El 9 de junio de 2019 4:55:05 a. m. GMT-05:00, Daniel Golle <daniel(a)makrotopia.org>
escribió:
We are using SAE with a pre-shared-key as well as BMX7 with signed
routing information to implement granular access control to our local
mesh and gateway here in Leipzig.
Does this setup control client access too, or just node access?
What do you mean by "granular access control"? Allow some nodes or clients top
generate internet traffic and others only local traffic?
Having a community profile for "hardened LibreMesh" could be useful for various
installations. And might some of these security settings be sane defaults LibreMesh? I
remember once seeing a table in LuCI that showed me all the active connections,
effectively allowing me to spy on my neighbors, and I think the by default we don't
want that ability.