[GH-ISSUE #2320] Access Control: possibility to create not bidirectional rules (one direction) & port ranges in ACLs #4871

Open
opened 2026-08-05 01:00:08 -04:00 by saavagebueno · 0 comments
Owner

Originally created by @florian-obradovic on GitHub (Jul 24, 2024).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/2320

Dear Team,

as an admin I want to create one-way / not bidirectional ACLs where I am allowed to:

  1. ICMP ping everyone (I want to ping all machines but they shouldn't be allowed to ping all admin machines) < this works with stateful firewalls
  2. access all machines with all ports for all protocols / or two rules for each proto (UDP / TCP)
  3. define port ranges in ACL like 1433-1438 or 1-65535

CleanShot 2024-07-24 at 22 56 47@2x

Best regards, Flo.

Originally created by @florian-obradovic on GitHub (Jul 24, 2024). Original GitHub issue: https://github.com/netbirdio/netbird/issues/2320 Dear Team, as an admin I want to create one-way / not bidirectional ACLs where I am allowed to: 1. ICMP ping everyone (I want to ping all machines but they shouldn't be allowed to ping all admin machines) < this works with stateful firewalls 2. access all machines with all ports for all protocols / or two rules for each proto (UDP / TCP) 3. define port ranges in ACL like 1433-1438 or 1-65535 ![CleanShot 2024-07-24 at 22 56 47@2x](https://github.com/user-attachments/assets/45207a79-46da-4163-97e7-0e424612468f) Best regards, Flo.
saavagebueno added the feature-request label 2026-08-05 01:00:08 -04:00
Sign in to join this conversation.
No Label feature-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#4871