Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
83 changes: 83 additions & 0 deletions src/PepperDash.Essentials.MobileControl/MobileControlConfig.cs
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,40 @@ public class MobileControlDirectServerPropertiesConfig
[JsonProperty("automaticallyForwardPortToCSLAN")]
public bool? AutomaticallyForwardPortToCSLAN { get; set; }

/// <summary>
/// Gets or sets the networks (CIDR notation) allowed to make HTTP requests to the direct server
/// </summary>
/// <remarks>
/// Example: ["192.168.10.0/24", "192.168.5.10/32"]. When the list has any entries, HTTP requests
/// (GET, POST, OPTIONS) from any other address have the connection closed without a response,
/// except loopback and clients on the Control Subnet, which are always allowed.
Comment thread
anthony-lopez-pd marked this conversation as resolved.
/// When null or empty, no filtering is done (default).
/// Invalid entries are logged and skipped, so a list containing only invalid entries still turns
/// filtering on. Does not apply to websocket connections, which are already gated by a per-client token.
/// </remarks>
[JsonProperty("allowedClientNetworks")]
public List<string> AllowedClientNetworks { get; set; }

/// <summary>
/// Gets or sets whether a request for a path the server does not handle gets no reply
/// </summary>
/// <remarks>
/// When true the connection is closed without a response. When false or absent (default) the server
/// replies 404, as it always has. Replying means writing to a connection the client may already have
/// reset, which throws from inside the HTTP stack, so noisy environments may prefer true.
Comment thread
anthony-lopez-pd marked this conversation as resolved.
/// </remarks>
[JsonProperty("dropUnrecognisedRequests")]
public bool? DropUnrecognisedRequests { get; set; }

/// <summary>
/// Gets or sets the automatic blocking of addresses that send a burst of unwanted requests
/// </summary>
/// <remarks>
/// Absent or "enabled": false (default) means no automatic blocking.
/// </remarks>
[JsonProperty("autoBlock")]
public MobileControlAutoBlockConfig AutoBlock { get; set; }

/// <summary>
/// Gets or sets the CSLanUiDeviceKeys
/// </summary>
Expand Down Expand Up @@ -104,6 +138,55 @@ public MobileControlDirectServerPropertiesConfig()
}
}

/// <summary>
/// Settings for blocking, at the processor, an address that sends a burst of unwanted requests
/// </summary>
/// <remarks>
/// Counts requests for unrecognised paths and requests refused by allowedClientNetworks. When one address
/// reaches requestsPerMinute within a minute it is added to the processor's blocked-IP list (a total block,
/// every port) and removed again after blockMinutes. The processor's own lockout setting does not apply to
/// manual blocks, so Essentials removes only the blocks it added. 4-series appliances only.
/// Never blocks loopback, the Control Subnet, the processor's own addresses, allowedClientNetworks or neverBlock.
/// </remarks>
public class MobileControlAutoBlockConfig
{
/// <summary>
/// Gets or sets whether automatic blocking is on (default false)
/// </summary>
[JsonProperty("enabled")]
public bool Enabled { get; set; }

/// <summary>
/// Gets or sets whether to only log what would be blocked, without blocking anything
/// </summary>
[JsonProperty("dryRun")]
public bool DryRun { get; set; }

/// <summary>
/// Gets or sets how many unwanted requests from one address within a minute trigger a block (default 10, minimum 3)
/// </summary>
[JsonProperty("requestsPerMinute")]
public int RequestsPerMinute { get; set; } = 10;

/// <summary>
/// Gets or sets how long a block lasts, in minutes (default 30, 1 to 1440)
/// </summary>
[JsonProperty("blockMinutes")]
public int BlockMinutes { get; set; } = 30;

/// <summary>
/// Gets or sets the most blocks Essentials will hold at once (default 8, 1 to 64)
/// </summary>
[JsonProperty("maxConcurrentBlocks")]
public int MaxConcurrentBlocks { get; set; } = 8;

/// <summary>
/// Gets or sets networks (CIDR notation) that are never blocked, for example VPN and monitoring hosts
/// </summary>
[JsonProperty("neverBlock")]
public List<string> NeverBlock { get; set; }
}

/// <summary>
/// Represents a MobileControlLoggingConfig
/// </summary>
Expand Down
Loading
Loading