Lo stai leggendo. Eppure, sulla pagina di stato del laboratorio, risulta giù. Non è un guasto: è il firewall in uscita di arx che fa il suo lavoro.
You are reading it. Yet on the lab's status page it shows as down. Nothing is broken: arx's outbound firewall is doing its job.
Chi non ci arrivaWho cannot get here
Il monitor di uptime gira su status.selif.org, un sito come gli altri. arx limita ciò che ogni sito può raggiungere su internet: il monitor ha un elenco di domini consentiti, e questo non c'è. Così, ogni minuto, il controllo viene fermato prima di partire.
The uptime monitor runs on status.selif.org, a site like any other. arx limits what each site may reach on the internet: the monitor has a list of allowed domains, and this one is not on it. So every minute the check is stopped before it leaves.
Qui sopra, dal vivo: il badge del monitor per questo sito. Rosso, anche se la pagina che stai leggendo funziona.
Above, live: the monitor's badge for this site. Red, even though the page you are reading works.
monitormonitor→nftables→Squid del sitothe site's Squid✕blocked.selif.org
Come funzionaHow it works
Ogni sito gira con un suo utente di sistema. nftables riconosce le connessioni in uscita di quell'utente e manda quelle verso le porte 80 e 443 a una porta di Squid riservata al sito.
Squid legge il nome del sito richiesto, anche in HTTPS, senza decifrare niente: lo prende dall'inizio della connessione (SNI).
Se il nome è nell'elenco del sito, la connessione prosegue. Se no, Squid la chiude, e il monitor vede un errore.
Ogni altra porta è chiusa, salvo regole aperte apposta. Un sito bucato può parlare solo con le destinazioni in elenco, non con qualunque server.
Every site runs as its own system user. nftables recognises that user's outbound connections and sends those to ports 80 and 443 to a Squid port reserved for the site.
Squid reads the requested site name, even over HTTPS, without decrypting anything: it takes it from the start of the connection (SNI).
If the name is on the site's list, the connection goes on. If not, Squid closes it and the monitor sees an error.
Every other port is closed unless a rule opens it. A compromised site can talk only to the destinations on its list, not to any server.
Nel pannello di arx, la pagina di ogni sito elenca cosa ha provato a raggiungere nelle ultime 24 ore. Le destinazioni bloccate sono proprio quelle che l'admin valuta se aggiungere all'elenco.
In the arx panel, each site's page lists what it tried to reach in the last 24 hours. The blocked destinations are exactly the ones the admin decides whether to add to the list.