diff --git a/my-rules.json b/my-rules.json index e38ed18..a58d15a 100644 --- a/my-rules.json +++ b/my-rules.json @@ -16,14 +16,13 @@ // {"action": "accept", "src": ["*"], "dst": ["*:*"]}, // Random can - {"action": "accept", "src": ["tag:Random"], "dst": ["*:*"]}, - + {"action": "accept", "src": ["tag:Random"], "dst": ["*:*"]}, + // Host can {"action": "accept", "src": ["tag:Host"], "dst": ["tag:Service:*"]}, // Hidden serves {"action": "accept", "src": ["*"], "dst": ["tag:Hidden:*"]}, - ], // Define postures that will be applied to all rules without any specific @@ -57,22 +56,20 @@ { "action": "accept", "src": ["tag:Random"], - "dst": ["autogroup:taged"], + "dst": ["tag:Host", "tag:Service"], "users": ["autogroup:nonroot", "root"], }, ], // Test access rules every time they're saved. - "tests": [ - { - "src": "tag:Bridge", - "accept": ["tag:Random:80"], - "deny": ["tag:Host:80"], - }, + "tests": [ { - "src": "tag:Random", + "src": "tag:Bridge", + "deny": ["tag:Host:80"], + }, + { + "src": "tag:Random", "accept": ["tag:Bridge:80", "tag:Host:80"], }, - ], + ], } -