From b51f5f77137588cc8b71887407a7d0339ce4c530 Mon Sep 17 00:00:00 2001 From: Chrison Simtian Date: Fri, 9 Oct 2026 21:48:37 +1300 Subject: [PATCH] Warn that the gateway may not enforce IPv6 interface-id matches Claude-Session: https://claude.ai/code/session_01V2afcTcowT1YVBwLzrJFtH --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 8f52b5d..bc2b39a 100644 --- a/README.md +++ b/README.md @@ -167,6 +167,7 @@ await fw.CreateAsync(spec, names); - **Equality is semantic**, so `live == desired` is the drift check. - **`FirewallPolicyJson.FromJson`** returns a reason instead of a spec for anything outside the subset: domain/app/region filters, schedules, matching lists and the like. A caller can never mistake "can't compare" for "matches". - **`Ipv6InterfaceId`** is written with the `/::ffff:ffff:ffff:ffff` mask, so it matches the host suffix under *any* delegated prefix. Pinning a full IPv6 address breaks the day the ISP re-delegates. + ⚠ **The controller accepts this but the gateway may not enforce it.** On a UCG running UniFi OS 5.1.33 / Network 10.6.106, an External → LAN allow matched by IID was stored correctly (`matching_target: IID`) and then matched **nothing**: the hit counter froze and inbound traffic was dropped. Check the policy's hit counter after switching a rule to an IID match, and fall back to the full address if it stays flat. - **Updates are PUT (full replacement).** Only ever write `USER_DEFINED` policies (`LiveFirewallPolicy.IsUserDefined`). - **Ordering is not managed.** New user policies land at index 10000, ahead of the predefined allow/block defaults. - Generated against the 10.4.57 spec and checked live against Network 10.6.106.