What’s the best way to re-create it with default settings?
Since 7 months saltstack states for sys-* were updated to support disposable sys-*: a) is this part of v4.0.4? b) how could I use it if it’s part of v4.0.4? Thanks in advance! P.
In my vm-to-be-exposed I used besides the service I actually want to expose the following:
- python3 -m http.server
- netcat -lv port
Connections in my local network to this AppVM using the IP of my qubes-NetVM all fail with a timeout. If I'm trying to connect from my qubes box to a simple ubuntu with an exposed port it works.
That's why my hypothesis was that I messed up my firewall qube.
Start at sys-net - you should have a rule directing inbound traffic to
<port> to sys-firewall.
Open a terminal in sys-net, and observe the counters in PRE-ROUTING and
FORWARD.
Attempt to make a connection - the counters should increment.
Do the same in sys-firewall.
Again, when you try to make a connection, you should see the counters
increment.
Do the same in the target qube. Here you should see the counter
increment in the filter chain.
Stepping down the network chain like this will help you identify where
your problem lies.