|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Layer: L4 Transport ยท Build flags: PROTOCORE_ENABLE_IP_ALLOWLIST
This drops any TCP connection whose source address falls outside a set of CIDR rules - a coarse first-line firewall in front of every listener (HTTP, WS, TLS, etc.), evaluated at accept time before any bytes are read. Rules live in a fixed BSS table, so there is no heap cost.
Adding rules. Unlike the throttles (which are flag-only), the allowlist has a small API: add CIDR rules as text with Tcp.listener->ip_allow_add_cidr("network/prefix"). IPv4 and IPv6 are both accepted; a bare address (no /prefix) is a single-host rule (/32 for v4, /128 for v6):
Matching is a full-address prefix compare per family, so a v4 peer is only ever tested against v4 rules and a v6 peer only against v6 rules - there is no lossy hashing or address flattening that a peer could exploit.
Fail-open until you add a rule. An empty allowlist allows everything (so enabling the feature before adding rules never locks you out). Add at least one rule to actually restrict access.
Know its limits. This filters by source IP, which a determined attacker can spoof, so treat it as a coarse first layer and pair it with the accept throttles and real authentication. It is excellent for "only my LAN may even open a socket."
The listener.h include is what brings in Tcp.listener->ip_allow_add_cidr.
Connect from an address inside 192.168.1.0/24 (allowed) and from one outside it (connection dropped at accept).
The complete sketch (IpAllowlist.ino), reproduced verbatim with added explanatory comments: