|
D-125 egress isolation gate: PASS / CLOSED -- bridge-in proven end to end (2 identical runs)
Measurement disproved the missing-rule hypothesis first: operator-run nft dumps show virbr4 structurally identical to the working virbr11, with all three masquerade rules present INCLUDING the generic one, already fired -- so the pre-staged net-destroy/net-start was correctly not run. Matrix re-probe: gateway ping 0, internet ping 0, curl 1.1.1.1 301, curl archive.ubuntu.com 200, twice. Run-2's one-off ICMP failure recorded UNEXPLAINED rather than swept. Side observation kept: the WAN segment cannot reach the Office1 LAN through the ISP NAT (D-122/SEC-010 intent holding) -- queued as an explicit hardening assertion. CURRENT-STATE position + G10 row updated in this commit (GA-R1/C1). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KiUu1oqt76tWvV4vEC3NAr |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/d125-egress-gate-20260720-matrix.txt 0 → 100644 |
|---|
| docs/changelog-20260719-dc0-deploy-stepB.md |
|---|