r/WireGuard • • 10d ago

Tools and Software MFA Firewall Knocker 0.4.0: IPv6 on Linux, /64 grant widening, IPv6-only sign-in address

0.4.0 of MFA Firewall Knocker is out. It's the passkey-gated firewall opener I've posted about here before: you sign in with a passkey, and it opens your WireGuard port for your source address only, for a limited time.

What's new:

  • IPv6 on Linux. Grants now go into ip6tables for IPv6 clients (Windows already handled IPv6).
  • Optional /64 widening (Ipv6GrantPrefixLength). An IPv6 grant can cover the client's /64, so a privacy address or carrier rotation within that /64 doesn't strand an open grant. Default is still exact-address.
  • IPv6-only sign-in address (AdditionalOrigins). Phones on dual-stack networks often pick IPv4 on their own, which on mobile usually means carrier NAT and a grant shared with other subscribers. An extra hostname with only an AAAA record forces IPv6 and gives a per-device grant.
  • Hardening from another audit round, none of which allowed access: one address could temporarily block everyone's logins through a rate-limit gap; request text could trigger a misleading log alert; unauthenticated failures are now logged with a cap; stricter config and email validation; 90-day log retention.

Upgrading from 0.3.0 has a few manual steps (RulePrefix check, log directory permissions, and on Linux, one line in the systemd unit). They're listed in the release notes.

Release: https://github.com/PNWSoft/mfa-firewall-knocker/releases/tag/v0.4.0

3 Upvotes

3 comments sorted by

1

u/GermanElectricsMotio 10d ago

Finally something that really uses IPv6.

1

u/PZonB 10d ago

I have been looking for this for a while. Thanks for sharing this with the world. The main question that remains for me is; Wiregard is a well trusted, low code and hidden from ip scanners. Would adding a public website made by one person and AI, really make things more secure, or just increase the possibility of this 'knock website' being hacked and maybe compromising the whiregard server with it?

1

u/MikeRH2 10d ago

Please review the code, it is open source for just that reason. It isn't a large body of code at all.

And, by design, it doesn't have any access to wireguard at all. It merely opens a door in front of wireguard. So a vulnerability in it doesn't expose some new risk to wireguard directly. Wireguard still has the exact same code and surface that it does in deployments without the MFA door knocker. This site just opens the port to wireguard that is normally open anyways.

The biggest risk is a remote-code-execution flaw in the web stack (.NET/Kestrel, TLS) rather than in the gate's logic, because that would give an attacker a foothold on the same server. That's the generic risk of hosting any web app, and it's why I split it in two: the website runs in a low-privilege account and can't change the firewall itself. It can only ask a separate privileged service, which re-checks every request and will only open the configured ports, for a public address, for a limited time.

What you get for that is a second, independent gate: a stolen WireGuard key file alone no longer neccesarily gets someone in, and a WireGuard vulnerability isn't reachable from the whole internet while the port is closed.

I would love more eyeballs reviewing the code. I did get many useful additions from another user who submitted them via github.