Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Associated IP address support for Identities #2509

Open
surennaidu opened this issue Oct 29, 2024 · 0 comments
Open

Associated IP address support for Identities #2509

surennaidu opened this issue Oct 29, 2024 · 0 comments

Comments

@surennaidu
Copy link

In the IIoT / OT space, edge software cannot be installed on all devices and issued identities due to the hardware and OS limitations. These devices such as industrial computers, PLCs, other automation systems etc are networked to gateways. These gateways can run the ziti edge software. The ask is to be able to add identities per device that is connected to the gateway running the ziti edge software and map the identities by IP address ( longest prefix match with default being 0.0.0.0/0). This would allow the traffic dial and bind to be restricted till the last device that is not running a ziti edge software. Granular access and policy management can be achieved while simplifying service configs. If the IP address of the device does not match with the "associated IP address", then the device is not allowed to use the identity over ziti. This support is requested for ZET for Linux initially.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant