Change the default value of --network-allow-private-ips
to false
for mainnet
and fuji
#1773
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Why this should be merged
It's generally unexpected behavior that avalanchego may attempt to connect to private IPs when run with the default configurations.
How this works
Because it is fairly common for nodes to need to connect to private IPs with non-production networks, this doesn't change the default value of
--network-allow-private-ips
for non-production networks. However, formainnet
andfuji
the default value will befalse
.How this was tested
Running on mainnet - this PR blocks a large number of connection dial attempts:
(the list goes on, but this was just the first few I cared to see)