Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Info
titleStatus:

Firewall Rules Copied, New Rules Need Creation and Review.

Here be firewall rules:

ProtocolSourcePortDestinationPortDescription
IPv4 *CameraVLAN (192.168.4.0/24)*192.168.1.17/32 (NVR)*Allow Cameras to Reach NVR
IPv4 UDPCameraVLAN (192.168.4.0/24)*AD_DNS_SERVERS (7.150,7.151)123 (NTP)Allow Cameras NTP Traffic
IPv4 *192.168.5.19/32*AD_DNS_SERVERS (7.150,7.151)*

Allow Media PC to reach DC(s)

(Adjust: Narrow Ports) 🔧

IPv4 *WirelessClients (192.168.2.0/24)*192.168.99.2 (UniFi Controller)*

Allow Clients to reach UniFi Controller

IPv4 *IoT Network (192.168.5.0/24)***

Allow IoT to reach *

(Remove, Create New Rules) ⚠️

IPv4 *FAFO Network (192.168.8.0/24)***

Allow FAFO to reach *

(Remove, Create New Rules) ⚠️

IPv4 *Wireless Clients (192.168.2.0/24)***

Allow Wireless Clients to reach *

(Remove, Create New Rules) ⚠️

IPv4 *Phone Network (192.168.6.0/24)***

Allow Phones to reach *

(Remove, Create New Rules) ⚠️

IPv4 *10GB VM Network (192.168.7.0/24)***

Allow VMs to reach *

(Remove, Create New Rules) ⚠️

IPv4 *Default Network (192.168.1.0/24)***

Allow Default VLAN to reach *

(Remove, Create New Rules) ⚠️

IPv4 *Management Network (192.168.99.0/24)*Default VLAN (192.168.1.0/24)*

Allow Management VLAN to reach default VLAN

(Remove, Create New Rules) ⚠️

IPv4 *Management Network (192.168.99.0/24)*AD_DNS_SERVERS (7.150,7.151)*Allow Management VLAN to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧
IPv4 *192.168.99.2 (UniFi Controller)*AD_DNS_SERVERS (7.150,7.151)*

Allow UniFi Controller to Reach AD/DNS/NTP Server(s)

(Adjust: Narrow Ports) 🔧

IPv4 *192.168.99.2 (UniFi Controller)***Allow UniFi Controller to Reach *
(Remove, Create New Rules) ⚠️
IPv4 *WittNet_Network (192.168.20.0/24)*AD_DNS_SERVERS (7.150,7.151)*Allow WittNet Peers to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧
IPv4 *WittNet_Network (192.168.20.0/24)*KMS_SERVER (192.168.7.37)*

Allow WittNet Peers to Reach KMS Server

(Adjust: Narrow Ports) 🔧

IPv4 *192.168.20.21 (OffsiteVMHost1)*192.168.99.12 (Proxmox Datacenter Manager)*

Allow OffsiteVMHost1 to reach Proxmox DCM

(Adjust: Narrow Ports) 🔧

IPv4 *192.168.20.13 (Offsite RODC)*AD_DNS_SERVERS (7.150,7.151)*Allow Offsite RODC to reach AD/DNS/NTP Sever(s) (Adjust: Narrow Ports) 🔧
IPv4 *192.168.20.15 (Offsite NAS)*AD_DNS_SERVERS (7.150,7.151)*Allow Offsite NAS to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧
IPv4 *WirelessClients (192.168.2.0/24)*Default VLAN (192.168.1.0/24)*Allow Wireless Clients to reach Default VLAN Clients (Adjust: Scope) 🔧
IPv4 *10GBVMNetwork (192.168.7.0/24)*Default VLAN (192.168.1.0/24)*Allow 10GBVMNetwork to reach Default VLAN Clients (Adjust: Scope) 🔧
IPv4 *Default VLAN (192.168.1.0/24)*Phone VLAN (192.168.6.0/24)*

Allow Default VLAN to reach Phones

(Adjust: Reconsider?) 🔧

IPv4 * Phone VLAN (192.168.6.0/24)*AD_DNS_SERVER(s)*

Allow Phones to Reach DNS/NTP Server(s)

(Adjust: Narrow Ports) 🔧

IPv4 *Default VLAN (192.168.1.0/24)*FAFO VLAN (192.168.8.0/24)*

Allow Default VLAN to reach FAFO VLAN

(Adjust: Reconsider?) 🔧

IPv4 *Default VLAN (192.168.1.0/24)*10GBVMNetwork (192.168.7.0/24)*

Allow Default VLAN to reach 10GB VM Network

(Adjust: Narrow Scope) 🔧

IPv4 *FAFO Network (192.168.8.0/24)*AD_DNS_SERVER(s) (7.150,7.151)*Allow FAFO Network to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧
IPv4 *FAFO Network (192.168.8.0/24)*192.168.1.16 (NAS)*

Allow FAFO Network to reach NAS

(Adjust: Reconsider?) 🔧

IPv4 *Management VLAN Network (192.168.99.0/24)***

Allow Management VLAN to reach * (Remove, Create New Rules) ⚠️

IPv4 *192.168.7.11 (HomeBridge)*IoT VLAN (192.168.5.0/24)*Allow Homebridge to reach IoT Devices
IPv4 *IoT VLAN (192.168.5.0/24)*192.168.7.11 (HomeBridge)*Allow IoT Devices to reach Homebridge
IPv4 *PhoneVLAN Network (192.168.6.0/24)*FAFO Network (192.168.8.0/24)*Allow Phones to reach FAFO Network
IPv4 *WittNet WAN (97.85.180.137/32)*WAN Address/Interface*

Allow WittNet WG VPN to Connect

(Adjust: Narrow to WG Ports) 🔧 

IPv4 *NOCIX WAN (63.141.225.139/32)*WAN Address/Interface*

Allow NOCIX WG VPN to Connect

(Adjust: Narrow to WG Ports) 🔧

IPv4 *10.4.4.1/32 (Cloudrouter WG Tun.)***Allow Cloudrouter WG Tun. to Connect
IPv4 *10.3.3.2/32 (WittNet WG Tun.)***Allow WittNet WG Tun. to Connect
IPv4 ***WAN Address5201 (iPerf3)Allow iPerf3 Packets Inbound on WAN Address. (Disable, But Keep) check mark button 
IPv4 *192.168.51.3/32 (Cloud MCRouter)*Pterodactyl Hosts (7.102-105)*

Allow Cloud MCRouter to reach Onsite Pterodactyl Hosts

(Adjust: Narrow Ports) 🔧

IPv4 *192.168.52.12/32 (ConnectWise Server)*Allowed_CW_SVR_Hosts (7.37,150,151,156,162)*Allow ConnectWise Server to Reach Various Host(s) onsite.
IPv4 ICMP192.168.52.5/32 (Uptime Kuma)*AD_DNS_SERVER(s) (7.150-151)*Allow Uptime Kuma to Ping AD/DNS/NTP Server(s) onsite.
IPv4 ICMP192.168.52.5/32 (Uptime Kuma)*Plex Server (192.168.1.16)*Allow Uptime Kuma to Ping Plex
IPv4 *192.168.7.10/32 (Veeam)*VM_Hosts (192.168.99.4,32,37,38)*Allow Veeam to reach VM Host(s)
IPv4 *192.168.52.10/32 (Cloud Redbot)*Plex_Arr_Sever(s) (1.16,7.36)*Allow Redbot to reach onsite Plex Server(s), *Arr Stack, and Tautulli
IPv4 TCP/UDP63.141.225.139/32 (NOCIX WAN)*WAN Address51824 (WG)Allow Wireguard Traffic from PNET-HQ to NOCIX
IPv4 TCP/UDP75.132.53.238/32 (WittNet WAN)*WAN Address51822 (WG)Allow Wireguard Traffic from PNET-HQ to WittNet






PROPOSED ADDITIONS:




IPv4 *all_subnets (EVERYTHING)*!(INVERT) all_private_networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)*Disallow all subnets to ping other subnets without implicit rules, including other hosts within existing subnet.
IPv4 *192.168.2.0/24 (Wireless Clients)*AD_DNS_SERVER(s) (7.150-151)*Allow Wireless Clients Access to AD/DNS/NTP
IPv4 *192.168.7.0/24 (VM Network)*AD_DNS_SERVER(s) (7.150-151)*Allow VM Network to reach AD/DNS/NTP
IPv4 *192.168.8.0/24 (FAFO network)*AD_DNS_SERVER(s) (7.150-151)*Allow FAFO Network to reach AD/DNS/NTP
IPv4 *192.168.99.0/24 (Management Network)*AD_DNS_SERVER(s) (7.150-151)*Allow Management Network to reach AD/DNS/NTP
IPv4 *192.168.1.0/24 (Default VLAN)*AD_DNS_SERVER(s) (7.150-151)*Allow Default VLAN Clients to reach AD/DNS/NTP
IPv4 *192.168.6.0/24 (Phone VLAN)*CUCM_SERVER(s) (8.30-33)*Allow Phones to reach CUCM Server(s)
IPv4 *192.168.2.0/24 (Wireless Clients)*FILE_SERVER(s) 192.168.7.156*Allow Wireless Clients to reach File Server
IPv4 *192.168.7.0/24 (VM Network)*FILE_SERVER(s) 192.168.7.156*Allow VM Network to reach file server.
IPv4 *CUCM_SERVER(s) (8.30-33)*AD_DNS_SERVER(s) (7.150-151)*Allow CUCM Server(s) to reach AD/DNS/NTP