| Info | ||
|---|---|---|
| ||
Firewall Rules Copied, Rules (all) copied into UXG-Pro, Pending Testing. |
Here be firewall rules:
| Protocol | Source | Port | Destination | Port | Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IPv4 * | CameraVLAN (192.168.4.0/24) | * | 192.168.1.17/32 (NVR) | * | Allow Cameras to Reach NVR | ||||||||||
| IPv4 UDP | CameraVLAN (192.168.4.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | 123 (NTP) | Allow Cameras NTP Traffic | ||||||||||
| IPv4 * | 192.168.5.19/32 | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Media PC to reach DC(s) (Adjust: Narrow Ports) 🔧 | ||||||||||
| IPv4 * | WirelessClients (192.168.2.0/24) | * | 192.168.99.2 (UniFi Controller) | * | Allow Clients to reach UniFi Controller | ||||||||||
| IPv4 * | IoTManagement Network (192.168. | 599.0/24) | * | *AD_DNS_SERVERS (7.150,7.151) | * | Allow | IoTManagement VLAN to reach | * (Change) ⚠️AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | FAFOWittNet_Network (192.168. | 820.0/24) | * | *AD_DNS_SERVERS (7.150,7.151) | * | Allow | FAFO to reach * (Change) ⚠️WittNet Peers to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | ||||||||
| IPv4 * | Wireless ClientsWittNet_Network (192.168. | 220.0/24) | * | *KMS_SERVER (192.168.7.37) | * | Allow | Wireless Clients to reach * (Change) ⚠️WittNet Peers to Reach KMS Server (Adjust: Narrow Ports) 🔧 | ||||||||
| IPv4 * | Phone Network (192.168.20.21 (OffsiteVMHost1) | * | 192.168. | 6.0/2499.12 (Proxmox Datacenter Manager) | * | Allow OffsiteVMHost1 to reach Proxmox DCM REDUNDANT ❌ | |||||||||
| IPv4 * | 192.168.20.13 (Offsite RODC) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow | PhonesOffsite RODC to reach | * (Change) ⚠️AD/DNS/NTP Sever(s) REDUNDANT ❌ | ||||||||
| IPv4 * | 10GB VM Network (192.168. | 7.0/2420.15 (Offsite NAS) | * | *AD_DNS_SERVERS (7.150,7.151) | * | Allow | VMsOffsite NAS to reach | * (Change) ⚠️AD/DNS/NTP Server(s) REDUNDANT ❌ | |||||||
| IPv4 * | Default NetworkWirelessClients (192.168. | 12.0/24) | * | *Default VLAN (192.168.1.0/24) | * | Allow Wireless Clients to reach Default VLAN | to reach * (Change) ⚠️Clients (Adjust: Scope) 🔧 | ||||||||
| IPv4 * | Management Network10GBVMNetwork (192.168. | 997.0/24) | * | Default VLAN (192.168.1.0/24) | * | Allow | Management VLAN10GBVMNetwork to reach | defaultDefault VLAN Clients ( | Change) ⚠️Adjust: Scope) 🔧 | ||||||
| IPv4 * | Management NetworkDefault VLAN (192.168. | 991.0/24) | * | AD_DNS_SERVERS (7.150,7.151Phone VLAN (192.168.6.0/24) | * | Allow | Management Default VLAN to reach | AD/DNS/NTP Server(s) Phones (Adjust: Reconsider? | (Adjust: Narrow Ports) 🔧 | ||||||
| IPv4 * | Phone VLAN (192.168. | 99.2 (UniFi Controller6.0/24) | * | AD_DNS_ | SERVERS (7.150,7.151SERVER(s) | * | Allow | UniFi Controller Phones to Reach | AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | ||||||
| IPv4 * | Default VLAN (192.168.1.0/24) | * | FAFO VLAN (192.168. | 99.2 (UniFi Controller)8.0/24) | * | Allow Default VLAN to reach FAFO VLAN (Adjust: Reconsider?) 🔧 | |||||||||
| IPv4 * | Default VLAN (192.168.1.0/24) | * | 10GBVMNetwork (192.168.7.0/24) | * | Allow Default VLAN to reach 10GB VM Network (Adjust: Narrow Scope) 🔧 | ||||||||||
| IPv4 * | FAFO | * | * | * | Allow UniFi Controller to Reach * (Change) ⚠️ | IPv4 * | WittNet_Network (192.168. | 208.0/24) | * | AD_DNS_ | SERVERSSERVER(s) (7.150,7.151) | * | Allow | WittNet PeersFAFO Network to | Reachreach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 |
| IPv4 * | WittNet_FAFO Network (192.168. | 208.0/24) | * | KMS_SERVER (192.168. | 71. | 3716 (NAS) | * | Allow | WittNet Peers to Reach KMS Server FAFO Network to reach NAS (Adjust: Reconsider?) 🔧 | ||||||
| IPv4 * | 192.168.7.11 (HomeBridge) | * | IoT VLAN (192.168.5.0/24) | * | Allow Homebridge to reach IoT Devices | ||||||||||
| IPv4 * | IoT VLAN (192.168.5.0/24) | * | 192.168.7.11 (HomeBridge) | * | Allow IoT Devices to reach Homebridge | ||||||||||
| IPv4 * | PhoneVLAN Network (192.168.6.0/24) | * | FAFO Network (192.168.8.0/24) | * | Allow Phones to reach FAFO Network | ||||||||||
| IPv4 * | WittNet WAN (97.85.180.137/32) | * | WAN Address/Interface | * | Allow WittNet WG VPN to Connect NOT NEEDED ❌ | ||||||||||
| IPv4 * | NOCIX WAN (63.141.225.139/32) | * | WAN Address/Interface | * | Allow NOCIX WG VPN to Connect NOT NEEDED ❌ | ||||||||||
| IPv4 * | 10.4.4.1/32 (Cloudrouter WG Tun.) | * | * | * | Allow Cloudrouter WG Tun. to Connect NOT NEEDED ❌ | ||||||||||
| IPv4 * | 10.3.3.2/32 (WittNet WG Tun.) | * | * | * | Allow WittNet WG Tun. to Connect NOT NEEDED ❌ | ||||||||||
| IPv4 * | * | * | WAN Address | 5201 (iPerf3) | Allow iPerf3 Packets Inbound on WAN Address. NOT NEEDED ❌ | ||||||||||
| IPv4 | Narrow Ports) 🔧IPv4 * | 192.168.20.21 (OffsiteVMHost1) | * | 192.168. | 99.12 (Proxmox Datacenter Manager51.3/32 (Cloud MCRouter) | * | Pterodactyl Hosts (7.102-105) | * | Allow | OffsiteVMHost1 Cloud MCRouter to reach | Proxmox DCM Onsite Pterodactyl Hosts (Adjust: Narrow Ports) 🔧 | ||||
| IPv4 * | 192.168. | 2052. | 13 (Offsite RODC12/32 (ConnectWise Server) | * | ADAllowed_CW_ | DNSSVR_ | SERVERSHosts (7.37,150, | 7.151,156,162) | * | Allow | Offsite RODC to reach AD/DNS/NTP SeverConnectWise Server to Reach Various Host(s) | (Adjust: Narrow Ports) 🔧onsite. | |||
| IPv4 | *ICMP | 192.168. | 2052. | 15 (Offsite NAS5/32 (Uptime Kuma) | * | AD_DNS_ | SERVERSSERVER(s) (7.150 | ,7.-151) | * | Allow | Offsite NASUptime Kuma to | reachPing AD/DNS/NTP Server(s) | (Adjust: Narrow Ports) 🔧onsite. | ||
| IPv4 | *ICMP | WirelessClients (192.168. | 252. | 0/245/32 (Uptime Kuma) | * | Default VLANPlex Server (192.168.1. | 0/2416) | * | Allow | Wireless Clients to reach Default VLAN Clients (Adjust: Scope) 🔧Uptime Kuma to Ping Plex | |||||
| IPv4 * | 10GBVMNetwork (192.168.7. | 010/ | 2432 (Veeam) | * | Default VLANVM_Hosts (192.168. | 1.0/2499.4,32,37,38) | * | Allow | 10GBVMNetworkVeeam to reach | Default VLAN Clients (Adjust: Scope) 🔧VM Host(s) | |||||
| IPv4 * | Default VLAN (192.168.52.10/32 (Cloud Redbot) | * | Plex_Arr_Sever(s) (1 | .0/24.16,7.36) | * | Allow Redbot to reach onsite Plex Server(s), *Arr Stack, and Tautulli | |||||||||
| IPv4 TCP/UDP | 63.141.225.139/32 (NOCIX WAN) | * | WAN Address | 51824 (WG) | Allow Wireguard Traffic from PNET-HQ to NOCIX NOT NEEDED ❌ | ||||||||||
| IPv4 TCP/UDP | 75.132.53.238/32 (WittNet WAN) | * | WAN Address | 51822 (WG) | Allow Wireguard Traffic from PNET-HQ to WittNet NOT NEEDED ❌ | ||||||||||
| PROPOSED ADDITIONS: | |||||||||||||||
| IPv4 * | 192.168.2.0/24 (Wireless Clients | Phone VLAN (192.168.6.0/24) | * | Allow Default VLAN to reach Phones (Adjust: Reconsider?) 🔧 | IPv4 * | Phone VLAN (192.168.6.0/24) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow | Phones to ReachWireless Clients Access to AD/DNS/NTP | Server||||
| IPv4 * | 192.168.7.0/24 (VM Network) | * | AD_DNS_SERVER(s) ( | Adjust: Narrow Ports) 🔧7.150-151) | * | Allow VM Network to reach AD/DNS/NTP | |||||||||
| IPv4 * | Default VLAN (192.168.1.0/24 (Default VLAN) | * | FAFO VLAN (AD_DNS_SERVER(s) (7.150-151) | * | Allow Default VLAN Clients to reach AD/DNS/NTP | ||||||||||
| IPv4 * | 192.168. | 86.0/24 (Phone VLAN) | * | CUCM_SERVER(s) (8.30-33) | * | Allow | Default VLANPhones to reach | FAFO VLAN (Adjust: Reconsider?) 🔧CUCM Server(s) | |||||||
| IPv4 * | Default VLAN (192.168. | 12.0/24 (Wireless Clients) | * | 10GBVMNetworkFILE_SERVER(s) 192.168.7. | 0/24)156 | * | Allow | Default VLAN to reach 10GB VM Network (Adjust: Narrow Scope) 🔧Wireless Clients to reach File Server | |||||||
| IPv4 * | 192.168.7.0/24 (VM Network) | * | FILE_SERVER(s) 192.168.7.156 | * | Allow VM Network to reach file server. NOT NEEDED ❌ | ||||||||||
| IPv4 * | CUCM_SERVER(s) (8.30-33 | IPv4 * | FAFO Network (192.168.8.0/24) | * | AD_DNS_SERVER(s) (7.150 | ,7.-151) | * | Allow | FAFO Network CUCM Server(s) to reach AD/DNS/NTP | Server(s) (Adjust: Narrow Ports) 🔧NOT NEEDED ❌ | |||||
| IPv4 * | NEWT_PROXY (7.69) | * | NEWT_APPROVED_NETWORKS (1.0/24,7.0/24,8.0/24,99.0/24) | * | Allow Pangolin Newt to reach servers it needs to proxy, as well as clients behind newt to reach those servers. | ||||||||||
| IPv4 * | 192.168.7.36 (Tautulli) | * | 192.168.1.16 (NAS) | 32400 (Plex) | Allow Tautulli to reach NAS. | ||||||||||
| IPv4 * | 192.168.7.27 (Tracearr | IPv4 * | FAFO Network (192.168.8.0/24) | * | 192.168.1.16 (NAS) | *32400 (Plex) | Allow | FAFO NetworkTracearr to reach NAS | (Adjust: Reconsider?) 🔧. | ||||||
| IPv4 * | 192.168.1.0/24, 192.168.8.0/24, 192.168.99.0/24 | * | 192.168.7.37 (KMS) | 1688 (KMS) | Allow Clients to Activate Microsoft Products. | ||||||||||
| IPv4 * | 192.168.7.0/24 | * | DUO_PROXIES (7.148-149) | 389 (LDAP) | Allow VM Network Clients to authenticate w/LDAP via DUO. NOT NEEDED ❌ | ||||||||||
| IPv4 * | CUCM_SERVER(s) (8.30-33) | * | CUCM_SERVER(s) (8.30-33) | * | Allow CUCM Stack to communicate with one another. NOT NEEDED ❌ | ||||||||||
| IPv4 * | 192.168.1.0/24 (Default VLAN) | * | CUCM_SERVER(s) (8.30-33) | * | Allow Default VLAN to communicate (Desktop Jabber) | IPv4 * | Management VLAN Network (192.168.99.0/24) | * | * | * | Allow Management VLAN to reach * (Change) ⚠️|||||
| IPv4 * | 192.168.7. | 11 (HomeBridge0/24 (VM Network) | * | 192.168.7.162 (SMTP_LB) | 25 | Allow VM Network to communicate with SMTP_LB NOT NEEDED ❌ | |||||||||
| IPv4 * | IoT VLAN (192.168. | 599.0/24 (Management Network) | * | 192.168.7.162 (SMTP_LB) | 25 | Allow Management Network to communicate with SMTP_LB | |||||||||
| IPv4 * | 192.168.7.162 (SMTP_LB) | * | 192.168.52.3 (Mailcow, Remote) | 25 | Allow SMTP_LB to reach Mailcow | ||||||||||
| IPv4 * | 192.168.7.62 (Scrypted) | * | Allow Homebridge to reach IoT Devices | IPv4 * | IoT VLAN (192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR) | * | Allow Scrypted to communicate with IoT Network (Speakers, etc.) | ||||||||
| IPv4 * | AD_DNS_SERVER(s) (7.150-7.151) | * | PI_HOLE_SERVER(s) (7.50-51) | * | Allow DCs to reach PiHole(s) NOT NEEDED ❌ | ||||||||||
| IPv4 * | 192.168.7. | 11 (HomeBridge5 (MC_Router) | * | Pterodactyl_Wings (192.168.7.102-105) | * | Allow | IoT Devices to reach HomebridgeMC-Router to Route to Pterodactyl Wings. NOT NEEDED ❌ | ||||||||
| IPv4 * | PhoneVLAN Network (192.168.7.11 (Homebridge) | * | 192.168. | 65.0/24 (IoT Network), 192.168.1.17 (NVR) | * | Allow Homebridge to communicate with IoT Clients | |||||||||
| IPv4 * | FAFO Network (192.168.7.75 (Tugtainer) | * | 192.168. | 87.0/24 (VM Network) | * | Allow Tugtainer to Check Docker Updates on VM Hosts. NOT NEEDED ❌ | |||||||||
| IPv4 * | 192.168.7.161 (SMTP-HA1) | * | 192.168.7.162 (SMTP-HA2) | * | Allow SMTP-HA1 to reach SMTP-HA2 to do VIP Checks. NOT NEEDED ❌ | ||||||||||
| IPv4 * | 192.168.7.162 (SMTP-HA2) | * | Allow Phones to reach FAFO Network192.168.7.161 (SMTP-HA1) | * | Allow SMTP-HA2 to reach SMTP-HA1 to do VIP Checks. NOT NEEDED ❌ |