Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Info
titleStatus:

Firewall Rules Copied, Rules (all) copied into UXG-Pro, Pending Testing.

Here be firewall rules:

IoT 5* IoT * (Change) ⚠️FAFO 8* FAFO to reach * (Change)  ⚠️Wireless Clients 2* Wireless Clients to reach * (Change)  ⚠️Phone Network (6.0/24 Phones * (Change)  ⚠️10GB VM Network (7.0/24* VMs * (Change)  ⚠️Default Network 1* to reach * (Change)  ⚠️Management Network 99 Management VLAN default Change)  ⚠️Management Network 99AD_DNS_SERVERS (7.150,7.151 Management AD/DNS/NTP Server(s) (Adjust: Narrow Ports99.2 (UniFi ControllerSERVERS (7.150,7.151 UniFi Controller AD/99.2 (UniFi Controller)WittNet_20SERVERS WittNet Peers Reach WittNet_20KMS_SERVER (737 WittNet Peers to Reach KMS Server Narrow Ports) 🔧99.12 (Proxmox Datacenter Manager OffsiteVMHost1 Proxmox DCM 2013 (Offsite RODCADDNSSERVERS 7. Offsite RODC to reach AD/DNS/NTP Sever (Adjust: Narrow Ports) 🔧 *2015 (Offsite NASSERVERS ,7. Offsite NAS reach (Adjust: Narrow Ports) 🔧 *WirelessClients (20/24Default VLAN 0/24 Wireless Clients to reach Default VLAN Clients (Adjust: Scope) 🔧10GBVMNetwork (024Default VLAN 1.0/24 10GBVMNetwork Default VLAN Clients (Adjust: Scope) 🔧Default VLAN (.0/24Phone VLAN (192.168.6.0/24 Phones to Reach ServerAdjust: Narrow Ports) 🔧Default VLAN (FAFO VLAN (8 Default VLAN FAFO VLAN (Adjust: Reconsider?) 🔧Default VLAN (110GBVMNetwork 0/24) Default VLAN to reach 10GB VM Network (Adjust: Narrow Scope) 🔧FAFO Network (192.168.8.0/24,7. FAFO Network Server(s) (Adjust: Narrow Ports) 🔧FAFO Network (192.168.8.0/24* FAFO Network (Adjust: Reconsider?) 🔧Allow Management VLAN to reach * (Change)  ⚠️11 (HomeBridgeIoT VLAN (5IoT VLAN (11 (HomeBridge IoT Devices to reach HomebridgePhoneVLAN Network (6FAFO Network (8Allow Phones to reach FAFO Network
ProtocolSourcePortDestinationPortDescription
IPv4 *CameraVLAN (192.168.4.0/24)*192.168.1.17/32 (NVR)*Allow Cameras to Reach NVR
IPv4 UDPCameraVLAN (192.168.4.0/24)*AD_DNS_SERVERS (7.150,7.151)123 (NTP)Allow Cameras NTP Traffic
IPv4 *192.168.5.19/32*AD_DNS_SERVERS (7.150,7.151)*

Allow Media PC to reach DC(s)

(Adjust: Narrow Ports) 🔧

IPv4 *WirelessClients (192.168.2.0/24)*192.168.99.2 (UniFi Controller)*

Allow Clients to reach UniFi Controller

IPv4 *Management Network (192.168.99.0/24)*AD_DNS_SERVERS (7.150,7.151)*Allow Management VLAN to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧
IPv4 *WittNet_Network (192.168.20.0/24)*AD_DNS_SERVERS (7.150,7.151)*Allow WittNet Peers to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧
IPv4 *WittNet_Network (192.168.20.0/24)*KMS_SERVER (192.168.7.37)*

Allow

WittNet Peers to Reach KMS Server

(Adjust: Narrow Ports) 🔧

IPv4 *192.168.20.21 (OffsiteVMHost1)*192.168.99.12 (Proxmox Datacenter Manager)*

Allow OffsiteVMHost1 to reach Proxmox DCM

REDUNDANT ❌

IPv4 *192.168.20.13 (Offsite RODC)*AD_DNS_SERVERS (7.150,7.151)*Allow Offsite RODC to reach AD/DNS/NTP Sever(s) REDUNDANT ❌
IPv4 *192.168.20.15 (Offsite NAS)*AD_DNS_SERVERS (7.150,7.151)*Allow Offsite NAS to reach AD/DNS/NTP Server(s) REDUNDANT ❌
IPv4 *WirelessClients (192.168.2.0/24)*Default VLAN (192.168.1.0/24)*Allow Wireless Clients to reach Default VLAN Clients (Adjust: Scope) 🔧
IPv4 *10GBVMNetwork (192.168.7.0/24)*Default VLAN (192.168.1.0/24)*Allow 10GBVMNetwork to reach Default VLAN Clients (Adjust: Scope) 🔧
IPv4 *Default VLAN (192.168.1.0/24)*Phone VLAN (192.168.6.0/24)*

Allow

Default VLAN to reach

Phones

(Adjust: Reconsider?

) 🔧

IPv4 * Phone VLAN (192.168.6.0/24)*AD_DNS_SERVER(s)*

Allow

Phones to Reach

DNS/NTP Server(s)

(Adjust: Narrow Ports) 🔧

IPv4 *Default VLAN (192.168.1.0/24)*FAFO VLAN (192.168.8.0/24)*

Allow Default VLAN to reach FAFO VLAN

(Adjust: Reconsider?) 🔧

IPv4 *Default VLAN (192.168.1.0/24)*10GBVMNetwork (192.168.7.0/24)*

Allow Default VLAN to reach 10GB VM Network

(Adjust: Narrow Scope) 🔧

IPv4 *FAFO ***Allow UniFi Controller to Reach *
(Change)  ⚠️
IPv4 * Network (192.168.8.0/24)*AD_DNS_SERVER(s) (7.150,7.151)*Allow FAFO Network to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧
IPv4 *FAFO Network (192.168.8.0/24)*192.168.1.16 (NAS)*

Allow

FAFO Network to reach NAS

(Adjust: Reconsider?) 🔧

IPv4 *192.168.7.11 (HomeBridge)*IoT VLAN (192.168.5.0/24)*Allow Homebridge to reach IoT Devices
IPv4 *IoT VLAN (192.168.5.0/24)*192.168.7.11 (HomeBridge)*Allow IoT Devices to reach Homebridge
IPv4 *PhoneVLAN Network (192.168.6.0/24)*FAFO Network (192.168.8.0/24)*Allow Phones to reach FAFO Network
IPv4 *WittNet WAN (97.85.180.137/32)*WAN Address/Interface*

Allow WittNet WG VPN to Connect

NOT NEEDED ❌ 

IPv4 *NOCIX WAN (63.141.225.139/32)*WAN Address/Interface*

Allow NOCIX WG VPN to Connect

NOT NEEDED ❌

IPv4 *10.4.4.1/32 (Cloudrouter WG Tun.)***Allow Cloudrouter WG Tun. to Connect
NOT NEEDED ❌
IPv4 *10.3.3.2/32 (WittNet WG Tun.)***

Allow WittNet WG Tun. to Connect

NOT NEEDED ❌

IPv4 ***WAN Address5201 (iPerf3)Allow iPerf3 Packets Inbound on WAN Address. NOT NEEDED ❌
IPv4 IPv4 *192.168.20.21 (OffsiteVMHost1) *192.168.51.3/32 (Cloud MCRouter)*Pterodactyl Hosts (7.102-105)*

Allow

Cloud MCRouter to reach

Onsite Pterodactyl Hosts

(Adjust: Narrow Ports) 🔧

IPv4 *192.168.52.12/32 (ConnectWise Server)*Allowed_CW_SVR_Hosts (7.37,150,151,156,162)*Allow ConnectWise Server to Reach Various Host(s) onsite.
IPv4 ICMP192.168.52.5/32 (Uptime Kuma)*AD_DNS_SERVER(s) (7.150-151)*Allow Uptime Kuma to Ping AD/DNS/NTP Server(s) onsite.
IPv4 ICMP192.168.52.5/32 (Uptime Kuma)*Plex Server (192.168.1.16)*Allow Uptime Kuma to Ping Plex
IPv4 *192.168.7.10/32 (Veeam)*VM_Hosts (192.168.99.4,32,37,38)*Allow Veeam to reach VM Host(s)
IPv4 *192.168.52.10/32 (Cloud Redbot)*Plex_Arr_Sever(s) (1.16,7.36)*Allow Redbot to reach onsite Plex Server(s), *Arr Stack, and Tautulli
IPv4 TCP/UDP63.141.225.139/32 (NOCIX WAN)*WAN Address51824 (WG)

Allow Wireguard Traffic from PNET-HQ to NOCIX

NOT NEEDED ❌

IPv4 TCP/UDP75.132.53.238/32 (WittNet WAN)*WAN Address51822 (WG)

Allow Wireguard Traffic from PNET-HQ to WittNet

NOT NEEDED ❌







PROPOSED ADDITIONS:




IPv4 *192.168.2.0/24 (Wireless ClientsPhone VLAN (192.168.6.0/24)*Allow Default VLAN to reach Phones (Adjust: Reconsider?) 🔧IPv4 * )*AD_DNS_SERVER(s) (7.150-151)*Allow Wireless Clients Access to AD/DNS/NTP
IPv4 *192.168.7.0/24 (VM Network)*AD_DNS_SERVER(s) (7.150-151)*Allow VM Network to reach AD/DNS/NTP
IPv4 *192.168.1.0/24 (Default VLAN)*AD_DNS_SERVER(s) (7.150-151)*Allow Default VLAN Clients to reach AD/DNS/NTP
IPv4 *192.168.6.0/24 (Phone VLAN)*CUCM_SERVER(s) (8.30-33)*Allow Phones to reach CUCM Server(s)
IPv4 *192.168.2.0/24 (Wireless Clients)*FILE_SERVER(s) 192.168.7.156*Allow Wireless Clients to reach File Server
IPv4 *192.168.7.0/24 (VM Network)*FILE_SERVER(s) 192.168.7.156*

Allow VM Network to reach file server.

NOT NEEDED ❌

IPv4 *CUCM_SERVER(s) (8.30-33IPv4 *)*AD_DNS_SERVER(s) (7.150-151)*

Allow

CUCM Server(s) to reach AD/DNS/NTP

NOT NEEDED ❌

IPv4 *NEWT_PROXY (7.69)*NEWT_APPROVED_NETWORKS (1.0/24,7.0/24,8.0/24,99.0/24)*Allow Pangolin Newt to reach servers it needs to proxy, as well as clients behind newt to reach those servers.
IPv4 *192.168.7.36 (Tautulli)*192.168.1.16 (NAS)32400 (Plex)Allow Tautulli to reach NAS.
IPv4 *192.168.7.27 (TracearrIPv4 *)*192.168.1.16 (NAS)32400 (Plex)Allow Tracearr to reach NAS.
IPv4 *192.168.1.0/24, 192.168.8.0/24, 192.168.99.0/24*192.168.7.37 (KMS)1688 (KMS)Allow Clients to Activate Microsoft Products.
IPv4 *192.168.7.0/24*DUO_PROXIES (7.148-149)389 (LDAP)

Allow VM Network Clients to authenticate w/LDAP via DUO.

NOT NEEDED ❌

IPv4 *CUCM_SERVER(s) (8.30-33)*CUCM_SERVER(s) (8.30-33)*

Allow CUCM Stack to communicate with one another.

NOT NEEDED ❌

IPv4 *192.168.1.0/24 (Default VLAN)*CUCM_SERVER(s) (8.30-33)*Allow Default VLAN to communicate (Desktop Jabber)IPv4 *Management VLAN Network (192.168.99.0/24)***
IPv4 *192.168.7.0/24 (VM Network)*192.168.7.162 (SMTP_LB)25

Allow VM Network to communicate with SMTP_LB

NOT NEEDED ❌

IPv4 *192.168.99.0/24 (Management Network)*192.168.7.162 (SMTP_LB)25Allow Management Network to communicate with SMTP_LB
IPv4 *192.168.7.162 (SMTP_LB)*192.168.52.3 (Mailcow, Remote)25Allow SMTP_LB to reach Mailcow
IPv4 *192.168.7.62 (Scrypted)*Allow Homebridge to reach IoT DevicesIPv4 *192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR)*Allow Scrypted to communicate with IoT Network (Speakers, etc.)
IPv4 *AD_DNS_SERVER(s) (7.150-7.151)*PI_HOLE_SERVER(s) (7.50-51)*

Allow DCs to reach PiHole(s)

NOT NEEDED ❌

IPv4 *192.168.7.5 (MC_Router)*Pterodactyl_Wings (192.168.7.102-105)*

Allow

MC-Router to Route to Pterodactyl Wings.

NOT NEEDED ❌

IPv4 *192.168.7.11 (Homebridge)*192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR)*

Allow Homebridge to communicate with IoT Clients

IPv4 *192.168.7.75 (Tugtainer)*192.168.7.0/24 (VM Network)*

Allow Tugtainer to Check Docker Updates on VM Hosts.

NOT NEEDED ❌

IPv4 *192.168.7.161 (SMTP-HA1)*192.168.7.162 (SMTP-HA2)*

Allow SMTP-HA1 to reach SMTP-HA2 to do VIP Checks.

NOT NEEDED ❌

IPv4 *192.168.7.162 (SMTP-HA2)*192.168.7.161 (SMTP-HA1)*

Allow SMTP-HA2 to reach SMTP-HA1 to do VIP Checks.

NOT NEEDED ❌