| Info | ||
|---|---|---|
| ||
Firewall Rules Copied, Rules (all) copied into UXG-Pro, Pending Testing. |
Here be firewall rules:
| Protocol | Source | Port | Destination | Port | Description | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IPv4 * | CameraVLAN (192.168.4.0/24) | * | 192.168.1.17/32 (NVR) | * | Allow Cameras to Reach NVR | |||||||
| IPv4 UDP | CameraVLAN (192.168.4.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | 123 (NTP) | Allow Cameras NTP Traffic | |||||||
| IPv4 * | 192.168.5.19/32 | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Media PC to reach DC(s) (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | WirelessClients (192.168.2.0/24) | * | 192.168.99.2 (UniFi Controller) | * | Allow Clients to reach UniFi Controller | |||||||
| IPv4 * | IoT Network (192.168.5.0/24) | * | * | * | Allow IoT to reach * (Change) ⚠️ | |||||||
| IPv4 * | FAFO Network (192.168.8.0/24) | * | * | * | Allow FAFO to reach * (Change) ⚠️ | |||||||
| IPv4 * | Wireless Clients (192.168.2.0/24) | * | * | * | Allow Wireless Clients to reach * (Change) ⚠️ | |||||||
| IPv4 * | Phone Network (192.168.6.0/24) | * | * | * | Allow Phones to reach * (Change) ⚠️ | |||||||
| IPv4 * | 10GB VM Network (192.168.7.0/24) | * | * | * | Allow VMs to reach * (Change) ⚠️ | |||||||
| IPv4 * | Default Network (192.168.1.0/24) | * | * | * | Allow Default VLAN to reach * (Change) ⚠️ | |||||||
| IPv4 * | Management Network (192.168.99.0/24) | * | Default VLAN (192.168.1.0/24) | * | ||||||||
| IPv4 * | Management Network (192.168.99.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Management VLAN to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 | *192.168.99.2 (UniFi Controller) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow UniFi Controller to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | 192.168.99.2 (UniFi Controller) | * | * | * | Allow UniFi Controller to Reach * (Change) ⚠️ | |||||||
| IPv4 * | WittNet_Network (192.168.20.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow WittNet Peers to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | WittNet_Network (192.168.20.0/24) | * | KMS_SERVER (192.168.7.37) | * | Allow WittNet Peers to Reach KMS Server (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | 192.168.20.21 (OffsiteVMHost1) | * | 192.168.99.12 (Proxmox Datacenter Manager) | * | Allow OffsiteVMHost1 to reach Proxmox DCM | (Adjust: Narrow Ports) 🔧REDUNDANT ❌ | ||||||
| IPv4 * | 192.168.20.13 (Offsite RODC) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Offsite RODC to reach AD/DNS/NTP Sever(s) | (Adjust: Narrow Ports) 🔧REDUNDANT ❌ | ||||||
| IPv4 * | 192.168.20.15 (Offsite NAS) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Offsite NAS to reach AD/DNS/NTP Server(s) | (Adjust: Narrow Ports) 🔧REDUNDANT ❌ | ||||||
| IPv4 * | WirelessClients (192.168.2.0/24) | * | Default VLAN (192.168.1.0/24) | * | Allow Wireless Clients to reach Default VLAN Clients (Adjust: Scope) 🔧 | |||||||
| IPv4 * | 10GBVMNetwork (192.168.7.0/24) | * | Default VLAN (192.168.1.0/24) | * | Allow 10GBVMNetwork to reach Default VLAN Clients (Adjust: Scope) 🔧 | |||||||
| IPv4 * | Default VLAN (192.168.1.0/24) | * | Phone VLAN (192.168.6.0/24) | * | Allow Default VLAN to reach Phones (Adjust: Reconsider?) 🔧 | |||||||
| IPv4 * | Phone VLAN (192.168.6.0/24) | * | AD_DNS_SERVER(s) | * | Allow Phones to Reach DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | Default VLAN (192.168.1.0/24) | * | FAFO VLAN (192.168.8.0/24) | * | Allow Default VLAN to reach FAFO VLAN (Adjust: Reconsider?) 🔧 | |||||||
| IPv4 * | Default VLAN (192.168.1.0/24) | * | 10GBVMNetwork (192.168.7.0/24) | * | Allow Default VLAN to reach 10GB VM Network (Adjust: Narrow Scope) 🔧 | |||||||
| IPv4 * | FAFO Network (192.168.8.0/24) | * | AD_DNS_SERVER(s) (7.150,7.151) | * | Allow FAFO Network to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | FAFO Network (192.168.8.0/24) | * | 192.168.1.16 (NAS) | * | Allow FAFO Network to reach NAS (Adjust: Reconsider?) 🔧 | |||||||
| IPv4 * | Management VLAN Network (192.168 | .99. | 0/24)* | * | * | Allow Management VLAN to reach * (Change) ⚠️ | IPv4 * | 192.168.7.11 (HomeBridge) | * | IoT VLAN (192.168.5.0/24) | * | Allow Homebridge to reach IoT Devices |
| IPv4 * | IoT VLAN (192.168.5.0/24) | * | 192.168.7.11 (HomeBridge) | * | Allow IoT Devices to reach Homebridge | |||||||
| IPv4 * | PhoneVLAN Network (192.168.6.0/24) | * | FAFO Network (192.168.8.0/24) | * | Allow Phones to reach FAFO Network | |||||||
| IPv4 * | WittNet WAN (97.85.180.137/32) | * | WAN Address/Interface | * | Allow WittNet WG VPN to Connect | (Adjust: Narrow to WG Ports) 🔧 NOT NEEDED ❌ | ||||||
| IPv4 * | NOCIX WAN (63.141.225.139/32) | * | WAN Address/Interface | * | Allow NOCIX WG VPN to Connect | (Adjust: Narrow to WG Ports) 🔧 NOT NEEDED ❌ | ||||||
| IPv4 * | 10.4.4.1/32 (Cloudrouter WG Tun.) | * | * | * | Allow Cloudrouter WG Tun. to Connect NOT NEEDED ❌ | |||||||
| IPv4 * | 10.3.3.2/32 (WittNet WG Tun.) | * | * | * | Allow WittNet WG Tun. to Connect NOT NEEDED ❌ | |||||||
| IPv4 * | * | * | WAN Address | 5201 (iPerf3) | Allow iPerf3 Packets Inbound on WAN Address. | (Disable, But Keep)NOT NEEDED ❌ | ||||||
| IPv4 * | 192.168.51.3/32 (Cloud MCRouter) | * | Pterodactyl Hosts (7.102-105) | * | Allow Cloud MCRouter to reach Onsite Pterodactyl Hosts (Adjust: Narrow Ports) 🔧 | |||||||
| IPv4 * | 192.168.52.12/32 (ConnectWise Server) | * | Allowed_CW_SVR_Hosts (7.37,150,151,156,162) | * | Allow ConnectWise Server to Reach Various Host(s) onsite. | |||||||
| IPv4 ICMP | 192.168.52.5/32 (Uptime Kuma) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow Uptime Kuma to Ping AD/DNS/NTP Server(s) onsite. | |||||||
| IPv4 ICMP | 192.168.52.5/32 (Uptime Kuma) | * | Plex Server (192.168.1.16) | * | Allow Uptime Kuma to Ping Plex | |||||||
| IPv4 * | 192.168.7.10/32 (Veeam) | * | VM_Hosts (192.168.99.4,32,37,38) | * | Allow Veeam to reach VM Host(s) | |||||||
| IPv4 * | 192.168.52.10/32 (Cloud Redbot) | * | Plex_Arr_Sever(s) (1.16,7.36) | * | Allow Redbot to reach onsite Plex Server(s), *Arr Stack, and Tautulli | |||||||
| IPv4 TCP/UDP | 63.141.225.139/32 (NOCIX WAN) | * | WAN Address | 51824 (WG) | Allow Wireguard Traffic from PNET-HQ to NOCIX NOT NEEDED ❌ | |||||||
| IPv4 TCP/UDP | 75.132.53.238/32 (WittNet WAN) | * | WAN Address | 51822 (WG) | Allow Wireguard Traffic from PNET-HQ to WittNet NOT NEEDED ❌ | |||||||
| PROPOSED ADDITIONS: | ||||||||||||
| IPv4 | *all_subnets (EVERYTHING) | * | !(INVERT) all_private_networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) | * | Disallow all subnets to ping other subnets without implicit rules, including other hosts within existing subnet.* | 192.168.2.0/24 (Wireless Clients) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow Wireless Clients Access to AD/DNS/NTP | ||
| IPv4 * | 192.168.7.0/24 (VM Network) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow VM Network to reach AD/DNS/NTP | |||||||
| IPv4 * | 192.168.1.0/24 (Default VLAN) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow Default VLAN Clients to reach AD/DNS/NTP | |||||||
| IPv4 * | 192.168.6.0/24 (Phone VLAN) | * | CUCM_SERVER(s) (8.30-33) | * | Allow Phones to reach CUCM Server(s) | |||||||
| IPv4 * | 192.168.2.0/24 (Wireless Clients) | * | FILE_SERVER(s) 192.168.7.156 | * | Allow Wireless Clients to reach File Server | |||||||
| IPv4 * | 192.168.7.0/24 (VM Network) | * | FILE_SERVER(s) 192.168.7.156 | * | Allow VM Network to reach file server. NOT NEEDED ❌ | |||||||
| IPv4 * | CUCM_SERVER(s) (8.30-33) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow CUCM Server(s) to reach AD/DNS/NTP NOT NEEDED ❌ | |||||||
| IPv4 * | NEWT_PROXY (7.69) | * | NEWT_APPROVED_NETWORKS (1.0/24,7.0/24,8.0/24,99.0/24) | * | Allow Pangolin Newt to reach servers it needs to proxy, as well as clients behind newt to reach those servers. | |||||||
| IPv4 * | 192.168.7.36 (Tautulli) | * | 192.168.1.16 (NAS) | 32400 (Plex) | Allow Tautulli to reach NAS. | |||||||
| IPv4 * | 192.168.7.27 (Tracearr) | * | 192.168.1.16 (NAS) | 32400 (Plex) | Allow Tracearr to reach NAS. | |||||||
| IPv4 * | 192.168.1.0/24, 192.168.8.0/24, 192.168.99.0/24 | * | 192.168.7.37 (KMS) | 1688 (KMS) | Allow Clients to Activate Microsoft Products. | |||||||
| IPv4 * | 192.168.7.0/24 | * | DUO_PROXIES (7.148-149) | 389 (LDAP) | Allow VM Network Clients to authenticate w/LDAP via DUO. NOT NEEDED ❌ | |||||||
| IPv4 * | CUCM_SERVER(s) (8.30-33) | * | CUCM_SERVER(s) (8.30-33) | * | Allow CUCM Stack to communicate with one another. NOT NEEDED ❌ | |||||||
| IPv4 * | 192.168.1.0/24 (Default VLAN) | * | CUCM_SERVER(s) (8.30-33) | * | Allow Default VLAN to communicate (Desktop Jabber) | |||||||
| IPv4 * | 192.168.7.0/24 (VM Network) | * | 192.168.7.162 (SMTP_LB) | 25 | Allow VM Network to communicate with SMTP_LB NOT NEEDED ❌ | |||||||
| IPv4 * | 192.168.99.0/24 (Management Network) | * | 192.168.7.162 (SMTP_LB) | 25 | Allow Management Network to communicate with SMTP_LB | |||||||
| IPv4 * | 192.168.7.162 (SMTP_LB) | * | 192.168.52.3 (Mailcow, Remote) | 25 | Allow SMTP_LB to reach Mailcow | |||||||
| IPv4 * | 192.168.7.62 (Scrypted) | * | 192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR) | * | Allow Scrypted to communicate with IoT Network (Speakers, etc.) | |||||||
| IPv4 * | AD_DNS_SERVER(s) (7.150-7.151) | * | PI_HOLE_SERVER(s) (7.50-51) | * | Allow DCs to reach PiHole(s) NOT NEEDED ❌ | |||||||
| IPv4 * | 192.168.7.5 (MC_Router) | * | Pterodactyl_Wings (192.168.7.102-105) | * | Allow MC-Router to Route to Pterodactyl Wings. NOT NEEDED ❌ | |||||||
| IPv4 * | 192.168.7.11 (Homebridge) | * | 192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR) | * | Allow Homebridge to communicate with IoT Clients | |||||||
| IPv4 * | 192.168.7.75 (Tugtainer) | * | 192.168.7.0/24 (VM Network) | * | Allow Tugtainer to Check Docker Updates on VM Hosts. NOT NEEDED ❌ | |||||||
| IPv4 * | 192.168.7.161 (SMTP-HA1) | * | 192.168.7.162 (SMTP-HA2) | * | Allow SMTP-HA1 to reach SMTP-HA2 to do VIP Checks. NOT NEEDED ❌ | |||||||
| IPv4 * | 192.168.7.162 (SMTP-HA2) | * | 192.168.7.161 (SMTP-HA1) | * | Allow SMTP-HA2 to reach SMTP-HA1 to do VIP Checks. NOT NEEDED ❌ |