Here be firewall rules:
| Protocol | Source | Port | Destination | Port | Description |
|---|---|---|---|---|---|
| IPv4 * | CameraVLAN (192.168.4.0/24) | * | 192.168.1.17/32 (NVR) | * | Allow Cameras to Reach NVR |
| IPv4 UDP | CameraVLAN (192.168.4.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | 123 (NTP) | Allow Cameras NTP Traffic |
| IPv4 * | 192.168.5.19/32 | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Media PC to reach DC(s) (Adjust: Narrow Ports) π§ |
| IPv4 * | WirelessClients (192.168.2.0/24) | * | 192.168.99.2 (UniFi Controller) | * | Allow Clients to reach UniFi Controller |
(Remove, Create New Rules) β οΈ | |||||
(Remove, Create New Rules) β οΈ | |||||
(Remove, Create New Rules) β οΈ | |||||
(Remove, Create New Rules) β οΈ | |||||
(Remove, Create New Rules) β οΈ | |||||
(Remove, Create New Rules) β οΈ | |||||
(Remove, Create New Rules) β οΈ | |||||
| IPv4 * | Management Network (192.168.99.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Management VLAN to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) π§ |
| IPv4 * | 192.168.99.2 (UniFi Controller) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow UniFi Controller to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) π§ |
(Remove, Create New Rules) β οΈ | |||||
| IPv4 * | WittNet_Network (192.168.20.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow WittNet Peers to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) π§ |
| IPv4 * | WittNet_Network (192.168.20.0/24) | * | KMS_SERVER (192.168.7.37) | * | Allow WittNet Peers to Reach KMS Server (Adjust: Narrow Ports) π§ |
| IPv4 * | 192.168.20.21 (OffsiteVMHost1) | * | 192.168.99.12 (Proxmox Datacenter Manager) | * | Allow OffsiteVMHost1 to reach Proxmox DCM (Adjust: Narrow Ports) π§ |
| IPv4 * | 192.168.20.13 (Offsite RODC) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Offsite RODC to reach AD/DNS/NTP Sever(s) (Adjust: Narrow Ports) π§ |
| IPv4 * | 192.168.20.15 (Offsite NAS) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Offsite NAS to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) π§ |
| IPv4 * | WirelessClients (192.168.2.0/24) | * | Default VLAN (192.168.1.0/24) | * | Allow Wireless Clients to reach Default VLAN Clients (Adjust: Scope) π§ |
| IPv4 * | 10GBVMNetwork (192.168.7.0/24) | * | Default VLAN (192.168.1.0/24) | * | Allow 10GBVMNetwork to reach Default VLAN Clients (Adjust: Scope) π§ |
| IPv4 * | Default VLAN (192.168.1.0/24) | * | Phone VLAN (192.168.6.0/24) | * | Allow Default VLAN to reach Phones (Adjust: Reconsider?) π§ |
| IPv4 *Β | Phone VLAN (192.168.6.0/24) | * | AD_DNS_SERVER(s) | * | Allow Phones to Reach DNS/NTP Server(s) (Adjust: Narrow Ports) π§ |
| IPv4 * | Default VLAN (192.168.1.0/24) | * | FAFO VLAN (192.168.8.0/24) | * | Allow Default VLAN to reach FAFO VLAN (Adjust: Reconsider?) π§ |
| IPv4 * | Default VLAN (192.168.1.0/24) | * | 10GBVMNetwork (192.168.7.0/24) | * | Allow Default VLAN to reach 10GB VM Network (Adjust: Narrow Scope) π§ |
| IPv4 * | FAFO Network (192.168.8.0/24) | * | AD_DNS_SERVER(s) (7.150,7.151) | * | Allow FAFO Network to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) π§ |
| IPv4 * | FAFO Network (192.168.8.0/24) | * | 192.168.1.16 (NAS) | * | Allow FAFO Network to reach NAS (Adjust: Reconsider?) π§ |
| |||||
| IPv4 * | 192.168.7.11 (HomeBridge) | * | IoT VLAN (192.168.5.0/24) | * | Allow Homebridge to reach IoT Devices |
| IPv4 * | IoT VLAN (192.168.5.0/24) | * | 192.168.7.11 (HomeBridge) | * | Allow IoT Devices to reach Homebridge |
| IPv4 * | PhoneVLAN Network (192.168.6.0/24) | * | FAFO Network (192.168.8.0/24) | * | Allow Phones to reach FAFO Network |
| IPv4 * | WittNet WAN (97.85.180.137/32) | * | WAN Address/Interface | * | Allow WittNet WG VPN to Connect (Adjust: Narrow to WG Ports) π§Β |
| IPv4 * | NOCIX WAN (63.141.225.139/32) | * | WAN Address/Interface | * | Allow NOCIX WG VPN to Connect (Adjust: Narrow to WG Ports) π§ |
| IPv4 * | 10.4.4.1/32 (Cloudrouter WG Tun.) | * | * | * | Allow Cloudrouter WG Tun. to Connect |
| IPv4 * | 10.3.3.2/32 (WittNet WG Tun.) | * | * | * | Allow WittNet WG Tun. to Connect |
| IPv4 * | * | * | WAN Address | 5201 (iPerf3) | Allow iPerf3 Packets Inbound on WAN Address. (Disable, But Keep) |
| IPv4 * | 192.168.51.3/32 (Cloud MCRouter) | * | Pterodactyl Hosts (7.102-105) | * | Allow Cloud MCRouter to reach Onsite Pterodactyl Hosts (Adjust: Narrow Ports) π§ |
| IPv4 * | 192.168.52.12/32 (ConnectWise Server) | * | Allowed_CW_SVR_Hosts (7.37,150,151,156,162) | * | Allow ConnectWise Server to Reach Various Host(s) onsite. |
| IPv4 ICMP | 192.168.52.5/32 (Uptime Kuma) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow Uptime Kuma to Ping AD/DNS/NTP Server(s) onsite. |
| IPv4 ICMP | 192.168.52.5/32 (Uptime Kuma) | * | Plex Server (192.168.1.16) | * | Allow Uptime Kuma to Ping Plex |
| IPv4 * | 192.168.7.10/32 (Veeam) | * | VM_Hosts (192.168.99.4,32,37,38) | * | Allow Veeam to reach VM Host(s) |
| IPv4 * | 192.168.52.10/32 (Cloud Redbot) | * | Plex_Arr_Sever(s) (1.16,7.36) | * | Allow Redbot to reach onsite Plex Server(s), *Arr Stack, and Tautulli |
| IPv4 TCP/UDP | 63.141.225.139/32 (NOCIX WAN) | * | WAN Address | 51824 (WG) | Allow Wireguard Traffic from PNET-HQ to NOCIX |
| IPv4 TCP/UDP | 75.132.53.238/32 (WittNet WAN) | * | WAN Address | 51822 (WG) | Allow Wireguard Traffic from PNET-HQ to WittNet |
| PROPOSED ADDITIONS: | |||||
| IPv4 * | all_subnets (EVERYTHING) | * | !(INVERT) all_private_networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) | * | Disallow all subnets to ping other subnets without implicit rules, including other hosts within existing subnet. |