Firewall Rules Copied, Rules (all) copied into UXG-Pro, Pending Testing. |
Here be firewall rules:
| Protocol | Source | Port | Destination | Port | Description |
|---|---|---|---|---|---|
| IPv4 * | CameraVLAN (192.168.4.0/24) | * | 192.168.1.17/32 (NVR) | * | Allow Cameras to Reach NVR |
| IPv4 UDP | CameraVLAN (192.168.4.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | 123 (NTP) | Allow Cameras NTP Traffic |
| IPv4 * | 192.168.5.19/32 | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Media PC to reach DC(s) (Adjust: Narrow Ports) 🔧 |
| IPv4 * | WirelessClients (192.168.2.0/24) | * | 192.168.99.2 (UniFi Controller) | * | Allow Clients to reach UniFi Controller |
| IPv4 * | Management Network (192.168.99.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Management VLAN to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 |
| IPv4 * | WittNet_Network (192.168.20.0/24) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow WittNet Peers to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 |
| IPv4 * | WittNet_Network (192.168.20.0/24) | * | KMS_SERVER (192.168.7.37) | * | Allow WittNet Peers to Reach KMS Server (Adjust: Narrow Ports) 🔧 |
| IPv4 * | 192.168.20.21 (OffsiteVMHost1) | * | 192.168.99.12 (Proxmox Datacenter Manager) | * | Allow OffsiteVMHost1 to reach Proxmox DCM REDUNDANT ❌ |
| IPv4 * | 192.168.20.13 (Offsite RODC) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Offsite RODC to reach AD/DNS/NTP Sever(s) REDUNDANT ❌ |
| IPv4 * | 192.168.20.15 (Offsite NAS) | * | AD_DNS_SERVERS (7.150,7.151) | * | Allow Offsite NAS to reach AD/DNS/NTP Server(s) REDUNDANT ❌ |
| IPv4 * | WirelessClients (192.168.2.0/24) | * | Default VLAN (192.168.1.0/24) | * | Allow Wireless Clients to reach Default VLAN Clients (Adjust: Scope) 🔧 |
| IPv4 * | 10GBVMNetwork (192.168.7.0/24) | * | Default VLAN (192.168.1.0/24) | * | Allow 10GBVMNetwork to reach Default VLAN Clients (Adjust: Scope) 🔧 |
| IPv4 * | Default VLAN (192.168.1.0/24) | * | Phone VLAN (192.168.6.0/24) | * | Allow Default VLAN to reach Phones (Adjust: Reconsider?) 🔧 |
| IPv4 * | Phone VLAN (192.168.6.0/24) | * | AD_DNS_SERVER(s) | * | Allow Phones to Reach DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 |
| IPv4 * | Default VLAN (192.168.1.0/24) | * | FAFO VLAN (192.168.8.0/24) | * | Allow Default VLAN to reach FAFO VLAN (Adjust: Reconsider?) 🔧 |
| IPv4 * | Default VLAN (192.168.1.0/24) | * | 10GBVMNetwork (192.168.7.0/24) | * | Allow Default VLAN to reach 10GB VM Network (Adjust: Narrow Scope) 🔧 |
| IPv4 * | FAFO Network (192.168.8.0/24) | * | AD_DNS_SERVER(s) (7.150,7.151) | * | Allow FAFO Network to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) 🔧 |
| IPv4 * | FAFO Network (192.168.8.0/24) | * | 192.168.1.16 (NAS) | * | Allow FAFO Network to reach NAS (Adjust: Reconsider?) 🔧 |
| IPv4 * | 192.168.7.11 (HomeBridge) | * | IoT VLAN (192.168.5.0/24) | * | Allow Homebridge to reach IoT Devices |
| IPv4 * | IoT VLAN (192.168.5.0/24) | * | 192.168.7.11 (HomeBridge) | * | Allow IoT Devices to reach Homebridge |
| IPv4 * | PhoneVLAN Network (192.168.6.0/24) | * | FAFO Network (192.168.8.0/24) | * | Allow Phones to reach FAFO Network |
| IPv4 * | WittNet WAN (97.85.180.137/32) | * | WAN Address/Interface | * | Allow WittNet WG VPN to Connect NOT NEEDED ❌ |
| IPv4 * | NOCIX WAN (63.141.225.139/32) | * | WAN Address/Interface | * | Allow NOCIX WG VPN to Connect NOT NEEDED ❌ |
| IPv4 * | 10.4.4.1/32 (Cloudrouter WG Tun.) | * | * | * | Allow Cloudrouter WG Tun. to Connect NOT NEEDED ❌ |
| IPv4 * | 10.3.3.2/32 (WittNet WG Tun.) | * | * | * | Allow WittNet WG Tun. to Connect NOT NEEDED ❌ |
| IPv4 * | * | * | WAN Address | 5201 (iPerf3) | Allow iPerf3 Packets Inbound on WAN Address. NOT NEEDED ❌ |
| IPv4 * | 192.168.51.3/32 (Cloud MCRouter) | * | Pterodactyl Hosts (7.102-105) | * | Allow Cloud MCRouter to reach Onsite Pterodactyl Hosts (Adjust: Narrow Ports) 🔧 |
| IPv4 * | 192.168.52.12/32 (ConnectWise Server) | * | Allowed_CW_SVR_Hosts (7.37,150,151,156,162) | * | Allow ConnectWise Server to Reach Various Host(s) onsite. |
| IPv4 ICMP | 192.168.52.5/32 (Uptime Kuma) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow Uptime Kuma to Ping AD/DNS/NTP Server(s) onsite. |
| IPv4 ICMP | 192.168.52.5/32 (Uptime Kuma) | * | Plex Server (192.168.1.16) | * | Allow Uptime Kuma to Ping Plex |
| IPv4 * | 192.168.7.10/32 (Veeam) | * | VM_Hosts (192.168.99.4,32,37,38) | * | Allow Veeam to reach VM Host(s) |
| IPv4 * | 192.168.52.10/32 (Cloud Redbot) | * | Plex_Arr_Sever(s) (1.16,7.36) | * | Allow Redbot to reach onsite Plex Server(s), *Arr Stack, and Tautulli |
| IPv4 TCP/UDP | 63.141.225.139/32 (NOCIX WAN) | * | WAN Address | 51824 (WG) | Allow Wireguard Traffic from PNET-HQ to NOCIX NOT NEEDED ❌ |
| IPv4 TCP/UDP | 75.132.53.238/32 (WittNet WAN) | * | WAN Address | 51822 (WG) | Allow Wireguard Traffic from PNET-HQ to WittNet NOT NEEDED ❌ |
| PROPOSED ADDITIONS: | |||||
| IPv4 * | 192.168.2.0/24 (Wireless Clients) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow Wireless Clients Access to AD/DNS/NTP |
| IPv4 * | 192.168.7.0/24 (VM Network) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow VM Network to reach AD/DNS/NTP |
| IPv4 * | 192.168.1.0/24 (Default VLAN) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow Default VLAN Clients to reach AD/DNS/NTP |
| IPv4 * | 192.168.6.0/24 (Phone VLAN) | * | CUCM_SERVER(s) (8.30-33) | * | Allow Phones to reach CUCM Server(s) |
| IPv4 * | 192.168.2.0/24 (Wireless Clients) | * | FILE_SERVER(s) 192.168.7.156 | * | Allow Wireless Clients to reach File Server |
| IPv4 * | 192.168.7.0/24 (VM Network) | * | FILE_SERVER(s) 192.168.7.156 | * | Allow VM Network to reach file server. NOT NEEDED ❌ |
| IPv4 * | CUCM_SERVER(s) (8.30-33) | * | AD_DNS_SERVER(s) (7.150-151) | * | Allow CUCM Server(s) to reach AD/DNS/NTP NOT NEEDED ❌ |
| IPv4 * | NEWT_PROXY (7.69) | * | NEWT_APPROVED_NETWORKS (1.0/24,7.0/24,8.0/24,99.0/24) | * | Allow Pangolin Newt to reach servers it needs to proxy, as well as clients behind newt to reach those servers. |
| IPv4 * | 192.168.7.36 (Tautulli) | * | 192.168.1.16 (NAS) | 32400 (Plex) | Allow Tautulli to reach NAS. |
| IPv4 * | 192.168.7.27 (Tracearr) | * | 192.168.1.16 (NAS) | 32400 (Plex) | Allow Tracearr to reach NAS. |
| IPv4 * | 192.168.1.0/24, 192.168.8.0/24, 192.168.99.0/24 | * | 192.168.7.37 (KMS) | 1688 (KMS) | Allow Clients to Activate Microsoft Products. |
| IPv4 * | 192.168.7.0/24 | * | DUO_PROXIES (7.148-149) | 389 (LDAP) | Allow VM Network Clients to authenticate w/LDAP via DUO. NOT NEEDED ❌ |
| IPv4 * | CUCM_SERVER(s) (8.30-33) | * | CUCM_SERVER(s) (8.30-33) | * | Allow CUCM Stack to communicate with one another. NOT NEEDED ❌ |
| IPv4 * | 192.168.1.0/24 (Default VLAN) | * | CUCM_SERVER(s) (8.30-33) | * | Allow Default VLAN to communicate (Desktop Jabber) |
| IPv4 * | 192.168.7.0/24 (VM Network) | * | 192.168.7.162 (SMTP_LB) | 25 | Allow VM Network to communicate with SMTP_LB NOT NEEDED ❌ |
| IPv4 * | 192.168.99.0/24 (Management Network) | * | 192.168.7.162 (SMTP_LB) | 25 | Allow Management Network to communicate with SMTP_LB |
| IPv4 * | 192.168.7.162 (SMTP_LB) | * | 192.168.52.3 (Mailcow, Remote) | 25 | Allow SMTP_LB to reach Mailcow |
| IPv4 * | 192.168.7.62 (Scrypted) | * | 192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR) | * | Allow Scrypted to communicate with IoT Network (Speakers, etc.) |
| IPv4 * | AD_DNS_SERVER(s) (7.150-7.151) | * | PI_HOLE_SERVER(s) (7.50-51) | * | Allow DCs to reach PiHole(s) NOT NEEDED ❌ |
| IPv4 * | 192.168.7.5 (MC_Router) | * | Pterodactyl_Wings (192.168.7.102-105) | * | Allow MC-Router to Route to Pterodactyl Wings. NOT NEEDED ❌ |
| IPv4 * | 192.168.7.11 (Homebridge) | * | 192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR) | * | Allow Homebridge to communicate with IoT Clients |
| IPv4 * | 192.168.7.75 (Tugtainer) | * | 192.168.7.0/24 (VM Network) | * | Allow Tugtainer to Check Docker Updates on VM Hosts. NOT NEEDED ❌ |
| IPv4 * | 192.168.7.161 (SMTP-HA1) | * | 192.168.7.162 (SMTP-HA2) | * | Allow SMTP-HA1 to reach SMTP-HA2 to do VIP Checks. NOT NEEDED ❌ |
| IPv4 * | 192.168.7.162 (SMTP-HA2) | * | 192.168.7.161 (SMTP-HA1) | * | Allow SMTP-HA2 to reach SMTP-HA1 to do VIP Checks. NOT NEEDED ❌ |