Status:

Firewall Rules Copied, Rules (all) copied into UXG-Pro, Pending Testing.

Here be firewall rules:

ProtocolSourcePortDestinationPortDescription
IPv4 *CameraVLAN (192.168.4.0/24)*192.168.1.17/32 (NVR)*Allow Cameras to Reach NVR
IPv4 UDPCameraVLAN (192.168.4.0/24)*AD_DNS_SERVERS (7.150,7.151)123 (NTP)Allow Cameras NTP Traffic
IPv4 *192.168.5.19/32*AD_DNS_SERVERS (7.150,7.151)*

Allow Media PC to reach DC(s)

(Adjust: Narrow Ports) πŸ”§

IPv4 *WirelessClients (192.168.2.0/24)*192.168.99.2 (UniFi Controller)*

Allow Clients to reach UniFi Controller

IPv4 *Management Network (192.168.99.0/24)*AD_DNS_SERVERS (7.150,7.151)*Allow Management VLAN to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) πŸ”§
IPv4 *WittNet_Network (192.168.20.0/24)*AD_DNS_SERVERS (7.150,7.151)*Allow WittNet Peers to Reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) πŸ”§
IPv4 *WittNet_Network (192.168.20.0/24)*KMS_SERVER (192.168.7.37)*

Allow WittNet Peers to Reach KMS Server

(Adjust: Narrow Ports) πŸ”§

IPv4 *192.168.20.21 (OffsiteVMHost1)*192.168.99.12 (Proxmox Datacenter Manager)*

Allow OffsiteVMHost1 to reach Proxmox DCM

REDUNDANT ❌

IPv4 *192.168.20.13 (Offsite RODC)*AD_DNS_SERVERS (7.150,7.151)*Allow Offsite RODC to reach AD/DNS/NTP Sever(s) REDUNDANT ❌
IPv4 *192.168.20.15 (Offsite NAS)*AD_DNS_SERVERS (7.150,7.151)*Allow Offsite NAS to reach AD/DNS/NTP Server(s) REDUNDANT ❌
IPv4 *WirelessClients (192.168.2.0/24)*Default VLAN (192.168.1.0/24)*Allow Wireless Clients to reach Default VLAN Clients (Adjust: Scope) πŸ”§
IPv4 *10GBVMNetwork (192.168.7.0/24)*Default VLAN (192.168.1.0/24)*Allow 10GBVMNetwork to reach Default VLAN Clients (Adjust: Scope) πŸ”§
IPv4 *Default VLAN (192.168.1.0/24)*Phone VLAN (192.168.6.0/24)*

Allow Default VLAN to reach Phones

(Adjust: Reconsider?) πŸ”§

IPv4 *Β Phone VLAN (192.168.6.0/24)*AD_DNS_SERVER(s)*

Allow Phones to Reach DNS/NTP Server(s)

(Adjust: Narrow Ports) πŸ”§

IPv4 *Default VLAN (192.168.1.0/24)*FAFO VLAN (192.168.8.0/24)*

Allow Default VLAN to reach FAFO VLAN

(Adjust: Reconsider?) πŸ”§

IPv4 *Default VLAN (192.168.1.0/24)*10GBVMNetwork (192.168.7.0/24)*

Allow Default VLAN to reach 10GB VM Network

(Adjust: Narrow Scope) πŸ”§

IPv4 *FAFO Network (192.168.8.0/24)*AD_DNS_SERVER(s) (7.150,7.151)*Allow FAFO Network to reach AD/DNS/NTP Server(s) (Adjust: Narrow Ports) πŸ”§
IPv4 *FAFO Network (192.168.8.0/24)*192.168.1.16 (NAS)*

Allow FAFO Network to reach NAS

(Adjust: Reconsider?) πŸ”§

IPv4 *192.168.7.11 (HomeBridge)*IoT VLAN (192.168.5.0/24)*Allow Homebridge to reach IoT Devices
IPv4 *IoT VLAN (192.168.5.0/24)*192.168.7.11 (HomeBridge)*Allow IoT Devices to reach Homebridge
IPv4 *PhoneVLAN Network (192.168.6.0/24)*FAFO Network (192.168.8.0/24)*Allow Phones to reach FAFO Network
IPv4 *WittNet WAN (97.85.180.137/32)*WAN Address/Interface*

Allow WittNet WG VPN to Connect

NOT NEEDED ❌ 

IPv4 *NOCIX WAN (63.141.225.139/32)*WAN Address/Interface*

Allow NOCIX WG VPN to Connect

NOT NEEDED ❌

IPv4 *10.4.4.1/32 (Cloudrouter WG Tun.)***Allow Cloudrouter WG Tun. to Connect
NOT NEEDED ❌
IPv4 *10.3.3.2/32 (WittNet WG Tun.)***

Allow WittNet WG Tun. to Connect

NOT NEEDED ❌

IPv4 ***WAN Address5201 (iPerf3)Allow iPerf3 Packets Inbound on WAN Address. NOT NEEDED ❌
IPv4 *192.168.51.3/32 (Cloud MCRouter)*Pterodactyl Hosts (7.102-105)*

Allow Cloud MCRouter to reach Onsite Pterodactyl Hosts

(Adjust: Narrow Ports) πŸ”§

IPv4 *192.168.52.12/32 (ConnectWise Server)*Allowed_CW_SVR_Hosts (7.37,150,151,156,162)*Allow ConnectWise Server to Reach Various Host(s) onsite.
IPv4 ICMP192.168.52.5/32 (Uptime Kuma)*AD_DNS_SERVER(s) (7.150-151)*Allow Uptime Kuma to Ping AD/DNS/NTP Server(s) onsite.
IPv4 ICMP192.168.52.5/32 (Uptime Kuma)*Plex Server (192.168.1.16)*Allow Uptime Kuma to Ping Plex
IPv4 *192.168.7.10/32 (Veeam)*VM_Hosts (192.168.99.4,32,37,38)*Allow Veeam to reach VM Host(s)
IPv4 *192.168.52.10/32 (Cloud Redbot)*Plex_Arr_Sever(s) (1.16,7.36)*Allow Redbot to reach onsite Plex Server(s), *Arr Stack, and Tautulli
IPv4 TCP/UDP63.141.225.139/32 (NOCIX WAN)*WAN Address51824 (WG)

Allow Wireguard Traffic from PNET-HQ to NOCIX

NOT NEEDED ❌

IPv4 TCP/UDP75.132.53.238/32 (WittNet WAN)*WAN Address51822 (WG)

Allow Wireguard Traffic from PNET-HQ to WittNet

NOT NEEDED ❌







PROPOSED ADDITIONS:




IPv4 *192.168.2.0/24 (Wireless Clients)*AD_DNS_SERVER(s) (7.150-151)*Allow Wireless Clients Access to AD/DNS/NTP
IPv4 *192.168.7.0/24 (VM Network)*AD_DNS_SERVER(s) (7.150-151)*Allow VM Network to reach AD/DNS/NTP
IPv4 *192.168.1.0/24 (Default VLAN)*AD_DNS_SERVER(s) (7.150-151)*Allow Default VLAN Clients to reach AD/DNS/NTP
IPv4 *192.168.6.0/24 (Phone VLAN)*CUCM_SERVER(s) (8.30-33)*Allow Phones to reach CUCM Server(s)
IPv4 *192.168.2.0/24 (Wireless Clients)*FILE_SERVER(s) 192.168.7.156*Allow Wireless Clients to reach File Server
IPv4 *192.168.7.0/24 (VM Network)*FILE_SERVER(s) 192.168.7.156*

Allow VM Network to reach file server.

NOT NEEDED ❌

IPv4 *CUCM_SERVER(s) (8.30-33)*AD_DNS_SERVER(s) (7.150-151)*

Allow CUCM Server(s) to reach AD/DNS/NTP

NOT NEEDED ❌

IPv4 *NEWT_PROXY (7.69)*NEWT_APPROVED_NETWORKS (1.0/24,7.0/24,8.0/24,99.0/24)*Allow Pangolin Newt to reach servers it needs to proxy, as well as clients behind newt to reach those servers.
IPv4 *192.168.7.36 (Tautulli)*192.168.1.16 (NAS)32400 (Plex)Allow Tautulli to reach NAS.
IPv4 *192.168.7.27 (Tracearr)*192.168.1.16 (NAS)32400 (Plex)Allow Tracearr to reach NAS.
IPv4 *192.168.1.0/24, 192.168.8.0/24, 192.168.99.0/24*192.168.7.37 (KMS)1688 (KMS)Allow Clients to Activate Microsoft Products.
IPv4 *192.168.7.0/24*DUO_PROXIES (7.148-149)389 (LDAP)

Allow VM Network Clients to authenticate w/LDAP via DUO.

NOT NEEDED ❌

IPv4 *CUCM_SERVER(s) (8.30-33)*CUCM_SERVER(s) (8.30-33)*

Allow CUCM Stack to communicate with one another.

NOT NEEDED ❌

IPv4 *192.168.1.0/24 (Default VLAN)*CUCM_SERVER(s) (8.30-33)*Allow Default VLAN to communicate (Desktop Jabber)
IPv4 *192.168.7.0/24 (VM Network)*192.168.7.162 (SMTP_LB)25

Allow VM Network to communicate with SMTP_LB

NOT NEEDED ❌

IPv4 *192.168.99.0/24 (Management Network)*192.168.7.162 (SMTP_LB)25Allow Management Network to communicate with SMTP_LB
IPv4 *192.168.7.162 (SMTP_LB)*192.168.52.3 (Mailcow, Remote)25Allow SMTP_LB to reach Mailcow
IPv4 *192.168.7.62 (Scrypted)*192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR)*Allow Scrypted to communicate with IoT Network (Speakers, etc.)
IPv4 *AD_DNS_SERVER(s) (7.150-7.151)*PI_HOLE_SERVER(s) (7.50-51)*

Allow DCs to reach PiHole(s)

NOT NEEDED ❌

IPv4 *192.168.7.5 (MC_Router)*Pterodactyl_Wings (192.168.7.102-105)*

Allow MC-Router to Route to Pterodactyl Wings.

NOT NEEDED ❌

IPv4 *192.168.7.11 (Homebridge)*192.168.5.0/24 (IoT Network), 192.168.1.17 (NVR)*

Allow Homebridge to communicate with IoT Clients

IPv4 *192.168.7.75 (Tugtainer)*192.168.7.0/24 (VM Network)*

Allow Tugtainer to Check Docker Updates on VM Hosts.

NOT NEEDED ❌

IPv4 *192.168.7.161 (SMTP-HA1)*192.168.7.162 (SMTP-HA2)*

Allow SMTP-HA1 to reach SMTP-HA2 to do VIP Checks.

NOT NEEDED ❌

IPv4 *192.168.7.162 (SMTP-HA2)*192.168.7.161 (SMTP-HA1)*

Allow SMTP-HA2 to reach SMTP-HA1 to do VIP Checks.

NOT NEEDED ❌



  • No labels