From 85ef31674515d584a04124f5bdefaf7fa5bf1349 Mon Sep 17 00:00:00 2001 From: Jose Martinez Date: Thu, 7 May 2026 10:30:29 +0200 Subject: [PATCH] feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source Replace open any/any inbound rule on Synology NAT with explicit TCP ports: 443 (Synology), 9890 (Vaultwarden), 4769 (Zabbix), 8080 (Snipe-IT), 3000 (Metabase), 3333 (Gitea), 8081 (phpIPAM). Access allowed from any IP. Co-Authored-By: Claude Sonnet 4.6 --- sites/BCN01-LAB/appliance.tf | 11 +++-------- 1 file changed, 3 insertions(+), 8 deletions(-) diff --git a/sites/BCN01-LAB/appliance.tf b/sites/BCN01-LAB/appliance.tf index a79eb3e..fb49fe0 100644 --- a/sites/BCN01-LAB/appliance.tf +++ b/sites/BCN01-LAB/appliance.tf @@ -7,14 +7,9 @@ locals { uplink = "internet2" allowed_inbound = [ { - protocol = "any" - destination_ports = ["Any"] - allowed_ips = ["188.0.0.0/8"] - }, - { - protocol = "any" - destination_ports = ["Any"] - allowed_ips = ["57.133.120.176/28"] + protocol = "tcp" + destination_ports = ["443", "9890", "4769", "8080", "3000", "3333", "8081"] + allowed_ips = ["Any"] }, ] },