feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source
Replace open any/any inbound rule on Synology NAT with explicit TCP ports: 443 (Synology), 9890 (Vaultwarden), 4769 (Zabbix), 8080 (Snipe-IT), 3000 (Metabase), 3333 (Gitea), 8081 (phpIPAM). Access allowed from any IP. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
6d0f186795
commit
85ef316745
@@ -7,14 +7,9 @@ locals {
|
|||||||
uplink = "internet2"
|
uplink = "internet2"
|
||||||
allowed_inbound = [
|
allowed_inbound = [
|
||||||
{
|
{
|
||||||
protocol = "any"
|
protocol = "tcp"
|
||||||
destination_ports = ["Any"]
|
destination_ports = ["443", "9890", "4769", "8080", "3000", "3333", "8081"]
|
||||||
allowed_ips = ["188.0.0.0/8"]
|
allowed_ips = ["Any"]
|
||||||
},
|
|
||||||
{
|
|
||||||
protocol = "any"
|
|
||||||
destination_ports = ["Any"]
|
|
||||||
allowed_ips = ["57.133.120.176/28"]
|
|
||||||
},
|
},
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user