feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source
Replace open any/any inbound rule on Synology NAT with explicit TCP ports: 443 (Synology), 9890 (Vaultwarden), 4769 (Zabbix), 8080 (Snipe-IT), 3000 (Metabase), 3333 (Gitea), 8081 (phpIPAM). Access allowed from any IP. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
6d0f186795
commit
85ef316745
@@ -7,14 +7,9 @@ locals {
|
||||
uplink = "internet2"
|
||||
allowed_inbound = [
|
||||
{
|
||||
protocol = "any"
|
||||
destination_ports = ["Any"]
|
||||
allowed_ips = ["188.0.0.0/8"]
|
||||
},
|
||||
{
|
||||
protocol = "any"
|
||||
destination_ports = ["Any"]
|
||||
allowed_ips = ["57.133.120.176/28"]
|
||||
protocol = "tcp"
|
||||
destination_ports = ["443", "9890", "4769", "8080", "3000", "3333", "8081"]
|
||||
allowed_ips = ["Any"]
|
||||
},
|
||||
]
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user