10. Appendix
Appendix A - Hardware
|
Device |
Description |
Link |
|
Protectli FW6D |
OPNsense firewall/router appliance |
|
|
UniFi U6+ Access Point |
Dual-band WiFi 6 AP (managed by UniFi Controller) |
Appendix B - Software
|
Software |
Purpose |
Link |
|
OPNsense |
Firewall, router, DNS resolver, IDS/IPS |
|
|
UniFi Network Server (Controller) |
WiFi AP management and firmware control |
Appendix C - Firewall Rule Sets
Aliases:
|
Alias |
Type |
Content |
Description |
|
RFC1918 |
Network |
192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12 |
All private IP ranges |
|
Geo_US |
GeoIP |
United States |
U.S. IP address ranges |
|
print_ports |
Port |
515, 631, 9100 |
Printing — LPD, IPP, RAW |
|
scan_ports |
Port |
139, 445 |
SMB scan-to-folder (Windows only) |
|
scanback |
Port |
137, 161, 54925 |
Brother iPrint&Scan scanning (UDP only) |
|
unifi_ports |
Port |
443, 8080, 8443 |
UniFi AP management |
Rules:
|
VLAN |
Action |
Dir |
TCP/IP |
Protocol |
Source |
Destination |
Ports |
Description |
|
All |
Pass |
in |
IPv4 |
TCP/UDP |
(VLAN) net |
(VLAN) address |
53 |
DNS to Unbound |
|
HOME |
Pass |
in |
IPv4 |
TCP |
HOME net |
Home address |
443 |
OPNsense WebGUI |
|
Admin |
Pass |
in |
IPv4 |
TCP |
Admin net |
Admin address |
443 |
OPNsense WebGUI — emergency access |
|
HOME |
Pass |
in |
IPv4 |
TCP |
HOME net |
VLAN99_MGMT net |
unifi_ports |
UniFi controller management |
|
MGMT |
Pass |
in |
IPv4 |
TCP |
MGMT net |
192.168.99.100 |
unifi_ports |
Controller reach to AP |
|
MGMT |
Pass |
in |
IPv4 |
TCP |
192.168.99.100 |
VLAN10_HOME net |
8080 |
AP inform back to controller |
|
HOME, MOBILE, GUEST, WORK1, WORK2, WORK3 |
Pass |
in |
IPv4 |
TCP |
(VLAN) net |
VLAN50_PRINT net |
print_ports |
Printing |
|
HOME |
Pass |
in |
IPv4 |
UDP |
HOME net |
VLAN50_PRINT net |
scanback |
Mac scanning to printer |
|
|
Pass |
in |
IPv4 |
UDP |
VLAN50_PRINT net |
VLAN10_HOME net |
scanback |
Printer scan response to Mac |
|
|
Pass |
in |
IPv4 |
TCP |
VLAN50_PRINT net |
RFC1918 |
scan_ports |
SMB scan-to-folder — Windows; enable when needed |
|
All |
Block |
in |
IPv4 |
* |
(VLAN) net |
RFC1918 |
* |
Block inter-VLAN lateral movement |
|
IoT, |
Block |
in |
IPv4 |
UDP |
(VLAN) net |
Any |
443 |
Block QUIC |
|
IoT, |
Pass |
in |
IPv4 |
* |
(VLAN) net |
Geo_US |
* |
Internet — U.S. destinations only |
|
IoT, |
Block |
in |
IPv4 |
* |
(VLAN) net |
! Geo_US |
* |
Block non-U.S. destinations (logged) |
|
HOME, MOBILE, GUEST, WORK1, WORK2, WORK3 |
Pass |
in |
IPv4 |
* |
(VLAN) net |
any |
* |
Internet access |
|
MGMT, Admin |
Block |
in |
IPv4 |
* |
(VLAN) net |
any |
* |
Block all remaining traffic |
Notes:
- “In” = traffic entering the interface from that VLAN toward others or WAN
- The DNS pass rule appears at the top of every interface's rule set. The explicit pass is necessary because the VLAN gateway address (where Unbound listens) falls within RFC1918 space and would otherwise be caught by the RFC1918 block rule.
- For IoT and PRINT, the RFC1918 block is evaluated before the GeoIP rules, so the Geo_US pass and non-U.S. block only ever act on public internet traffic.
- Logging is enabled for all “block” and geoIP rules
- The SMB scan-to-folder rule (PRINT, disabled) is disabled by default. Enable temporarily for Windows scan-to-folder, then disable when finished.
- For MGMT and Admin, the final block-all rule ensures no internet access regardless.
- The static AP IP 192.168.99.100 used in the MGMT rules is maintained via a DHCP static reservation on VLAN99_MGMT.
No comments to display
No comments to display