Skip to main content

10. Appendix

Appendix A - Hardware

Device

Description

Link

Protectli FW6D

OPNsense firewall/router appliance

https://protectli.com/product/fw6d/

UniFi U6+ Access Point

Dual-band WiFi 6 AP (managed by UniFi Controller)

https://techspecs.ui.com/unifi/wifi/u6-plus

Appendix B - Software

Software

Purpose

Link

OPNsense

Firewall, router, DNS resolver, IDS/IPS

https://opnsense.org/

UniFi Network Server (Controller)

WiFi AP management and firmware control

https://ui.com/download/releases/network-server

Appendix C - Firewall Rule Sets

Aliases:

Alias

Type

Content

Description

RFC1918

Network

192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12

All private IP ranges

Geo_US

GeoIP

United States

U.S. IP address ranges

print_ports

Port

515, 631, 9100

Printing — LPD, IPP, RAW

scan_ports

Port

139, 445

SMB scan-to-folder (Windows only)

scanback

Port

137, 161, 54925

Brother iPrint&Scan scanning (UDP only)

unifi_ports

Port

443, 8080, 8443

UniFi AP management

 

Rules:

VLAN

Action

Dir

TCP/IP

Protocol

Source

Destination

Ports

Description

All

Pass

in

IPv4

TCP/UDP

(VLAN) net

(VLAN) address

53

DNS to Unbound

HOME

Pass

in

IPv4

TCP

HOME net

Home address

443

OPNsense WebGUI

Admin

Pass

in

IPv4

TCP

Admin net

Admin address

443

OPNsense WebGUI — emergency access

HOME

Pass

in

IPv4

TCP

HOME net

VLAN99_MGMT net

unifi_ports

UniFi controller management

MGMT

Pass

in

IPv4

TCP

MGMT net

192.168.99.100

unifi_ports

Controller reach to AP

MGMT

Pass

in

IPv4

TCP

192.168.99.100

VLAN10_HOME net

8080

AP inform back to controller

HOME, MOBILE, GUEST, WORK1, WORK2, WORK3

Pass

in

IPv4

TCP

(VLAN) net

VLAN50_PRINT net

print_ports

Printing

HOME

Pass

in

IPv4

UDP

HOME net

VLAN50_PRINT net

scanback

Mac scanning to printer

PRINT

Pass

in

IPv4

UDP

VLAN50_PRINT net

VLAN10_HOME net

scanback

Printer scan response to Mac

PRINT

Pass

in

IPv4

TCP

VLAN50_PRINT net

RFC1918

scan_ports

SMB scan-to-folder — Windows; enable when needed

All

Block

in

IPv4

*

(VLAN) net

RFC1918

*

Block inter-VLAN lateral movement

IoT,

PRINT

Block

in

IPv4

UDP

(VLAN) net

Any

443

Block QUIC

IoT,

PRINT

Pass

in

IPv4

*

(VLAN) net

Geo_US

*

Internet — U.S. destinations only

IoT,

PRINT

Block

in

IPv4

*

(VLAN) net

! Geo_US

*

Block non-U.S. destinations (logged)

HOME, MOBILE, GUEST, WORK1, WORK2, WORK3

Pass

in

IPv4

*

(VLAN) net

any

*

Internet access

MGMT,

Admin

Block

in

IPv4

*

(VLAN) net

any

*

Block all remaining traffic

Notes:

  • “In” = traffic entering the interface from that VLAN toward others or WAN
  • The DNS pass rule appears at the top of every interface's rule set. The explicit pass is necessary because the VLAN gateway address (where Unbound listens) falls within RFC1918 space and would otherwise be caught by the RFC1918 block rule.
  • For IoT and PRINT, the RFC1918 block is evaluated before the GeoIP rules, so the Geo_US pass and non-U.S. block only ever act on public internet traffic.
  • Logging is enabled for all “block” and geoIP rules
  • The SMB scan-to-folder rule (PRINT, disabled) is disabled by default. Enable temporarily for Windows scan-to-folder, then disable when finished.
  • For MGMT and Admin, the final block-all rule ensures no internet access regardless.
  • The static AP IP 192.168.99.100 used in the MGMT rules is maintained via a DHCP static reservation on VLAN99_MGMT.