Commit Graph

71 Commits

Author SHA1 Message Date
packetcat 39c53f1eae remove iperf testing rule for deirdre 2023-03-02 10:05:38 -05:00
packetcat ddc0a433af add rule to allow some iperf testing on deirdre 2023-03-02 09:55:21 -05:00
packetcat 4449336212 rename firewall ruleset files for new hostnames 2022-12-18 10:03:38 -05:00
staticsafe 2955428f01 add 2002:2d8d:56bb::2d8d:56bb to deirdre.asininetech.net.rules.v6 2022-01-13 09:30:24 -05:00
staticsafe 5f0de6725c add tailscale ipv6 addresses to allow list 2021-11-21 12:38:51 -05:00
staticsafe 834890958b add tailscale subnet to allow list 2021-11-20 23:07:47 -05:00
staticsafe 3ffa834b4a fix typo in demonreach.asininetech.net.rules.v4 2021-09-04 13:50:34 -04:00
staticsafe c8a274c39a fix more incorrect syntax in demonreach.asininetech.net.rules.v6 2021-09-04 13:49:25 -04:00
staticsafe 1a658b71a0 fix NAT rules in demonreach.asininetech.net.rules.v6 2021-09-04 13:48:06 -04:00
staticsafe cac6aab56a add some wireguard specific rules to demonreach 2021-09-04 13:45:10 -04:00
staticsafe 9852a4ea21 remove tinc ports in deirdre 2021-04-05 09:18:44 -04:00
staticsafe 4085481ed0 remove elasticsearch ports from deirdre firewall rules 2021-04-05 09:18:06 -04:00
staticsafe 9aec73785d add rules to allow outbound NTP to deirdre 2021-04-05 08:29:25 -04:00
staticsafe 0b3265d75c add a new IP into deirdre and erlking ipsets
remove waldo ipsets and rules
2021-03-17 09:56:10 -04:00
staticsafe 71fc82ed22 remove namshiel.asininetech.net.rules.* 2020-07-05 14:33:29 -04:00
staticsafe f5f09ebc58 add 2001:19f0:6001:5aa0:5400:2ff:fecf:eee5 to drop for deirdre 2020-07-05 14:31:44 -04:00
staticsafe 27b9e93b0d reference nasties ipset for erlking and waldo 2020-04-15 10:54:52 -04:00
staticsafe 8aa1d869ba clean up unnecessary comments in firewall rulesets 2020-04-14 22:41:05 -04:00
staticsafe a7888e95bf set FLUSH_ON_STOP to 0 2020-04-14 22:36:13 -04:00
staticsafe 358b88ea60 we use a default file for netfilter-persistent 2020-04-14 22:29:56 -04:00
staticsafe 53d62d54f5 let's try this again with destroy 2020-04-14 22:15:06 -04:00
staticsafe 377a5bcebf temporarily comment out firewall rule 2020-04-14 22:12:03 -04:00
staticsafe 92f286bbd6 should be src for ipset based rule 2020-04-14 22:03:31 -04:00
staticsafe c267ec243f use ipset instead of a bunch of INPUTs 2020-04-14 22:02:50 -04:00
staticsafe 835384a24d add rulesets for uriel.asininetech.net. 2020-04-04 19:19:53 -04:00
staticsafe 66eebc37d3 add moz.com crawler to firewall block list on web servers 2020-03-28 23:10:00 -04:00
staticsafe 1de56b96b9 remove grevane.asininetech.net.rules.*, not needed anymore 2020-03-23 11:26:08 -04:00
staticsafe 7fb64da246 no need for 127/8 rules in demonreach.asininetech.net.rules.v4 2020-03-08 22:56:18 -04:00
staticsafe 10c45c850b DNS resolving issues in demonreach.asininetech.net.rules.v4? 2020-03-08 15:58:13 -04:00
staticsafe f9e74ee5aa allow TCP DNS as well for VPN subnet 2020-03-04 17:50:43 -05:00
staticsafe 13f9b1575c add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6 2020-03-04 17:16:48 -05:00
staticsafe a0d1c0598d remove port 1723 from demonreach.asininetech.net.rules.v4 2020-03-04 13:49:55 -05:00
staticsafe 12e58f3c01 add port 1723 to demonreach.asininetech.net.rules.v4 2020-03-04 13:45:18 -05:00
staticsafe 907b86492b add a DROP rule in deirdre.asininetech.net.rules.v4 2020-02-25 23:31:22 -05:00
staticsafe e866d062a9 add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4 2020-02-20 14:46:21 -05:00
staticsafe db59ab205e add rule to drop SearchAtlas crawler 2020-02-20 14:26:02 -05:00
staticsafe c6997dcd39 add drop for Seekport crawler IP to deirdre and waldo 2020-02-14 19:29:13 -05:00
staticsafe 2af73d2d4e allow ES traffic over Tinc VPN 2020-01-19 10:35:58 -05:00
staticsafe bc92c9d437 Port opening for Tinc 2020-01-18 20:49:05 -05:00
staticsafe 869d80e6f7 we need to secure port 9300 on namshiel as well 2020-01-18 18:00:08 -05:00
staticsafe e306a60ea6 add namshiel related files 2020-01-18 17:29:03 -05:00
staticsafe a0e26301cf deirdre should be able to talk outbound 9200 for ES 2020-01-18 17:17:51 -05:00
staticsafe 9e1e20d33f Remove port 4949 from allowed ports
deirdre no longer using munin-node
2020-01-06 10:17:29 -05:00
staticsafe da2f7aef93 Remove catsith.asininetech.net.rules.v4 and catsith.asininetech.net.rules.v6
catsith is gone
2020-01-06 10:16:20 -05:00
staticsafe 3b73edf491 add firewall rule to drop aggressive crawler in catsith.asininetech.net.rules.v6 2019-12-23 18:40:54 -05:00
staticsafe 85d19dd3a0 add ipset package install to ubuntu/roles/firewall-ruleset-deploy/tasks/main.yml 2019-11-17 16:22:27 -05:00
staticsafe ab33cd0200 Add yet another Bytespider range to block list to firewall rules. 2019-10-17 12:20:28 -04:00
staticsafe 7c7ff101e5 Missed a Bytespider crawler range 2019-10-17 12:03:15 -04:00
staticsafe f5d7c6dc39 Block aggressive Bytespider crawler across web servers 2019-10-17 11:58:42 -04:00
staticsafe afa8aa556c Add firewall rules to drop kiwifarms subnets. 2019-10-11 00:00:45 -04:00