--- Nftables::Service[recursor_udp_dns_rec].orig
+++ Nftables::Service[recursor_udp_dns_rec]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['172.16.0.0/21', '172.16.128.0/24', '172.16.129.0/24', '172.16.130.0/24', '172.16.131.0/24', '172.16.16.0/21', '172.16.24.0/24', '172.16.8.0/21', '172.20.1.0/24', '172.20.1.25', '172.20.2.0/24', '172.20.2.32', '172.20.254.0/24', '172.20.255.0/24', '172.20.3.0/24', '172.20.3.18', '172.20.4.0/24', '172.20.5.0/24', '185.15.56.0/25', '185.15.56.0/25', '185.15.56.160/28', '185.15.57.0/29', '185.15.57.16/29', '185.15.57.24/29', '208.80.153.42', '208.80.154.78', '2620:0:860:2:208:80:153:42', '2620:0:861:3:208:80:154:78', '2a02:ec80:a000:100::/64', '2a02:ec80:a000:1::/64', '2a02:ec80:a000:201::/64', '2a02:ec80:a000:201::25', '2a02:ec80:a000:202::/64', '2a02:ec80:a000:202::32', '2a02:ec80:a000:203::/64', '2a02:ec80:a000:203::18', '2a02:ec80:a000:204::/64', '2a02:ec80:a000:2ff::/64', '2a02:ec80:a000:4000::/64', '2a02:ec80:a100:100::/64', '2a02:ec80:a100:1::/64', '2a02:ec80:a100:205::/64', '2a02:ec80:a100:2ff::/64', '2a02:ec80:a100:4000::/64']
+ port => 53
Nftables::Service[bird-bgp]
- Parameters differences:
--- Nftables::Service[bird-bgp].orig
+++ Nftables::Service[bird-bgp]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['172.20.2.1', '2a02:ec80:a000:202::1']
+ port => 179
- Nftables::Service[ssh-from-cloudcumin-masters]
- Parameters differences:
--- Nftables::Service[ssh-from-cloudcumin-masters].orig
+++ Nftables::Service[ssh-from-cloudcumin-masters]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['10.192.32.140', '10.64.48.148', '2620:0:860:103:10:192:32:140', '2620:0:861:107:10:64:48:148']
+ port => 22
- Nftables::Service[mysql_designate]
- Parameters differences:
--- Nftables::Service[mysql_designate].orig
+++ Nftables::Service[mysql_designate]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['172.20.1.25', '172.20.2.32', '172.20.3.18', '2a02:ec80:a000:201::25', '2a02:ec80:a000:202::32', '2a02:ec80:a000:203::18']
+ port => 3306
- Nftables::Service[recursor_tcp_dns_rec]
- Parameters differences:
--- Nftables::Service[recursor_tcp_dns_rec].orig
+++ Nftables::Service[recursor_tcp_dns_rec]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['172.16.0.0/21', '172.16.128.0/24', '172.16.129.0/24', '172.16.130.0/24', '172.16.131.0/24', '172.16.16.0/21', '172.16.24.0/24', '172.16.8.0/21', '172.20.1.0/24', '172.20.1.25', '172.20.2.0/24', '172.20.2.32', '172.20.254.0/24', '172.20.255.0/24', '172.20.3.0/24', '172.20.3.18', '172.20.4.0/24', '172.20.5.0/24', '185.15.56.0/25', '185.15.56.0/25', '185.15.56.160/28', '185.15.57.0/29', '185.15.57.16/29', '185.15.57.24/29', '208.80.153.42', '208.80.154.78', '2620:0:860:2:208:80:153:42', '2620:0:861:3:208:80:154:78', '2a02:ec80:a000:100::/64', '2a02:ec80:a000:1::/64', '2a02:ec80:a000:201::/64', '2a02:ec80:a000:201::25', '2a02:ec80:a000:202::/64', '2a02:ec80:a000:202::32', '2a02:ec80:a000:203::/64', '2a02:ec80:a000:203::18', '2a02:ec80:a000:204::/64', '2a02:ec80:a000:2ff::/64', '2a02:ec80:a000:4000::/64', '2a02:ec80:a100:100::/64', '2a02:ec80:a100:1::/64', '2a02:ec80:a100:205::/64', '2a02:ec80:a100:2ff::/64', '2a02:ec80:a100:4000::/64']
+ port => 53
- Nftables::Service[bacula-file-daemon-backup1014.eqiad.wmnet]
- Parameters differences:
--- Nftables::Service[bacula-file-daemon-backup1014.eqiad.wmnet].orig
+++ Nftables::Service[bacula-file-daemon-backup1014.eqiad.wmnet]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['10.64.183.10', '2620:0:861:13d:10:64:183:10']
+ port => 9102
- Nftables::Service[bird-bfd-echo]
- Parameters differences:
--- Nftables::Service[bird-bfd-echo].orig
+++ Nftables::Service[bird-bfd-echo]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ src_sets => ['LINK_LOCAL']
+ desc =>
+ notrack => False
+ src_ips => ['172.20.2.1', '2a02:ec80:a000:202::1']
+ port => 3785
- Nftables::Service[bird-bfd-control]
- Parameters differences:
--- Nftables::Service[bird-bfd-control].orig
+++ Nftables::Service[bird-bfd-control]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ src_sets => ['LINK_LOCAL']
+ desc =>
+ notrack => False
+ src_ips => ['172.20.2.1', '2a02:ec80:a000:202::1']
+ port => 3784
- Nftables::Service[full-monitoring-metrics-access-udp]
- Parameters differences:
--- Nftables::Service[full-monitoring-metrics-access-udp].orig
+++ Nftables::Service[full-monitoring-metrics-access-udp]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ port_range => [1, 65535]
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['10.64.0.82', '10.64.16.62', '10.64.32.85', '10.64.48.171', '208.80.153.42', '208.80.154.78', '2620:0:860:2:208:80:153:42', '2620:0:861:101:10:64:0:82', '2620:0:861:102:10:64:16:62', '2620:0:861:103:10:64:32:85', '2620:0:861:107:10:64:48:171', '2620:0:861:3:208:80:154:78']