--- Nftables::Service[authdns_update_ssh_rule].orig
+++ Nftables::Service[authdns_update_ssh_rule]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['103.102.166.10', '103.102.166.8', '185.15.58.37', '185.15.58.5', '185.15.59.2', '185.15.59.34', '195.200.68.37', '195.200.68.4', '198.35.26.34', '198.35.26.7', '208.80.153.107', '208.80.153.48', '208.80.153.74', '208.80.154.153', '208.80.154.6', '208.80.154.77']
+ port => 22
Nftables::Service[ssh-from-bastion]
- Parameters differences:
--- Nftables::Service[ssh-from-bastion].orig
+++ Nftables::Service[ssh-from-bastion]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['103.102.166.103', '185.15.58.6', '185.15.59.99', '195.200.68.99', '198.35.26.104', '2001:df2:e500:3:103:102:166:103', '208.80.153.110', '208.80.154.7', '2620:0:860:4:208:80:153:110', '2620:0:861:1:208:80:154:7', '2620:0:863:3:198:35:26:104', '2a02:ec80:300:3:185:15:59:99', '2a02:ec80:600:1:185:15:58:6', '2a02:ec80:700:3:195:200:68:99']
+ port => 22
- Nftables::Service[ssh-from-cumin-masters]
- Parameters differences:
--- Nftables::Service[ssh-from-cumin-masters].orig
+++ Nftables::Service[ssh-from-cumin-masters]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ src_sets => ['CUMIN_MASTERS']
+ desc =>
+ notrack => False
+ port => 22
- Nftables::Service[bird-bfd-multi-ctl]
- Parameters differences:
--- Nftables::Service[bird-bfd-multi-ctl].orig
+++ Nftables::Service[bird-bfd-multi-ctl]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['208.80.153.192', '208.80.153.193', '2620:0:860:ffff::1', '2620:0:860:ffff::2']
+ port => 4784
- Nftables::Service[full-monitoring-metrics-access-tcp]
- Parameters differences:
--- Nftables::Service[full-monitoring-metrics-access-tcp].orig
+++ Nftables::Service[full-monitoring-metrics-access-tcp]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ port_range => [1, 65535]
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['10.192.16.75', '10.192.32.67', '10.192.39.10', '10.192.9.11', '208.80.153.42', '208.80.154.78', '2620:0:860:102:10:192:16:75', '2620:0:860:103:10:192:32:67', '2620:0:860:10a:10:192:9:11', '2620:0:860:11e:10:192:39:10', '2620:0:860:2:208:80:153:42', '2620:0:861:3:208:80:154:78']
- Nftables::Service[bird-bgp]
- Parameters differences:
--- Nftables::Service[bird-bgp].orig
+++ Nftables::Service[bird-bgp]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['208.80.153.192', '208.80.153.193', '2620:0:860:ffff::1', '2620:0:860:ffff::2']
+ port => 179
- Nftables::Service[udp_dns_auth_monitor]
- Parameters differences:
--- Nftables::Service[udp_dns_auth_monitor].orig
+++ Nftables::Service[udp_dns_auth_monitor]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ desc =>
+ notrack => True
+ src_ips => ['10.0.0.0/8', '103.102.166.0/24', '127.0.0.0/8', '185.15.58.0/24', '185.15.59.0/24', '185.71.138.0/24', '195.200.68.0/24', '198.35.26.0/23', '2001:67c:930::/48', '2001:df2:e500::/48', '208.80.152.0/22', '2620:0:860::/46', '2a02:ec80::/32', '::1/128']
+ port => 5353
- Nftables::Service[tcp_dns_auth_monitor]
- Parameters differences:
--- Nftables::Service[tcp_dns_auth_monitor].orig
+++ Nftables::Service[tcp_dns_auth_monitor]
+ prio => 10
+ unrestricted_access => False
+ proto => tcp
+ ensure => present
+ desc =>
+ notrack => True
+ src_ips => ['10.0.0.0/8', '103.102.166.0/24', '127.0.0.0/8', '185.15.58.0/24', '185.15.59.0/24', '185.71.138.0/24', '195.200.68.0/24', '198.35.26.0/23', '2001:67c:930::/48', '2001:df2:e500::/48', '208.80.152.0/22', '2620:0:860::/46', '2a02:ec80::/32', '::1/128']
+ port => 5353
- Nftables::Service[bird-bfd-echo]
- Parameters differences:
--- Nftables::Service[bird-bfd-echo].orig
+++ Nftables::Service[bird-bfd-echo]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ src_sets => ['LINK_LOCAL']
+ desc =>
+ notrack => False
+ src_ips => ['208.80.153.192', '208.80.153.193', '2620:0:860:ffff::1', '2620:0:860:ffff::2']
+ port => 3785
- Nftables::Service[bird-bfd-control]
- Parameters differences:
--- Nftables::Service[bird-bfd-control].orig
+++ Nftables::Service[bird-bfd-control]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ ensure => present
+ src_sets => ['LINK_LOCAL']
+ desc =>
+ notrack => False
+ src_ips => ['208.80.153.192', '208.80.153.193', '2620:0:860:ffff::1', '2620:0:860:ffff::2']
+ port => 3784
- Nftables::Service[full-monitoring-metrics-access-udp]
- Parameters differences:
--- Nftables::Service[full-monitoring-metrics-access-udp].orig
+++ Nftables::Service[full-monitoring-metrics-access-udp]
+ prio => 10
+ unrestricted_access => False
+ proto => udp
+ port_range => [1, 65535]
+ ensure => present
+ desc =>
+ notrack => False
+ src_ips => ['10.192.16.75', '10.192.32.67', '10.192.39.10', '10.192.9.11', '208.80.153.42', '208.80.154.78', '2620:0:860:102:10:192:16:75', '2620:0:860:103:10:192:32:67', '2620:0:860:10a:10:192:9:11', '2620:0:860:11e:10:192:39:10', '2620:0:860:2:208:80:153:42', '2620:0:861:3:208:80:154:78']