--- Nftables::Service[opensearch-inter-node-9500].orig
+++ Nftables::Service[opensearch-inter-node-9500]
+ notrack => True
+ port => 9500
+ desc =>
+ src_ips => ['10.192.11.18', '10.192.11.19', '10.192.11.20', '10.192.11.22', '10.192.11.23', '10.192.11.24', '10.192.11.25', '10.192.13.16', '10.192.13.18', '10.192.13.19', '10.192.13.20', '10.192.14.12', '10.192.21.30', '10.192.21.31', '10.192.23.16', '10.192.23.22', '10.192.23.23', '10.192.23.24', '10.192.23.25', '10.192.26.17', '10.192.26.18', '10.192.28.14', '10.192.28.15', '10.192.28.16', '10.192.28.17', '10.192.28.18', '10.192.28.19', '10.192.29.8', '10.192.31.18', '10.192.31.19', '10.192.31.20', '10.192.31.21', '10.192.36.9', '10.192.37.13', '10.192.37.14', '10.192.38.8', '10.192.39.20', '10.192.39.21', '10.192.39.22', '10.192.39.23', '10.192.39.24', '10.192.4.6', '10.192.42.13', '10.192.42.15', '10.192.42.16', '10.192.42.17', '10.192.42.18', '10.192.6.17', '10.192.6.18', '10.192.6.19', '10.192.9.18', '10.192.9.19', '10.192.9.20', '10.192.9.21', '10.192.9.22', '2620:0:860:100:10:192:4:6', '2620:0:860:105:10:192:26:17', '2620:0:860:105:10:192:26:18', '2620:0:860:107:10:192:6:17', '2620:0:860:107:10:192:6:18', '2620:0:860:107:10:192:6:19', '2620:0:860:10a:10:192:9:18', '2620:0:860:10a:10:192:9:19', '2620:0:860:10a:10:192:9:20', '2620:0:860:10a:10:192:9:21', '2620:0:860:10a:10:192:9:22', '2620:0:860:10c:10:192:11:18', '2620:0:860:10c:10:192:11:19', '2620:0:860:10c:10:192:11:20', '2620:0:860:10c:10:192:11:22', '2620:0:860:10c:10:192:11:23', '2620:0:860:10c:10:192:11:24', '2620:0:860:10c:10:192:11:25', '2620:0:860:10e:10:192:13:16', '2620:0:860:10e:10:192:13:18', '2620:0:860:10e:10:192:13:19', '2620:0:860:10e:10:192:13:20', '2620:0:860:10f:10:192:14:12', '2620:0:860:111:10:192:21:30', '2620:0:860:111:10:192:21:31', '2620:0:860:113:10:192:23:16', '2620:0:860:113:10:192:23:22', '2620:0:860:113:10:192:23:23', '2620:0:860:113:10:192:23:24', '2620:0:860:113:10:192:23:25', '2620:0:860:115:10:192:28:14', '2620:0:860:115:10:192:28:15', '2620:0:860:115:10:192:28:16', '2620:0:860:115:10:192:28:17', '2620:0:860:115:10:192:28:18', '2620:0:860:115:10:192:28:19', '2620:0:860:116:10:192:29:8', '2620:0:860:11a:10:192:31:18', '2620:0:860:11a:10:192:31:19', '2620:0:860:11a:10:192:31:20', '2620:0:860:11a:10:192:31:21', '2620:0:860:11b:10:192:36:9', '2620:0:860:11c:10:192:37:13', '2620:0:860:11c:10:192:37:14', '2620:0:860:11d:10:192:38:8', '2620:0:860:11e:10:192:39:20', '2620:0:860:11e:10:192:39:21', '2620:0:860:11e:10:192:39:22', '2620:0:860:11e:10:192:39:23', '2620:0:860:11e:10:192:39:24', '2620:0:860:121:10:192:42:13', '2620:0:860:121:10:192:42:15', '2620:0:860:121:10:192:42:16', '2620:0:860:121:10:192:42:17', '2620:0:860:121:10:192:42:18']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
Nftables::Service[ssh-from-bastion]
- Parameters differences:
--- Nftables::Service[ssh-from-bastion].orig
+++ Nftables::Service[ssh-from-bastion]
+ notrack => False
+ port => 22
+ desc =>
+ src_ips => ['103.102.166.103', '185.15.58.6', '185.15.59.99', '195.200.68.99', '198.35.26.104', '2001:df2:e500:3:103:102:166:103', '208.80.153.110', '208.80.154.7', '2620:0:860:4:208:80:153:110', '2620:0:861:1:208:80:154:7', '2620:0:863:3:198:35:26:104', '2a02:ec80:300:3:185:15:59:99', '2a02:ec80:600:1:185:15:58:6', '2a02:ec80:700:3:195:200:68:99']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
- Nftables::Service[ssh-from-cumin-masters]
- Parameters differences:
--- Nftables::Service[ssh-from-cumin-masters].orig
+++ Nftables::Service[ssh-from-cumin-masters]
+ notrack => False
+ port => 22
+ desc =>
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present
+ src_sets => ['CUMIN_MASTERS']
- Nftables::Service[full-monitoring-metrics-access-udp]
- Parameters differences:
--- Nftables::Service[full-monitoring-metrics-access-udp].orig
+++ Nftables::Service[full-monitoring-metrics-access-udp]
+ notrack => False
+ desc =>
+ src_ips => ['10.192.16.75', '10.192.32.67', '10.192.39.10', '10.192.9.11', '208.80.153.42', '208.80.154.78', '2620:0:860:102:10:192:16:75', '2620:0:860:103:10:192:32:67', '2620:0:860:10a:10:192:9:11', '2620:0:860:11e:10:192:39:10', '2620:0:860:2:208:80:153:42', '2620:0:861:3:208:80:154:78']
+ proto => udp
+ unrestricted_access => False
+ prio => 10
+ port_range => [1, 65535]
+ ensure => present
- Nftables::Service[opensearch-inter-node-9300]
- Parameters differences:
--- Nftables::Service[opensearch-inter-node-9300].orig
+++ Nftables::Service[opensearch-inter-node-9300]
+ notrack => True
+ port => 9300
+ desc =>
+ src_ips => ['10.192.11.18', '10.192.11.19', '10.192.11.20', '10.192.11.22', '10.192.11.23', '10.192.11.24', '10.192.11.25', '10.192.13.16', '10.192.13.18', '10.192.13.19', '10.192.13.20', '10.192.14.12', '10.192.21.30', '10.192.21.31', '10.192.23.16', '10.192.23.22', '10.192.23.23', '10.192.23.24', '10.192.23.25', '10.192.26.17', '10.192.26.18', '10.192.28.14', '10.192.28.15', '10.192.28.16', '10.192.28.17', '10.192.28.18', '10.192.28.19', '10.192.29.8', '10.192.31.18', '10.192.31.19', '10.192.31.20', '10.192.31.21', '10.192.36.9', '10.192.37.13', '10.192.37.14', '10.192.38.8', '10.192.39.20', '10.192.39.21', '10.192.39.22', '10.192.39.23', '10.192.39.24', '10.192.4.6', '10.192.42.13', '10.192.42.15', '10.192.42.16', '10.192.42.17', '10.192.42.18', '10.192.6.17', '10.192.6.18', '10.192.6.19', '10.192.9.18', '10.192.9.19', '10.192.9.20', '10.192.9.21', '10.192.9.22', '2620:0:860:100:10:192:4:6', '2620:0:860:105:10:192:26:17', '2620:0:860:105:10:192:26:18', '2620:0:860:107:10:192:6:17', '2620:0:860:107:10:192:6:18', '2620:0:860:107:10:192:6:19', '2620:0:860:10a:10:192:9:18', '2620:0:860:10a:10:192:9:19', '2620:0:860:10a:10:192:9:20', '2620:0:860:10a:10:192:9:21', '2620:0:860:10a:10:192:9:22', '2620:0:860:10c:10:192:11:18', '2620:0:860:10c:10:192:11:19', '2620:0:860:10c:10:192:11:20', '2620:0:860:10c:10:192:11:22', '2620:0:860:10c:10:192:11:23', '2620:0:860:10c:10:192:11:24', '2620:0:860:10c:10:192:11:25', '2620:0:860:10e:10:192:13:16', '2620:0:860:10e:10:192:13:18', '2620:0:860:10e:10:192:13:19', '2620:0:860:10e:10:192:13:20', '2620:0:860:10f:10:192:14:12', '2620:0:860:111:10:192:21:30', '2620:0:860:111:10:192:21:31', '2620:0:860:113:10:192:23:16', '2620:0:860:113:10:192:23:22', '2620:0:860:113:10:192:23:23', '2620:0:860:113:10:192:23:24', '2620:0:860:113:10:192:23:25', '2620:0:860:115:10:192:28:14', '2620:0:860:115:10:192:28:15', '2620:0:860:115:10:192:28:16', '2620:0:860:115:10:192:28:17', '2620:0:860:115:10:192:28:18', '2620:0:860:115:10:192:28:19', '2620:0:860:116:10:192:29:8', '2620:0:860:11a:10:192:31:18', '2620:0:860:11a:10:192:31:19', '2620:0:860:11a:10:192:31:20', '2620:0:860:11a:10:192:31:21', '2620:0:860:11b:10:192:36:9', '2620:0:860:11c:10:192:37:13', '2620:0:860:11c:10:192:37:14', '2620:0:860:11d:10:192:38:8', '2620:0:860:11e:10:192:39:20', '2620:0:860:11e:10:192:39:21', '2620:0:860:11e:10:192:39:22', '2620:0:860:11e:10:192:39:23', '2620:0:860:11e:10:192:39:24', '2620:0:860:121:10:192:42:13', '2620:0:860:121:10:192:42:15', '2620:0:860:121:10:192:42:16', '2620:0:860:121:10:192:42:17', '2620:0:860:121:10:192:42:18']
+ proto => tcp
+ unrestricted_access => False
+ prio => 10
+ ensure => present