Files
ansible-mln/monitoring/security/FIREWALL_RULES.md
T
2026-08-08 12:04:57 +02:00

166 lines
4.5 KiB
Markdown

# Firewall Configuration Rules
Updated: 2026-06-10
## Overview
Firewall rules for monitoring stack with Wazuh, Dozzle, Beszel, and VPN infrastructure.
---
## monitoring-uber (185.103.167.138)
### Inbound Rules (INPUT)
| Port | Protocol | Source | Purpose | Status |
|------|----------|--------|---------|--------|
| 22 | TCP | Admin IPs | SSH administration | ALLOW |
| 22 | TCP | 185.103.166.119 (prod) | SSH — BLOCKED | **DROP** |
| 22 | TCP | 185.103.166.112 (pre-prod) | SSH — BLOCKED | **DROP** |
| 22 | TCP | 80.96.58.164 (s3) | SSH — BLOCKED | **DROP** |
| 1514 | TCP | 185.103.166.119 | Wazuh agents (prod) | ALLOW |
| 1514 | TCP | 185.103.166.112 | Wazuh agents (pre-prod) | ALLOW |
| 51820 | UDP | Any | WireGuard VPN | ALLOW |
| 443 | TCP | 10.0.0.0/24 | Wazuh Dashboard (VPN) | ALLOW |
| 8080 | TCP | 10.0.0.0/24 | Dozzle logs (VPN) | ALLOW |
| 8090 | TCP | 10.0.0.0/24 | Beszel monitoring (VPN) | ALLOW |
| 9000-9001 | TCP | 10.0.0.0/24 | S3/RustFS (VPN) | ALLOW |
### Outbound Rules (OUTPUT)
- **Default:** ACCEPT (all traffic allowed)
- Allows DNS, updates, internet access
### Forward Rules (FORWARD)
- **Default:** DROP (no transit traffic)
### Persistence
- Rules saved to `/etc/iptables/rules.v4`
- Auto-loaded on boot via `iptables-persistent`
---
## vpn-uber (45.150.111.158)
### Inbound Rules (INPUT)
| Port | Protocol | Source | Purpose | Status |
|------|----------|--------|---------|--------|
| 22 | TCP | Any | SSH administration | ALLOW |
| 51820 | UDP | Any | WireGuard VPN | ALLOW |
| 10001 | TCP | 10.0.0.0/24 | Beszel agent (from VPN only) | ALLOW |
### Outbound Rules (OUTPUT)
- **Default:** ACCEPT (all traffic allowed)
### Forward Rules (FORWARD)
- **Default:** ACCEPT
- Enables routing: wg0 ↔ eth0 (VPN ↔ Internet)
- ESTABLISHED/RELATED always allowed
### Network Features
- NAT masquerade: `eth0` (POSTROUTING)
- IP forwarding: enabled (`net.ipv4.ip_forward=1`)
- Allows VPN clients to reach internet through VPN server
### Persistence
- Rules saved to `/etc/iptables/rules.v4`
- IP forwarding saved to `/etc/sysctl.conf`
---
## Security Hardening
### Principle: Least Privilege
1. **SSH restrictions**: Production servers (prod, pre-prod, s3) **cannot** SSH into monitoring-uber
- Prevents lateral movement if a prod server is compromised
- Admins must SSH directly to monitoring-uber or via VPN
2. **Service isolation**: All user-facing services (Wazuh, Dozzle, Beszel) accessible **only via VPN**
- Not exposed to public internet
- Network: 10.0.0.0/24 (private VPN)
3. **Port whitelist**: Only required ports open
- Wazuh agent ingest: 1514/tcp (prod/pre-prod only)
- VPN: 51820/udp (all)
- SSH: 22/tcp (admin access, blocked from prod servers)
- Monitoring agents: 10001/tcp (VPN only)
### Attack Surface Reduction
- Production agents cannot access monitoring infrastructure
- Monitoring dashboard only accessible via VPN
- No exposed dashboards or logs to public internet
- SSH brute-force: limited by rate (ESTABLISHED/RELATED state tracking)
---
## Updating Rules
### monitoring-uber
```bash
ssh root@185.103.167.138
./firewall-monitoring-uber.sh
```
### vpn-uber
```bash
ssh root@45.150.111.158
./firewall-vpn-server.sh
```
### Verify Rules Applied
```bash
# Check current rules
iptables -L INPUT -n
iptables -L FORWARD -n
# Check saved rules
cat /etc/iptables/rules.v4
```
### Restore Rules on Boot
Rules are automatically restored via `/etc/iptables/rules.v4` if `iptables-persistent` is installed:
```bash
apt-get install iptables-persistent
```
---
## Beszel Agent Configuration
Beszel agents installed on all infrastructure servers:
| Server | Type | Port | Access |
|--------|------|------|--------|
| prod-uber | Docker | 10001 | Public IP (185.103.166.119:10001) |
| pre-prod-uber | Docker | 10001 | Public IP (185.103.166.112:10001) |
| s3-uber | Docker | 10001 | Public IP (80.96.58.164:10001) |
| vpn-uber | Binarie (systemd) | 10001 | VPN IP (10.0.0.1:10001) |
**Note:** vpn-uber agent is accessible **only from VPN** due to firewall rules.
---
## Troubleshooting
### Service not reachable
```bash
# Check if service is listening
ss -tlnp | grep <port>
# Check firewall allows traffic
iptables -L INPUT -n | grep <port>
# Test connectivity
nc -zv <ip> <port>
```
### SSH access denied from prod
- Expected behavior (security hardening)
- Use admin SSH keys or SSH via VPN instead
### Beszel agent shows offline
- Check agent is listening: `ss -tlnp | grep 10001`
- Check firewall allows Beszel dashboard to reach agent
- Verify network routing between monitoring-uber and agent server