mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
Firewall Fun
This commit is contained in:
@@ -1,113 +0,0 @@
|
|||||||
firewall:
|
|
||||||
grid:
|
|
||||||
hosts:
|
|
||||||
analyst_workstations: []
|
|
||||||
analyst: []
|
|
||||||
standalone: []
|
|
||||||
eval: []
|
|
||||||
idh: []
|
|
||||||
manager: []
|
|
||||||
heavynodes: []
|
|
||||||
searchnodes: []
|
|
||||||
receivers: []
|
|
||||||
|
|
||||||
portgroups:
|
|
||||||
standalone:
|
|
||||||
- playbook
|
|
||||||
- mysql
|
|
||||||
- kibana
|
|
||||||
- redis
|
|
||||||
- influxdb
|
|
||||||
- elasticsearch_rest
|
|
||||||
- elasticsearch_node
|
|
||||||
- docker_registry
|
|
||||||
- yum
|
|
||||||
- sensoroni
|
|
||||||
- beats_5044
|
|
||||||
- beats_5644
|
|
||||||
- elastic_agent_control
|
|
||||||
- elastic_agent_data
|
|
||||||
- elasticsearch_rest
|
|
||||||
- endgame
|
|
||||||
- strelka_frontend
|
|
||||||
- syslog
|
|
||||||
- nginx
|
|
||||||
analyst_workstation: []
|
|
||||||
ports:
|
|
||||||
all:
|
|
||||||
tcp:
|
|
||||||
- '0:65535'
|
|
||||||
udp:
|
|
||||||
- '0:65535'
|
|
||||||
agrules:
|
|
||||||
tcp:
|
|
||||||
- 7788
|
|
||||||
beats_5044:
|
|
||||||
tcp:
|
|
||||||
- 5044
|
|
||||||
beats_5644:
|
|
||||||
tcp:
|
|
||||||
- 5644
|
|
||||||
beats_5066:
|
|
||||||
tcp:
|
|
||||||
- 5066
|
|
||||||
docker_registry:
|
|
||||||
tcp:
|
|
||||||
- 5000
|
|
||||||
elasticsearch_node:
|
|
||||||
tcp:
|
|
||||||
- 9300
|
|
||||||
elasticsearch_rest:
|
|
||||||
tcp:
|
|
||||||
- 9200
|
|
||||||
elastic_agent_control:
|
|
||||||
tcp:
|
|
||||||
- 8220
|
|
||||||
elastic_agent_data:
|
|
||||||
tcp:
|
|
||||||
- 5055
|
|
||||||
endgame:
|
|
||||||
tcp:
|
|
||||||
- 3765
|
|
||||||
influxdb:
|
|
||||||
tcp:
|
|
||||||
- 8086
|
|
||||||
kibana:
|
|
||||||
tcp:
|
|
||||||
- 5601
|
|
||||||
mysql:
|
|
||||||
tcp:
|
|
||||||
- 3306
|
|
||||||
nginx:
|
|
||||||
tcp:
|
|
||||||
- 80
|
|
||||||
- 443
|
|
||||||
playbook:
|
|
||||||
tcp:
|
|
||||||
- 3200
|
|
||||||
redis:
|
|
||||||
tcp:
|
|
||||||
- 6379
|
|
||||||
- 9696
|
|
||||||
salt_manager:
|
|
||||||
tcp:
|
|
||||||
- 4505
|
|
||||||
- 4506
|
|
||||||
sensoroni:
|
|
||||||
tcp:
|
|
||||||
- 443
|
|
||||||
ssh:
|
|
||||||
tcp:
|
|
||||||
- 22
|
|
||||||
strelka_frontend:
|
|
||||||
tcp:
|
|
||||||
- 57314
|
|
||||||
syslog:
|
|
||||||
tcp:
|
|
||||||
- 514
|
|
||||||
udp:
|
|
||||||
- 514
|
|
||||||
yum:
|
|
||||||
tcp:
|
|
||||||
- 443
|
|
||||||
|
|
||||||
0
salt/firewall/hostgroups/analyst
Normal file
0
salt/firewall/hostgroups/analyst
Normal file
0
salt/firewall/hostgroups/analyst_workstations
Normal file
0
salt/firewall/hostgroups/analyst_workstations
Normal file
0
salt/firewall/hostgroups/eval
Normal file
0
salt/firewall/hostgroups/eval
Normal file
0
salt/firewall/hostgroups/heavynodes
Normal file
0
salt/firewall/hostgroups/heavynodes
Normal file
0
salt/firewall/hostgroups/idh
Normal file
0
salt/firewall/hostgroups/idh
Normal file
0
salt/firewall/hostgroups/manager
Normal file
0
salt/firewall/hostgroups/manager
Normal file
0
salt/firewall/hostgroups/receivers
Normal file
0
salt/firewall/hostgroups/receivers
Normal file
0
salt/firewall/hostgroups/searchnodes
Normal file
0
salt/firewall/hostgroups/searchnodes
Normal file
0
salt/firewall/hostgroups/standalone
Normal file
0
salt/firewall/hostgroups/standalone
Normal file
0
salt/firewall/portgroups/analyst
Normal file
0
salt/firewall/portgroups/analyst
Normal file
0
salt/firewall/portgroups/analyst_workstations
Normal file
0
salt/firewall/portgroups/analyst_workstations
Normal file
0
salt/firewall/portgroups/eval
Normal file
0
salt/firewall/portgroups/eval
Normal file
0
salt/firewall/portgroups/heavynodes
Normal file
0
salt/firewall/portgroups/heavynodes
Normal file
0
salt/firewall/portgroups/idh
Normal file
0
salt/firewall/portgroups/idh
Normal file
0
salt/firewall/portgroups/manager
Normal file
0
salt/firewall/portgroups/manager
Normal file
0
salt/firewall/portgroups/receivers
Normal file
0
salt/firewall/portgroups/receivers
Normal file
0
salt/firewall/portgroups/searchnodes
Normal file
0
salt/firewall/portgroups/searchnodes
Normal file
19
salt/firewall/portgroups/standalone
Normal file
19
salt/firewall/portgroups/standalone
Normal file
@@ -0,0 +1,19 @@
|
|||||||
|
playbook
|
||||||
|
mysql
|
||||||
|
kibana
|
||||||
|
redis
|
||||||
|
influxdb
|
||||||
|
elasticsearch_rest
|
||||||
|
elasticsearch_node
|
||||||
|
docker_registry
|
||||||
|
yum
|
||||||
|
sensoroni
|
||||||
|
beats_5044
|
||||||
|
beats_5644
|
||||||
|
elastic_agent_control
|
||||||
|
elastic_agent_data
|
||||||
|
elasticsearch_rest
|
||||||
|
endgame
|
||||||
|
strelka_frontend
|
||||||
|
syslog
|
||||||
|
nginx
|
||||||
78
salt/firewall/ports/ports.yaml
Normal file
78
salt/firewall/ports/ports.yaml
Normal file
@@ -0,0 +1,78 @@
|
|||||||
|
firewall:
|
||||||
|
ports:
|
||||||
|
all:
|
||||||
|
tcp:
|
||||||
|
- '0:65535'
|
||||||
|
udp:
|
||||||
|
- '0:65535'
|
||||||
|
agrules:
|
||||||
|
tcp:
|
||||||
|
- 7788
|
||||||
|
beats_5044:
|
||||||
|
tcp:
|
||||||
|
- 5044
|
||||||
|
beats_5644:
|
||||||
|
tcp:
|
||||||
|
- 5644
|
||||||
|
beats_5066:
|
||||||
|
tcp:
|
||||||
|
- 5066
|
||||||
|
docker_registry:
|
||||||
|
tcp:
|
||||||
|
- 5000
|
||||||
|
elasticsearch_node:
|
||||||
|
tcp:
|
||||||
|
- 9300
|
||||||
|
elasticsearch_rest:
|
||||||
|
tcp:
|
||||||
|
- 9200
|
||||||
|
elastic_agent_control:
|
||||||
|
tcp:
|
||||||
|
- 8220
|
||||||
|
elastic_agent_data:
|
||||||
|
tcp:
|
||||||
|
- 5055
|
||||||
|
endgame:
|
||||||
|
tcp:
|
||||||
|
- 3765
|
||||||
|
influxdb:
|
||||||
|
tcp:
|
||||||
|
- 8086
|
||||||
|
kibana:
|
||||||
|
tcp:
|
||||||
|
- 5601
|
||||||
|
mysql:
|
||||||
|
tcp:
|
||||||
|
- 3306
|
||||||
|
nginx:
|
||||||
|
tcp:
|
||||||
|
- 80
|
||||||
|
- 443
|
||||||
|
playbook:
|
||||||
|
tcp:
|
||||||
|
- 3200
|
||||||
|
redis:
|
||||||
|
tcp:
|
||||||
|
- 6379
|
||||||
|
- 9696
|
||||||
|
salt_manager:
|
||||||
|
tcp:
|
||||||
|
- 4505
|
||||||
|
- 4506
|
||||||
|
sensoroni:
|
||||||
|
tcp:
|
||||||
|
- 443
|
||||||
|
ssh:
|
||||||
|
tcp:
|
||||||
|
- 22
|
||||||
|
strelka_frontend:
|
||||||
|
tcp:
|
||||||
|
- 57314
|
||||||
|
syslog:
|
||||||
|
tcp:
|
||||||
|
- 514
|
||||||
|
udp:
|
||||||
|
- 514
|
||||||
|
yum:
|
||||||
|
tcp:
|
||||||
|
- 443
|
||||||
@@ -1,42 +1,86 @@
|
|||||||
firewall:
|
firewall:
|
||||||
grid:
|
hostgroups:
|
||||||
hosts:
|
analyst_workstations:
|
||||||
analyst_workstations:
|
description: List of IP Addresses or CIDR blocks to allow analyst workstations.
|
||||||
description: List of IP Addresses or CIDR blocks to allow analyst workstations.
|
file: True
|
||||||
global: True
|
title: Analyst Workstations
|
||||||
title: Analyst Workstations
|
analyst:
|
||||||
analyst:
|
description: List of IP Addresses or CIDR blocks to allow analyst connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow analyst connections.
|
file: True
|
||||||
global: True
|
title: Analysts
|
||||||
title: Analysts
|
standalone:
|
||||||
standalone:
|
description: List of IP Addresses or CIDR blocks to allow standalone connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow standalone connections.
|
file: True
|
||||||
global: True
|
title: Standalone
|
||||||
title: Standalone
|
advanced: True
|
||||||
advanced: True
|
eval:
|
||||||
eval:
|
description: List of IP Addresses or CIDR blocks to allow eval connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow eval connections.
|
file: True
|
||||||
global: True
|
title: Eval
|
||||||
title: Eval
|
advanced: True
|
||||||
advanced: True
|
idh:
|
||||||
idh:
|
description: List of IP Addresses or CIDR blocks to allow idh connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow idh connections.
|
file: True
|
||||||
global: True
|
title: IDH Nodes
|
||||||
title: IDH Nodes
|
manager:
|
||||||
manager:
|
description: List of IP Addresses or CIDR blocks to allow manager connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow manager connections.
|
file: True
|
||||||
global: True
|
title: Manager
|
||||||
title: Manager
|
advanced: True
|
||||||
advanced: True
|
heavynodes:
|
||||||
heavynodes:
|
description: List of IP Addresses or CIDR blocks to allow heavynode connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow heavynode connections.
|
file: True
|
||||||
global: True
|
title: Heavy Nodes
|
||||||
title: Heavy Nodes
|
searchnodes:
|
||||||
searchnodes:
|
description: List of IP Addresses or CIDR blocks to allow searchnode connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow searchnode connections.
|
file: True
|
||||||
global: True
|
title: Searchnodes
|
||||||
title: Searchnodes
|
receivers:
|
||||||
receivers:
|
description: List of IP Addresses or CIDR blocks to allow receiver connections.
|
||||||
description: List of IP Addresses or CIDR blocks to allow receiver connections.
|
file: True
|
||||||
global: True
|
title: Receivers
|
||||||
title: Receivers
|
portgroups:
|
||||||
|
analyst_workstations:
|
||||||
|
description: List of ports for analyst workstations.
|
||||||
|
file: True
|
||||||
|
title: Analyst Workstations
|
||||||
|
analyst:
|
||||||
|
description: List of ports for analyst connections.
|
||||||
|
file: True
|
||||||
|
title: Analysts
|
||||||
|
standalone:
|
||||||
|
description: List of ports for standalone connections.
|
||||||
|
file: True
|
||||||
|
title: Standalone
|
||||||
|
advanced: True
|
||||||
|
eval:
|
||||||
|
description: List of ports for eval connections.
|
||||||
|
file: True
|
||||||
|
title: Eval
|
||||||
|
advanced: True
|
||||||
|
idh:
|
||||||
|
description: List of ports for idh connections.
|
||||||
|
file: True
|
||||||
|
title: IDH Nodes
|
||||||
|
manager:
|
||||||
|
description: List of ports for manager connections.
|
||||||
|
file: True
|
||||||
|
title: Manager
|
||||||
|
advanced: True
|
||||||
|
heavynodes:
|
||||||
|
description: List of ports for heavynode connections.
|
||||||
|
file: True
|
||||||
|
title: Heavy Nodes
|
||||||
|
searchnodes:
|
||||||
|
description: List of ports for searchnode connections.
|
||||||
|
file: True
|
||||||
|
title: Searchnodes
|
||||||
|
receivers:
|
||||||
|
description: List of ports for receiver connections.
|
||||||
|
file: True
|
||||||
|
title: Receivers
|
||||||
|
ports:
|
||||||
|
ports__yaml:
|
||||||
|
description: List of ports in YAML used for port groups.
|
||||||
|
file: True
|
||||||
|
title: Ports
|
||||||
Reference in New Issue
Block a user