Firewall Rules
|
--
Local Network
Server Firewall (UFW) ACTIVE
Default incoming: deny · outgoing: allow · routed: allow · logging on (low)
Port Action Source Comment
1422/tcp ALLOW IN Anywhere SSH
80/tcp ALLOW IN Anywhere HTTP nginx
443/tcp ALLOW IN Anywhere HTTPS nginx
21115:21119/tcp ALLOW IN Anywhere RustDesk TCP
21116/udp ALLOW IN Anywhere RustDesk UDP
51820/udp ALLOW IN Anywhere WireGuard VPN
8080/tcp ALLOW IN Anywhere UnifiedBGM Management Panel
HTTPS Hostnames (nginx)
Hostname Backend
rustdesk-rpp-bma.vitamatric.com 127.0.0.1:8080
unifiled-rpp-bma.vitamatric.com 127.0.0.1:8080
vpn-rpp-bma.vitamatric.com 127.0.0.1:8080
smartbgm-rpp-bma.vitamatric.com 127.0.0.1:4012/api/internal/novnc-auth$is_args$args
stardust-rpp-bma.vitamatric.com 127.0.0.1:4012/api/internal/novnc-auth$is_args$args
Listening Ports 27
Port Proto Bind Scope Service
80 TCP 0.0.0.0 public HTTP nginx (SmartBGM Platform / panel hostnames)
80 TCP :: public HTTP nginx (SmartBGM Platform / panel hostnames)
443 TCP 0.0.0.0 public HTTPS nginx (SmartBGM Platform / panel hostnames)
443 TCP :: public HTTPS nginx (SmartBGM Platform / panel hostnames)
1422 TCP 0.0.0.0 public SSH
1422 TCP :: public SSH
4011 TCP 127.0.0.1 localhost SmartBGM Admin
4012 TCP 127.0.0.1 localhost SmartBGM API
4443 TCP 127.0.0.1 localhost SmartBGM Admin HTTPS (IP mode)
6901 TCP 127.0.0.1 localhost RustDesk noVNC viewer
6902 TCP 127.0.0.1 localhost RustDesk VNC control API
8080 TCP 0.0.0.0 public UnifiedBGM Management Panel
9090 TCP 127.0.0.1 localhost Mock HIS
21115 TCP 0.0.0.0 public RustDesk NAT test
21115 TCP :: public RustDesk NAT test
21116 TCP 0.0.0.0 public RustDesk ID / rendezvous
21116 TCP :: public RustDesk ID / rendezvous
21116 UDP 0.0.0.0 public RustDesk ID / rendezvous
21116 UDP :: public RustDesk ID / rendezvous
21117 TCP 0.0.0.0 public RustDesk relay
21117 TCP :: public RustDesk relay
21118 TCP 0.0.0.0 public RustDesk WebSocket
21118 TCP :: public RustDesk WebSocket
21119 TCP 0.0.0.0 public RustDesk WebSocket relay
21119 TCP :: public RustDesk WebSocket relay
27017 TCP 127.0.0.1 localhost MongoDB primary
27018 TCP 127.0.0.1 localhost MongoDB archive
Add Firewall Rule
Per-device AP Rules 0 rules
# Status MAC Address Port Protocol Action Description Controls

No per-device AP rules

These MAC rules apply to WiFi AP clients. This Unified Server has no wlan0 AP, so this list stays empty. Host UFW rules are listed above.