rdmsm4x-changelog-20260915-1850-udm-wan-exposure-closed
rdmsm4x-changelog-20260915-1850-udm-wan-exposure-closed
Closed the UDM's internet-facing console:
udm/gw.dataroo.net now reach it through the
Cloudflare tunnel, and UniFi's Direct Remote Access is off, so both WAN
IPs no longer answer on 443/80. Verified from off-site in both
directions.
- When: 2026-09-15 18:42 – 18:50 EDT
- Scope: Cloudflare (tunnel ingress + 2 CNAMEs), UDM
ace.settingkey=mgmt,systemctl restart unifi - Tickets: SEC-20260915-01 resolved; SEC-20260915-02 opened (credential rotation)
- Detail:
~/dev/net/fleet-netmgmt/docs/findings.md§ 2026-09-15 evening
Changes
- Tunnel
dataroo-homelab-tunnel: added ingressudm.dataroo.netandgw.dataroo.net→https://192.168.1.1(noTLSVerify), applied as a full 6-rule PUT. cloudflared loaded config v12. - DNS:
udmandgwCNAMEs repointed fromudm.18a.dataroo.netto the tunnel (still proxied, still Access-gated). - UDM:
ace.settingkey=mgmtdirect_connect_enabledtrue → false (matched=1 modified=1), thensystemctl restart unifi.
Verification (external vantage: jdmbair13m5 on Starlink, egress 129.222.242.166, control 1.1.1.1:443 ok)
- 13:59 → both WAN IPs served "UniFi OS" 200 on 443. 18:48:45 → 75.127.200.210 and 69.124.66.186 closed on both 443 and 80.
- LAN
https://192.168.1.1= 200 from rdmsm4x (unchanged). udm.dataroo.netthrough the tunnel = 200 "UniFi OS" using the fleet service token under a temporary policy, deleted right after; app back to Owner-only; unauthenticated = 302.
Undo
Set direct_connect_enabled back to true + restart unifi
(backup
/data/backup-claude/setting-mgmt-20260915-184619.json); PUT
~/dev/net/cloudflare/backups/dataroo-homelab-tunnel-config-20260915-1842-pre-udm.json;
repoint both CNAMEs to udm.18a.dataroo.net.
Owner actions (Rich)
- SEC-20260915-02 — rotate UDM device credentials. A
whole
mgmtconfig document was printed into this session's transcript (device SSH password + hashes, API token, management key). Values are not repeated in any file. Rotate the device SSH password and regenerate the API token in UniFi. No fleet script references them (onlyFLEET_UNIFI_ROOT_*). - Confirm ui.com / UniFi mobile remote access still works; it now uses UI's relay rather than a direct connection.
- Unrelated:
~/.secrets/global.envwas rewritten at 18:44:13 by something else; exactly one value changed,APP_SECRET. Not this session.