Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260915-1850-udm-wan-exposure-closed

rdmsm4x-changelog-20260915-1850-udm-wan-exposure-closed

Closed the UDM's internet-facing console: udm/gw.dataroo.net now reach it through the Cloudflare tunnel, and UniFi's Direct Remote Access is off, so both WAN IPs no longer answer on 443/80. Verified from off-site in both directions.

Changes

  1. Tunnel dataroo-homelab-tunnel: added ingress udm.dataroo.net and gw.dataroo.net → https://192.168.1.1 (noTLSVerify), applied as a full 6-rule PUT. cloudflared loaded config v12.
  2. DNS: udm and gw CNAMEs repointed from udm.18a.dataroo.net to the tunnel (still proxied, still Access-gated).
  3. UDM: ace.setting key=mgmt direct_connect_enabled true → false (matched=1 modified=1), then systemctl restart unifi.

Undo

Set direct_connect_enabled back to true + restart unifi (backup /data/backup-claude/setting-mgmt-20260915-184619.json); PUT ~/dev/net/cloudflare/backups/dataroo-homelab-tunnel-config-20260915-1842-pre-udm.json; repoint both CNAMEs to udm.18a.dataroo.net.

Owner actions (Rich)