Documents the missing and incorrect UniFi policies found during zone policy review: FAMILY to CADDY action fix, all CADDY to TRUSTED backend app policies, CADDY to IoT policies, and public DNS block policies per zone. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
3.7 KiB
Caddy Firewall Policies — Missing and Incorrect Rules
Audit findings from the zone policy review. Apply these in UniFi
Settings → Policy Engine → Policy Table in the order shown. All
custom policies must be above the built-in Block All Traffic terminal
rule.
1. Fix: Allow FAMILY to CADDY (currently set to Block)
The existing Allow FAMILY to CADDY policy has Action = Block. Edit
it and change the action to Allow.
| Field | Value |
|---|---|
| Name | Allow FAMILY to CADDY |
| Action | Allow (currently wrong — set to Block) |
| Source zone | FAMILY |
| Source IP | Any |
| Destination zone | CADDY |
| Destination IP | Any |
| Destination port | 443 |
| Protocol | TCP |
2. CADDY → TRUSTED Backend App Policies
Caddy at 10.0.15.5 cannot proxy to any backend apps in the TRUSTED zone
until these policies exist. Create one policy per row.
Every policy in this table uses:
- Action: Allow
- Source zone:
CADDY - Source IP:
10.0.15.5 - Destination zone:
TRUSTED - Protocol: TCP
| Policy name | Destination IP | Destination port(s) | Purpose |
|---|---|---|---|
ALLOW CADDY to arr stack |
10.0.10.20 |
6767,7878,8000,8080,8096,8191,8282,8989,9696 |
Arr-stack LXC (bazarr, radarr, gluetun, qbittorrent, emby, flaresolverr, sabnzbd, sonarr, prowlarr) |
ALLOW CADDY to Technitium UI |
10.0.10.5 |
5380 |
Technitium admin UI |
ALLOW CADDY to Proxmox |
10.0.10.10 |
8006 |
Proxmox VE |
ALLOW CADDY to PBS |
10.0.10.8 |
8007 |
Proxmox Backup Server |
ALLOW CADDY to LAN web devices |
10.0.1.6 |
80 |
Lite-8 PoE switch UI |
ALLOW CADDY to Beszel |
10.0.10.13 |
8090 |
Beszel monitoring |
ALLOW CADDY to Drawio |
10.0.10.9 |
8080 |
Draw.io |
ALLOW CADDY to Gramps |
10.0.10.17 |
5000 |
Gramps Web |
ALLOW CADDY to Immich |
10.0.10.15 |
2283 |
Immich |
ALLOW CADDY to IT Tools |
10.0.10.7 |
80 |
IT Tools |
ALLOW CADDY to Paperless |
10.0.10.11 |
8000 |
Paperless-ngx |
ALLOW CADDY to YTD |
10.0.10.14 |
3033 |
MeTube / YTD |
ALLOW CADDY to Bento PDF |
10.0.10.6 |
8080 |
Bento PDF |
3. CADDY → IoT Backend Policies
Caddy cannot proxy to Home Assistant or Zigbee until these exist.
Every policy in this table uses:
- Action: Allow
- Source zone:
CADDY - Source IP:
10.0.15.5 - Destination zone:
IoT - Protocol: TCP
| Policy name | Destination IP | Destination port(s) | Purpose |
|---|---|---|---|
ALLOW CADDY to Home Automation |
10.0.30.6 |
8080,8123 |
Zigbee2MQTT and Home Assistant |
ALLOW CADDY to Zigbee |
10.0.30.5 |
80 |
SLZB-06U Zigbee coordinator UI |
4. Public DNS Block Policies (per zone)
Without these, devices can bypass Technitium by querying public resolvers
(8.8.8.8, 1.1.1.1, etc.) directly. Place each policy above the
broad External allow for its zone.
Every policy in this table uses:
- Action: Block
- Source IP: Any
- Destination zone:
External - Destination IP: Any
- Protocol: TCP/UDP
- Destination port:
53
| Policy name | Source zone |
|---|---|
BLOCK FAMILY public DNS |
FAMILY |
BLOCK MEDIA public DNS |
MEDIA |
BLOCK IoT public DNS |
IoT |
BLOCK GUEST public DNS |
GUEST |
Policy Order Reference
Within each zone's rule set, the evaluation order must be:
specific allows (DNS, DHCP, Caddy, app pinholes)
public DNS block (above the External allow)
External allow
Gateway DHCP allow
Gateway block
Block All Traffic ← built-in terminal rule
If a broad block rule sits above a specific allow, the block wins and the intended traffic is dropped. Use Reorder in UniFi to verify positions after adding new policies.