FireBrick Firewall - Steam Client

From AAISP Support Site
Revision as of 09:25, 7 March 2016 by CrazyTeeka (talk | contribs)

This firewall allows both inbound and outbound traffic to the steam client, all other traffic is blocked.


Static DNS

By using static DNS we avoid unexpected IP addresses that will be blocked by the firewall:

<dns resolvers="2001:8b0::2020 2001:8b0::2021 217.169.20.20 217.169.20.21">
   <host name="a1507.d.akamai.net"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="a1697.g.akamai.net"
         ip="23.63.99.219 23.67.255.202 104.86.110.24 104.86.110.75"/>
   <host name="a1737.g.akamai.net"
         ip="23.63.99.208 23.63.99.240 104.86.110.24 104.86.110.81"/>
   <host name="a1843.g.akamai.net"
         ip="23.67.255.200 23.67.255.208 104.86.110.27 104.86.110.35"/>
   <host name="api.steampowered.com"
         ip="23.195.77.152 23.205.213.78 92.122.219.245 104.71.179.142 173.223.184.147"/>
   <host name="cdn.akamai.steamstatic.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="cdn.store.steampowered.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="cgpromotion.azurewebsites.net"
         ip="104.40.183.236"/>
   <host name="cgpromotion.blob.core.windows.net"
         ip="168.61.57.78"/>
   <host name="clientconfig.akamai.steamstatic.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="dreamfallchapters.azurewebsites.net"
         ip="191.238.8.26"/>
   <host name="images.akamai.steamusercontent.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="media.steampowered.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="media2.steampowered.com"
         ip="205.185.216.10 205.185.216.42"/>
   <host name="media3.steampowered.com"
         ip="8.253.70.30 8.253.70.110 8.253.70.142 8.254.191.46 8.254.191.94 8.254.191.238"/>
   <host name="media4.steampowered.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="repo.steampowered.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="steamcdn-a.akamaihd.net"
         ip="23.67.255.200 23.67.255.208 104.86.110.27 104.86.110.35"/>
   <host name="steamcloud-eu.storage.googleapis.com"
         ip="216.58.198.208 216.58.198.240 216.58.213.112"/>
   <host name="steamcloudams.blob.core.windows.net"
         ip="168.61.58.14"/>
   <host name="steamclouddub.blob.core.windows.net"
         ip="191.235.193.40"/>
   <host name="steamcommunity-a.akamaihd.net"
         ip="23.63.99.219 23.67.255.202 104.86.110.24 104.86.110.75"/>
   <host name="steamcommunity.com"
         ip="23.195.77.152 23.205.213.78 92.122.219.245 104.71.179.142 173.223.184.147"/>
   <host name="steamstore-a.akamaihd.net"
         ip="23.63.99.208 23.63.99.240 104.86.110.24 104.86.110.81"/>
   <host name="store.akamai.steamstatic.com"
         ip="23.63.98.10 23.63.98.17 23.63.98.18 23.63.98.19 23.63.98.26 23.63.98.27 23.63.98.32 23.63.98.33 23.63.98.41 23.63.98.43 23.63.99.58 23.63.99.90 104.86.110.249 104.86.111.137"/>
   <host name="store.steampowered.com"
         ip="23.195.77.152 23.205.213.78 92.122.219.245 104.71.179.142 173.223.184.147"/>
</dns>


Firewall

Outbound Rules - Change the MAC address in the source-mac= element to your own:

<rule-set name="Steam Client: Outbound" source-interface="LAN" target-interface="pppoe" no-match-action="continue">
  <rule name="Steam OS: NTP"
        target-port="123"
        protocol="17"
        action="accept"/>
  <rule name="Steam Client: TCP"
        target-port="27014-27050"
        protocol="6"
        action="accept"/>
  <rule name="Steam Client: UDP"
        target-port="3478 4379 4380 27000-27030"
        protocol="17"
        action="accept"/>
  <rule name="CDN: Akamai"
        target-ip="23.63.98.0/23 23.67.255.0/24 23.195.64.0/20 23.205.212.0/22 92.122.218.0/23 104.71.176.0/20 104.86.110.0/23 173.223.176.0/20"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="CDN: Highwinds"
        target-ip="205.185.216.10 205.185.216.42"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="CDN: Level 3"
        target-ip="8.253.70.30 8.253.70.110 8.253.70.142 8.254.191.46 8.254.191.94 8.254.191.238 212.73.205.178"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="Steam Cloud: Amazon Web Services"
        target-ip="54.231.130.0/23 54.231.132.0/22 54.231.136.0/22 54.231.140.0/23 54.231.142.0/24"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="Steam Cloud: Google Cloud Platform"
        target-ip="216.58.198.208 216.58.198.240 216.58.213.112"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="Steam Cloud: Microsoft Azure"
        target-ip="104.40.183.236 168.61.57.78 168.61.58.14 191.235.193.40 191.238.8.26"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="Paypal Payments"
        target-ip="66.235.148.64 66.235.148.128/31"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="Valve Software"
        target-ip="103.10.124.0/24 146.66.155.0/24 155.133.245.0/24 155.133.248.0/24 162.254.192.0/21 205.196.6.0/24"
        target-port="80 443"
        protocol="6"
        action="accept"/>
  <rule name="Deny All"
        source-mac="408D5C57F303 D8CB8AA2464E"
        action="reject"/>
</rule-set>

Inbound Rules - Change the IP address in the target-ip= element to your own:

<rule-set name="Steam Client: Inbound" target-interface="LAN" no-match-action="reject">
<rule name="Allow Firebrick" source-interface="self"/>
<rule name="Steam Client: TCP" target-ip="217.169.11.114/31" target-port="27014-27050" protocol="6" action="accept"/>
<rule name="Steam Client: UDP" target-ip="217.169.11.114/31" target-port="3478 4379 4380 27000-27030" protocol="17" action="accept"/>
</rule-set>


Technical Notes

Steam used to have a huge amount of servers (some from Limelight CDN) located around the world and older versions of the software used an inefficient method to connect users to the servers. Steam has made a big improvement on the game delivery system by using 3 different high performing CDN companies: Akamai, Highwinds and Level 3.

  • media.steampowered.com = Akamai
  • media2.steampowered.com = Highwinds
  • media3.steampowered.com = Level 3
  • media4.steampowered.com = Akamai

Running steam will download a small file (containing a list of files with SHA-1 checksums and size in bytes to check if steam is up to date) from:

  • client-download.steampowered.com

If steam is outdated, it will need to download the updated files by randomly selecting one of the CDN hosts and that host will be used to serve the files.

Origin Server

The origin server is where each CDN will pull the files from. The origin server hostnames are:

  • cdn-01-origin.steampowered.com
  • cdn-01.steampowered.com

Steam Cloud

The steam cloud normally stores saved game data, allowing you to use that data on another system. Here is a list of which hostnames belong to which game:

Deponia: The Complete Journey

  • cgpromotion.azurewebsites.net
  • cgpromotion.blob.core.windows.net

Deponia Doomsday

  • cgpromotion.azurewebsites.net
  • cgpromotion.blob.core.windows.net

Dreamfall Chapters

  • dreamfallchapters.azurewebsites.net
  • steamcloud-dub.s3.amazonaws.com