Archived
Adds an inbound ACCEPT rule for TCP 45876 so the beszel hub can poll the agent running on pve1. Scoped to +mgmt (192.168.2.0/24) to stay consistent with the existing default-deny policy. Rule applied live on pve1 via pve-firewall restart (2026-07-24). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>