- Open firewall ports (dhcp, tftp, http, 4011) on bastion start - Close firewall ports on bastion shutdown - Auto-detect firewall zone for interface - Fix reprovision SSH to use execFileSync with explicit key path Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>