For now we allow all UDP traffic. I'll look into doing something clever. This isn't puppetized, either. (imported from commit bdf53df87a5f6c8af6d950b25946b5ec8a4f910b)