Following up from an IRC discussion.
184.108.40.206/23 is used/reserved for WMCS dynamic public IPs, which mean that ports on that range will often be opening/closing.
To reduce the mail noise sent to email@example.com, it has been suggested to only send notification about that range to cloud-admin.
The current way diffscan is deployed makes it impossible to have two different instances of diffscan running in parallel, it should be easy though to change it (after all, it's a cronjob, a text file, and a python script).
Even easier (at least as a short/medium time solution) is to:
1/ Remove 220.127.116.11/23 from the current (root@) diffscan instance
2/ Add a 2nd instance of diffscan (on a separate host) to scan 18.104.22.168/23
For that, once a host has been selected (probably not worth creating a VM only for that), the diffscan profile needs to be applied to the VM (via horizon), and then the following Hiera facts need to be applied to that VM:
profile::diffscan::ipranges: - 22.214.171.124/23 profile::diffscan::emailto: firstname.lastname@example.org profile::diffscan::groupname: Labs-to-public-v4 <-- no space or special characters, will be in the email's subject