Skip to content Skip to site navigation

ITS/AS/ACS Linux Systems Template Rules

Attention Application Owners & Rule Delegates

The following set of firewall policies, referred to as "Template Rules", are provided for administrators of Linux based servers that require a specific set of source hosts/nets and services allowed for administration.

When applying these Template rules, please consider any additional necessary "custom" policies to guarantee the inbound or outbound connectivity that servers will require. Those "custom" policy requests can be made via the Firewall Rule Request form.

Please contact the Firewall Team (firewall-team@lists.stanford.edu) with any questions.

Firewall Template Rules

Traffic Inbound to the Firewall
From To Ports Description
tl_afs_nets tl_linux_hosts tl_afs3-callback AFS3 Callback (udp:7000-7010)
tl_bastion_hosts tl_linux_hosts tl_bastion_access ssh (tcp:22)
remctl (tcp:4373)
IPMI (udp:623)
tl_nagios_servers tl_linux_hosts tl_nagios Nagios monitoring (tcp:4373)
NTP (udp:123)
tl_monitor_servers tl_linux_hosts tl_monitor monitor (tcp:4949)
Traffic Outbound from the Firewall
From To Ports Description
tl_linux_hosts Untrust tl_http(s) http(s) (tcp:80 tcp:443)
tl_linux_hosts Untrust tl_bind bind (tcp:53 udp:53)
Group Object Definitions
Group Members
tl_bastion_hosts luckdragon
smtp-dr
casper
castoff
tl_afs_nets 171.64.7.0/24
171.64.17.0/24
171.67.16.0/22
171.67.20.0/24
171.67.22.0/24
tl_nagios_servers nagios01
nagios02
providence
tl_monitor_servers memory2
 

Roles

Template Owner

Responsible for determining, maintaining and modifying the template rules and membership of the different server groups. The application owner is notified regarding any changes to the template.

Current Template Owners

  • Roshni Mudgal (representing AS)
  • David Hoffman (representing ISO)
  • Noah Abramson (representing ITS)

System Administrators

Request rule approval from the application owner.

ISO Security

The ISO group will audit the rules and make recommendations as needed or upon request from either the System Administrators or the Application Owners. In addition, any changes to this template must be reviewed by ISO prior to implementation.

Last modified March 6, 2024