Skip to content Skip to site navigation

ITS CRC Template Rules

Attention Application Owners & Rule Delegates

The following set of firewall policies, referred to as "Template Rules", are provided for administrators of Windows based servers that require a specific set of source hosts/nets and services allowed for administration.

When applying these Template rules, please consider any additional necessary "custom" policies to guarantee the inbound or outbound connectivity that servers will require. Those "custom" policy requests can be made via the Firewall Rule Request form.

Please contact the Firewall Team (firewall-team@lists.stanford.edu) with any questions.

Firewall Template Rules

Traffic Inbound to the Firewall

From To Ports Description
tcrc_afs_nets tcrc_crc_hosts tcrc_afs AFS3 (udp:7000-7010)
tcrc_lbst_servers tcrc_crc_hosts tcrc_lbst ssh (tcp:22)
remctl (tcp:4373)
(tcp:5985-5986)
IPMI (udp:623)
tcrc_nagios_servers tcrc_crc_hosts tcrc_nagios Nagios monitoring (tcp:4373)
Nagios plugin (tcp:5666)
NTP (udp:123)
tcrc_pbst_servers tcrc_crc_hosts tcrc_monitor MS Services (tcp/udp:135)
MS Services (tcp/udp:139
MS Services (tcp:443)
MS Services (tcp/udp:445)
IPMI (udp:623)
MS RDP (tcp/udp:3389)
Dell Mgmt (tcp:3668)
Custom (tcp:4900-5000)
Custom (tcp:5900-5901)
Custom (tcp:5985-5986)
tcrc_bigfix_servers tcrc_crc_hosts tcrc_monitor Bigfix (udp:52311)
tcrc_paw_vpn tcrc_crc_hosts tcrc_monitor SSH (tcp:22)
Web (tcp:80)
MS Services (tcp:135)
MS Services (udp:137)
MS Services (udp:138)
MS Services (tcp:139
MS Services (tcp:443)
MS Services (tcp:445)
IPMI (udp:623)
MS RDP (tcp/udp:3389)
Dell Mgmt (tcp:3668)
Dell OM (tcp:1311)
Remctl (tcp:4373)
Custom (tcp:5985-5986)

Group Object Definitions

Group Members
tcrc_afs_nets 171.64.7.0/24
171.64.17.0/24
171.67.16.0/22
171.67.20.0/24
171.67.22.0/24
tcrc_lbst_servers 171.67.26.96/28
tcrc_nagios_servers 171.67.217.112/28
tcrc_paw_vpn 171.67.52.0/23
 

Roles

Template Owner

Responsible for determining, maintaining and modifying the template rules and membership of the different server groups. The application owner is notified regarding any changes to the template.

Current Template Owners

  • Noah Abrahamson
  • Kim Seidler

System Administrators

Request rule approval from the application owner.

ISO Security

The ISO group will audit the rules and make recommendations as needed or upon request from either the System Administrators or the Application Owners. In addition, any changes to this template must be reviewed by ISO prior to implementation.

Last modified February 28, 2024