Secure Research Lab Network
Please note: In September 2026, rates will change for a small number of technology services provided by University IT. View FY27 rate changes.
The Secure Research Lab Network (SRLN) provides a secure method for university research labs and facilities to connect necessary yet non-compliant devices to the Stanford network. It utilizes controlled access and University IT (UIT)-managed security measures, including Network Access Control (SUNAC) and the University Firewall service, to ensure that these devices do not compromise the safety of the broader university network. SRLN offers pre-configured options and a five-year extended compliance exemption.
Features
The SRLN creates a small, firewalled, SUNAC-enabled network that separates a lab or core facility's noncompliant devices from other machines on the Stanford University Network (SUNet). The University Firewall service regulates inbound and outbound access, and Local Network Administrators (LNAs) are authorized to manage and configure the firewall settings, ensuring routine operational tasks can be completed without interruption. This network configuration helps remove the reliance on easy-to-lose, insecure USB drives for data transfer.
Additional features include:
- Service consultation: LNAs and appropriate UIT staff will meet for an initial consultation for planning a Secure Research Lab Network.
- LNA controls:
- LNAs can choose from a menu of commonly used services, for example, Globus, Google Drive, and iLab.
- UIT firewall engineers can quickly enable these services on the network.
- LNAs may submit firewall-rule requests through the Netdocs portal.
- Research Data Transfer: The SRLN is designed to enable the transfer of research data out of the local network to common storage locations, such as the Oak Storage Service and Google Cloud Storage.
- SUNAC, which enables restricting University firewalled network resources to specific SUNet ID(s) within a workgroup.
Designed for
Labs, core facilities, and other groups connected to the SUNet that have devices that are unable to comply with University compliance requirements.
Requirements
- Machines must be connected to SUNet switches.
- Machines not configured to meet compliance requirements*.
- End users who connect to devices remotely must be able to use the VPN or the eduroam Wi-Fi network**.
* If convenient, it is acceptable to place compliant devices into a Secure Research Lab Network if those devices are used to communicate with non-compliant devices (for example, for data transfer). However, this might impose overly restrictive limits on the usability of compliant devices. Your consultant will help you determine the best way to connect your devices.
** Remote access can be provided for vendors who need to support their equipment.
Data security
May be used to handle Low, or Moderate-Risk Data, as defined by the Information Security Office.
Rates
Free of charge
Get started
Lab or service center managers initiate the migration to a Secure Research Lab Network by contacting their LNA. Not sure if the Secure Research Lab Network is right for you? Explore the Frequently Asked Questions page for more details.
LNAs begin by submitting a Help request for a Secure Research Lab Network consultation.
For groups without an LNA, we recommend contacting CRC Research Lab Support via email at crc-research-lab-support@stanford.edu.
Get help
- Support for onboarding/migrating to the SRLN service is provided by the Information Security Office (ISO) and University IT (UIT) network engineers during normal business hours. To contact the network engineers and begin setup, please submit a Help request.
- Normal business hours are Monday through Friday, from 8 a.m. to 5 p.m. No after-hours support is available for the SRLN service, other than support required to ensure the functionality of SUNAC, the firewalls, and associated University IT network devices.
- Scheduled maintenance windows for the SRLN and University IT-managed firewalls are Thursday, 4 a.m. to 6 a.m.; Saturday, 5 a.m. to 8 a.m.; and Sunday, 5 a.m. to 8 a.m.
- Support after enrollment is provided by your LNA. Groups without an LNA should consider engaging the CRC Research Lab Support service.
