Sorry it took me so long to pick this back up.

The 10.140.136 addresses are on VLAN 286, and the 10.140.134 address are on VLAN 297. 
I don't really see an easy way around adding gateways for these VLANs..  Because our backup, and monitoring servers are both on VLAN 808, and trunking these layer2 across buildings in frowned upon.

----
Daniel Murphy-Olson      
Sr. Systems Administrator
Computing, Environment and Life Sciences
Argonne National Laboratory
630-252-0055

From: Schmitz, Corby B.
Sent: Tuesday, March 18, 2014 11:32 AM
To: Murphy-Olson, Daniel E.; core-sysadmins@mcs.anl.gov
Subject: Re: Firewall Request Link

The net in this list is not routed on-site. Do we need to add routing, and a gateway? Is this tied to vlan 297? 

-- 
corby

From: <Murphy-Olson>, Dan Olson <dolson@mcs.anl.gov>
Date: Tuesday, March 18, 2014 11:15 AM
To: Corby Schmitz <cschmitz@anl.gov>, "core-sysadmins@mcs.anl.gov" <core-sysadmins@mcs.anl.gov>
Subject: RE: Firewall Request Link

OS/App version information included inline.

----
Daniel Murphy-Olson      
Sr. Systems Administrator
Computing, Environment and Life Sciences Division
Argonne National Laboratory
630-252-0055

From: Murphy-Olson, Daniel E.
Sent: Tuesday, March 18, 2014 10:23 AM
To: Schmitz, Corby B.; core-sysadmins@mcs.anl.gov
Subject: RE: Firewall Request Link

Corby, 

This doesn't work for me currently.  I get "Not Authorized".

The request I was trying to submit is:

permit tcp port 10000,2049,443,80 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.8.3(TSM 6.4 on RHEL 6.5). #NDMP, API, and nfs from TSM
permit tcp port 2049 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.13.0/24 #nfs from systems net
permit tcp port 22 and udp port 161 to 10.140.134.22(NetApp Release 8.1.1 7-Mode) and 10.140.134.23(NetApp Release 8.1.1 7-Mode) from 140.221.9.203(Centos 6.5) and 140.221.6.203(Centos 6.5) #ssh and snmp from bastions

All of these are for our netapp infrastructure in 221.

----
Daniel Murphy-Olson      
Sr. Systems Administrator
Computing, Environment and Life Sciences Division
Argonne National Laboratory
630-252-0055

From: core-sysadmins-bounces@lists.mcs.anl.gov [core-sysadmins-bounces@lists.mcs.anl.gov] on behalf of Schmitz, Corby B. [cschmitz@anl.gov]
Sent: Thursday, December 05, 2013 9:03 AM
To: core-sysadmins@mcs.anl.gov
Subject: Firewall Request Link

This is the new location for firewall requests:

I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. 

-- 
corby