This is the new location for firewall requests: https://argonne.service-now.com/com.glideapp.servicecatalog_cat_item_view.do... I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. -- corby
Corby, This doesn't work for me currently. I get "Not Authorized". The request I was trying to submit is: permit tcp port 10000,2049,443,80 to 10.140.136.22 and 10.140.136.23 from 140.221.8.3. #NDMP, API, and nfs from TSM permit tcp port 2049 to 10.140.136.22 and 10.140.136.23 from 140.221.13.0/24 #nfs from systems net permit tcp port 22 and udp port 161 to 10.140.134.22 and 10.140.134.23 from 140.221.9.203 and 140.221.6.203 #ssh and snmp from bastions All of these are for our netapp infrastructure in 221. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: [email protected] [[email protected]] on behalf of Schmitz, Corby B. [[email protected]] Sent: Thursday, December 05, 2013 9:03 AM To: [email protected] Subject: Firewall Request Link This is the new location for firewall requests: https://argonne.service-now.com/com.glideapp.servicecatalog_cat_item_view.do... I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. -- corby
OS/App version information included inline. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: Murphy-Olson, Daniel E. Sent: Tuesday, March 18, 2014 10:23 AM To: Schmitz, Corby B.; [email protected] Subject: RE: Firewall Request Link Corby, This doesn't work for me currently. I get "Not Authorized". The request I was trying to submit is: permit tcp port 10000,2049,443,80 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.8.3(TSM 6.4 on RHEL 6.5). #NDMP, API, and nfs from TSM permit tcp port 2049 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.13.0/24 #nfs from systems net permit tcp port 22 and udp port 161 to 10.140.134.22(NetApp Release 8.1.1 7-Mode) and 10.140.134.23(NetApp Release 8.1.1 7-Mode) from 140.221.9.203(Centos 6.5) and 140.221.6.203(Centos 6.5) #ssh and snmp from bastions All of these are for our netapp infrastructure in 221. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: [email protected] [[email protected]] on behalf of Schmitz, Corby B. [[email protected]] Sent: Thursday, December 05, 2013 9:03 AM To: [email protected] Subject: Firewall Request Link This is the new location for firewall requests: https://argonne.service-now.com/com.glideapp.servicecatalog_cat_item_view.do... I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. -- corby
I have a firewall request I need to submit as well. IF there's an updated link we can use, I'm happy to give it a shot. From: <Murphy-Olson>, "Daniel E." <[email protected]<mailto:[email protected]>> Date: Tuesday, March 18, 2014 at 11:15 AM To: "Corby B. Schmitz" <[email protected]<mailto:[email protected]>>, "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: RE: Firewall Request Link OS/App version information included inline. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: Murphy-Olson, Daniel E. Sent: Tuesday, March 18, 2014 10:23 AM To: Schmitz, Corby B.; [email protected]<mailto:[email protected]> Subject: RE: Firewall Request Link Corby, This doesn't work for me currently. I get "Not Authorized". The request I was trying to submit is: permit tcp port 10000,2049,443,80 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.8.3(TSM 6.4 on RHEL 6.5). #NDMP, API, and nfs from TSM permit tcp port 2049 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.13.0/24 #nfs from systems net permit tcp port 22 and udp port 161 to 10.140.134.22(NetApp Release 8.1.1 7-Mode) and 10.140.134.23(NetApp Release 8.1.1 7-Mode) from 140.221.9.203(Centos 6.5) and 140.221.6.203(Centos 6.5) #ssh and snmp from bastions All of these are for our netapp infrastructure in 221. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: [email protected]<mailto:[email protected]> [[email protected]<mailto:[email protected]>] on behalf of Schmitz, Corby B. [[email protected]<mailto:[email protected]>] Sent: Thursday, December 05, 2013 9:03 AM To: [email protected]<mailto:[email protected]> Subject: Firewall Request Link This is the new location for firewall requests: https://argonne.service-now.com/com.glideapp.servicecatalog_cat_item_view.do... I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. -- corby
https://webapps.inside.anl.gov/ihw/resources/networking/conduit/ -- corby From: <Leggett>, Torrance Leggett <[email protected]<mailto:[email protected]>> Date: Tuesday, March 18, 2014 11:29 AM To: Dan Olson <[email protected]<mailto:[email protected]>>, Corby Schmitz <[email protected]<mailto:[email protected]>>, "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: Re: Firewall Request Link I have a firewall request I need to submit as well. IF there's an updated link we can use, I'm happy to give it a shot. From: <Murphy-Olson>, "Daniel E." <[email protected]<mailto:[email protected]>> Date: Tuesday, March 18, 2014 at 11:15 AM To: "Corby B. Schmitz" <[email protected]<mailto:[email protected]>>, "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: RE: Firewall Request Link OS/App version information included inline. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: Murphy-Olson, Daniel E. Sent: Tuesday, March 18, 2014 10:23 AM To: Schmitz, Corby B.; [email protected]<mailto:[email protected]> Subject: RE: Firewall Request Link Corby, This doesn't work for me currently. I get "Not Authorized". The request I was trying to submit is: permit tcp port 10000,2049,443,80 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.8.3(TSM 6.4 on RHEL 6.5). #NDMP, API, and nfs from TSM permit tcp port 2049 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.13.0/24 #nfs from systems net permit tcp port 22 and udp port 161 to 10.140.134.22(NetApp Release 8.1.1 7-Mode) and 10.140.134.23(NetApp Release 8.1.1 7-Mode) from 140.221.9.203(Centos 6.5) and 140.221.6.203(Centos 6.5) #ssh and snmp from bastions All of these are for our netapp infrastructure in 221. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From:[email protected]<mailto:[email protected]> [[email protected]<mailto:[email protected]>] on behalf of Schmitz, Corby B. [[email protected]<mailto:[email protected]>] Sent: Thursday, December 05, 2013 9:03 AM To: [email protected]<mailto:[email protected]> Subject: Firewall Request Link This is the new location for firewall requests: https://argonne.service-now.com/com.glideapp.servicecatalog_cat_item_view.do... I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. -- corby
The net in this list is not routed on-site. Do we need to add routing, and a gateway? Is this tied to vlan 297? -- corby From: <Murphy-Olson>, Dan Olson <[email protected]<mailto:[email protected]>> Date: Tuesday, March 18, 2014 11:15 AM To: Corby Schmitz <[email protected]<mailto:[email protected]>>, "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: RE: Firewall Request Link OS/App version information included inline. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: Murphy-Olson, Daniel E. Sent: Tuesday, March 18, 2014 10:23 AM To: Schmitz, Corby B.; [email protected]<mailto:[email protected]> Subject: RE: Firewall Request Link Corby, This doesn't work for me currently. I get "Not Authorized". The request I was trying to submit is: permit tcp port 10000,2049,443,80 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.8.3(TSM 6.4 on RHEL 6.5). #NDMP, API, and nfs from TSM permit tcp port 2049 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.13.0/24 #nfs from systems net permit tcp port 22 and udp port 161 to 10.140.134.22(NetApp Release 8.1.1 7-Mode) and 10.140.134.23(NetApp Release 8.1.1 7-Mode) from 140.221.9.203(Centos 6.5) and 140.221.6.203(Centos 6.5) #ssh and snmp from bastions All of these are for our netapp infrastructure in 221. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: [email protected]<mailto:[email protected]> [[email protected]<mailto:[email protected]>] on behalf of Schmitz, Corby B. [[email protected]<mailto:[email protected]>] Sent: Thursday, December 05, 2013 9:03 AM To: [email protected]<mailto:[email protected]> Subject: Firewall Request Link This is the new location for firewall requests: https://argonne.service-now.com/com.glideapp.servicecatalog_cat_item_view.do... I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. -- corby
Sorry it took me so long to pick this back up. The 10.140.136 addresses are on VLAN 286, and the 10.140.134 address are on VLAN 297. I don't really see an easy way around adding gateways for these VLANs.. Because our backup, and monitoring servers are both on VLAN 808, and trunking these layer2 across buildings in frowned upon. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: Schmitz, Corby B. Sent: Tuesday, March 18, 2014 11:32 AM To: Murphy-Olson, Daniel E.; [email protected] Subject: Re: Firewall Request Link The net in this list is not routed on-site. Do we need to add routing, and a gateway? Is this tied to vlan 297? -- corby From: <Murphy-Olson>, Dan Olson <[email protected]<mailto:[email protected]>> Date: Tuesday, March 18, 2014 11:15 AM To: Corby Schmitz <[email protected]<mailto:[email protected]>>, "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: RE: Firewall Request Link OS/App version information included inline. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: Murphy-Olson, Daniel E. Sent: Tuesday, March 18, 2014 10:23 AM To: Schmitz, Corby B.; [email protected]<mailto:[email protected]> Subject: RE: Firewall Request Link Corby, This doesn't work for me currently. I get "Not Authorized". The request I was trying to submit is: permit tcp port 10000,2049,443,80 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.8.3(TSM 6.4 on RHEL 6.5). #NDMP, API, and nfs from TSM permit tcp port 2049 to 10.140.136.22(NetApp Release 8.1.1 7-Mode) and 10.140.136.23(NetApp Release 8.1.1 7-Mode) from 140.221.13.0/24 #nfs from systems net permit tcp port 22 and udp port 161 to 10.140.134.22(NetApp Release 8.1.1 7-Mode) and 10.140.134.23(NetApp Release 8.1.1 7-Mode) from 140.221.9.203(Centos 6.5) and 140.221.6.203(Centos 6.5) #ssh and snmp from bastions All of these are for our netapp infrastructure in 221. ---- Daniel Murphy-Olson Sr. Systems Administrator Computing, Environment and Life Sciences Division Argonne National Laboratory 630-252-0055<callto:630-252-0055> ________________________________ From: [email protected]<mailto:[email protected]> [[email protected]<mailto:[email protected]>] on behalf of Schmitz, Corby B. [[email protected]<mailto:[email protected]>] Sent: Thursday, December 05, 2013 9:03 AM To: [email protected]<mailto:[email protected]> Subject: Firewall Request Link This is the new location for firewall requests: https://argonne.service-now.com/com.glideapp.servicecatalog_cat_item_view.do... I know its ugly, but it is what it is. We are working on the back-end support for this to allow automated installation of rules (on the standard side). This will affect only networks behind the LWFW. -- corby
participants (3)
-
Leggett, Torrance I. -
Murphy-Olson, Daniel E. -
Schmitz, Corby B.