guides:firewall_settings
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
guides:firewall_settings [2019/12/05 20:07] – brett.zamora | guides:firewall_settings [2025/09/16 16:14] (current) – 216.9.23.34 | ||
---|---|---|---|
Line 5: | Line 5: | ||
- | {{tablelayout? | + | {{tablelayout? |
^ Host ^ IP Address ^ Description ^ | ^ Host ^ IP Address ^ Description ^ | ||
- | | dev-ws02.certna.org | 204.246.133.236 | APEX installation | + | | dev-ws02.certna.org | 204.246.133.236 | APEX installation |
- | | apex-prd.certna.org | 204.246.133.237 | APEX production ERDS application servers. | + | | apex-setup.certna.org | 204.246.133.236 | APEX installation |
- | | apex-prd.certnag2g.org | 209.170.199.196 | APEX production G2G application servers. | + | | apex-prd.certna.org | 204.246.133.237 | APEX production ERDS web| |
- | | reports.certna.org | 204.246.133.238 | APEX production ERDS report servers. | + | | apex-prd.certnag2g.org | 209.170.199.196 | APEX production G2G web| |
- | | reports.certnag2g.org | 209.170.199.202 | APEX production G2G report servers. | + | | reports.certna.org | 204.246.133.238 | APEX production ERDS reports| |
- | | *.digicert.com | * | DigiCert | + | | reports.certnag2g.org | 209.170.199.202 | APEX production G2G reports| |
- | | *.entrust.com | * | Entrust PKI certificate services. (Note 1) | | + | | *.digicert.com | * | PKI certificates |
- | | *.entrust.net | * | Entrust | + | | *.ssl.com | * | Code Signing certificate (Note 2) | |
- | | *.godaddy.com | * | SSL certificate services. | + | | *.godaddy.com | * | SSL certificates |
- | **Note 1:** Several digital certificates are used in support of CeRTNA/APEX, these include SSL certificates, PKI certificates for digital signatures, PKI certificates for encryption/ | + | CeRTNA |
- | CeRTNA recognizes that different firewalls are in service at our customers and that firewall features functions can vary broadly. CeRTNA prefers to minimize the amount of IT administrative support required by creating rules based on the following tolerance and/or capabilities of your firewall: | + | **Note 1:** CeRTNA recognizes that different firewalls are in service at our customers and that firewall features functions can vary broadly. CeRTNA prefers to minimize the amount of IT administrative support required by creating rules based on the following tolerance and/or capabilities of your firewall: |
- | | + | |
- | | + | |
- | | + | |
The preceding list is sorted in order of preference. | The preceding list is sorted in order of preference. | ||
+ | |||
+ | |||
+ | **Note 2:** Several digital certificates are used in support of CeRTNA/ | ||
+ | |||
+ | === Workstation Support === | ||
In addition to the locations listed above, there are some additional hosts that you also want to allow in order to facilitate the retrieval of Windows Updates and for CeRTNA remote support. | In addition to the locations listed above, there are some additional hosts that you also want to allow in order to facilitate the retrieval of Windows Updates and for CeRTNA remote support. | ||
Line 32: | Line 37: | ||
{{tablelayout? | {{tablelayout? | ||
^ Host ^ IP Address ^ Description ^ | ^ Host ^ IP Address ^ Description ^ | ||
- | | wiki.certna.org | 184.168.131.241 | CeRTNA' | + | | *.microsoft.com | * | Top-level Microsoft domain, to avoid issues with Windows functionality. |
- | | *.microsoft.com | * | Top-level Microsoft domain, to avoid issues with Windows functionality. | | + | |
| *.update.microsoft.com | * | General Windows update domain. | | | *.update.microsoft.com | * | General Windows update domain. | | ||
- | | *.gotomeeting.com | * | Top-level domain for GoToMeeting web meeting. | | ||
- | | *.citrixonline.com | * | GoToMeeting is implemented using Citrix servers. | | ||
- | Configuring the firewall rules for Windows Updates and other fundamental OS support, for example, virus definition files for Symantec | + | Configuring the firewall rules for Windows Updates and other fundamental OS support, for example, virus definition files for Endpoint Protection or other 3rd party system management tools is the responsibility of your organizations IT staff. The information provided in the preceding table is here simply point out that there are additional URL's that may need to be accommodated |
+ | |||
+ | |||
+ | **Note 3:** Support for Teams meetings and screensharing is also required for remote support of the APEX software. | ||
guides/firewall_settings.1575576422.txt.gz · Last modified: by brett.zamora