guides:firewall_settings
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| guides:firewall_settings [2025/06/19 20:51] – greg.dapkus | guides:firewall_settings [2025/10/23 21:04] (current) – 216.9.23.34 | ||
|---|---|---|---|
| Line 5: | Line 5: | ||
| - | {{tablelayout? | + | {{tablelayout? |
| ^ Host ^ IP Address ^ Description ^ | ^ Host ^ IP Address ^ Description ^ | ||
| | dev-ws02.certna.org | 204.246.133.236 | APEX installation | | | dev-ws02.certna.org | 204.246.133.236 | APEX installation | | ||
| Line 13: | Line 13: | ||
| | reports.certna.org | 204.246.133.238 | APEX production ERDS reports| | | reports.certna.org | 204.246.133.238 | APEX production ERDS reports| | ||
| | reports.certnag2g.org | 209.170.199.202 | APEX production G2G reports| | | reports.certnag2g.org | 209.170.199.202 | APEX production G2G reports| | ||
| - | | CeRTNA-APEX-g6bygtdgh0aqh0fh.z01.azurefd.us | + | | *.sectigo.com | * | PKI certificates |
| - | | *.digicert.com | * | DigiCert | + | | *.digicert.com | * | PKI certificates (Note 2) | |
| - | | *.ssl.com | * | SSL Code Signing certificate (Note 2) | | + | | *.ssl.com | * | Code Signing certificate (Note 2) | |
| | *.godaddy.com | * | SSL certificates (Note 2) | | | *.godaddy.com | * | SSL certificates (Note 2) | | ||
| Line 25: | Line 25: | ||
| - Use wildcard domains if possible. (Ex: *.certna.org or *.certnag2g.org) | - Use wildcard domains if possible. (Ex: *.certna.org or *.certnag2g.org) | ||
| - Use host names if possible. (Ex: apex-prd.certna.org or reports.certna.org) | - Use host names if possible. (Ex: apex-prd.certna.org or reports.certna.org) | ||
| - | - Last resort, use IP addresses. (Static IPs will be retired on Auguust 2,2025.) | + | - Last resort, use IP addresses. |
| - | - The IP of our cloud WAF is not Static. A list of possible ranges is below. | + | |
| The preceding list is sorted in order of preference. | The preceding list is sorted in order of preference. | ||
| Line 32: | Line 31: | ||
| **Note 2:** Several digital certificates are used in support of CeRTNA/ | **Note 2:** Several digital certificates are used in support of CeRTNA/ | ||
| + | |||
| + | === Workstation Support === | ||
| In addition to the locations listed above, there are some additional hosts that you also want to allow in order to facilitate the retrieval of Windows Updates and for CeRTNA remote support. | In addition to the locations listed above, there are some additional hosts that you also want to allow in order to facilitate the retrieval of Windows Updates and for CeRTNA remote support. | ||
| Line 43: | Line 44: | ||
| - | **Note 3:** Support for Teams meetings and screensharing is also required for remote support of the APEX software | + | **Note 3:** Support for Teams meetings and screensharing is also required for remote support of the APEX software. |
| - | ==== Cloud WAF IP Ranges ==== | ||
| - | * 20.140.48.68/ | ||
| - | * 20.140.56.68/ | ||
| - | * 20.140.64.68/ | ||
| - | * 20.140.72.68/ | ||
| - | * 20.140.77.113/ | ||
| - | * 20.140.147.200/ | ||
| - | * 20.140.151.73/ | ||
| - | * 20.140.151.74/ | ||
| - | * 20.140.152.48/ | ||
| - | * 20.141.10.208/ | ||
| - | * 20.141.12.33/ | ||
| - | * 20.141.12.34/ | ||
| - | * 20.141.16.158/ | ||
| - | * 20.141.18.104/ | ||
| - | * 20.141.19.32/ | ||
| - | * 20.159.108.84/ | ||
| - | * 52.127.49.64/ | ||
| - | * 52.181.33.42/ | ||
| - | * 52.181.33.44/ | ||
| - | * 52.181.33.46/ | ||
| - | * 52.181.33.48/ | ||
| - | * 52.181.33.50/ | ||
| - | * 52.181.33.52/ | ||
| - | * 52.181.33.54/ | ||
| - | * 52.181.33.56/ | ||
| - | * 52.182.32.230/ | ||
| - | * 52.182.33.4/ | ||
| - | * 52.182.33.6/ | ||
| - | * 52.182.33.8/ | ||
| - | * 52.182.33.10/ | ||
| - | * 52.182.33.12/ | ||
| - | * 52.182.33.14/ | ||
| - | * 52.182.33.48/ | ||
| - | * 52.227.226.250/ | ||
| - | * 52.227.227.12/ | ||
| - | * 52.227.227.23/ | ||
| - | * 52.227.227.25/ | ||
| - | * 52.227.227.29/ | ||
| - | * 52.227.227.31/ | ||
| - | * 52.227.227.33/ | ||
| - | * 52.227.227.35/ | ||
| - | * 52.235.253.120/ | ||
| - | * 52.243.152.68/ | ||
| - | * 52.243.155.57/ | ||
| - | * 52.243.156.34/ | ||
| - | * 52.243.156.157/ | ||
| - | * 52.243.156.164/ | ||
| - | * 52.243.156.166/ | ||
| - | * 52.243.156.209/ | ||
| - | * 52.243.156.212/ | ||
| - | * 52.244.34.47/ | ||
| - | * 52.244.34.118/ | ||
| - | * 52.244.34.125/ | ||
| - | * 52.244.34.127/ | ||
| - | * 52.244.34.129/ | ||
| - | * 52.244.34.131/ | ||
| - | * 52.244.34.133/ | ||
| - | * 52.244.34.135/ | ||
| - | * 52.244.239.112/ | ||
| - | * 52.245.153.184/ | ||
| - | * 2001: | ||
| - | * 2001: | ||
| - | * 2001: | ||
| - | * 2001: | ||
| - | * 2001: | ||
| - | * 2001: | ||
| - | * 2001: | ||
| - | * 2001: | ||
guides/firewall_settings.1750366282.txt.gz · Last modified: by greg.dapkus
