guides:firewall_settings
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
guides:firewall_settings [2025/06/19 20:52] – greg.dapkus | guides:firewall_settings [2025/09/16 16:14] (current) – 216.9.23.34 | ||
---|---|---|---|
Line 13: | Line 13: | ||
| reports.certna.org | 204.246.133.238 | APEX production ERDS reports| | | reports.certna.org | 204.246.133.238 | APEX production ERDS reports| | ||
| reports.certnag2g.org | 209.170.199.202 | APEX production G2G reports| | | reports.certnag2g.org | 209.170.199.202 | APEX production G2G reports| | ||
- | | CeRTNA-APEX-g6bygtdgh0aqh0fh.z01.azurefd.us | * (Note 1) | APEX Cloud WAF | | + | | *.digicert.com | * | PKI certificates (Note 2) | |
- | | *.digicert.com | * | DigiCert | + | | *.ssl.com | * | Code Signing certificate (Note 2) | |
- | | *.ssl.com | * | SSL Code Signing certificate (Note 2) | | + | |
| *.godaddy.com | * | SSL certificates (Note 2) | | | *.godaddy.com | * | SSL certificates (Note 2) | | ||
Line 25: | Line 24: | ||
- Use wildcard domains if possible. (Ex: *.certna.org or *.certnag2g.org) | - Use wildcard domains if possible. (Ex: *.certna.org or *.certnag2g.org) | ||
- Use host names if possible. (Ex: apex-prd.certna.org or reports.certna.org) | - Use host names if possible. (Ex: apex-prd.certna.org or reports.certna.org) | ||
- | - Last resort, use IP addresses. (Static IPs will be retired on Auguust 2,2025.) | + | - Last resort, use IP addresses. |
- | - The IP of our cloud WAF is not Static. A list of possible ranges is below. | + | |
The preceding list is sorted in order of preference. | The preceding list is sorted in order of preference. | ||
Line 32: | Line 30: | ||
**Note 2:** Several digital certificates are used in support of CeRTNA/ | **Note 2:** Several digital certificates are used in support of CeRTNA/ | ||
+ | |||
+ | === Workstation Support === | ||
In addition to the locations listed above, there are some additional hosts that you also want to allow in order to facilitate the retrieval of Windows Updates and for CeRTNA remote support. | In addition to the locations listed above, there are some additional hosts that you also want to allow in order to facilitate the retrieval of Windows Updates and for CeRTNA remote support. | ||
Line 43: | Line 43: | ||
- | **Note 3:** Support for Teams meetings and screensharing is also required for remote support of the APEX software | + | **Note 3:** Support for Teams meetings and screensharing is also required for remote support of the APEX software. |
- | ==== Cloud WAF IP Ranges ==== | ||
- | * 20.140.48.68/ | ||
- | * 20.140.56.68/ | ||
- | * 20.140.64.68/ | ||
- | * 20.140.72.68/ | ||
- | * 20.140.77.113/ | ||
- | * 20.140.147.200/ | ||
- | * 20.140.151.73/ | ||
- | * 20.140.151.74/ | ||
- | * 20.140.152.48/ | ||
- | * 20.141.10.208/ | ||
- | * 20.141.12.33/ | ||
- | * 20.141.12.34/ | ||
- | * 20.141.16.158/ | ||
- | * 20.141.18.104/ | ||
- | * 20.141.19.32/ | ||
- | * 20.159.108.84/ | ||
- | * 52.127.49.64/ | ||
- | * 52.181.33.42/ | ||
- | * 52.181.33.44/ | ||
- | * 52.181.33.46/ | ||
- | * 52.181.33.48/ | ||
- | * 52.181.33.50/ | ||
- | * 52.181.33.52/ | ||
- | * 52.181.33.54/ | ||
- | * 52.181.33.56/ | ||
- | * 52.182.32.230/ | ||
- | * 52.182.33.4/ | ||
- | * 52.182.33.6/ | ||
- | * 52.182.33.8/ | ||
- | * 52.182.33.10/ | ||
- | * 52.182.33.12/ | ||
- | * 52.182.33.14/ | ||
- | * 52.182.33.48/ | ||
- | * 52.227.226.250/ | ||
- | * 52.227.227.12/ | ||
- | * 52.227.227.23/ | ||
- | * 52.227.227.25/ | ||
- | * 52.227.227.29/ | ||
- | * 52.227.227.31/ | ||
- | * 52.227.227.33/ | ||
- | * 52.227.227.35/ | ||
- | * 52.235.253.120/ | ||
- | * 52.243.152.68/ | ||
- | * 52.243.155.57/ | ||
- | * 52.243.156.34/ | ||
- | * 52.243.156.157/ | ||
- | * 52.243.156.164/ | ||
- | * 52.243.156.166/ | ||
- | * 52.243.156.209/ | ||
- | * 52.243.156.212/ | ||
- | * 52.244.34.47/ | ||
- | * 52.244.34.118/ | ||
- | * 52.244.34.125/ | ||
- | * 52.244.34.127/ | ||
- | * 52.244.34.129/ | ||
- | * 52.244.34.131/ | ||
- | * 52.244.34.133/ | ||
- | * 52.244.34.135/ | ||
- | * 52.244.239.112/ | ||
- | * 52.245.153.184/ | ||
- | * 2001: | ||
- | * 2001: | ||
- | * 2001: | ||
- | * 2001: | ||
- | * 2001: | ||
- | * 2001: | ||
- | * 2001: | ||
- | * 2001: |
guides/firewall_settings.1750366360.txt.gz · Last modified: by greg.dapkus