-
Notifications
You must be signed in to change notification settings - Fork 39
patch firewall KU Leuven #560
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: patch-firewall
Are you sure you want to change the base?
Conversation
Update conf.py for NX download link
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I suggest to not add a new section called Additional Firewall layer as that is ambiguous and a bit confusing. Instead we can rename the previous section from Connections from Abroad to something like Location Access Restrictions; and then explain what restrictions are in place with a tabbed table per site:
- KU Leuven clusters:
- managed laptops
- unmanaged laptops
- UAntwerp clusters:
- restrictions from abroad based on IP (copy paste existing text in
Connections from Abroad)
- restrictions from abroad based on IP (copy paste existing text in
- UGent clusters:
- restrictions from abroad based on IP (copy paste existing text in
Connections from Abroad)
- restrictions from abroad based on IP (copy paste existing text in
- VUB clusters:
- restrictions from abroad based on IP (copy paste existing text in
Connections from Abroad)
- restrictions from abroad based on IP (copy paste existing text in
| Additional Firewall layer | ||
| ========================= | ||
|
|
||
| Beginning of March 2026 an extra firewall layeter will be introdcued to connect to VSC clusters at KU Leuven: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| Beginning of March 2026 an extra firewall layeter will be introdcued to connect to VSC clusters at KU Leuven: | |
| Beginning of March 2026 an extra firewall layer will be introduced to connect to VSC clusters at KU Leuven: |
| There will be a difference between connecting from a managed Ku Leuven laptop and unmanaged laptops. KU Leuven managed laptops will use only the MFA (certificate) for connections both from Belgium and from abroad (without requesting :ref:`additional firewall login <additional_firewall>`). | ||
|
|
||
| On the other (non-KU Leuven managed laptops) there are several possibilities to connect to the Ku Leuven VSC clusters: | ||
|
|
||
| * Certificate only connection is possible from VSC network (other VSC clusters), | ||
|
|
||
| * Certificate and firewall will be nessary for all other cases: connecting from VPN B zone, from other VSC usniversities, from other Belgian IP addresses and from abroad. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe it is clear to follow with a list:
| There will be a difference between connecting from a managed Ku Leuven laptop and unmanaged laptops. KU Leuven managed laptops will use only the MFA (certificate) for connections both from Belgium and from abroad (without requesting :ref:`additional firewall login <additional_firewall>`). | |
| On the other (non-KU Leuven managed laptops) there are several possibilities to connect to the Ku Leuven VSC clusters: | |
| * Certificate only connection is possible from VSC network (other VSC clusters), | |
| * Certificate and firewall will be nessary for all other cases: connecting from VPN B zone, from other VSC usniversities, from other Belgian IP addresses and from abroad. | |
| There will be a difference between connecting from a managed KU Leuven laptop and unmanaged laptops. | |
| KU Leuven managed laptops | |
| Use MFA (certificate) for connections both from Belgium and from abroad. No need to request :ref:`additional firewall login <additional_firewall>`. | |
| Non-managed laptops | |
| There are several possibilities to connect to the KU Leuven VSC clusters: | |
| * Certificate only connection is possible from the VSC network (_i.e._ other VSC clusters) | |
| * Certificate and firewall will be necessary for all other cases: connecting from VPN B zone, from other VSC universities, from other Belgian IP addresses and from abroad |
It is indeed not an additional firewall layer, only a local change in our KU Leuven firewall setup. It moves from the node to the network, but that's not relevant to the user. Changing the "Abroad" section to 'location access restriction' looks like a good solution. |
Preparation for new central firewall setup at KU Leuven (not yet to be merged to master until almost applied)