Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 12 Next »

Purpose

The goal of this is to give trusted people on campus and within OIT, who request a lot of firewall rule changes or need to audit rules for their group, read-only access to firewall rules in a secure manner.  People often request access so they can audit their rules without a manual request of the security team, and want to be more knowledgeable of existing rules when they request new changes from the security team.  This will replace the insecure practice of emailing firewall rule configurations or people saving them locally.  However in most cases they still have to know how to interpret a raw Cisco ASA configuration.

Access Requirements

  1. Network Restriction: Limited to on-campus or via VPN
  2. Authentication: WebAuth + Duo Multi-Factor Authentication (instructions here)
  3. Authorization: KSAMS role membership (access request instructions here)
    1. For Campus Server Registration access: ITSEC "Firewall Rule Viewer - Campus" role
    2. For OIT internal access (which includes campus too): ITSEC "Firewall Rule Viewer - OIT" role

Instructions

  1. Login to https://systems.oit.uci.edu/FirewallRuleViewer/
  2. Choose Firewall (if the firewall you need is not listed, please contact security@uci.edu)
  3. Click Submit to view the rules configuration, some firewall device technical information, date/time it was last changed and the date/time it was last refreshed
    • Note: These are filtered yet raw Cisco firewall configuration files, you must be somewhat knowledgeable in networking to understand them
    • Note: Scheduled refresh of configuration data daily at 6:20am, 12:20pm, 5:20pm, 10:20pm

 

  • No labels