Secure Internet Border


A secure internet border is one of the many levels of security required to protect University data. Computers and other devices that are connected to our campus network are regularly scanned, attacked, and attempted to be compromised from the internet. OIT implements additional security controls at the internet border to block malicious attacks from being directed toward the University systems. This secure internet border initiative can impact University device(s) and service(s) that need to provide services to users on the internet.

SSH, SFTP and SCP (Port 22) and HTTP and HTTPS (Port 80/443) Exemption

Any servers providing SSH, SFTP and SCP (port 22) services are not exempt from any blocks or rules as part of the secure internet border. To connect using this protocol, administrators must first authenticate through a VPN, which will prompt multi-factor authentication. Port 22 exceptions for general internet access will only be made if Duo is in place on the system.

Any new requests for port 443 (HTTPS) will require an exception request. Access requests for the insecure port 80 (HTTP) will no longer be accepted. Existing servers providing services on either port 80 (HTTP) or port 443 (HTTPS) are configured for continued access.

This change does not impact OIT managed servers in the data center.  This change only relates to the internet border firewall which is managed separately by ESS.  Only those systems managed by departments outside the central data center are impacted.

Exemptions

  1. All IPSec VPN traffic is allowed.
  2. Computer Science networks are exempt from these blocks and any other IPS rules.
  3. All servers behind the OIT Firewalls will be exempt via the fw-servernet public IP address ranges for those networks.
  4. All individual exceptions that have been requested by departments.

Options

  1. If the device does not need to be accessible from outside the campus network, you do not need to take any action.  
  2. You should use VPN access to connect to this device from outside the campus network.  
  3. You must request an exception to continue to allow connectivity to the device from outside the campus network.   Exemption requests will be handled using a request form in the Princeton Service Portal: Exception Request for blocking port(s) or protocols

All exemptions will be reviewed by the Information Security Office (ISO).  Approved requests will be sent to Networking for implementation.