A secure internet border is one of the many levels of security required to protect University data. Computers and other devices that are connected to our campus network are regularly scanned, attacked, and attempted to be compromised from the internet. OIT implements additional security controls at the internet border to block malicious attacks from being directed toward the University systems. This secure internet border initiative can impact University device(s) and service(s) that need to provide services to users on the internet.
Any servers providing SSH, SFTP and SCP (port 22) services are not exempt from any blocks or rules as part of the secure internet border. To connect using this protocol, administrators must first authenticate through a VPN, which will prompt multi-factor authentication. Port 22 exceptions for general internet access will only be made if Duo is in place on the system.
Any new requests for port 443 (HTTPS) will require an exception request. Access requests for the insecure port 80 (HTTP) will no longer be accepted. Existing servers providing services on either port 80 (HTTP) or port 443 (HTTPS) are configured for continued access.
This change does not impact OIT managed servers in the data center. This change only relates to the internet border firewall which is managed separately by ESS. Only those systems managed by departments outside the central data center are impacted.
All exemptions will be reviewed by the Information Security Office (ISO). Approved requests will be sent to Networking for implementation.