|
Network Service Access to User Managed MachinesSince June 2008, all computers in the Faculty of Engineering and Computer Science other than AITS-managed servers have "client-only" network access; that is, they are able to initiate connections to other computers outside their local network, but are not be able to accept traffic initiated from machines outside their local network, with the following exceptions:
Procedure for requesting permission to offer network serviceTo request permission to offer a network service, the responsible faculty member must send a message to facultyhelp at encs.concordia.ca specifying
"Grandfathering"User-managed computers that had been acting as servers prior to June 18, 2008 have not been automatically blocked, but AITS staff will communicate with the responsible faculty members to determine precisely which services need to be offered, so that these machines can be smoothly integrated into the new framework.Vulnerability monitoringAll computers in the Faculty of Engineering and Computer Science, including user-managed computers, must allow vulnerability scanning by AITS's two Nessus vulnerability scanners: 132.205.96.199 and 132.205.96.150. That is, no computer should deny service to these addresses. If a user-managed computer is found to have a known vulnerability, the registered administrator of the machine will be notified and must take the required action to correct the problem.
Author: Michael Assels
Credits: Anne Bennett Last update: 2009/04/28 -- Michael Assels |
|||||||
If you have any comments about the website please e-mail us. |