Global InfraGlobal Infra Cloud

Assets

Asset reference for Proxy.

Edit

This page documents the following assets:

  • Acl Biz — Access rule on the business HTTPS proxy (proxy-biz). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-biz is dedicated to outgoing business traffic such as bank transactions, token validation and vendor or partner APIs. Destinations can only be reached on ports 22, 80, 389, 443, 636 and 1024-65535; all other ports are blocked.
  • Acl Infra — Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.
  • Acl Proxy Biz — Global Infrastructure proxy bizs
  • Acl Proxy Infra — Global Infrastructure proxy infras
  • Infra Acl — Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.

Acl Biz

Access rule on the business HTTPS proxy (proxy-biz). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-biz is dedicated to outgoing business traffic such as bank transactions, token validation and vendor or partner APIs. Destinations can only be reached on ports 22, 80, 389, 443, 636 and 1024-65535; all other ports are blocked.

Schema

The following properties describe a Acl Biz:

PropertyTypeDescription
from
Required
list(string)Source hosts allowed to open the flow. Each entry is a short hostname (e.g. "lb0101e1") or a regex matching short hostnames (e.g. "^lb[0-9]{4}e[1-3]$"). A regex is recommended so the rule keeps working after a source host is rebuilt. Full domain names, IP addresses and subnets are not accepted.
Examples:["^console02[0-9]{2}e[1-3]$"]
name
RequiredForceNew
stringUnique name of the access rule on proxy-biz. 1 to 40 characters, alphanumeric with hyphens or underscores (no spaces). Set once at creation and cannot be changed afterwards.
Examples:ca-bank
to
Required
list(string)External destinations the source hosts may reach. Each entry is a domain name (e.g. "credit-agricole.fr"), a leading-dot domain to also match its subdomains (e.g. ".credit-agricole.fr"), a domain regex (escape dots and anchor with $, e.g. "api[0-9]{2}\.credit-agricole\.fr$"), an IP address, or the keyword "all". URLs, port numbers, protocols and subnets are not accepted.
Examples:["credit-agricole.fr"]

Examples


Acl Infra

Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.

Schema

The following properties describe a Acl Infra:

PropertyTypeDescription
from
Required
list(string)Source hosts allowed to open the flow. Each entry is a short hostname (e.g. "lb0101e1") or a regex matching short hostnames (e.g. "^lb[0-9]{4}e[1-3]$"). A regex is recommended so the rule keeps working after a source host is rebuilt. Full domain names, IP addresses and subnets are not accepted.
Examples:["^console02[0-9]{2}e[1-3]$"]
name
RequiredForceNew
stringUnique name of the access rule on proxy-infra. 1 to 40 characters, alphanumeric with hyphens or underscores (no spaces). Set once at creation and cannot be changed afterwards.
Examples:slack-notifications
to
Required
list(string)External destinations the source hosts may reach. Each entry is a domain name (e.g. "slack.com"), a leading-dot domain to also match its subdomains (e.g. ".slack.com"), a domain regex (escape dots and anchor with $, e.g. "hooks[0-9]{2}\.slack\.com$"), an IP address, or the keyword "all". URLs, port numbers, protocols and subnets are not accepted.
Examples:["slack.com"]

Examples


Acl Proxy Biz

Global Infrastructure proxy bizs

Schema

The following properties describe a Acl Proxy Biz:

PropertyTypeDescription
from
Required
list(string)List of source addresses/networks
Examples:["^console02[0-9]{2}e[1-3]$"]
name
RequiredForceNew
string
Examples:my rule
to
Required
list(string)List of destination addresses/networks
Examples:["credit-agricole.fr"]

Examples


Acl Proxy Infra

Global Infrastructure proxy infras

Schema

The following properties describe a Acl Proxy Infra:

PropertyTypeDescription
from
Required
list(string)List of source addresses/networks
Examples:["^console02[0-9]{2}e[1-3]$"]
name
RequiredForceNew
string
Examples:my rule
to
Required
list(string)List of destination addresses/networks
Examples:["slack.com"]

Examples


Infra Acl

Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.

Schema

The following properties describe a Infra Acl:

PropertyTypeDescription
from
Required
list(string)Source hosts allowed to open the flow. Each entry is a short hostname (e.g. "lb0101e1") or a regex matching short hostnames (e.g. "^lb[0-9]{4}e[1-3]$"). A regex is recommended so the rule keeps working after a source host is rebuilt. Full domain names, IP addresses and subnets are not accepted.
Examples:["^console02[0-9]{2}e[1-3]$"]
name
RequiredForceNew
stringUnique name of the access rule on proxy-infra. 1 to 40 characters, alphanumeric with hyphens or underscores (no spaces). Set once at creation and cannot be changed afterwards.
Examples:slack-notifications
to
Required
list(string)External destinations the source hosts may reach. Each entry is a domain name (e.g. "slack.com"), a leading-dot domain to also match its subdomains (e.g. ".slack.com"), a domain regex (escape dots and anchor with $, e.g. "hooks[0-9]{2}\.slack\.com$"), an IP address, or the keyword "all". URLs, port numbers, protocols and subnets are not accepted.
Examples:["slack.com"]

Examples

On this page