Assets
Asset reference for Proxy.
This page documents the following assets:
- Acl Biz — Access rule on the business HTTPS proxy (proxy-biz). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-biz is dedicated to outgoing business traffic such as bank transactions, token validation and vendor or partner APIs. Destinations can only be reached on ports 22, 80, 389, 443, 636 and 1024-65535; all other ports are blocked.
- Acl Infra — Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.
- Acl Proxy Biz — Global Infrastructure proxy bizs
- Acl Proxy Infra — Global Infrastructure proxy infras
- Infra Acl — Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.
Acl Biz
Access rule on the business HTTPS proxy (proxy-biz). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-biz is dedicated to outgoing business traffic such as bank transactions, token validation and vendor or partner APIs. Destinations can only be reached on ports 22, 80, 389, 443, 636 and 1024-65535; all other ports are blocked.
Schema
The following properties describe a Acl Biz:
| Property | Type | Description |
|---|---|---|
from Required | list(string) | Source hosts allowed to open the flow. Each entry is a short hostname (e.g. "lb0101e1") or a regex matching short hostnames (e.g. "^lb[0-9]{4}e[1-3]$"). A regex is recommended so the rule keeps working after a source host is rebuilt. Full domain names, IP addresses and subnets are not accepted. Examples: ["^console02[0-9]{2}e[1-3]$"] |
name RequiredForceNew | string | Unique name of the access rule on proxy-biz. 1 to 40 characters, alphanumeric with hyphens or underscores (no spaces). Set once at creation and cannot be changed afterwards. Examples: ca-bank |
to Required | list(string) | External destinations the source hosts may reach. Each entry is a domain name (e.g. "credit-agricole.fr"), a leading-dot domain to also match its subdomains (e.g. ".credit-agricole.fr"), a domain regex (escape dots and anchor with $, e.g. "api[0-9]{2}\.credit-agricole\.fr$"), an IP address, or the keyword "all". URLs, port numbers, protocols and subnets are not accepted. Examples: ["credit-agricole.fr"] |
Examples
Acl Infra
Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.
Schema
The following properties describe a Acl Infra:
| Property | Type | Description |
|---|---|---|
from Required | list(string) | Source hosts allowed to open the flow. Each entry is a short hostname (e.g. "lb0101e1") or a regex matching short hostnames (e.g. "^lb[0-9]{4}e[1-3]$"). A regex is recommended so the rule keeps working after a source host is rebuilt. Full domain names, IP addresses and subnets are not accepted. Examples: ["^console02[0-9]{2}e[1-3]$"] |
name RequiredForceNew | string | Unique name of the access rule on proxy-infra. 1 to 40 characters, alphanumeric with hyphens or underscores (no spaces). Set once at creation and cannot be changed afterwards. Examples: slack-notifications |
to Required | list(string) | External destinations the source hosts may reach. Each entry is a domain name (e.g. "slack.com"), a leading-dot domain to also match its subdomains (e.g. ".slack.com"), a domain regex (escape dots and anchor with $, e.g. "hooks[0-9]{2}\.slack\.com$"), an IP address, or the keyword "all". URLs, port numbers, protocols and subnets are not accepted. Examples: ["slack.com"] |
Examples
Acl Proxy Biz
Global Infrastructure proxy bizs
Schema
The following properties describe a Acl Proxy Biz:
| Property | Type | Description |
|---|---|---|
from Required | list(string) | List of source addresses/networks Examples: ["^console02[0-9]{2}e[1-3]$"] |
name RequiredForceNew | string | Examples: my rule |
to Required | list(string) | List of destination addresses/networks Examples: ["credit-agricole.fr"] |
Examples
Acl Proxy Infra
Global Infrastructure proxy infras
Schema
The following properties describe a Acl Proxy Infra:
| Property | Type | Description |
|---|---|---|
from Required | list(string) | List of source addresses/networks Examples: ["^console02[0-9]{2}e[1-3]$"] |
name RequiredForceNew | string | Examples: my rule |
to Required | list(string) | List of destination addresses/networks Examples: ["slack.com"] |
Examples
Infra Acl
Access rule on the infrastructure HTTPS proxy (proxy-infra). All outgoing flows are denied by default, so each rule explicitly authorizes a set of internal source hosts to reach one or more external destinations. proxy-infra is dedicated to outgoing infrastructure traffic such as system updates and paging or monitoring services. Destinations can only be reached on ports 80, 443, 8080 and 8443; all other ports are blocked.
Schema
The following properties describe a Infra Acl:
| Property | Type | Description |
|---|---|---|
from Required | list(string) | Source hosts allowed to open the flow. Each entry is a short hostname (e.g. "lb0101e1") or a regex matching short hostnames (e.g. "^lb[0-9]{4}e[1-3]$"). A regex is recommended so the rule keeps working after a source host is rebuilt. Full domain names, IP addresses and subnets are not accepted. Examples: ["^console02[0-9]{2}e[1-3]$"] |
name RequiredForceNew | string | Unique name of the access rule on proxy-infra. 1 to 40 characters, alphanumeric with hyphens or underscores (no spaces). Set once at creation and cannot be changed afterwards. Examples: slack-notifications |
to Required | list(string) | External destinations the source hosts may reach. Each entry is a domain name (e.g. "slack.com"), a leading-dot domain to also match its subdomains (e.g. ".slack.com"), a domain regex (escape dots and anchor with $, e.g. "hooks[0-9]{2}\.slack\.com$"), an IP address, or the keyword "all". URLs, port numbers, protocols and subnets are not accepted. Examples: ["slack.com"] |