Closed Bug 790719 Opened 12 years ago Closed 12 years ago

Lots of flows for KMS

Categories

(Infrastructure & Operations Graveyard :: NetOps: DC ACL Request, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: dustin, Assigned: cransom)

References

Details

Windows updates are over tcp/1688

Everything windows needs to talk to this port, so we'll need access from entire vlans:
 vlan40 in scl1
 vlan69 in scl1, scl3, and phx1
to
 kms1.ad.mozilla.com:tcp/1688

It's quite possible that we'll eventually have other kms/wsus hosts, if that helps think about how to design the policy.  If you'd like to pre-allocate a block of IPs, we can move kms1.ad.mozilla.com into it pretty easily (it's not in prod yet).
Assignee: network-operations → cransom
(In reply to Dustin J. Mitchell [:dustin] from comment #0)
> Windows updates are over tcp/1688
> 
> Everything windows needs to talk to this port, so we'll need access from
> entire vlans:
>  vlan40 in scl1
This has been added.
>  vlan69 in scl1, scl3, and phx1
These already existed in previous policies.
> to
>  kms1.ad.mozilla.com:tcp/1688
> 
> It's quite possible that we'll eventually have other kms/wsus hosts, if that
> helps think about how to design the policy.  If you'd like to pre-allocate a
> block of IPs, we can move kms1.ad.mozilla.com into it pretty easily (it's
> not in prod yet).

Unless we get into the dozens of kms hosts, I don't think it's necessary. The way projects tend to grow (and decay), carving out blocks of IPs ends up being a self defeating mental exercise and it's just simpler to add in groups of individual addresses rather than big blocks.
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
For the record, these aren't windows update, these are for KMS (licensing).  I confused myself with the name.  The flows are still correct :)
Summary: Lots of Windows Updates flows → Lots of flows for KMS
Blocks: 792995
Product: mozilla.org → Infrastructure & Operations
Product: Infrastructure & Operations → Infrastructure & Operations Graveyard
You need to log in before you can comment on or make changes to this bug.