[INSTRM-532] Tweak Subaru observing machine access to PFS core machines Created: 19/Oct/18  Updated: 04/Dec/19

Status: Open
Project: Instrument control development
Component/s: None
Affects Version/s: None
Fix Version/s: None

Type: Task Priority: Normal
Reporter: cloomis Assignee: Yoshida, Hiroshige
Resolution: Unresolved Votes: 0
Labels: MCS, Subaru, subaru-personnel
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified


 Description   

Also,

According to the ACL, GEN2 is permitted to those nodes, on IP level so no TCP control.

Kiaina

To all,

hope this is proper way to respond. Please define Summit networks? Is this common dhcp network provided in the observation room? I have below a list of summit networks and purpose.

Sum-inst - dhcp available only for instrumentation
Visitor - dhcp available in staff, obs room (general usage by all users)

Kiaina

We need a couple of changes made to access control from the main Subaru observing machines to the main PFS machines. To wit, please open access

  • From the 133.40.166/23 OCS network, which contains the observing and simulator Gen2 hosts, and only other OCS hosts.
  • To 133.40.164. {17,64,86}: gen2-ics, mhs-ics, and shell-ics. No port controls.

Also, to make observing more sane, we ask that the Hilo base and Summit networks be allowed to connect directly to pfs-gw, but ONLY to port 22.

Kiaina Schubert eric philip

 

 



 Comments   
Comment by kyono [ 19/Oct/18 ]

Since successful MCS commissioning run has highest priority, we opened access

133.40.166.0/24 -> 133.40.164.{17,64,86}

133.40.167.0/24-->133.40.164.{17,64,86}

as we worked together this afternoon.

 

For Hilo Base and Summit network, please give us some more time to consider how this should be. It will stay as it is now for MCS commissioning run at least.

Eiji

Comment by Kiaina Schubert [ 04/Dec/19 ]

to all,

I added the following to PFS access-list
503 permit tcp 133.40.174.0/24 133.40.164.16/32 eq 22 (PERMITS Summit Visitor)
504 permit tcp 133.40.144.0/22 133.40.164.16 eq 22 (PERMITS Hilo Base)

Kiaina

Generated at Sat Feb 10 16:25:59 JST 2024 using Jira 8.3.4#803005-sha1:1f96e09b3c60279a408a2ae47be3c745f571388b.