Skip to Main Content

NEW Firewall Exception Request Examples

Single Exception - Departmental Web Server

In this example the requester wants a departmental HTTP Web Server to be able to be reached by one or more IP addresses on the Internet.

  • Both Edge and Departmental firewalls have been checked on the Firewall Exception Request form to accommodate this traffic.
  • The IP assigned to the HTTP WebServer is specified as
  • IP restrictions (available to any/all IPs), action, and direction have been selected.
  • The departmental server does not contain or process sensitive data.
Single Exception - Departmental Web Server
Request Type(s) Inside IP Address or Range Service Group(s) Outside IP Address or Range Action Direction Sensitive Data
Departmental HTTP Web Server (port 80) any * Permit * Toward Inside IP * (No)

Single Exception - Departmental Web Server in the BDC

In the example below, the requester wants a departmental HTTP Web Server in the BDC,located at, to be able to send data to, and receive data from, the Internet.

  • Both Edge and Departmental firewalls have been checked on the Firewall Exception Request form to accommodate this traffic.
  • The IPs assigned to the server is specified as
  • IP restrictions (available to all IPs), action, and direction have been selected.
  • The BDC server does not contain or process sensitive data.
Single Exception - Departmental Web Server in BDC
Request Type(s) Inside IP Address or Range Service Group(s) Outside IP Address or Range Action Direction Sensitive Data
BDC HTTP Web Server (port 80) any * Permit * Bidirectional * Yes

Range Exception - Departmental Web Server Cluster

In the example below, the requester wants a departmental web server cluster that provides both HTTP service and HTTPS service to be able to be reached by one or more IP addresses on the Internet..

  • Both Edge and Departmental firewalls have been checked on the Firewall Exception Request form to accommodate this traffic.
  • The IPs assigned to the cluster are - (or Range for IPs have been specified using a hyphen (-).
  • IP restrictions (available to all IPs), action, and direction have been selected.
  • The specified server cluster does not contain or process sensitive data.
Range Exception - Departmental Web Server Cluster
Request Type(s) Inside IP Address or Range Service Group(s) Outside IP Address or Range Action Direction Sensitive Data
Departmental -
HTTP Web Server (port 80), HTTPS Web Server (port 443) any * Permit * Toward Inside IP * (No)

Multiple Exceptions - Multiple Departmental and BDC Servers

In the example below the requester wants the Departmental server that provides both HTTP service and HTTPS service to be able to send data to the Internet, the BDC server that provides STMP service to both send and receive data to the internet and the BDC Departmental server that provides SSH service to send data to the internet.

  • BDC, Edge and Departmental firewalls have been checked on the Firewall Exception Request form to accommodate this traffic.
  • Multiple IP ranges have been specified for the servers, using accepted notation.
  • IP restrictions (available to all IPs), action, and direction have been selected.
  • None of the servers processes or stores sensitive data.
Multiple Exceptions - Multiple Departmental and BDC Servers
Request Type(s) Inside IP Address or Range Service Group(s) Outside IP Address or Range Action Direction Sensitive Data
Departmental - HTTP Web Server (port 80), HTTPS Web Server (port 443) any * Permit * Toward Inside IP * (No)
BDC STMP (port 225) any * Permit * Bidirectional * (No)
Departmental SSH service (port 22) any * Permit * Toward Inside IP * (No)