Skip to content

Commit

Permalink
add global protect rules
Browse files Browse the repository at this point in the history
  • Loading branch information
Seb Norris committed Oct 16, 2023
1 parent 503fceb commit 727f4e5
Show file tree
Hide file tree
Showing 2 changed files with 20 additions and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -14,10 +14,28 @@ resource "aws_vpc_security_group_ingress_rule" "delius_core_frontend_alb_ingress
from_port = "443"
to_port = "443"
ip_protocol = "tcp"
cidr_ipv4 = "35.176.93.186/32" # Global Protect VPN
cidr_ipv4 = "81.134.202.29/32" # MoJ Digital VPN
}

resource "aws_vpc_security_group_ingress_rule" "delius_core_frontend_alb_ingress_http_allowlist" {
security_group_id = aws_security_group.delius_frontend_alb_security_group.id
description = "access into delius core frontend alb over http (will redirect)"
from_port = "80"
to_port = "80"
ip_protocol = "tcp"
cidr_ipv4 = "81.134.202.29/32" # MoJ Digital VPN
}

resource "aws_vpc_security_group_ingress_rule" "delius_core_frontend_alb_ingress_https_allowlist_gp" {
security_group_id = aws_security_group.delius_frontend_alb_security_group.id
description = "access into delius core frontend alb over https"
from_port = "443"
to_port = "443"
ip_protocol = "tcp"
cidr_ipv4 = "35.176.93.186/32" # Global Protect VPN
}

resource "aws_vpc_security_group_ingress_rule" "delius_core_frontend_alb_ingress_http_allowlist_gp" {
security_group_id = aws_security_group.delius_frontend_alb_security_group.id
description = "access into delius core frontend alb over http (will redirect)"
from_port = "80"
Expand Down
1 change: 1 addition & 0 deletions terraform/environments/delius-jitbit/lb.tf
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ resource "aws_security_group" "load_balancer_security_group" {
from_port = 443
to_port = 443
cidr_blocks = [
"81.134.202.29/32", # MoJ Digital VPN
"35.176.93.186/32", # Global Protect VPN
"217.33.148.210/32", # Digital studio
"195.59.75.0/24", # ARK internet (DOM1)
Expand Down

0 comments on commit 727f4e5

Please sign in to comment.