User Tools

Site Tools


security:addhealth

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
security:addhealth [2026/07/08 20:23] – [UCI Add Health server details] jnilssonsecurity:addhealth [2026/07/08 22:45] (current) jnilsson
Line 48: Line 48:
   * Maintaining administrative records such as access changes and system changes.   * Maintaining administrative records such as access changes and system changes.
   * Supporting UCI and UNC incident response activities.   * Supporting UCI and UNC incident response activities.
 +
 +===== Onboarding procedure =====
 +
 +When a new user is confirmed and approved by the PI:
 +  - Notify System administrators, who will create the user account
 +  - Authentication can be configured for new user accounts one of two ways:
 +    - Provide an [[:howto:sshkey|SSH key]] to [[socit@uci.edu]]
 +    - Schedule an on-boarding meeting (virtual or in-person) during which a password and MFA token will be configured.
 +  - Accounts will be set to expire after 1 year. Annual confirmation of current active users is required to re-enable accounts.
  
 ===== UCI Add Health server details ===== ===== UCI Add Health server details =====
Line 56: Line 65:
 ^ Session timeout | 30 minutes | ^ Session timeout | 30 minutes |
  
-===== Onboarding procedure =====+==== Firewall Restrictions: Allowed Network Access ====
  
-When a new user is confirmed and approved by the PI: +Only connections from on-campus or from the [[https://www.oit.uci.edu/services/security/vpn/|Cisco AnyConnect VPN]] will be allowed to connect to the serverIf you are off-campus or on a UCI-WiFi network, you must first connect to the VPN before attempting to connect to the Add Health server. 
-  Notify System administrators, who will create the user account + 
-  - Authentication can be configured for new user accounts one of two ways: +Firewall restrictions in place on the server only allow connections from these subnets: 
-    - Provide an [[:howto:sshkey|SSH key]] to socit@uci.edu +^ Subnet name ^ CIDR ^ 
-    Schedule an on-boarding meeting (virtual or in-person) during which a password and MFA token will be configured+| Campus Network 128.195 | 128.195.0.0/16 | 
-  - Accounts will be set to expire after 1 yearAnnual confirmation of current active users is required to re-enable accounts.+| Campus Network 128.200 | 128.200.0.0/16 | 
 +| VPN | 172.23.0.0/20 |
  
  
security/addhealth.1783542215.txt.gz · Last modified: 2026/07/08 20:23 by jnilsson