<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.reddnet.org/mwiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Wikiadmin</id>
	<title>ReddNet - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://www.reddnet.org/mwiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Wikiadmin"/>
	<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php/Special:Contributions/Wikiadmin"/>
	<updated>2026-05-25T00:42:56Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.3</generator>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4116</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4116"/>
		<updated>2012-05-03T19:32:59Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Depots =&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  The node uses an average of 250 Watts in regular usage, but in extreme instances may spike up to 350 Watts.  Please let us know whether your site uses 110V or 220V power so we can make sure the appropriate power cables are included.&lt;br /&gt;
&lt;br /&gt;
[http://www.reddnet.org/mwiki/index.php/REDDNet_Depot_Installation_Instructions Click here] to get information on the correct order for installing the depot hardware.&lt;br /&gt;
&lt;br /&gt;
= IP Addresses =&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
= Network Ports on your Switch =&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
= Required Network Ports =&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 192.111.108.101&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5120 and 5123&lt;br /&gt;
|remote cd/floppy&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 192.111.108.101 and 192.111.108.103&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 192.111.108.101 and 192.111.108.103&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/53&lt;br /&gt;
|dns&lt;br /&gt;
|allow DNS to 129.59.197.151&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 192.111.108.101 and 192.111.108.103&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4115</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4115"/>
		<updated>2012-01-13T22:42:40Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Depots =&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  The node uses an average of 250 Watts in regular usage, but in extreme instances may spike up to 350 Watts.  Please let us know whether your site uses 110V or 220V power so we can make sure the appropriate power cables are included.&lt;br /&gt;
&lt;br /&gt;
[http://www.reddnet.org/mwiki/index.php/REDDNet_Depot_Installation_Instructions Click here] to get information on the correct order for installing the depot hardware.&lt;br /&gt;
&lt;br /&gt;
= IP Addresses =&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
= Network Ports on your Switch =&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
= Required Network Ports =&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5120 and 5123&lt;br /&gt;
|remote cd/floppy&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60, 129.59.197.90, and 129.59.197.153&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60, 129.59.197.90, and 129.59.197.153&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/53&lt;br /&gt;
|dns&lt;br /&gt;
|allow DNS to 129.59.197.151&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60, 129.59.197.90, and 129.59.197.153&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4114</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4114"/>
		<updated>2010-09-07T20:36:30Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Depots =&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  The node uses an average of 250 Watts in regular usage, but in extreme instances may spike up to 350 Watts.  Please let us know whether your site uses 110V or 220V power so we can make sure the appropriate power cables are included.&lt;br /&gt;
&lt;br /&gt;
[http://www.reddnet.org/mwiki/index.php/REDDNet_Depot_Installation_Instructions Click here] to get information on the correct order for installing the depot hardware.&lt;br /&gt;
&lt;br /&gt;
= IP Addresses =&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
= Network Ports on your Switch =&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
= Required Network Ports =&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5120 and 5123&lt;br /&gt;
|remote cd/floppy&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/53&lt;br /&gt;
|dns&lt;br /&gt;
|allow DNS to 129.59.197.151&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4113</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4113"/>
		<updated>2010-09-02T21:00:56Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Depots =&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  The node uses an average of 250 Watts in regular usage, but in extreme instances may spike up to 350 Watts.  Please let us know whether your site uses 110V or 220V power so we can make sure the appropriate power cables are included.&lt;br /&gt;
&lt;br /&gt;
[http://www.reddnet.org/mwiki/index.php/REDDNet_Depot_Installation_Instructions Click here] to get information on the correct order for installing the depot hardware.&lt;br /&gt;
&lt;br /&gt;
= IP Addresses =&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
= Network Ports on your Switch =&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
= Required Network Ports =&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/53&lt;br /&gt;
|dns&lt;br /&gt;
|allow DNS to 129.59.197.151&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4100</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4100"/>
		<updated>2010-04-01T23:00:11Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
Before you begin, please make sure you have met the  [http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements basic site requirements]&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-back.jpeg|thumb|480px|Back of depot]]&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in an ethernet cable to the management port.&lt;br /&gt;
#  Plug in an appropriate network cables to the data ports (depends on whether you are using 10 Gb or 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.   It is recommended to plug the key into the external USB port on the back.  However, if you cannot for whatever reason, there are two USB ports inside the chassis on the motherboard.&lt;br /&gt;
#  Plug in the two power cables.&lt;br /&gt;
#  Turn on depot, and verify that the machine boots to a Linux command prompt.&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-motherboard-usb.jpg|thumb|480px|Motherboard with onboard USB ports highlighted]]&lt;br /&gt;
&lt;br /&gt;
= Configuring the depot for remote management =&lt;br /&gt;
&lt;br /&gt;
You will need to log into the BIOS on the depot and set up the remote IPMI function so we can administer it.&lt;br /&gt;
&lt;br /&gt;
#  Power on the depot.&lt;br /&gt;
#  Hit the &amp;quot;Del&amp;quot; button during boot to get to the BIOS&lt;br /&gt;
#  Push the right arrow button to tabe to the &amp;quot;Advanced&amp;quot; setting&lt;br /&gt;
#  Scroll down to &amp;quot;IPMI Configuration&amp;quot; and hit &amp;quot;Enter&amp;quot;&lt;br /&gt;
#  Scroll down to &amp;quot;Set LAN Configuration&amp;quot; and hit &amp;quot;Enter&amp;quot;&lt;br /&gt;
#  Select DHCP or Static IP addresses depending on which you will be using&lt;br /&gt;
#  If you use static IP's enter the IP address, subnet mask, and gateway address for the management port&lt;br /&gt;
#  Take note of the IP address for this box.   We will need it so we can log into it.&lt;br /&gt;
#  Hit &amp;quot;Esc&amp;quot; twice to return you to the main BIOS screen.&lt;br /&gt;
#  Click on &amp;quot;Exit&amp;quot;, then &amp;quot;Save Changes and Exit&amp;quot;&lt;br /&gt;
#  Finally, please email the IP address to REDDNet staff.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4099</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4099"/>
		<updated>2010-04-01T22:45:52Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
Before you begin, please make sure you have met the  [http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements basic site requirements]&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-back.jpeg|thumb|480px|Back of depot]]&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in an ethernet cable to the management port.&lt;br /&gt;
#  Plug in an appropriate network cables to the data ports (depends on whether you are using 10 Gb or 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.   It is recommended to plug the key into the external USB port on the back.  However, if you cannot for whatever reason, there are two USB ports inside the chassis on the motherboard.&lt;br /&gt;
#  Plug in the two power cables.&lt;br /&gt;
#  Turn on depot.&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-motherboard-usb.jpg|thumb|480px|Motherboard with onboard USB ports highlighted]]&lt;br /&gt;
&lt;br /&gt;
= Configuring the depot for remote management =&lt;br /&gt;
&lt;br /&gt;
You will need to log into the BIOS on the depot and set up the remote IPMI function so we can administer it.&lt;br /&gt;
&lt;br /&gt;
#  Power on the depot.&lt;br /&gt;
#  Hit the &amp;quot;Del&amp;quot; button during boot to get to the BIOS&lt;br /&gt;
#  Push the right arrow button to tabe to the &amp;quot;Advanced&amp;quot; setting&lt;br /&gt;
#  Scroll down to &amp;quot;IPMI Configuration&amp;quot; and hit &amp;quot;Enter&amp;quot;&lt;br /&gt;
#  Scroll down to &amp;quot;Set LAN Configuration&amp;quot; and hit &amp;quot;Enter&amp;quot;&lt;br /&gt;
#  Select DHCP or Static IP addresses depending on which you will be using&lt;br /&gt;
#  If you use static IP's enter the IP address, subnet mask, and gateway address for the management port&lt;br /&gt;
#  Take note of the IP address for this box.   We will need it so we can log into it.&lt;br /&gt;
#  Hit &amp;quot;Esc&amp;quot; twice to return you to the main BIOS screen.&lt;br /&gt;
#  Click on &amp;quot;Exit&amp;quot;, then &amp;quot;Save Changes and Exit&amp;quot;&lt;br /&gt;
#  Finally, please email the IP address to REDDNet staff.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4098</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4098"/>
		<updated>2010-04-01T21:56:45Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
Before you begin, please make sure you have met the  [http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements basic site requirements]&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-back.jpeg|thumb|480px|Back of depot]]&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in an ethernet cable to the management port.&lt;br /&gt;
#  Plug in an appropriate network cables to the data ports (depends on whether you are using 10 Gb or 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.   It is recommended to plug the key into the external USB port on the back.  However, if you cannot for whatever reason, there are two USB ports inside the chassis on the motherboard.&lt;br /&gt;
#  Plug in the two power cables.&lt;br /&gt;
#  Turn on depot.&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-motherboard-usb.jpg|thumb|480px|Motherboard with onboard USB ports highlighted]]&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=File:2010-depot-motherboard-usb.jpg&amp;diff=4097</id>
		<title>File:2010-depot-motherboard-usb.jpg</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=File:2010-depot-motherboard-usb.jpg&amp;diff=4097"/>
		<updated>2010-04-01T21:54:19Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: Photo of the motherboard in a standard 2010 depot.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Photo of the motherboard in a standard 2010 depot.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4096</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4096"/>
		<updated>2010-04-01T21:48:23Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
Before you begin, please make sure you have met the  [http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements basic site requirements]&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-back.jpeg|thumb|480px|Back of depot]]&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in an ethernet cable to the management port.&lt;br /&gt;
#  Plug in an appropriate network cables to the data ports (depends on whether you are using 10 Gb or 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.&lt;br /&gt;
#  Plug in power cable.&lt;br /&gt;
#  Turn on depot.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4095</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4095"/>
		<updated>2010-04-01T21:47:07Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
Before you begin, please make sure you have met the  [http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements basic site requirements]&lt;br /&gt;
&lt;br /&gt;
[[image:2010-depot-back.jpeg|thumb|480px|Back of depot]]&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in network cable to management port.&lt;br /&gt;
#  Plug in appropriate network cables (10 Gb / 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.&lt;br /&gt;
#  Plug in power cable.&lt;br /&gt;
#  Turn on depot.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=File:2010-depot-back.jpeg&amp;diff=4094</id>
		<title>File:2010-depot-back.jpeg</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=File:2010-depot-back.jpeg&amp;diff=4094"/>
		<updated>2010-04-01T21:40:53Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: This is a view of the back of a 2010 standard depot.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is a view of the back of a 2010 standard depot.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4093</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4093"/>
		<updated>2010-04-01T18:52:37Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Depots =&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  The node uses an average of 250 Watts in regular usage, but in extreme instances may spike up to 350 Watts.  Please let us know whether your site uses 110V or 220V power so we can make sure the appropriate power cables are included.&lt;br /&gt;
&lt;br /&gt;
[http://www.reddnet.org/mwiki/index.php/REDDNet_Depot_Installation_Instructions Click here] to get information on the correct order for installing the depot hardware.&lt;br /&gt;
&lt;br /&gt;
= IP Addresses =&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
= Network Ports on your Switch =&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
= Required Network Ports =&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4092</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4092"/>
		<updated>2010-04-01T18:51:47Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
Before you begin, please make sure you have met the  [http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements basic site requirements]&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in network cable to management port.&lt;br /&gt;
#  Plug in appropriate network cables (10 Gb / 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.&lt;br /&gt;
#  Plug in power cable.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4091</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4091"/>
		<updated>2010-04-01T18:50:57Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
Before you begin, please make sure you have met the basic site requirements listed at http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in network cable to management port.&lt;br /&gt;
#  Plug in appropriate network cables (10 Gb / 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.&lt;br /&gt;
#  Plug in power cable.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4090</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4090"/>
		<updated>2010-04-01T18:50:20Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Depots =&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  The node uses an average of 250 Watts in regular usage, but in extreme instances may spike up to 350 Watts.  Please let us know whether your site uses 110V or 220V power so we can make sure the appropriate power cables are included.&lt;br /&gt;
&lt;br /&gt;
= IP Addresses =&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
= Network Ports on your Switch =&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
= Required Network Ports =&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in network cable to management port.&lt;br /&gt;
#  Plug in appropriate network cables (10 Gb / 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.&lt;br /&gt;
#  Plug in power cable.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4089</id>
		<title>REDDNet Depot Installation Instructions</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Depot_Installation_Instructions&amp;diff=4089"/>
		<updated>2010-03-31T21:45:00Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: Created page with '= Installation instructions =  IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI m…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in network cable to management port.&lt;br /&gt;
#  Plug in appropriate network cables (10 Gb / 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.&lt;br /&gt;
#  Plug in power cable.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4088</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4088"/>
		<updated>2010-03-31T21:42:24Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Depots =&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  We will provide power requirements for this box at a later date.   You need to tell us if you site uses 110 or 220V power.&lt;br /&gt;
&lt;br /&gt;
= IP Addresses =&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
= Network Ports on your Switch =&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
= Required Network Ports =&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Installation instructions =&lt;br /&gt;
&lt;br /&gt;
IMPORTANT!!! Do not plug the power cable in until step 5.  If you plug the power in before connecting the management network cable, then the IPMI module will not initialize properly and remote management/KVM will not work.&lt;br /&gt;
&lt;br /&gt;
#  Unpack the machine, install the rails, and mount in your rack as you normally would. &lt;br /&gt;
#  Plug in network cable to management port.&lt;br /&gt;
#  Plug in appropriate network cables (10 Gb / 1 Gb)&lt;br /&gt;
#  Plug in the REDDNet USB key into a free USB port.&lt;br /&gt;
#  Plug in power cable.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4085</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4085"/>
		<updated>2010-03-31T17:13:22Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  We will provide power requirements for this box at a later date.   You need to tell us if you site uses 110 or 220V power.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/8080&lt;br /&gt;
|tomcat&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4084</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4084"/>
		<updated>2010-03-31T16:31:14Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot is a 2U server with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  The depots connect to the network via 10 Gb ethernet (preferred) or 1 Gb ethernet.  We will provide power requirements for this box at a later date.   You need to tell us if you site uses 110 or 220V power.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic (in order of preference):&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics your switch requires, as well as if you need a connecting fiber cable.&lt;br /&gt;
&lt;br /&gt;
* At sites without 10 Gb support but which support link aggregation, we can use two 1 Gb ethernet cables bonded together in 802.3ad mode to get 2 Gb/sec performance.  This requires a switch which supports 802.3ad bonding, and two switch ports and two ethernet cables per depot.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4083</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4083"/>
		<updated>2010-03-31T15:15:01Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration a 2U server, with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.   You need to tell us if you site uses 110 or 220V power.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic:&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics you require, as well as if you need fiber.&lt;br /&gt;
&lt;br /&gt;
* Each depot has two network interfaces, so if supported by your switch, we can use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   &lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4082</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4082"/>
		<updated>2010-03-31T15:14:16Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic:&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics you require, as well as if you need fiber.&lt;br /&gt;
&lt;br /&gt;
* Each depot has two network interfaces, so if supported by your switch, we can use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   &lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4081</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4081"/>
		<updated>2010-03-31T15:13:06Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic:&lt;br /&gt;
&lt;br /&gt;
* Preferably,the depot can connect via 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.   Please let us know what type of optics you require, as well as if you need fiber.&lt;br /&gt;
&lt;br /&gt;
* Each depot has two network interfaces, so if supported by your switch, we can use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   &lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interfaces:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4080</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4080"/>
		<updated>2010-03-31T15:10:14Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 4-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic:&lt;br /&gt;
&lt;br /&gt;
* Each depot has two network interfaces, so if supported by your switch, we can use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   &lt;br /&gt;
&lt;br /&gt;
* The depot may optionally include 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interfaces:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4079</id>
		<title>REDDnet LStore Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4079"/>
		<updated>2010-03-30T21:28:57Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Data Security==&lt;br /&gt;
&lt;br /&gt;
L-Store is currently under development.  At the moment, data is not encrypted in transit or in storage.  If the user desires, they may use common encryption tools such as OpenSSL or GnuPG to encrypt their data before uploading.&lt;br /&gt;
&lt;br /&gt;
Cursory work on an OpenSSL-encrypted upload/download has been done, but is not yet ready for public use.&lt;br /&gt;
&lt;br /&gt;
==Data Integrity==&lt;br /&gt;
&lt;br /&gt;
When the client uploads a file to the depots, it can optionally compute a MD5 hash of the file and store that information in the metadata on the server.   Downloaded files can be hashed and compared with the stored value to verify integrity (though this is not yet automated).&lt;br /&gt;
&lt;br /&gt;
We intended to make the choice of hash user-selectable in the future.  We intend to support SHA-1, SHA-256, SHA-512 hashes, and possibly other hashes as supported by the base SSL library.&lt;br /&gt;
&lt;br /&gt;
==Data Reliability==&lt;br /&gt;
&lt;br /&gt;
Data stored on depots is encoded with RAID 5 redundancy.  The user may specify this redundancy across hard drives, across depots, and/or across sites.  REDDNet monitors depots for drive failures using Nagios, and if a loss of redundancy is detected we correct the error on our end.&lt;br /&gt;
&lt;br /&gt;
In addition, we are working on a generalized Reed-Solomon code that will allow users to specify an arbitrary amount of redundancy.  For example, you could have 10 drives and have 4 of them fail before you lost redundancy.   We expect this generalized redundancy code to be completed in summer 2010.&lt;br /&gt;
&lt;br /&gt;
==Access Permissions==&lt;br /&gt;
&lt;br /&gt;
We are implementing a generic policy framework that allows for custom security policies (role-based, Unix ACL and permissions) based on user requirements.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4078</id>
		<title>REDDnet LStore Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4078"/>
		<updated>2010-03-30T21:27:43Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Data Security==&lt;br /&gt;
&lt;br /&gt;
L-Store is currently under development.  At the moment, data is not encrypted in transit or in storage.  If the user desires, they may use common encryption tools such as OpenSSL or GnuPG to encrypt their data before uploading.&lt;br /&gt;
&lt;br /&gt;
Cursory work on an OpenSSL-encrypted upload/download has been done, but is not yet ready for public use.&lt;br /&gt;
&lt;br /&gt;
==Data Integrity==&lt;br /&gt;
&lt;br /&gt;
When the client uploads a file to the depots, it computes a MD5 hash of the file and stores that information in the metadata on the server.   Downloaded files can be hashed and compared with the stored value to verify integrity (though this is not yet automated).&lt;br /&gt;
&lt;br /&gt;
We intended to make the choice of hash user-selectable in the future.  We intend to support SHA-1, SHA-256, SHA-512 hashes, and possibly other hashes as supported by the base SSL library.&lt;br /&gt;
&lt;br /&gt;
==Data Reliability==&lt;br /&gt;
&lt;br /&gt;
Data stored on depots is encoded with RAID 5 redundancy.  The user may specify this redundancy across hard drives, across depots, and/or across sites.  REDDNet monitors depots for drive failures using Nagios, and if a loss of redundancy is detected we correct the error on our end.&lt;br /&gt;
&lt;br /&gt;
In addition, we are working on a generalized Reed-Solomon code that will allow users to specify an arbitrary amount of redundancy.  For example, you could have 10 drives and have 4 of them fail before you lost redundancy.   We expect this generalized redundancy code to be completed in summer 2010.&lt;br /&gt;
&lt;br /&gt;
==Access Permissions==&lt;br /&gt;
&lt;br /&gt;
We are implementing a generic policy framework that allows for custom security policies (role-based, Unix ACL and permissions) based on user requirements.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_Remote_Site_Security_Overview&amp;diff=4077</id>
		<title>REDDnet Remote Site Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_Remote_Site_Security_Overview&amp;diff=4077"/>
		<updated>2010-03-30T21:27:33Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Physical security==&lt;br /&gt;
&lt;br /&gt;
Locations at remote sites depend on user requirements.  It is strongly suggested that  access to the room be restricted by key, pass card, or another token.  The room should not be accessible to the general public.  Only administrative and technical contacts as defined in the MoU will be granted restricted login rights to the depots for maintenance purposes.&lt;br /&gt;
&lt;br /&gt;
==Network security==&lt;br /&gt;
&lt;br /&gt;
Remote depots require several network ports open to either Vanderbilt or the world for proper functioning and monitoring.  A list of required ports may be found at:&lt;br /&gt;
&lt;br /&gt;
http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements&lt;br /&gt;
&lt;br /&gt;
Remote sites must ensure that these ports are open as described, both at a departmental level and at your organization's perimeter firewall.  &lt;br /&gt;
&lt;br /&gt;
Remote depots will have an IPTables firewall to limit connections by port and by source/destination to only those required for operation.  This will be maintained by REDDNet staff.&lt;br /&gt;
&lt;br /&gt;
==OS security==&lt;br /&gt;
&lt;br /&gt;
REDDNet monitors CERT, CryptoGram, and other security forums daily for new security errata.  We use apt-get to keep all depots up-to-date with security fixes at least once a week (and usually every 1-2 days).  All machines are updated as soon as Ubuntu/Debian releases a security update.&lt;br /&gt;
&lt;br /&gt;
When critical vulnerabilities are discovered, we may disable services or install our own custom update until such time as the vendor releases their own update.&lt;br /&gt;
&lt;br /&gt;
==Application security==&lt;br /&gt;
&lt;br /&gt;
Due to firewall restrictions we cannot perform Nessus scans of remote depots.    We encourage local sites (either departmentally or globally) to perform their own regular Nessus scans on remote depots.  When a weakness is discovered at any depot, REDDNet staff will propagate the fix to all other depots.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4076</id>
		<title>REDDnet Vanderbilt Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4076"/>
		<updated>2010-03-30T21:27:21Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Physical security==&lt;br /&gt;
&lt;br /&gt;
Core REDDNet hardware at Vanderbilt University is located in Vanderbilt's Network Operations Center (NOC).  The NOC command center is staffed 24/7/365 by VU's Information Technology Services (ITS) staff.  The facility is secured by card access and access is limited to ITS, VU Management Information Systems staff, and owners of the systems housed in the NOC.  All visitors to the NOC must sign in and are under constant video surveillance while inside.&lt;br /&gt;
&lt;br /&gt;
==Network security==&lt;br /&gt;
&lt;br /&gt;
REDDNet core equipment is secured by a FreeBSD firewall operating as a transparent bridge.  As a transparent bridge, the firewall does not have an IP address, and is not detectable from the outside world.  All off-campus access is logged to aid in forensic analysis should that proves necessary.&lt;br /&gt;
&lt;br /&gt;
All Vanderbilt core equipment also has IPTables firewalls.  Rulesets on both local IPTables and the primary FreeBSD firewall are kept in sync to allow them to perform failover security if one layer should be down.&lt;br /&gt;
Network traffic is limited by port and by source/destination to only those necessary for proper functioning and monitoring.  A complete list of ports opened may be found at:&lt;br /&gt;
&lt;br /&gt;
http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements&lt;br /&gt;
&lt;br /&gt;
==OS security==&lt;br /&gt;
&lt;br /&gt;
REDDNet monitors CERT, CryptoGram, and other security forums daily for new security errata.  We use apt-get to keep all Vanderbilt core hardware up-to-date with security fixes at least once a week (and usually every 1-2 days).  All machines are updated as soon as Ubuntu/Debian releases a security update.&lt;br /&gt;
&lt;br /&gt;
When critical vulnerabilities are discovered, we may disable services or install our own custom update until such time as the vendor releases their own update.&lt;br /&gt;
&lt;br /&gt;
==Application security==&lt;br /&gt;
&lt;br /&gt;
All REDDNet core infrastructure and storage depots are scanned monthly using Nessus to search for potential exploits.  Hardware and services are monitored via Nagios and SNMP.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4075</id>
		<title>REDDnet LStore Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4075"/>
		<updated>2010-03-30T21:13:01Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Email&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Data Security==&lt;br /&gt;
&lt;br /&gt;
L-Store is currently under development.  At the moment, data is not encrypted in transit or in storage.  If the user desires, they may use common encryption tools such as OpenSSL or GnuPG to encrypt their data before uploading.&lt;br /&gt;
&lt;br /&gt;
Cursory work on an OpenSSL-encrypted upload/download has been done, but is not yet ready for public use.&lt;br /&gt;
&lt;br /&gt;
==Data Integrity==&lt;br /&gt;
&lt;br /&gt;
When the client uploads a file to the depots, it computes a MD5 hash of the file and stores that information in the metadata on the server.   Downloaded files can be hashed and compared with the stored value to verify integrity (though this is not yet automated).&lt;br /&gt;
&lt;br /&gt;
We intended to make the choice of hash user-selectable in the future.  We intend to support SHA-1, SHA-256, SHA-512 hashes, and possibly other hashes as supported by the base SSL library.&lt;br /&gt;
&lt;br /&gt;
==Data Reliability==&lt;br /&gt;
&lt;br /&gt;
Data stored on depots is encoded with RAID 5 redundancy.  The user may specify this redundancy across hard drives, across depots, and/or across sites.  REDDNet monitors depots for drive failures using Nagios, and if a loss of redundancy is detected we correct the error on our end.&lt;br /&gt;
&lt;br /&gt;
In addition, we are working on a generalized Reed-Solomon code that will allow users to specify an arbitrary amount of redundancy.  For example, you could have 10 drives and have 4 of them fail before you lost redundancy.   We expect this generalized redundancy code to be completed in summer 2010.&lt;br /&gt;
&lt;br /&gt;
==Access Permissions==&lt;br /&gt;
&lt;br /&gt;
We are implementing a generic policy framework that allows for custom security policies (role-based, Unix ACL and permissions) based on user requirements.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4074</id>
		<title>REDDnet LStore Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4074"/>
		<updated>2010-03-30T21:12:36Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Email&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Data Security==&lt;br /&gt;
&lt;br /&gt;
L-Store is currently under development.  At the moment, data is not encrypted in transit or in storage.  If the user desires, they may use common encryption tools such as OpenSSL or GnuPG to encrypt their data before uploading.&lt;br /&gt;
&lt;br /&gt;
Cursory work on an OpenSSL-encrypted upload/download has been done, but is not yet ready for public use.&lt;br /&gt;
&lt;br /&gt;
==Data Integrity==&lt;br /&gt;
&lt;br /&gt;
When the client uploads a file to the depots, it computes a MD5 hash of the file and stores that information in the metadata on the server.   Downloaded files can be hashed and compared with the stored value to verify integrity (though this is not yet automated).&lt;br /&gt;
&lt;br /&gt;
We intended to make the choice of hash user-selectable in the future.  We intend to support SHA-1, SHA-256, SHA-512 hashes, and possibly other hashes as supported by the base SSL library.&lt;br /&gt;
&lt;br /&gt;
==Data Reliability==&lt;br /&gt;
&lt;br /&gt;
Data stored on depots is encoded with RAID 5 redundancy.  The user may specify this redundancy across hard drives, across depots, and/or across sites.  REDDNet monitors depots for drive failures using Nagios, and if a loss of redundancy is detected we correct the error on our end.&lt;br /&gt;
&lt;br /&gt;
In addition, we are working on a generalized Reed-Solomon code that will allow users to specify an arbitrary amount of redundancy.  For example, you could have 10 drives and have 4 of them fail before you lost redundancy.   We expect this generalized redundancy code to be completed in summer 2010.&lt;br /&gt;
&lt;br /&gt;
==Access Permissions==&lt;br /&gt;
&lt;br /&gt;
We implement a generic policy framework that allows for custom security policies (role-based, Unix ACL and permissions).&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4073</id>
		<title>REDDnet LStore Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4073"/>
		<updated>2010-03-30T21:04:55Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Email&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Data Security==&lt;br /&gt;
&lt;br /&gt;
L-Store is currently under development.  At the moment, data is not encrypted in transit or in storage.  If the user desires, they may use common encryption tools such as OpenSSL or GnuPG to encrypt their data before uploading.&lt;br /&gt;
&lt;br /&gt;
Cursory work on an OpenSSL-encrypted upload/download has been done, but is not yet ready for public consumption.&lt;br /&gt;
&lt;br /&gt;
==Data Integrity==&lt;br /&gt;
&lt;br /&gt;
When the client uploads a file to the depots, it computes a MD5 hash of the file and stores that information in the metadata on the server.   Downloaded files can be hashed and compared with the stored value to verify integrity (though this is not yet automated).&lt;br /&gt;
&lt;br /&gt;
We intended to make the choice of hash user-selectable in the future.  We intend to support SHA-1, SHA-256, SHA-512 hashes, and other hashes supported by the base SSL library.&lt;br /&gt;
&lt;br /&gt;
==Data Reliability==&lt;br /&gt;
&lt;br /&gt;
Data stored on depots is encoded with RAID 5 redundancy.  The user may specify this redundancy across hard drives, across depots, and/or across sites.  REDDNet monitors depots for drive failures using Nagios, and if a loss of redundancy is detected we correct the error on our end.&lt;br /&gt;
&lt;br /&gt;
In addition, we are working on a generalized Reed-Solomon code that will allow users to specify an arbitrary amount of redundancy.  For example, you could have 10 drives and have 4 of them fail before you lost redundancy.   We expect this generalized redundancy code to be completed in summer 2010.&lt;br /&gt;
&lt;br /&gt;
==Access Permissions==&lt;br /&gt;
&lt;br /&gt;
We implement a generic policy framework that allows for custom security policies (role-based, Unix ACL and permissions).&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4072</id>
		<title>REDDnet LStore Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4072"/>
		<updated>2010-03-30T21:01:48Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Email&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Data Encryption==&lt;br /&gt;
&lt;br /&gt;
L-Store is currently under development.  At the moment, data is not encrypted in transit or in storage.  If the user desires, they may use common encryption tools such as OpenSSL or GnuPG to encrypt their data before uploading.&lt;br /&gt;
&lt;br /&gt;
Cursory work on an OpenSSL-encrypted upload/download has been done, but is not yet ready for public consumption.&lt;br /&gt;
&lt;br /&gt;
==Data Integrity==&lt;br /&gt;
&lt;br /&gt;
When the client uploads a file to the depots, it computes a MD5 hash of the file and stores that information in the metadata on the server.   Downloaded files can be hashed and compared with the stored value to verify integrity (though this is not yet automated).&lt;br /&gt;
&lt;br /&gt;
We intended to make the choice of hash user-selectable in the future.  We intend to support SHA-1, SHA-256, SHA-512 hashes, and other hashes supported by the base SSL library.&lt;br /&gt;
&lt;br /&gt;
==Data Redundancy==&lt;br /&gt;
&lt;br /&gt;
Data stored on depots is encoded with RAID 5 redundancy.  The user may specify this redundancy across hard drives, across depots, and/or across sites.  REDDNet monitors depots for drive failures using Nagios, and if a loss of redundancy is detected we correct the error on our end.&lt;br /&gt;
&lt;br /&gt;
In addition, we are working on a generalized Reed-Solomon code that will allow users to specify an arbitrary amount of redundancy.  For example, you could have 10 drives and have 4 of them fail before you lost redundancy.   We expect this generalized redundancy code to be completed in summer 2010.&lt;br /&gt;
&lt;br /&gt;
==Access Permissions==&lt;br /&gt;
&lt;br /&gt;
We implement a generic policy framework that allows for custom security policies (role-based, Unix ACL and permissions).&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4071</id>
		<title>REDDnet LStore Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_LStore_Security_Overview&amp;diff=4071"/>
		<updated>2010-03-30T21:01:37Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: Created page with '==Security overview==  REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  …'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Email&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Data Encryption==&lt;br /&gt;
&lt;br /&gt;
L-Store is currently under development.  At the moment, data is not encrypted in transit or in storage.  If the user desires, they may use common encryption tools such as OpenSSL or GnuPG to encrypt their data before uploading.&lt;br /&gt;
&lt;br /&gt;
Cursory work on an OpenSSL-encrypted upload/download has been done, but is not yet ready for public consumption.&lt;br /&gt;
&lt;br /&gt;
==Data Integrity==&lt;br /&gt;
&lt;br /&gt;
When the client uploads a file to the depots, it computes a MD5 hash of the file and stores that information in the metadata on the server.   Downloaded files can be hashed and compared with the stored value to verify integrity (though this is not yet automated).&lt;br /&gt;
&lt;br /&gt;
We intended to make the choice of hash user-selectable in the future.  We intend to support SHA-1, SHA-256, SHA-512 hashes, and other hashes supported by the base SSL library.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Data Redundancy==&lt;br /&gt;
&lt;br /&gt;
Data stored on depots is encoded with RAID 5 redundancy.  The user may specify this redundancy across hard drives, across depots, and/or across sites.  REDDNet monitors depots for drive failures using Nagios, and if a loss of redundancy is detected we correct the error on our end.&lt;br /&gt;
&lt;br /&gt;
In addition, we are working on a generalized Reed-Solomon code that will allow users to specify an arbitrary amount of redundancy.  For example, you could have 10 drives and have 4 of them fail before you lost redundancy.   We expect this generalized redundancy code to be completed in summer 2010.&lt;br /&gt;
&lt;br /&gt;
==Access Permissions==&lt;br /&gt;
&lt;br /&gt;
We implement a generic policy framework that allows for custom security policies (role-based, Unix ACL and permissions).&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_Remote_Site_Security_Overview&amp;diff=4070</id>
		<title>REDDnet Remote Site Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_Remote_Site_Security_Overview&amp;diff=4070"/>
		<updated>2010-03-30T20:58:57Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: Created page with '==Security overview==  REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  …'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Email&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Physical security==&lt;br /&gt;
&lt;br /&gt;
Locations at remote sites depend on user requirements.  It is strongly suggested that  access to the room be restricted by key, pass card, or another token.  The room should not be accessible to the general public.  Only administrative and technical contacts as defined in the MoU will be granted restricted login rights to the depots for maintenance purposes.&lt;br /&gt;
&lt;br /&gt;
==Network security==&lt;br /&gt;
&lt;br /&gt;
Remote depots require several network ports open to either Vanderbilt or the world for proper functioning and monitoring.  A list of required ports may be found at:&lt;br /&gt;
&lt;br /&gt;
http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements&lt;br /&gt;
&lt;br /&gt;
Remote sites must ensure that these ports are open as described, both at a departmental level and at your organization's perimeter firewall.  &lt;br /&gt;
&lt;br /&gt;
Remote depots will have an IPTables firewall to limit connections by port and by source/destination to only those required for operation.  This will be maintained by REDDNet staff.&lt;br /&gt;
&lt;br /&gt;
==OS security==&lt;br /&gt;
&lt;br /&gt;
REDDNet monitors CERT, CryptoGram, and other security forums daily for new security errata.  We use apt-get to keep all depots up-to-date with security fixes at least once a week (and usually every 1-2 days).  All machines are updated as soon as Ubuntu/Debian releases a security update.&lt;br /&gt;
&lt;br /&gt;
When critical vulnerabilities are discovered, we may disable services or install our own custom update until such time as the vendor releases their own update.&lt;br /&gt;
&lt;br /&gt;
==Application security==&lt;br /&gt;
&lt;br /&gt;
Due to firewall restrictions we cannot perform Nessus scans of remote depots.    We encourage local sites (either departmentally or globally) to perform their own regular Nessus scans on remote depots.  When a weakness is discovered at any depot, REDDNet staff will propagate the fix to all other depots.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4069</id>
		<title>REDDnet Vanderbilt Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4069"/>
		<updated>2010-03-30T20:56:21Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Role&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Name&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Email&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Physical security==&lt;br /&gt;
&lt;br /&gt;
Core REDDNet hardware at Vanderbilt University is located in Vanderbilt's Network Operations Center (NOC).  The NOC command center is staffed 24/7/365 by VU's Information Technology Services (ITS) staff.  The facility is secured by card access and access is limited to ITS, VU Management Information Systems staff, and owners of the systems housed in the NOC.  All visitors to the NOC must sign in and are under constant video surveillance while inside.&lt;br /&gt;
&lt;br /&gt;
==Network security==&lt;br /&gt;
&lt;br /&gt;
REDDNet core equipment is secured by a FreeBSD firewall operating as a transparent bridge.  As a transparent bridge, the firewall does not have an IP address, and is not detectable from the outside world.  All off-campus access is logged to aid in forensic analysis should that proves necessary.&lt;br /&gt;
&lt;br /&gt;
All Vanderbilt core equipment also has IPTables firewalls.  Rulesets on both local IPTables and the primary FreeBSD firewall are kept in sync to allow them to perform failover security if one layer should be down.&lt;br /&gt;
Network traffic is limited by port and by source/destination to only those necessary for proper functioning and monitoring.  A complete list of ports opened may be found at:&lt;br /&gt;
&lt;br /&gt;
http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements&lt;br /&gt;
&lt;br /&gt;
==OS security==&lt;br /&gt;
&lt;br /&gt;
REDDNet monitors CERT, CryptoGram, and other security forums daily for new security errata.  We use apt-get to keep all Vanderbilt core hardware up-to-date with security fixes at least once a week (and usually every 1-2 days).  All machines are updated as soon as Ubuntu/Debian releases a security update.&lt;br /&gt;
&lt;br /&gt;
When critical vulnerabilities are discovered, we may disable services or install our own custom update until such time as the vendor releases their own update.&lt;br /&gt;
&lt;br /&gt;
==Application security==&lt;br /&gt;
&lt;br /&gt;
All REDDNet core infrastructure and storage depots are scanned monthly using Nessus to search for potential exploits.  Hardware and services are monitored via Nagios and SNMP.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4068</id>
		<title>REDDnet Vanderbilt Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4068"/>
		<updated>2010-03-30T20:55:54Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!Role&lt;br /&gt;
!Name&lt;br /&gt;
!Email&lt;br /&gt;
!Phone&lt;br /&gt;
|-&lt;br /&gt;
|Primary&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|-&lt;br /&gt;
|Secondary&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Physical security==&lt;br /&gt;
&lt;br /&gt;
Core REDDNet hardware at Vanderbilt University is located in Vanderbilt's Network Operations Center (NOC).  The NOC command center is staffed 24/7/365 by VU's Information Technology Services (ITS) staff.  The facility is secured by card access and access is limited to ITS, VU Management Information Systems staff, and owners of the systems housed in the NOC.  All visitors to the NOC must sign in and are under constant video surveillance while inside.&lt;br /&gt;
&lt;br /&gt;
==Network security==&lt;br /&gt;
&lt;br /&gt;
REDDNet core equipment is secured by a FreeBSD firewall operating as a transparent bridge.  As a transparent bridge, the firewall does not have an IP address, and is not detectable from the outside world.  All off-campus access is logged to aid in forensic analysis should that proves necessary.&lt;br /&gt;
&lt;br /&gt;
All Vanderbilt core equipment also has IPTables firewalls.  Rulesets on both local IPTables and the primary FreeBSD firewall are kept in sync to allow them to perform failover security if one layer should be down.&lt;br /&gt;
Network traffic is limited by port and by source/destination to only those necessary for proper functioning and monitoring.  A complete list of ports opened may be found at:&lt;br /&gt;
&lt;br /&gt;
http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements&lt;br /&gt;
&lt;br /&gt;
==OS security==&lt;br /&gt;
&lt;br /&gt;
REDDNet monitors CERT, CryptoGram, and other security forums daily for new security errata.  We use apt-get to keep all Vanderbilt core hardware up-to-date with security fixes at least once a week (and usually every 1-2 days).  All machines are updated as soon as Ubuntu/Debian releases a security update.&lt;br /&gt;
&lt;br /&gt;
When critical vulnerabilities are discovered, we may disable services or install our own custom update until such time as the vendor releases their own update.&lt;br /&gt;
&lt;br /&gt;
==Application security==&lt;br /&gt;
&lt;br /&gt;
All REDDNet core infrastructure and storage depots are scanned monthly using Nessus to search for potential exploits.  Hardware and services are monitored via Nagios and SNMP.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4067</id>
		<title>REDDnet Vanderbilt Security Overview</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDnet_Vanderbilt_Security_Overview&amp;diff=4067"/>
		<updated>2010-03-30T20:54:57Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: Created page with '==Security overview==  REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  …'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Security overview==&lt;br /&gt;
&lt;br /&gt;
REDDNet's current security plan maintains a level of security that balances security requirements with the service and academic freedom our users expect.  We are capable of enforcing stricter security measures than those outlined in this document should a specific need arise.&lt;br /&gt;
&lt;br /&gt;
==Security contacts==&lt;br /&gt;
&lt;br /&gt;
The primary contact person for questions about or problems with REDDNet-related security is&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|Mathew Binkley&lt;br /&gt;
|Mathew.Binkley@vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-5857&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The secondary contact person is:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|Alan Tackett&lt;br /&gt;
|Alan.Tackett@accre.vanderbilt.edu&lt;br /&gt;
|Phone: (615) 322-1028&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Physical security==&lt;br /&gt;
&lt;br /&gt;
Core REDDNet hardware at Vanderbilt University is located in Vanderbilt's Network Operations Center (NOC).  The NOC command center is staffed 24/7/365 by VU's Information Technology Services (ITS) staff.  The facility is secured by card access and access is limited to ITS, VU Management Information Systems staff, and owners of the systems housed in the NOC.  All visitors to the NOC must sign in and are under constant video surveillance while inside.&lt;br /&gt;
&lt;br /&gt;
==Network security==&lt;br /&gt;
&lt;br /&gt;
REDDNet core equipment is secured by a FreeBSD firewall operating as a transparent bridge.  As a transparent bridge, the firewall does not have an IP address, and is not detectable from the outside world.  All off-campus access is logged to aid in forensic analysis should that proves necessary.&lt;br /&gt;
&lt;br /&gt;
All Vanderbilt core equipment also has IPTables firewalls.  Rulesets on both local IPTables and the primary FreeBSD firewall are kept in sync to allow them to perform failover security if one layer should be down.&lt;br /&gt;
Network traffic is limited by port and by source/destination to only those necessary for proper functioning and monitoring.  A complete list of ports opened may be found at:&lt;br /&gt;
&lt;br /&gt;
http://www.reddnet.org/mwiki/index.php/REDDNet_Site_Requirements&lt;br /&gt;
&lt;br /&gt;
==OS security==&lt;br /&gt;
&lt;br /&gt;
REDDNet monitors CERT, CryptoGram, and other security forums daily for new security errata.  We use apt-get to keep all Vanderbilt core hardware up-to-date with security fixes at least once a week (and usually every 1-2 days).  All machines are updated as soon as Ubuntu/Debian releases a security update.&lt;br /&gt;
&lt;br /&gt;
When critical vulnerabilities are discovered, we may disable services or install our own custom update until such time as the vendor releases their own update.&lt;br /&gt;
&lt;br /&gt;
==Application security==&lt;br /&gt;
&lt;br /&gt;
All REDDNet core infrastructure and storage depots are scanned monthly using Nessus to search for potential exploits.  Hardware and services are monitored via Nagios and SNMP.&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4066</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4066"/>
		<updated>2010-03-05T16:05:43Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
We support three types of network connectivity for data traffic:&lt;br /&gt;
&lt;br /&gt;
* Each depot has two network interfaces, so if supported by your switch, we can use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   &lt;br /&gt;
&lt;br /&gt;
* The depot may optionally include 10 Gb ethernet for those sites that can use it.  This requires your primary switch to have a 10 Gb optical port and a fiber cable long enough to stretch between depot and switch.&lt;br /&gt;
&lt;br /&gt;
* Otherwise, the depot will use one of its 1 Gb network ports (requires one switch port/cable per depot).&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interfaces:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4065</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4065"/>
		<updated>2010-03-05T00:26:59Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interfaces:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4064</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4064"/>
		<updated>2010-03-05T00:24:09Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interfaces:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|www&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 and 5901&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59.0.0/16&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Depot network interface:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|http&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4063</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4063"/>
		<updated>2010-03-05T00:18:17Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* Management interfaces:  22/tcp (ssh), 80/tcp (www), 443/tcp (https), &lt;br /&gt;
&lt;br /&gt;
For the usual depot network interface, please see the chart below:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|http&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900&lt;br /&gt;
|vnc&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4062</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4062"/>
		<updated>2010-03-04T23:34:52Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 24 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Interface&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|mgmt + data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|data&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|data&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|http&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900&lt;br /&gt;
|vnc&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|data&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|data&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4061</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4061"/>
		<updated>2010-03-04T21:19:34Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Service&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Interface&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22&lt;br /&gt;
|ssh&lt;br /&gt;
|mgmt + data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666&lt;br /&gt;
|nagios&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714&lt;br /&gt;
|ibp&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823&lt;br /&gt;
|bwctl&lt;br /&gt;
|data&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861&lt;br /&gt;
|owamp&lt;br /&gt;
|data&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80&lt;br /&gt;
|http&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443&lt;br /&gt;
|https&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900&lt;br /&gt;
|vnc&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123&lt;br /&gt;
|ntp&lt;br /&gt;
|data&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161&lt;br /&gt;
|snmpv3&lt;br /&gt;
|data&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4060</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4060"/>
		<updated>2010-03-04T21:17:24Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Interface&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22 (ssh)&lt;br /&gt;
|mgmt + data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666 (nagios)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714 (ibp)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823 (bwctl)&lt;br /&gt;
|data&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861 (owamp)&lt;br /&gt;
|data&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80 (http)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443 (https)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 (vnc)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123 (ntp)&lt;br /&gt;
|data&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161 (snmpv3)&lt;br /&gt;
|data&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4059</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4059"/>
		<updated>2010-03-04T21:17:12Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Interface&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22 (ssh)&lt;br /&gt;
|mgmt + data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666 (nagios)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714 (ibp)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823 (bwctl)&lt;br /&gt;
|data&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861 (owamp)&lt;br /&gt;
|data&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80 (http)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443 (https)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 (vnc)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123 (ntp)&lt;br /&gt;
|data&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161 (snmpv3)&lt;br /&gt;
|data&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4058</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4058"/>
		<updated>2010-03-04T21:16:54Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
{| align=&amp;quot;center&amp;quot;&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Interface&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22 (ssh)&lt;br /&gt;
|mgmt + data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666 (nagios)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714 (ibp)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823 (bwctl)&lt;br /&gt;
|data&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861 (owamp)&lt;br /&gt;
|data&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80 (http)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443 (https)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 (vnc)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123 (ntp)&lt;br /&gt;
|data&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161 (snmpv3)&lt;br /&gt;
|data&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4057</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4057"/>
		<updated>2010-03-04T21:16:30Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
{| align=&amp;quot;center&amp;quot;&lt;br /&gt;
!style=&amp;quot;background:#000000;color:#ff8888&amp;quot;|Port&lt;br /&gt;
! Interface&lt;br /&gt;
! Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22 (ssh)&lt;br /&gt;
|mgmt + data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666 (nagios)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714 (ibp)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823 (bwctl)&lt;br /&gt;
|data&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861 (owamp)&lt;br /&gt;
|data&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80 (http)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443 (https)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 (vnc)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123 (ntp)&lt;br /&gt;
|data&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161 (snmpv3)&lt;br /&gt;
|data&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4056</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4056"/>
		<updated>2010-03-04T21:13:45Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
! Port&lt;br /&gt;
! Interface&lt;br /&gt;
! Notes&lt;br /&gt;
|-&lt;br /&gt;
|tcp/22 (ssh)&lt;br /&gt;
|mgmt + data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5666 (nagios)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|-&lt;br /&gt;
|tcp/6714 (ibp)&lt;br /&gt;
|data&lt;br /&gt;
|from all depots to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/4823 (bwctl)&lt;br /&gt;
|data&lt;br /&gt;
|from 1st depot to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/861 (owamp)&lt;br /&gt;
|data&lt;br /&gt;
|from 2nd to world&lt;br /&gt;
|-&lt;br /&gt;
|tcp/80 (http)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/443 (https)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|tcp/5900 (vnc)&lt;br /&gt;
|mgmt&lt;br /&gt;
|from all depots to 129.59/16&lt;br /&gt;
|-&lt;br /&gt;
|udp/123 (ntp)&lt;br /&gt;
|data&lt;br /&gt;
|allow outbound from local depots&lt;br /&gt;
|-&lt;br /&gt;
|udp/161 (snmpv3)&lt;br /&gt;
|data&lt;br /&gt;
|from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4055</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4055"/>
		<updated>2010-03-04T21:07:40Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require two externally-visible IP address for each depot.  One address is for the depot itself, the other is for the management console.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
In addition, each depot has an ethernet port for the management console.  The management consoles can connect directly to your primary network switch, or they can run off a smaller dumb switch to minimize the number of primary switch ports in use. &lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
Shorthand:&lt;br /&gt;
&lt;br /&gt;
* mgmt -&amp;gt;  Management interface&lt;br /&gt;
* data -&amp;gt;  Data transfer interface&lt;br /&gt;
&lt;br /&gt;
* tcp/22   (ssh)    : from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
* tcp/5666 (nagios) : from all to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
* tcp/6714 (ibp)    : from all to world&lt;br /&gt;
* tcp/4823 (bwctl)  : from 1st to world&lt;br /&gt;
* tcp/861  (owamp)  : from 2nd to world&lt;br /&gt;
* tcp/80   (http)   : from KVM and PDU's to 129.59/16&lt;br /&gt;
* tcp/443  (https)  : from KVM to 129.59/16&lt;br /&gt;
* tcp/21   (ftp)    : from PDU's to 129.59.197.90 (for firmware upgrades)&lt;br /&gt;
* tcp/5900 (vnc)    : from KVM to 129.59/16&lt;br /&gt;
* udp/123  (ntp)    : from alll allow outbound from local depots&lt;br /&gt;
* udp/161  (snmpv3) : from all to 129.59.197.60 and 129.59.197.90&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4054</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4054"/>
		<updated>2010-03-04T20:45:03Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   &lt;br /&gt;
&lt;br /&gt;
If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require one externally-visible IP address for each depot, PDU, or KVM.  &lt;br /&gt;
&lt;br /&gt;
=== Remote PDU ===&lt;br /&gt;
&lt;br /&gt;
We provide an APC PDU unit for every 4 depots. This allows us to power-cycle a hard-locked machine and do other forms of maintenance that aren't possible using the KVM alone.   &lt;br /&gt;
&lt;br /&gt;
Each PDU requires a 110 V power connection and a network connection with either static or DHCP-issued IP address.&lt;br /&gt;
&lt;br /&gt;
=== Remote KVM ===&lt;br /&gt;
&lt;br /&gt;
We provide a KVM unit for every 8 depots to allow us to manage the depot remotely.  The KVM requires a 110 V power connection (usually supplied by one of our PDU units) as well as a network connection with a externally-visible IP address.&lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* tcp/22   (ssh)    : from all local depots/PDUs to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
* tcp/5666 (nagios) : from all local depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
* tcp/6714 (ibp)    : from all local depots to world&lt;br /&gt;
* tcp/4823 (bwctl)  : from 1st local depot to world&lt;br /&gt;
* tcp/861  (owamp)  : from 2nd local depot to world&lt;br /&gt;
* tcp/80   (http)   : from KVM and PDU's to 129.59/16&lt;br /&gt;
* tcp/443  (https)  : from KVM to 129.59/16&lt;br /&gt;
* tcp/21   (ftp)    : from PDU's to 129.59.197.90 (for firmware upgrades)&lt;br /&gt;
* tcp/5900 (vnc)    : from KVM to 129.59/16&lt;br /&gt;
* udp/123  (ntp)    : allow outbound from local depots&lt;br /&gt;
* udp/161  (snmpv3) : from all to 129.59.197.60 and 129.59.197.90&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
	<entry>
		<id>https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4053</id>
		<title>REDDNet Site Requirements</title>
		<link rel="alternate" type="text/html" href="https://www.reddnet.org/mwiki/index.php?title=REDDNet_Site_Requirements&amp;diff=4053"/>
		<updated>2010-03-04T20:44:32Z</updated>

		<summary type="html">&lt;p&gt;Wikiadmin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Depots ===&lt;br /&gt;
&lt;br /&gt;
Our standard depot contains one dual-core AMD Athlon CPU, 4 GB of RAM, two 1 Gb network ports, and 4-8 TB of storage space.  The standard depot draws approximately 300 W.&lt;br /&gt;
&lt;br /&gt;
We are evaluating a new depot configuration with one 8-core Intel I7, 12 GB of RAM, two 1 Gb network ports, and 23 TB of storage space.  This depot may optionally connect to the network via 10 Gb ethernet (via an add-on adapter).   We will provide power requirements for this box at a later date.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Network Ports on your Switch ===&lt;br /&gt;
&lt;br /&gt;
Each depot has two network interfaces, so if supported by your switch, we would like to use both interfaces in 802.3ad bonding mode for increased performance.  This requires two switch ports and two ethernet cables per depot.   &lt;br /&gt;
&lt;br /&gt;
If not supported, then each depot only requires one port/cable.&lt;br /&gt;
&lt;br /&gt;
=== IP Addresses ===&lt;br /&gt;
&lt;br /&gt;
We require one externally-visible IP address for each depot, PDU, or KVM.  &lt;br /&gt;
&lt;br /&gt;
=== Remote PDU ===&lt;br /&gt;
&lt;br /&gt;
We provide an APC PDU unit for every 4 depots. This allows us to power-cycle a hard-locked machine and do other forms of maintenance that aren't possible using the KVM alone.   &lt;br /&gt;
&lt;br /&gt;
Each PDU requires a 110 V power connection and a network connection with either static or DHCP-issued IP address.&lt;br /&gt;
&lt;br /&gt;
=== Remote KVM ===&lt;br /&gt;
&lt;br /&gt;
We provide a KVM unit for every 8 depots to allow us to manage the depot remotely.  The KVM requires a 110 V power connection (usually supplied by one of our PDU units) as well as a network connection with a externally-visible IP address.&lt;br /&gt;
&lt;br /&gt;
=== Required Network Ports ===&lt;br /&gt;
&lt;br /&gt;
These ports should be opened on your perimeter firewall (or firewalls if you have both organizational and departmental firewalls).&lt;br /&gt;
&lt;br /&gt;
* tcp/22   (ssh)    : from all local depots/PDUs to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
* tcp/5666 (nagios) : from all local depots to 129.59.197.60 and 129.59.197.90&lt;br /&gt;
* tcp/6714 (ibp)    : from all local depots to world&lt;br /&gt;
* tcp/4823 (bwctl)  : from 1st local depot to world&lt;br /&gt;
* tcp/861  (owamp)  : from 2nd local depot to world&lt;br /&gt;
* tcp/80   (http)   : from KVM and PDU's to 129.59/16&lt;br /&gt;
* tcp/443  (https)  : from KVM to 129.59/16&lt;br /&gt;
* tcp/21   (ftp)    : from PDU's to 129.59.197.90 (for firmware upgrades)&lt;br /&gt;
* tcp/5900 (vnc)    : from KVM to 129.59/16&lt;br /&gt;
* udp/123  (ntp)    : allow outbound from local depots&lt;br /&gt;
* udp/161  (snmpv3) : from all to 129.59.197.60 and 129.59.197.90&lt;/div&gt;</summary>
		<author><name>Wikiadmin</name></author>
	</entry>
</feed>