Skip to main content

About

Orka Cluster was designed with minimal internet access to increase security, however, you must set up some restricted internet access. This document lists the required URLs that must be enabled to use Orka Cluster. These are rulesets tested on a Cisco virtual Firepower appliance, running the Firepower Threat Defense operating system. These rulesets permit the minimum amount of traffic required for Orka functionality.
Orka Cluster customers must manage these URLs to support Orka Cluster functionality. This only applies to customers who have security requirements that filter URLs, either from the MacStadium side or through tunneling traffic to another firewall. The rulesets below cover two traffic categories: Client-Side and LAN-Side.

Overview

The ruleset are divided into two sections:
  • Client-Side Traffic: Any traffic whose destination is the Orka API controller, the Orka physical hosts, the Orka virtual machines, and the single sign-on (SSO).
  • LAN-Side Traffic: Any traffic originating from the Orka network that exists behind the firewall.
The document assumes that the Orka network is on 10.221.188.x.

Rulesets

Client-Side Ruleset

LAN-Side Ruleset