Subnet Access
This page summarises which ports and routes are open to what on the subnet sets.
The tables below describe the baseline rules applied to every business unit VPC. Some business units have additional bespoke rules - see business unit exceptions.
Allowed Traffic
All Subnets (Private, Public, Data)
| Traffic type | Port ranges | Source/Destination |
|---|---|---|
| Ingress & Egress | All | Business unit VPC |
| Ingress & Egress | All | Inter business unit VPCs where requested |
| Ingress & Egress | All | Private address ranges which are not part of the Modernisation Platform (Note, these will be blocked by the Firewall unless appropriate rules are in place) |
| Egress | 443 | 0.0.0.0/0 |
| Ingress | 1024 - 65535 | 0.0.0.0/0 |
Public Subnets
| Traffic type | Port ranges | Source/Destination |
|---|---|---|
| Ingress | 443 | 0.0.0.0/0 |
| Ingress | 1024 - 65535 | 0.0.0.0/0 |
| Egress | All | 0.0.0.0/0 |
Protected Subnets (for VPC endpoints)
| Traffic type | Port ranges | Source/Destination |
|---|---|---|
| Ingress | 25 | Business unit VPC |
| Ingress | 443 | Business unit VPC |
| Ingress | 587 | Business unit VPC |
| Ingress | 5439 | Business unit VPC |
| Egress | 1024 - 65535 | Business unit VPC |
Extending access
Two options in the environments-networks JSON change the NACL rules for a VPC:
additional_cidrsallows access from external CIDR ranges, such as PSN address ranges.additional_vpcsallows access from other Modernisation Platform ranges.
We try to avoid using additional_vpcs, as we want to limit east/west traffic movement inside the Modernisation Platform. See environments-networks json explained for more detail.
As NACLs are applied at VPC level, and VPCs are shared across a business unit, any change applies to every account in that business unit.
Business unit exceptions
The vpc-nacls module contains bespoke rules for some business units, added over time to support particular applications. These include rules for HMPPS, LAA and CICA.
If the baseline tables above suggest that the access you need is not permitted, it is worth checking whether a rule already exists for your business unit before assuming otherwise.
To check, or to request a new rule, please get in touch in #ask-modernisation-platform.