Skip to main content

Subnet Access

This page summarises which ports and routes are open to what on the subnet sets.

The tables below describe the baseline rules applied to every business unit VPC. Some business units have additional bespoke rules - see business unit exceptions.

Allowed Traffic

All Subnets (Private, Public, Data)

Traffic type Port ranges Source/Destination
Ingress & Egress All Business unit VPC
Ingress & Egress All Inter business unit VPCs where requested
Ingress & Egress All Private address ranges which are not part of the Modernisation Platform (Note, these will be blocked by the Firewall unless appropriate rules are in place)
Egress 443 0.0.0.0/0
Ingress 1024 - 65535 0.0.0.0/0

Public Subnets

Traffic type Port ranges Source/Destination
Ingress 443 0.0.0.0/0
Ingress 1024 - 65535 0.0.0.0/0
Egress All 0.0.0.0/0

Protected Subnets (for VPC endpoints)

Traffic type Port ranges Source/Destination
Ingress 25 Business unit VPC
Ingress 443 Business unit VPC
Ingress 587 Business unit VPC
Ingress 5439 Business unit VPC
Egress 1024 - 65535 Business unit VPC

Extending access

Two options in the environments-networks JSON change the NACL rules for a VPC:

  • additional_cidrs allows access from external CIDR ranges, such as PSN address ranges.
  • additional_vpcs allows access from other Modernisation Platform ranges.

We try to avoid using additional_vpcs, as we want to limit east/west traffic movement inside the Modernisation Platform. See environments-networks json explained for more detail.

As NACLs are applied at VPC level, and VPCs are shared across a business unit, any change applies to every account in that business unit.

Business unit exceptions

The vpc-nacls module contains bespoke rules for some business units, added over time to support particular applications. These include rules for HMPPS, LAA and CICA.

If the baseline tables above suggest that the access you need is not permitted, it is worth checking whether a rule already exists for your business unit before assuming otherwise.

To check, or to request a new rule, please get in touch in #ask-modernisation-platform.

This page was last reviewed on 14 September 2026. It needs to be reviewed again on 14 March 2027 by the page owner #modernisation-platform .