Firewall Services

The purpose of Firewall Exemption Services is to provide a secure and controlled process for allowing specific network traffic through the University of Louisville’s firewall infrastructure. These exemptions are granted to support academic, research, and administrative needs that require access to external systems, specialized applications, or non-standard network configurations.

Overview of Service

Firewall exemptions are managed by Information Technology Services (ITS) and are granted based on a formal review of security, compliance and operational requirements. The service ensures that exemptions are implemented safely and only when necessary, minimizing risk to university systems and data.

Key Features:

  • Review and approval of firewall exemption requests
  • Configuration of firewall rules to allow specific traffic
  • Support for inbound and outbound access exceptions
  • Logging and monitoring of exempted traffic
  • Integration with network and security policies

Benefits:

  • Enables access to necessary external systems and services
  • Supports specialized research and academic tools
  • Maintains institutional security posture through controlled exceptions
  • Provides documentation and audit trails for compliance
  • Facilitates collaboration with external partners and vendors

Service Details

  • Core Activities:

    • Evaluate firewall exemption requests for security and operational impact
    • Configure firewall rules to allow approved traffic
    • Monitor and log exempted connections
    • Review exemptions periodically for continued relevance
    • Provide guidance on secure alternatives when possible
  • Performance Metrics:

    • Request response and approval times
    • Number of active exemptions
    • Compliance with review and renewal schedules
    • Incident reports related to exempted traffic
  • Collaboration:
    Managed by ITS Network and Security teams in coordination with departmental IT staff and data stewards.

Boundaries and Constraints

  • Exemptions are granted only for university-owned systems and approved use cases.
  • Requests must include justification, source/destination IPs, ports, and protocols.
  • All exemptions are subject to periodic review and may be revoked if no longer needed.
  • Sensitive data access must comply with university security and privacy policies.
  • Firewall exemptions do not guarantee unrestricted access and may be limited in scope.

Eligibility

University of Louisville faculty, staff and administrators may request firewall exemptions for approved university-related activities. Requests must be submitted by authorized personnel and may require departmental approval.