Firewall changes are requested through the portal under Network → Firewall Change. Requests with complete information and a low risk score are fulfilled automatically; everything else routes to review. Incomplete requests are the single biggest cause of delay.
A complete request contains
- Source: IP, range or named group — "the app servers" is not a source
- Destination: same precision, plus the environment (prod/non-prod)
- Service: protocol and port, or a named service object
- Direction and zones: where the traffic originates and terminates
- Business justification: what breaks without this rule
- Duration: permanent, or an expiry date for project traffic
Risk tiers and lead times
- Tier 1 (auto-approved, ~15 min): non-prod to non-prod, named objects, standard services
- Tier 2 (1 business day): prod destinations, standard services, no any-objects
- Tier 3 (3 business days + security review): internet-facing, any-objects, or management-plane access
Standing guidance
Request the narrowest rule that works — broad rules attract Tier 3 review and take longer, so "any" is usually the slow path, not the shortcut. Time-bound rules for project traffic expire automatically; permanent rules are recertified annually and unclaimed ones are removed.
Was this article helpful?
95% of 1,167 readers found it useful