Lehigh protects the campus network with border firewalls positioned between our network and the internet. These firewalls operate on a **default-deny** basis: any connection attempt from off campus is blocked unless it has been specifically approved.
This is one layer of a broader defense. Every computer connected to Lehigh's network should also run its own firewall software, regardless of whether it sits behind the campus perimeter.
---
Before You Request an Exception: Use VPN
If you need to connect a single off-campus computer to Lehigh resources, use the [Lehigh VPN] instead of requesting a firewall exception.
VPN gives you access without opening a permanent hole in the perimeter. It requires no approval cycle, no named responsible party, and no ongoing patch obligation tied to a specific IP address. For most remote access needs, this is faster than the exception process below.
---
Requesting a Firewall Exception
Exceptions are granted only when VPN is not a workable option: for example, a lab server, a research application, or a departmental system that must accept inbound connections from specific external sources.
How to request one:
Exceptions are submitted by your computing consultant on your behalf. Contact your consultant, who will submit the request through Firewall Exception Request Form.
Information your consultant will need from you:
- The IP address of the system requiring the exception
- The specific port(s) and protocol(s) needed
- The business or research justification
- The name of the Lehigh faculty or staff member responsible for maintaining the security of that system
Typical turnaround time: 3 business days
---
Research Computing and Lab Systems
If your work requires inbound access for high-performance computing, a lab server, or a research tool that must be reachable from off campus, this falls under the standard exception process above. Include your research group, PI, or grant reference in the justification field so the request can be routed and prioritized appropriately.
If you're unsure whether your use case needs an exception at all, contact your computing consultant first. Many research computing needs can be met through VPN or through campus-hosted services that don't require a perimeter exception.
---
What We Won't Approve
Exceptions will not be granted for inherently insecure protocols, including:
- Telnet (port 23)
- FTP (port 21)
If a vendor or application requires one of these protocols, contact your computing consultant to discuss a secure alternative before submitting a request.
---
Your Responsibility if an Exception Is Granted
If a firewall exception is approved, the responsible faculty or staff member named on the request is accountable for:
- Applying all current and future security patches to the system
- Maintaining the system's overall security posture
Exceptions are reviewed on an ongoing basis. Failure to maintain the security of the system will result in revocation of the exception, regardless of business or research impact.
---
Questions
Contact your computing consultant with questions about this process.