Vendor Connectivity
Because the vendor, Horizant, specifically wants to connect to Denodo from their end and pull data, rather than we push data to them, the following VIPs were created:
lb-denodo-prod-horizon.it.tufts.edu
lb-denodo-stage-horizon.it.tuft.edu
lb-denodo-dev-horizon.it.tufts.edu
These VIPs will only allow connections from the following hosts over port 9999:
tuftsuat.horizantsolutions.com - 40.85.228.240
tufts.horizantsolutions.com - 172.203.163.243
This approach was approved by OIS for the following reasons:
Connection is limited by IP address and port
Vendor is using a service account that will be regularly rotated
Connection is encrypted
Data is level 2 sensitivity