Proposal 129521: Proposal to modify firewall rules

Hello everyone,

We’ve submitted a proposal to add a new rule to the replica firewall. The proposal is to allowlist the new IPv6 prefix 2a0b:21c0:4003:1::/64, used by the DFINITY-operated DC in London (ln1). As part of maintenance, we have assigned the London boundary node to a different IPv6 prefix. To finish the maintenance and bring the London boundary node back into the pool, we need to adapt the replica firewall.

This is only a temporary measure. Once the boundary nodes are split into API boundary nodes and HTTP gateways, and the API boundary nodes are fully deployed under the NNS, this will no longer be necessary.

Let me know if you have any questions!