Q What is the service?
The UKCloud Cross Domain Security Zone (CDSZ) enables customers to transfer data securely between the UKCloud Assured OFFICIAL (formerly IL2) cloud platform and the UKCloud Elevated OFFICIAL (formerly IL3) cloud platform using CESG-approved cross-domain security patterns.
This allows solutions hosted on the Elevated OFFICIAL cloud platform that are citizen facing to be accessed securely from the internet.
Two service options are available to enable use of the CDSZ:
- UKCloud Guard
- Walled Garden
Q Do I have to buy other UKCloud services to use services in the CDSZ?
Yes. UKCloud Cross Domain services are available only to customers purchasing other UKCloud services, such as IaaS (compute and storage) or PaaS (Hadoop and Digital Application Platform).
Q Is there a free trial available for either service?
The complex assurance requirements mean that trials aren’t available.
Q What is the process for applying for a service in the CDSZ?
If you’re already a UKCloud customer you can find the information you need in the UKCloud Portal Knowledge Centre, including a detailed description of the assurance process and an application form.
New customers should contact the UKCloud sales team to discuss their requirements.
Q What information do I need to include in my application for a service in the CDSZ?
As a minimum the application form must include:
- A business case explaining why a cross-domain solution is required
- The technical architecture of the solution — incorporating either the UKCloud Guard or your proposed Walled Garden solution
- An assurance plan — your proposed approach to ensuring that risks are correctly identified, appropriate mitigation is implemented and residual risks are accepted, so that both the UKCloud and customer SIROs can make an informed decision about the risks of the solution
Q How do I enable access from the internet to my solution hosted on the Elevated OFFICIAL cloud platform?
For citizen-facing solutions hosted on the Elevated OFFICIAL cloud platform that need to be accessible from the internet, you can use the UKCloud Guard, or build your own solution using the Walled Garden.
If you use the UKCloud Guard, you’ll need to deploy additional web servers on the Assured OFFICIAL cloud platform to perform pre-authentication, validation checking and initial anti-virus. The web servers can then communicate with your application server hosted on the Elevated OFFICIAL cloud platform via HTTP web services through the UKCloud Guard. Use of the UKCloud Guard is subject to approval by the UKCloud SIRO.
With the Walled Garden, you can create your own inspection, anti-malware and security services in the CDSZ between the internet-facing components on the Assured OFFICIAL cloud platform and the higher-security components hosted on the Elevated OFFICIAL cloud platform. Use of a self-managed Walled Garden is subject to approval by the UKCloud SIRO.
Direct connectivity into the UKCloud Elevated OFFICIAL cloud platform via the internet is possible using a CAPS-approved VPN solution using government-grade encryption products (eg X‑Kryptor). CPA-approved VPN solutions may be used subject to approval by the UKCloud SIRO. UKCloud can host the CAPS or CPA IPsec VPN gateway device within the Elevated OFFICIAL cloud platform, but procurement, configuration and ongoing management of the solution are your responsibility.
UKCloud also offers Secure Remote Access, a CPA-approved VPN solution that allows access to the Elevated OFFICIAL cloud platform via a self-managed Walled Garden within the CDSZ. For more information, see the UKCloud Secure Remote Access service definition on the Digital Marketplace.
Q Are there any bandwidth limitations for traffic traversing the Walled Garden firewalls in and out of the CDSZ?
Yes, there is a 1GiB throughput limitation to the CDSZ in both Farnborough and Corsham.
Q Is there storage capacity on CDSZ virtual machines (VMs)?
The storage capacity of a VM in the CDSZ is 60GiB.
UKCloud cannot provide additional storage in the CDSZ for designs involving patch repositories. We advise customers to engage a UKCloud solutions architect to create a design that allows use of storage on the Assured or the Elevated platform.