There are some filter rules we can implement on our firewall:
https://nsrc.org/workshops/2013/pacnog14-sns/raw-attachment/wiki/Agenda/Firewalls.pdf
We also want to be able to connect to these ports on srvX.ws.nsrc.org from outside:
ssh - port 22
See:
https://doc.pfsense.org/index.php/Restrict_access_to_management_interface https://doc.pfsense.org/index.php/Remote_firewall_Administration