HP A7533A - Brocade 4Gb SAN Switch Base Administrator's Manual page 137

Hp storageworks fabric os 5.3.x administrator guide (5697-0244, november 2009)
Hide thumbs Also See for A7533A - Brocade 4Gb SAN Switch Base:
Table of Contents

Advertisement

For an IP Filter policy rule, users can only select port numbers in either the well known or the registered port
number range, between 0 and 49151, inclusive. This means that customers have the ability to control how
to expose the management services hosted on a switch, but not the ability to affect the management traffic
that is initiated from a switch. A valid port number range is represented by a dash, for example 7-30.
Alternatively, service names can also be used instead of port number.
names and their corresponding port number.
Table 36
Supported services
Service name
Port number
https
443
rpc
897
secure rpc
898
snmp
161
ssh
22
sunprc
1 1 1
telnet
23
www
80
TCP and UDP protocols are valid selections. Fabric OS 5.3.0 does not support configuration to filter other
protocols. Implicitly, ICMP type 0 and type 8 packets are always allowed to support ICMP echo
request/reply on commands like ping and traceroute. For the action, only "permit" and "deny" are valid.
For every IP Filter policy, the following two rules are always assumed to be appended implicitly to the end
of the policy, see
Table
37. This is to ensure TCP and UDP traffics to dynamic port ranges is allowed, that
way management IP traffic initiated from a switch, such as syslog, radius and ftp, will not be affected.
Table 37
Implicit IP Filter rules
Source address
Destination
port
Any
1024-65535
Any
1024-65535
A switch with Fabric OS 5.3.0 or later will have a default IP Filter policy for IPv4 and IPv6. The default IP
Filter policy cannot be deleted or changed. When an alterative IP Filter policy is activated, the default IP
Filter policy becomes deactivated.
Table 38
Default IP policy rules
Rule number Source
address
1
Any
2
Any
3
Any
4
Any
5
Any
6
Any
7
Any
9
Any
10
Any
Protocol
TCP
UDP
Table 38
lists the rules of the default IP Filter policy.
Destination
Protocol
port
22
TCP
23
TCP
897
TCP
898
TCP
1 1 1
TCP
80
TCP
443
TCP
161
UDP
1 1 1
UDP
Table 36
lists the supported service
Action
Permit
Permit
Action
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Fabric OS 5.3.0 administrator guide 139

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents