19.2.7 Scenario 7: Provisioning the ONS 15454 Proxy Server
Figure 19-14 Scenario 7: ONS 15454 Proxy Server With ENEs on Multiple Rings (ANSI and ETSI)
ONS 15454
Gateway NE
10.10.10.100/24
ONS 15454
End NE
192.168.10.250/24
Table 19-3
configured as ENEs and GNEs. If the packet is addressed to the ONS 15454, additional rules, shown in
Table
Table 19-3 Proxy Server Firewall Filtering Rules
Packets Arriving At:
TCC2 Ethernet
interface
DCC interface
Cisco ONS 15454 DWDM Installation and Operations Guide, R4.7
19-16
Remote CTC
10.10.20.10
10.10.20.0/24
Interface 0/0
10.10.20.1
Router A
Interface 0/1
10.10.10.1
10.10.10.0/24
ONS 15454
End NE
192.168.10.150/24
ONS 15454
End NE
192.168.10.200/24
shows the rules the ONS 15454 follows to filter packets for the firewall when nodes are
19-4, are applied. Rejected packets are silently discarded.
Are Accepted if the Destination IP Address is:
The ONS 15454 itself
•
The ONS 15454's subnet broadcast address
•
Within the 224.0.0.0/8 network (reserved network used for standard
•
multicast messages)
Subnet mask = 255.255.255.255
•
•
The ONS 15454 itself
•
Any destination connected through another DCC interface
Within the 224.0.0.0/8 network
•
ONS 15454
Gateway NE
10.10.10.200/24
ONS 15454
End NE
192.168.80.250/24
Chapter 19
CTC Connectivity Reference
ONS 15454
End NE
192.168.60.150/24
ONS 15454
End NE
192.168.70.200/24
Ethernet
Optical Fiber
September 2004