Cisco ONS 15600 Reference Manual page 162

Hide thumbs Also See for ONS 15600:
Table of Contents

Advertisement

9.2.7 Scenario 7: Provisioning the ONS 15600 Proxy Server
Table 9-3
Packets Arriving At:
TSC Ethernet
interface
DCC interface
The rules in
discarded.
Table 9-4
Packets Arriving At:
TSC Ethernet
interface
DCC interface
If an ONS 15600 or CTC computer resides behind a firewall that uses port filtering, you must enable an
Internet Inter-ORB Protocol (IIOP) port on the ONS 15600 and/or CTC computer, depending on whether
one or both devices reside behind a firewall. You can enable an IIOP port on the
Provisioning > Network > General tabs in CTC.
Figure 9-13
For the computer to access the ONS 15600s, you must provision the IIOP listener port specified by your
firewall administrator on the ONS 15600. The ONS 15600 sends the port number to the CTC computer
during the initial contact between the devices using Hyper-Text Transfer Protocol (HTTP). After the
CTC computer obtains the ONS 15600 IIOP port, the computer opens a direct session with the node
using the specified IIOP port.
Cisco ONS 15600 Reference Manual, R6.0
9-16
Proxy Server Firewall Filtering Rules
Are Accepted if the IP Destination Address Is:
The ONS 15600 itself
The ONS 15600 subnet broadcast address
Within the 224.0.0.0/8 network (reserved network used for standard
multicast messages)
The ONS 15600 itself
Any destination connected through another DCC interface
Within the 224.0.0.0/8 network
Table 9-4
are applied if a packet is addressed to the ONS 15600. Rejected packets are
Proxy Server Firewall Filtering Rules When Packet Addressed to ONS 15600
Accepts
All IP protocols except user
datagram protocol (UDP)
All UDP packets except packets
address to the SNMP trap relay
port
All ICMP, OSPF, RSVP, and
LMP packets
All TCP packets except packets
addressed to the Telnet and
proxy server ports
shows ONS 15600s in a protected network and the CTC computer in an external network.
Chapter 9
Management Network Connectivity
Rejects
UDP packets addressed to the
SNMP trap relay port (391)
TCP packets addressed to the
Telnet port
TCP packets addressed to the
proxy server port
Protocols not listed in the
Accepted column

Advertisement

Table of Contents
loading

Table of Contents