Note:
Due to the size of SNMP packets, IP fragmentation may occur in the network.
Ensure the firewall will allow fragmented packets to reach the server(s).
Table 7-19
SSH / Telnet Firewall rules for traffic coming into the 5620 SAM
Auxiliary Statistics Collector Server(s) from the Managed Network
Protocol
From port
On
To port
On
Notes
TCP
>32768
Auxiliary Server(s)
22-23
Managed Network
SSH/SCP/Telnet request
TCP
22-23
Managed Network
> 32768
Auxiliary Server(s)
SSH/SCP/Telnet
response
Table 7-20
FTP Firewall rules for traffic coming into the 5620 SAM Auxiliary
Statistics Collector Server(s) from the Managed Network
Protocol
From port
On
To port
On
Notes
TCP
Any
Auxiliary Server(s)
21
Managed Network
FTP requests (example:
STM, Accounting
statistics, NE backups))
TCP
21
Managed Network
Any
Auxiliary Server(s)
FTP responses
TCP
> 1023
Managed Network
> 1023
Auxiliary Server(s)
Passive FTP ports for
data transfer (See
)
Note:
FTP access is only required for the 5620 SAM Auxiliary Statistics Collector.
Table 7-21
SNMP Firewall rules for traffic coming into the 5620 SAM Auxiliary
Call Trace Server(s) from the Managed Network
Protocol
From port
On
To port
On
Notes
UDP
>32768
Auxiliary Server(s)
161
Managed Network
SNMP request
UDP
161
Managed Network
> 32768
Auxiliary Server(s)
SNMP response
Note:
Due to the size of SNMP packets, IP fragmentation may occur in the network.
Ensure the firewall will allow fragmented packets to reach the server(s).
Security
Firewall and NAT rules
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
7-24
5620 SAM
3HE-09809-AAAG-TQZZA 13.0 R7
Issue 1
December 2015