4-19
Cisco ONS 15327 User Documentation, R3.3
June 2002
Chapter 4 IP Networking
ONS 15327 IP Addressing Scenarios
If you implement the proxy server scenario, keep the following rules in mind:
•
All DCC-connected ONS 15327s on the same Ethernet segment must have the same
Craft Access
Only
setting. Mixed values will produce unpredictable results, and may leave some nodes
unreachable through the shared Ethernet segment.
•
All DCC-connected ONS 15327s on the same Ethernet segment must have the same
Enable Firewall
setting. Mixed values will produce unpredictable results. Some nodes may become unreachable.
•
All DCC-connected ONS 15327s in the same SDCC area must have the same
Enable Firewall
setting. Mixed values will produce unpredictable results. Some nodes may become unreachable.
•
If you enable
Enable Firewall,
always enable
Enable Proxy
. If
Enable Proxy
is not enabled, CTC
will not be able to see nodes on the DCC side of the ONS 15327.
•
If
Craft Access Only
is enabled, enable
Enable Proxy
. If
Enable Proxy
is not enabled, CTC will not
be able to see nodes on the DCC side of the ONS 15327.
If nodes become unreachable in cases 1, 2 and 3, you can correct the setting by performing one of the
following:
•
Disconnect the craft computer from the unreachable ONS 15327. Connect to the ONS 15327
through another ONS 15327 in the network that has a DCC connection to the unreachable
ONS 15327.
•
Disconnect the Ethernet cable from the unreachable ONS 15327. Connect a CTC computer directly
to the ONS 15327.
Table 4-4
Proxy Server Firewall Filtering Rules When Packet Addressed to ONS 15327
Packets Arrive At
Accepted
Rejected
XTC Ethernet
Interface
•
All UDP packets except those in the
Rejected column
•
All TCP, OSPF and ICMP packets
•
UDP packets addressed to the
SNMP trap relay port (391) are
rejected
DCC Interface
•
All UDP packets
•
All TCP packets except those in the
Rejected column
•
OSPF packets
•
ICMP packets
•
TCP packets addressed to the telnet
port are rejected.
•
TCP packets addressed to the IO
card telnet ports are rejected.
•
TCP packets addressed to the proxy
server port are rejected.
Summary of Contents for ONS 15327
Page 22: ...Contents xxii Cisco ONS 15327 User Documentation June 2002 I N D E X ...
Page 30: ...Figures xxviii Cisco ONS 15327 User Documentation June 2002 ...
Page 44: ...Procedures xlii Cisco ONS 15454 Installation and Operations Guide R3 2 June 2002 ...
Page 540: ...Glossary GL 16 Cisco ONS 15327 User Documentation R3 3 June 2002 ...