9-16
Cisco ONS 15600 SDH Reference Manual, Release 9.0
78-18400-01
Chapter 9 Management Network Connectivity
9.2.7 Scenario 7: Provisioning the ONS 15600 SDH Proxy Server
The rules in
are applied if a packet is addressed to the ONS 15600 SDH. Rejected packets are
discarded.
If an ONS 15600 SDH or CTC computer resides behind a firewall that uses port filtering, you must
enable an Internet Inter-ORB Protocol (IIOP) port on the ONS 15600 SDH and/or CTC computer,
depending on whether one or both devices reside behind a firewall. You can enable an IIOP port on the
Provisioning > Network > General tab in CTC.
shows ONS 15600 SDHs in a protected network and the CTC computer in an external
network. For the computer to access the ONS 15600 SDHs, you must provision the IIOP listener port
specified by your firewall administrator on the ONS 15600 SDH. The ONS 15600 SDH sends the port
number to the CTC computer during the initial contact between the devices using Hyper-Text Transfer
Protocol (HTTP). After the CTC computer obtains the ONS 15600 SDH IIOP port, the computer opens
a direct session with the node using the specified IIOP port.
Table 9-3
Proxy Server Firewall Filtering Rules
Packets Arriving At:
Are Accepted if the IP Destination Address Is:
TSC Ethernet
interface
•
The ONS 15600 SDH itself
•
The ONS 15600 SDH subnet broadcast address
•
Within the 224.0.0.0/8 network (reserved network used for standard
multicast messages)
DCC interface
•
The ONS 15600 SDH itself
•
Any destination connected through another DCC interface
•
Within the 224.0.0.0/8 network
Table 9-4
Proxy Server Firewall Filtering Rules When Packet Addressed to ONS 15600 SDH
Packets Arriving At:
Accepts
Rejects
TSC Ethernet
interface
•
All IP protocols except user
datagram protocol (UDP)
•
All UDP packets except packets
address to the SNMP trap relay
port
•
UDP packets addressed to the
SNMP trap relay port (391)
DCC interface
•
All ICMP, OSPF, RSVP, and
LMP packets
•
All TCP packets except packets
addressed to the Telnet and
proxy server ports
•
TCP packets addressed to the
Telnet port
•
TCP packets addressed to the
proxy server port
•
Protocols not listed in the
Accepted column