9-13
Cisco ONS 15600 SDH Reference Manual, Release 9.0
78-18400-01
Chapter 9 Management Network Connectivity
9.2.7 Scenario 7: Provisioning the ONS 15600 SDH Proxy Server
9.2.7.1 Firewall Not Enabled
shows an ONS 15600 SDH proxy server implementation. A ONS 15600 SDH GNE is
connected to a central office LAN and to ONS 15600 SDH ENEs. The central office LAN is connected
to a NOC LAN, which has CTC computers. The NOC CTC computer and craft technicians must both be
able to access the ONS 15600 SDH ENEs. However, the craft technicians must be prevented from
accessing or seeing the NOC or central office LANs.
In the example, the ONS 15600 SDH GNE is assigned an IP address within the central office LAN and
is physically connected to the LAN through its LAN port. ONS 15600 SDH ENEs are assigned IP
addresses that are outside the central office LAN and given private network IP addresses. If the
ONS 15600 SDH ENEs are collocated, the craft LAN ports could be connected to a hub. However, the
hub should have no other network connections.
Figure 9-10
ONS 15600 SDH Proxy Server with GNE and ENEs on the Same Subnet
shows recommended settings for ONS 15600 SDH GNEs and ENEs in the configuration
shown in
Remote CTC
10.10.20.10
10.10.20.0/24
10.10.10.0/24
Interface 0/0
10.10.20.1
Router A
Interface 0/1
10.10.10.1
ONS 15600 SDH
GNE
10.10.10.100/24
ONS 15600 SDH
ENE
10.10.10.250/24
ONS 15600 SDH
ENE
10.10.10.150/24
ONS 15600 SDH
ENE
10.10.10.200/24
159609
Local/Craft CTC
192.168.20.20
Ethernet
SDH