9-22
Cisco ONS 15600 SDH Reference Manual, Release 9.0
78-18400-01
Chapter 9 Management Network Connectivity
9.4 External Firewalls
9.4 External Firewalls
This section provides sample access control lists for external firewalls.
lists the ports that are
used by the TSC.
The following ACL (access control list) example shows a firewall configuration when the SOCKS proxy
server gateway setting is not enabled. In the example, the CTC workstation's address is 192.168.10.10.
and the ONS 15600 SDH address is 10.10.10.100. The firewall is attached to the GNE, so the inbound
direction is from CTC to the GNE and the outbound direction is from the GNE to CTC. The CTC
Common Object Request Broker Architecture (CORBA) Standard constant is 683 and the TCC CORBA
Default is TCC Fixed (57790).
access-list 100 remark *** Inbound ACL, CTC -> NE ***
Table 9-6
Ports Used by the TSC
Port
Function
Action
1
1.
D = deny, NA = not applicable, OK = do not deny
0
Never used
D
20
FTP
D
21
FTP control
D
22
SSH (Secure Shell)
D
23
Telnet
D
80
HTTP
D
111
SUNRPC (Sun Remote Procedure Call)
D
161
SNMP traps destinations
D
162
SNMP traps destinations
D
513
rlogin
D
683
CORBA IIOP
OK
1080
Proxy server (socks)
D
2001-2017
I/O card Telnet
NA
2018
DCC processor on active TCC2/TCC2P
D
2361
TL1
D
3082
Raw TL1
D
3083
TL1
D
5001
MS-SPRing server port
D
5002
MS-SPRing client port
D
7200
SNMP alarm input port
D
9100
EQM port
D
9401
TCC boot port
D
9999
Flash manager
NA
10240-12287
Proxy client
D
57790
Default TCC listener port
OK