
Fabric OS 5.3.0 administrator guide 139
For an IP Filter policy rule, users can only select port numbers in either the well known or the registered port
number range, between 0 and 49151, inclusive. This means that customers have the ability to control how
to expose the management services hosted on a switch, but not the ability to affect the management traffic
that is initiated from a switch. A valid port number range is represented by a dash, for example 7-30.
Alternatively, service names can also be used instead of port number.
Table 36
lists the supported service
names and their corresponding port number.
TCP and UDP protocols are valid selections. Fabric OS 5.3.0 does not support configuration to filter other
protocols. Implicitly, ICMP type 0 and type 8 packets are always allowed to support ICMP echo
request/reply on commands like ping and traceroute. For the action, only “permit” and “deny” are valid.
For every IP Filter policy, the following two rules are always assumed to be appended implicitly to the end
of the policy, see
Table 37
. This is to ensure TCP and UDP traffics to dynamic port ranges is allowed, that
way management IP traffic initiated from a switch, such as syslog, radius and ftp, will not be affected.
A switch with Fabric OS 5.3.0 or later will have a default IP Filter policy for IPv4 and IPv6. The default IP
Filter policy cannot be deleted or changed. When an alterative IP Filter policy is activated, the default IP
Filter policy becomes deactivated.
Table 38
lists the rules of the default IP Filter policy.
Table 36
Supported services
Service name
Port number
https
443
rpc
897
secure rpc
898
snmp
161
ssh
22
sunprc
111
telnet
23
www
80
Table 37
Implicit IP Filter rules
Source address
Destination
port
Protocol
Action
Any
1024-65535
TCP
Permit
Any 1024-65535
UDP
Permit
Table 38
Default IP policy rules
Rule number Source
address
Destination
port
Protocol
Action
1
Any
22
TCP
Permit
2
Any
23
TCP
Permit
3
Any
897
TCP
Permit
4
Any
898
TCP
Permit
5
Any
111
TCP
Permit
6
Any
80
TCP
Permit
7
Any
443
TCP
Permit
9
Any
161
UDP
Permit
10
Any
111
UDP
Permit
Summary of Contents for AA979A - StorageWorks SAN Switch 2/8V
Page 1: ...HP StorageWorks Fabric OS 5 3 x administrator guide Part number 5697 0244 November 2009 ...
Page 16: ...16 ...
Page 20: ...18 ...
Page 24: ...24 Introducing Fabric OS CLI procedures ...
Page 116: ...118 Maintaining configurations ...
Page 170: ...172 Managing administrative domains ...
Page 200: ...202 Installing and maintaining firmware ...
Page 222: ...224 Routing traffic ...
Page 274: ...286 Administering FICON fabrics ...
Page 294: ...306 Working with diagnostic features ...
Page 350: ...362 Administering Extended Fabrics ...
Page 438: ...440 Configuring the PID format ...
Page 444: ...446 Configuring McData Open Fabric mode ...
Page 450: ...452 Understanding legacy password behaviour ...