–
DHCP options (Use Default)—Enable DHCP on the VCN by creating a set of DHCP
options, and using the default resolver.
There are additional VCN components that you may find useful for your OCSBC deployment.
These include:
•
Dynamic Routing Gateway
•
Local Peering Gateways
•
NAT Gateways
•
Service Gateways
Create Security Lists
Security lists specify the type of traffic allowed on a particular type of subnet. OCSBC
deployments typically need 2 lists, but you may use three if there are specific rules that apply
to your HA subnet and are different from your management subnet.
Rules set on security lists can be either stateful or stateless. Stateful rules employ connection
tracking and have the benefit of not requiring exit rules. However, there is a limit to the
number of connections allowed over stateful connections. and there is a performance hit.
Oracle, therefore, recommends stateless lists for media interfaces.
Note:
The OCSBC implements its own ACLs. Protocol access may require that you
configure OCI security lists and OCSBC ACLs. In addition, the port numbers you
use within OCSBC ACLs should match those configured in these security groups.
The security list for management ports can be stateful. Ports you should consider opening for
management interfaces include:
•
SSH—TCP port 22
•
NTP—UDP port 123
•
SNMP—UDP port 161
•
SNMP Trap—UDP port 162
The security list for media ports should be stateless. Ports you should consider opening for
management interfaces include:
•
SIP—UDP or TCP port 5060
•
SIP TLS—TCP port 5061
•
H323—TCP port 1719
•
RTP —UDP or TCP port 5004 and 5005
Oracle recommends using a private subnet for HA and a basic security list that allows all
local traffic. However, there are some deployments where this is not possible. In these cases,
create a security list with a port open for the port you've selected in redundancy-config, which
is typically port 9090.
Chapter 7
Create and Deploy on OCI
7-23
Содержание netra X5-2
Страница 101: ...Chapter 7 Create and Deploy on Azure 7 35 ...
Страница 127: ...Figure 11 7 BMC Step 9 10 Click Next after the write operation is complete Chapter 11 Creating a Build Image 11 5 ...
Страница 151: ...Appendix A Acme Packet 6300 6350 Physical Interfaces A 12 ...
Страница 152: ...Note The Quad 10 GbE NIU must go in slot 0 Appendix A Acme Packet 6300 6350 Physical Interfaces A 13 ...