Table 4-4 Proxy Server Firewall Filtering Rules When Packet Addressed To Ons 15327 - Cisco ONS 15327 User Documentation

Hide thumbs Also See for ONS 15327:
Table of Contents

Advertisement

Chapter 4
IP Networking
Table 4-4
Packets Arrive At
XTC Ethernet
Interface
DCC Interface
If you implement the proxy server scenario, keep the following rules in mind:
All DCC-connected ONS 15327s on the same Ethernet segment must have the same Craft Access
Only setting. Mixed values will produce unpredictable results, and may leave some nodes
unreachable through the shared Ethernet segment.
All DCC-connected ONS 15327s on the same Ethernet segment must have the same Enable Firewall
setting. Mixed values will produce unpredictable results. Some nodes may become unreachable.
All DCC-connected ONS 15327s in the same SDCC area must have the same Enable Firewall
setting. Mixed values will produce unpredictable results. Some nodes may become unreachable.
If you enable Enable Firewall, always enable Enable Proxy. If Enable Proxy is not enabled, CTC
will not be able to see nodes on the DCC side of the ONS 15327.
If Craft Access Only is enabled, enable Enable Proxy. If Enable Proxy is not enabled, CTC will not
be able to see nodes on the DCC side of the ONS 15327.
If nodes become unreachable in cases 1, 2 and 3, you can correct the setting by performing one of the
following:
Disconnect the craft computer from the unreachable ONS 15327. Connect to the ONS 15327
through another ONS 15327 in the network that has a DCC connection to the unreachable
ONS 15327.
Disconnect the Ethernet cable from the unreachable ONS 15327. Connect a CTC computer directly
to the ONS 15327.
June 2002
Proxy Server Firewall Filtering Rules When Packet Addressed to ONS 15327
Accepted
All UDP packets except those in the
Rejected column
All TCP, OSPF and ICMP packets
All UDP packets
All TCP packets except those in the
Rejected column
OSPF packets
ICMP packets
ONS 15327 IP Addressing Scenarios
Rejected
UDP packets addressed to the
SNMP trap relay port (391) are
rejected
TCP packets addressed to the telnet
port are rejected.
TCP packets addressed to the IO
card telnet ports are rejected.
TCP packets addressed to the proxy
server port are rejected.
Cisco ONS 15327 User Documentation, R3.3
4-19

Advertisement

Table of Contents
loading

Table of Contents