•
Scope of command and Span of Control
•
Client IP validation
5620 SAM network element communication
5620 SAM network element communication
The following configurations are documented in the
5620 SAM User Guide
, and help
secure communication between the network elements and 5620 SAM server installations:
•
SNMPv3
•
SSH for remote access to the network elements
•
SCP/SFTP for secure file transfer
•
NETCONF
5620 SAM and firewalls
5620 SAM and firewalls
A firewall can be deployed to protect the 5620 SAM server from the managed network
and to protect the server from the network hosting the 5620 SAM clients. The diagrams
below illustrate this and show the communications services that are required through the
firewalls. Installations of 5620 SAM can make use of the built in firewall using iptables.
Standalone Firewall products must not be collocated on servers hosting 5620 SAM
components. Only the built-in RHEL firewall used to enable filter rules lists can be
collocated with 5620 SAM components. See
“Firewall and NAT rules” (p. 7-16)
for more
details.
Some 5620 SAM operations require idle TCP ports to remain open for longer periods of
time. Therefore, customer's using a firewall that closes idle TCP connections should
adjust Operating System TCP keepalives to a value that ensures that the firewall will not
close sockets in use by 5620 SAM.
For some of the network elements described in
“GNE, Alcatel-Lucent OmniSwitch, 9471
WMM, eNodeB, and 5780 DSC considerations” (p. 5-20)
there is a requirement for the
5620 SAM GUI client to communicate directly with the network element using
specialized configuration tools.
Security
5620 SAM software installation
....................................................................................................................................................................................................................................
....................................................................................................................................................................................................................................
7-4
5620 SAM
3HE-09809-AAAG-TQZZA 13.0 R7
Issue 1
December 2015