13-26
Cisco ONS 15454 Reference Manual, R8.5
78-18106-01
Chapter 13 Management Network Connectivity
13.4 External Firewalls
The following ACL example shows a firewall configuration when the SOCKS proxy server gateway
setting is not enabled. In the example, the CTC workstation's address is 192.168.10.10. and the
ONS 15454 address is 10.10.10.100. The firewall is attached to the GNE, so inbound is CTC to the GNE
and outbound is from the GNE to CTC. The CTC CORBA Standard constant is 683 and the TCC CORBA
Default is TCC Fixed (57790).
access-list 100 remark *** Inbound ACL, CTC -> NE ***
access-list 100 remark
access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 eq www
access-list 100 remark *** allows initial contact with ONS 15454 using http (port 80) ***
access-list 100 remark
access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 eq 57790
access-list 100 remark *** allows CTC communication with ONS 15454 GNE (port 57790) ***
access-list 100 remark
access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 established
access-list 100 remark *** allows ACKs back from CTC to ONS 15454 GNE ***
access-list 101 remark *** Outbound ACL, NE -> CTC ***
access-list 101 remark
access-list 101 permit tcp host 10.10.10.100 host 192.168.10.10 eq 683
access-list 101 remark *** allows alarms etc., from the 15454 (random port) to the CTC
workstation (port 683) ***
access-list 100 remark
access-list 101 permit tcp host 10.10.10.100 host 192.168.10.10 established
access-list 101 remark *** allows ACKs from the 15454 GNE to CTC ***
The following ACL example shows a firewall configuration when the SOCKS proxy server gateway
setting is enabled. As with the first example, the CTC workstation address is 192.168.10.10 and the
ONS 15454 address is 10.10.10.100. The firewall is attached to the GNE, so inbound is CTC to the GNE
and outbound is from the GNE to CTC. CTC CORBA Standard constant is 683 and the TCC CORBA
Default is TCC Fixed (57790).
access-list 100 remark *** Inbound ACL, CTC -> NE ***
access-list 100 remark
access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 eq www
2361
TL1
D
3082
Raw TL1
D
3083
TL1
D
5001
BLSR
3
server port
D
5002
BLSR client port
D
7200
SNMP alarm input port
D
9100
EQM port
D
9401
TCC boot port
D
9999
Flash manager
D
10240-12287
Proxy client
D
57790
Default TCC listener port
OK
1.
D = deny, NA = not applicable, OK = do not deny
2.
CORBA IIOP = Common Object Request Broker Architecture Internet Inter-ORB Protocol
3.
BLSR = bidirectional line switched ring
Table 13-6
Ports Used by the TCC2/TCC2P (continued)
Port
Function
Action
1
Summary of Contents for 15454-DS1-14= - 1.544Mbps Expansion Module
Page 40: ...Tables xl Cisco ONS 15454 Reference Manual R8 5 78 18106 01 ...
Page 49: ...xlix Cisco ONS 15454 Reference Manual R8 5 78 18106 01 About this Manual ...
Page 51: ...li Cisco ONS 15454 Reference Manual R8 5 78 18106 01 About this Manual ...
Page 826: ...Index IN 30 Cisco ONS 15454 Reference Manual R8 5 78 18106 01 ...