Chapter 8 Management Network Connectivity

External Firewalls

Table 8-6

Ports Used by the 15310E-CTX-K9 (continued)

 

 

 

Port

Function

Action1

10240-12287

Proxy client

D

 

 

 

57790

Default TCC listener port

OK

 

 

 

1. D = deny, NA = not applicable, OK = do not deny

The following access control list (ACL) examples show a firewall configuration when the proxy server gateway setting is not enabled. In the example, the CTC workstation address is 192.168.10.10 and the ONS 15310-MA SDH address is 10.10.10.100. The firewall is attached to the GNE, so the inbound path is CTC to the GNE and the outbound path is from the GNE to CTC. The CTC CORBA Standard constant is 683 and the TCC CORBA Default is TCC Fixed (57790).

access-list 100

remark ***

Inbound ACL, CTC -> NE ***

access-list 100

remark

 

access-list 100

permit tcp

host 192.168.10.10 host 10.10.10.100 eq www

access-list 100

remark ***

allows initial contact with the 15310-MA SDH using http (port

80) ***

 

 

access-list 100

remark

 

access-list 100

permit tcp

host 192.168.10.10 host 10.10.10.100 eq 57790

access-list 100 remark *** allows CTC communication with the 15310-MA SDH GNE (port 57790)

***

 

 

access-list 100

remark

 

access-list 101

remark

 

access-list 101

permit tcp

host 10.10.10.100 host 192.168.10.10 eq 683

access-list 101

remark ***

allows alarms etc., from the 15310-MA SDH (random port) to the

CTC workstation

(port 683)

***

access-list 100

remark

 

access-list 101

permit tcp

host 10.10.10.100 host 192.168.10.10 established

access-list 101

remark ***

allows ACKs from the 15310-MA SDH GNE to CTC ***

 

 

The following ACL examples show a firewall configuration when the proxy server gateway setting is

 

 

enabled. As with the first example, the CTC workstation address is 192.168.10.10 and the

 

 

ONS 15310-MA SDH address is 10.10.10.100. The firewall is attached to the GNE, so the inbound path

 

 

is CTC to the GNE and the outbound path is from the GNE to CTC. The CTC CORBA Standard constant

 

 

is 683 and the TCC CORBA Default is TCC Fixed (57790).

 

 

access-list 100 remark *** Inbound ACL, CTC -> NE ***

 

 

access-list 100 remark

 

 

access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 eq www

 

 

access-list 100 remark *** allows initial contact with the 15310-MA SDH using http (port

 

 

80) ***

 

 

 

 

 

access-list 100 remark

 

 

access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 eq 1080

 

 

access-list 100 remark *** allows CTC communication with the 15310-MA SDH GNE proxy server

 

 

(port 1080) ***

 

 

access-list 100 remark

 

 

access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 established

 

 

access-list 100 remark *** allows ACKs from CTC to the 15310-MA SDH GNE ***

 

 

access-list 101 remark *** Outbound ACL, NE -> CTC ***

 

 

access-list 101 remark

 

 

access-list 101 permit tcp host 10.10.10.100 eq 1080 host 192.168.10.10

 

 

access-list 101 remark *** allows alarms and other communications from the 15310-MA SDH

 

 

(proxy server) to the CTC workstation

 

 

(port 683) ***

 

 

access-list 100 remark

 

 

access-list 101 permit tcp host 10.10.10.100 host 192.168.10.10 established

 

 

access-list 101 remark *** allows ACKs from the 15310-MA SDH GNE to CTC ***

 

 

Cisco ONS 15310-MA SDH Reference Manual, Release 9.1 and Release 9.2

 

 

 

 

 

 

 

 

 

 

 

 

78-19417-01

 

 

8-19

 

 

 

 

 

Page 165
Image 165
Cisco Systems 15310-MA manual Port Function Action, Proxy client 57790 Default TCC listener port

15310-MA specifications

Cisco Systems has established itself as a leader in the networking domain, offering a wide array of solutions to meet the needs of modern businesses. Among its impressive product lineup are the Cisco 15310-CL and 15310-MA routers, designed to provide advanced network performance and reliability.

The Cisco 15310-CL is a versatile platform that primarily serves as a carrier-class router aimed at supporting high-speed data and voice services. It is built to handle the demands of large enterprises and service providers, offering a robust design that ensures maximum uptime and performance. One of its standout features is its modular architecture, which enables users to customize their configurations based on specific application needs. This scalability allows for future expansion without the need for a complete hardware overhaul.

Key technologies integrated into the Cisco 15310-CL include high-density Ethernet interfaces and a comprehensive suite of Layer 2 and Layer 3 protocol support. The device is capable of supporting multiple types of connections, including TDM, ATM, and Ethernet. This flexibility makes it an ideal choice for organizations that require seamless migration between various service types. Moreover, with features such as MPLS (Multiprotocol Label Switching) support and advanced Quality of Service (QoS) mechanisms, the router ensures that critical applications receive the necessary bandwidth and low latency required for optimal performance.

In contrast, the Cisco 15310-MA focuses on access solutions, providing a cost-effective entry point for businesses looking to enhance their network capabilities. It is well-suited for smaller offices or branch locations that need reliable connectivity without the expense and complexity associated with larger systems. The device supports a range of access methods and provides essential features like firewall capabilities, VPN support, and comprehensive security measures to protect sensitive data.

Both models benefit from Cisco's commitment to security and manageability, offering features like enhanced encryption protocols and user authentication mechanisms that help safeguard networks against threats. Additionally, they can be managed through Cisco’s intuitive software tools, simplifying configuration and monitoring tasks for IT administrators.

The Cisco 15310-CL and 15310-MA are ideal solutions for businesses seeking to enhance their network infrastructure, ensuring firms can keep pace with evolving technology demands while maintaining a focus on security and performance. Their combination of advanced features, modular capabilities, and robust support makes them valuable assets in the networking landscape.