13-17
Cisco ONS 15454 Reference Manual, R7.0
78-17191-01
Chapter 13 Management Network Connectivity
13.2 13.2.7 IP Scenario 7: Provisioning the ONS 15454 SOCKS Proxy Server
Figure 13-13 IP Scenario 7: ONS 15454 SOCKS Proxy Server With ENEs on Multiple Rings
Table 13-3 shows the rules that the ONS 15454 follows to filter packets for the firewall when nodes are
configured as ENEs and GNEs.
If the packet is addressed to the ONS 15454 node, additional rules, shown in Tabl e 13- 4, are applied.
Rejected packets are silently discarded.
71675
Remote CTC
10.10.20.10
10.10.20.0/24
10.10.10.0/24
Interface 0/0
10.10.20.1
Router A
Interface 0/1
10.10.10.1
ONS 15454
GNE
10.10.10.100/24
ONS 15454
ENE
192.168.10.250/24
ONS 15454
ENE
192.168.10.150/24
ONS 15454
ENE
192.168.10.200/24
Ethernet
SONET
ONS 15454
GNE
10.10.10.200/24
ONS 15454
ENE
192.168.80.250/24
ONS 15454
ENE
192.168.60.150/24
ONS 15454
ENE
192.168.70.200/24
Table 13-3 SOCKS Proxy Server Firewall Filtering Rules
Packets Arriving At: Are Accepted if the Destination IP Address is:
TCC2/TCC2P
Ethernet interface
The ONS 15454 node itself
The ONS 15454 node’s subnet broadcast address
Within the 224.0.0.0/8 network (reserved network used for standard
multicast messages)
Subnet mask = 255.255.255.255
DCC interface The ONS 15454 node itself
Any destination connected through another DCC interface
Within the 224.0.0.0/8 network