Chapter 9 Management Network Connectivity

9.2.7 Scenario 7: Provisioning the ONS 15600 Proxy Server

Table 9-3 Proxy Server Firewall Filtering Rules

Packets Arriving At:

Are Accepted if the IP Destination Address Is:

 

 

TSC Ethernet

The ONS 15600 itself

interface

The ONS 15600 subnet broadcast address

 

 

Within the 224.0.0.0/8 network (reserved network used for standard

 

multicast messages)

 

 

DCC interface

The ONS 15600 itself

 

Any destination connected through another DCC interface

 

Within the 224.0.0.0/8 network

 

 

The rules in Table 9-4are applied if a packet is addressed to the ONS 15600. Rejected packets are discarded.

Table 9-4

Proxy Server Firewall Filtering Rules When Packet Addressed to ONS 15600

 

 

 

Packets Arriving At:

Accepts

Rejects

 

 

 

 

TSC Ethernet

 

All IP protocols except user

UDP packets addressed to the

interface

 

datagram protocol (UDP)

SNMP trap relay port (391)

 

 

All UDP packets except packets

 

 

 

address to the SNMP trap relay

 

 

 

port

 

 

 

 

 

DCC interface

 

All ICMP, OSPF, RSVP, and

TCP packets addressed to the

 

 

LMP packets

Telnet port

 

 

All TCP packets except packets

TCP packets addressed to the

 

 

addressed to the Telnet and

proxy server port

 

 

proxy server ports

Protocols not listed in the

 

 

 

 

 

 

Accepted column

 

 

 

 

If an ONS 15600 or CTC computer resides behind a firewall that uses port filtering, you must enable an Internet Inter-ORB Protocol (IIOP) port on the ONS 15600 and/or CTC computer, depending on whether one or both devices reside behind a firewall. You can enable an IIOP port on the

Provisioning > Network > General tabs in CTC.

Figure 9-13shows ONS 15600s in a protected network and the CTC computer in an external network. For the computer to access the ONS 15600s, you must provision the IIOP listener port specified by your firewall administrator on the ONS 15600. The ONS 15600 sends the port number to the CTC computer during the initial contact between the devices using Hyper-Text Transfer Protocol (HTTP). After the CTC computer obtains the ONS 15600 IIOP port, the computer opens a direct session with the node using the specified IIOP port.

Cisco ONS 15600 Reference Manual, R7.2

9-16

Page 176
Image 176
Cisco Systems ONS 15600 manual Packets Arriving At Accepts Rejects

ONS 15600 specifications

Cisco Systems ONS 15600 is a highly versatile optical networking platform designed to meet the demands of modern telecommunications and data services. This multiservice edge platform supports various transmission mediums and offers a wide array of features that enable efficient data transport. Ideal for service providers and large enterprises, the ONS 15600 is engineered to provide scalable and reliable optical transport solutions.

One of the notable features of the ONS 15600 is its capability to support multiple protocols, including SONET/SDH, Ethernet, OTN, and legacy TDM services. This flexibility allows users to tailor their networks according to specific service requirements while ensuring interoperability with existing infrastructure. The platform is designed to facilitate seamless service migration, accommodating both legacy and next-generation services.

The modular architecture of the ONS 15600 enhances its scalability. It allows for easy expansion by incorporating additional line cards or interface modules without requiring significant downtime. This modularity ensures that service providers can evolve their networks over time, responding to increasing bandwidth demands and new service offerings with ease.

Incorporating advanced technologies, the ONS 15600 employs Dense Wavelength Division Multiplexing (DWDM), significantly increasing the capacity of fiber networks by allowing multiple signals to be transmitted simultaneously over a single optical fiber. This capability helps to optimize fiber utilization and reduce operational costs. In addition, the platform supports Optical Transport Network (OTN) for improved error detection and correction, contributing to higher reliability and performance.

Another key characteristic of the ONS 15600 is its robust management capabilities. The platform can be managed through Cisco's Optical Networking Manager (ONM), providing a centralized interface for network configuration, monitoring, and troubleshooting. This enhances operational efficiency and minimizes downtime, allowing service providers to focus on delivering quality services to their customers.

The ONS 15600 also prioritizes security, offering various features like encryption and access control to safeguard sensitive data during transmission. With its combination of scalability, flexibility, and security, the Cisco ONS 15600 stands out as a reliable choice for organizations looking to enhance their optical networking capabilities while meeting the evolving demands of the digital landscape. Its commitment to quality and performance makes it a cornerstone of modern optical networks.