Chapter 9 Management Network Connectivity

9.5 External Firewalls

Table 9-7

Ports Used by the TSC (continued)

 

 

 

 

Port

Function

Action1

1080

Proxy server (socks)

D

 

 

 

2001-2017

I/O card Telnet

NA

 

 

 

2018

DCC processor on active TCC2/TCC2P

D

 

 

 

2361

TL1

D

 

 

 

3082

Raw TL1

D

 

 

 

3083

TL1

D

 

 

 

5001

BLSR server port

D

 

 

 

5002

BLSR client port

D

 

 

 

7200

SNMP alarm input port

D

 

 

 

9100

EQM port

D

 

 

 

9401

TCC boot port

D

 

 

 

9999

Flash manager

NA

 

 

 

10240-12287

Proxy client

D

 

 

 

57790

Default TCC listener port

OK

 

 

 

1. D = deny, NA = not applicable, OK = do not deny

The following ACL (access control list) example shows a firewall configuration when the SOCKS proxy server gateway setting is not enabled. In the example, the CTC workstation's address is 192.168.10.10. and the ONS 15600 address is 10.10.10.100. The firewall is attached to the GNE, so the inbound direction is from CTC to the GNE and the outbound direction is from the GNE to CTC. The CTC Common Object Request Broker Architecture (CORBA) Standard constant is 683 and the TCC CORBA Default is TCC Fixed (57790).

access-list 100 remark *** Inbound ACL, CTC -> NE ***

access-list 100 remark

access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 eq www

access-list 100 remark *** allows initial contact with ONS 15600 using http (port 80) ***

access-list 100 remark

access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 eq 57790

access-list 100 remark *** allows CTC communication with ONS 15600 GNE (port 57790) ***

access-list 100 remark

access-list 100 permit tcp host 192.168.10.10 host 10.10.10.100 established access-list 100 remark *** allows ACKs back from CTC to ONS 15600 GNE ***

access-list 101 remark *** Outbound ACL, NE -> CTC ***

access-list 101 remark

access-list 101 permit tcp host 10.10.10.100 host 192.168.10.10 eq 683

access-list 101 remark *** allows alarms etc., from the 15600 (random port) to the CTC workstation (port 683) ***

access-list 100 remark

access-list 101 permit tcp host 10.10.10.100 host 192.168.10.10 established access-list 101 remark *** allows ACKs from the 15600 GNE to CTC ***

The following ACL (access control list) example shows a firewall configuration when the SOCKS proxy server gateway setting is enabled. As with the first example, the CTC workstation address is 192.168.10.10 and the ONS 15600 address is 10.10.10.100. The firewall is attached to the GNE, so inbound is CTC to the GNE and outbound is from the GNE to CTC. CTC CORBA Standard constant (683) and TCC CORBA Default is TCC Fixed (57790).

Cisco ONS 15600 Reference Manual, R7.2

9-23

Page 183
Image 183
Cisco Systems ONS 15600 manual Raw TL1 3083

ONS 15600 specifications

Cisco Systems ONS 15600 is a highly versatile optical networking platform designed to meet the demands of modern telecommunications and data services. This multiservice edge platform supports various transmission mediums and offers a wide array of features that enable efficient data transport. Ideal for service providers and large enterprises, the ONS 15600 is engineered to provide scalable and reliable optical transport solutions.

One of the notable features of the ONS 15600 is its capability to support multiple protocols, including SONET/SDH, Ethernet, OTN, and legacy TDM services. This flexibility allows users to tailor their networks according to specific service requirements while ensuring interoperability with existing infrastructure. The platform is designed to facilitate seamless service migration, accommodating both legacy and next-generation services.

The modular architecture of the ONS 15600 enhances its scalability. It allows for easy expansion by incorporating additional line cards or interface modules without requiring significant downtime. This modularity ensures that service providers can evolve their networks over time, responding to increasing bandwidth demands and new service offerings with ease.

Incorporating advanced technologies, the ONS 15600 employs Dense Wavelength Division Multiplexing (DWDM), significantly increasing the capacity of fiber networks by allowing multiple signals to be transmitted simultaneously over a single optical fiber. This capability helps to optimize fiber utilization and reduce operational costs. In addition, the platform supports Optical Transport Network (OTN) for improved error detection and correction, contributing to higher reliability and performance.

Another key characteristic of the ONS 15600 is its robust management capabilities. The platform can be managed through Cisco's Optical Networking Manager (ONM), providing a centralized interface for network configuration, monitoring, and troubleshooting. This enhances operational efficiency and minimizes downtime, allowing service providers to focus on delivering quality services to their customers.

The ONS 15600 also prioritizes security, offering various features like encryption and access control to safeguard sensitive data during transmission. With its combination of scalability, flexibility, and security, the Cisco ONS 15600 stands out as a reliable choice for organizations looking to enhance their optical networking capabilities while meeting the evolving demands of the digital landscape. Its commitment to quality and performance makes it a cornerstone of modern optical networks.