This is a listing of ports and protocols used by the S8700 Media Server’s interface to the Customer’s LAN, i.e. the S8700-enterprise interface. On an Avaya S8700 Media Server in the Multi-connect this will the eth4. On an Avaya S8700 Media Server in the IP-Connect configuration this is on eth0, shared with the Control Network A (CNA) connection. This does not include IPSI traffic (yet).

Входящие на интерфейсе S8700 Enterprise

Порты назначения на S8700.

Protocol/PortNameServiceS8700/MV Usage
TCP/00020ftp-dataFTP data channelThe S8700 server can enable an ftp server to allow Upgrades and Patches to be placed on the server. [1]
TCP/00021ftpNormal FTP daemon
TCP/00022sshSecure ShellAvailable for customer use and future use by Avaya.
TCP/00023telnetNormal Telnet daemonShell access to S8700, generally not required, a shell is accessible through the SAT interface on the active server.
TCP/00080wwwWeb serverLogin screen will move to https
TCP/00443httpsSecure Web ServerPrimary web services port
TCP/00512 - 01023rshReturn path for std errorrsync over rsh is used to move translation files to the LSP. This will move to a more secure interface in a future release
TCP/05023def-satDEFINITY SAT telnet daemonRequired for inbound SAT (ASA), Optionally SAT can be through a CLAN.
UDP/00123ntpNetwork time protocolUsed to synchronize to external time server
UDP/0161snmpSNMP MIB sets/getsIf network management tool is used and native agent is available (MV1.2.1).

Исходящие на интерфейсе S8700 Enterprise

Исходящие порты S8700 не постоянны.

Protocol/portNameServiceS8700/MV Usage
TCP/00020ftp-dataFTP data channelsUsed for translation back-up to FTP server or getting files from ftp server.
TCP/00021ftpNormal FTP daemon
TCP/00022sshSecure ShellNot Required.
TCP/00023telnetNormal Telnet daemonNot Required; useful for trouble shooting.
TCP/00025smtpSMTPUsed for translation back-up via mail.
TCP/00080wwwHTTP Web server.Used when downloading files from an http server for updates or firmware download.
TCP/00514cmdRemote shell server (used by rsync)Required for sending translations to LSP
UDP/00053domainDNS serverRequired only if other services will be using it. e.g. Web addressing other server by name, accessing  http or ftp server for downloads
UDP/0162snmp-trapSNMP trapsIf network management tool is used or IP alarming is enabled.

[1].  When attempting to FTP a file from the S8700 server, a data session will be initiated from the server on a random high port.

Настройки файрвола

This table contains specific recommendations and for customers (based on network configuration). This assumes that the VisAbility management server is on the same network as the S8700. All administration will be performed from specific administration stations to the S8700 (not through the CLAN). The WEB administration can also be performed from these specific administration terminals. Deny all access unless specifically permitted.

ActionFromTCP/UDP port or ProtocolToTCP/UDP port or Protocol
PermitS8300 (LAN Spare Processor)TCP anyS8700-Enterprise-intfTCP 512-1023
PermitS8300 (LAN Spare Processor)TCP 514S8700-Enterprise-intfTCP any
PermitS8700-Enterprise-intfTCP 512-1023S8300 (LAN Spare Processor)TCP any
PermitS8700-Enterprise-intfTCP anyS8300 (LAN Spare Processor)TCP 514
These will allow the S8700 to synchronize translations with the LSP, not technically needed at 75 Wall. TCP session is initiated from the S8700 to the S8300 on port 514. A second session is then initiated from the S8300 to a port on the S8700 in the range 512-1023. There are plans to migrate away from this rsh protocol in a future release.
PermitASA work stationsTCP anyS8700-Enterprise-intfTCP 5023
PermitS8700-Enterprise-intfTCP 5023ASA work stationsTCP any
These will allow the Admin. Workstation to log into the server.
PermitWeb Admin. StationTCP anyS8700-Enterprise-intfTCP 80
PermitWeb Admin. StationTCP anyS8700-Enterprise-intfTCP 443
PermitS8700-Enterprise-intfTCP 80Web Admin. StationTCP any
PermitS8700-Enterprise-intfTCP 443Web Admin. StationTCP any
These will allow secure and unsecure web access to the server; the server will redirect unsecure sessions to https. These permits can be allowed the entire customer network, or just the subnets or hosts where the administration will occur from.
PermitS8700-Enterprise-intfUDP anyCustomer’s NetworkUDP 53
PermitCustomer’s NetworkUDP 53S8700-Enterprise-intfUDP any
This will allow the S8700 to perform DNS look-ups, not necessarily required, but nice if FTP or other services to the Customer’s network are used.
PermitS8700-Enterprise-intfUDP anyCustomer’s NetworkUDP 123
PermitCustomer’s NetworkUDP 123S8700-Enterprise-intfUDP any
Требуется только если включена синхронизация времени по NTP

Эти правила запрещают доступ извне Avaya Products, но разрешают доступ с локальной сети LAN заказчика.

ActionFromTCP/UDP port or ProtocolToTCP/UDP port or Protocol
PermitCustomer’s LANTCP anyS8700-Enterprise-intany
PermitS8700-Enterprise-intTCP establishedCustomer’s Networkany
These rules permit SAT, Telnet, Web and FTP Sessions to be originated into the S8700
PermitS8700-Enterprise-intfTCP anyS8300 (LAN Spare Processor)TCP 514
Enables translations to be sent to the LSP
PermitS8700-Enterprise-intTCP anyCustomer’s NetworkTCP 20
Enables FTP from customer network to S8700
PermitS8700-Enterprise-intfUDP anyCustomer’s NetworkUDP 53
PermitCustomer’s NetworkUDP 53S8700-Enterprise-intfUDP any
PermitS8700-Enterprise-intfUDP anyCustomer’s NetworkUDP 123
PermitCustomer’s NetworkUDP 123S8700-Enterprise-intfUDP any
Enables DNS and FTP service for S8700 Servers

CLAN

Открытые прослушивающие порты платы CLAN. Надо иметь ввиду, что S8700 общается с CLAN через плату IPSI (и TDM), а не через сетевой интерфейс CLAN.

PortTCP or UDPDescription
1719UDPH.323 RAS
1720TCPH.323 Signaling
1037TCPDual Connect CCMS (may be discontinued)
2945TCPH.248
5001TCPCMS (configurable)
5002TCPIntuity Audix
5003TCPDCS (6002-6008 for DCS/Intuity)
5023TCPSAT (Telnet)
XXTCPCDR - When inabled, CLAN acts as a client. Destination port is configured on CDR Server.

Порты RTP/RTCP для медиа динамические и согласовываются во время фазы регистрации.

IPSI

Список прослушивающих портов платы IPSI «listening» и их соответствующие порты на S8700.

S8700IPSItcp/udpcomment
any5010tcpmain control socket between PCD and SIM
any5011tcpipsiversion queries
any5012tcpserial number queries
any123udpntp
123anyudpntp
any23tcptelnet - for configuration after enable.
any21ftpDownload of firmware
any20ftp-dataDownload of firmware
3166?1956tcpcommand server (download, etc.)
anyanyicmpecho replies
any2312tcpUsed by development only for telnet shell access for debugging. Can be blocked by a firewall.