MGC supports legacy VxWorks-based firewall also known as Port Access Restrictions.
You can administer the feature through CLI commands only. No GUI interface is provided. Use the portAccessHelp CLI command to view the Help.
Configuration is done on each MGC. You cannot configure system-wide parameters.
The feature has three states:
Off: Firewall is not active.
Default: Firewall runs default configuration.
Custom: Firewall runs custom configuration.
The default configuration is to allow the following incoming connections:
Protocol
Port number
Service
TCP
22
SSH
TCP
15000
PBX link
UDP
500
IPSec IKE
UDP
15003
RUDP HB
Custom configuration is read from the /u/db/customport.xml file, which should be manually uploaded by an administrator.
Upgrade from CS 1000 to Device Adapter MGC loadware does not change the firewall state. If you are migrating MGCs that run a custom firewall configuration, you must allow UDP port 15003.
The DSP ports are handled by the DSP and are not covered by the firewall.