Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Panel

In this section:

Table of Contents
maxLevel4

The

Spacevars
0series4
  platforms (SBC 5000 series, SBC 7000, SBC SWe) listen to the TCP/IP network ports listed in the following tables. Some of these ports will not be open if the corresponding product features are not configured.

Noteinfo
iconfalse
titleNote

The actual ports that the

Spacevars
0product
listens to depends on the actual system configuration.


Warning
titleWarning

Due to an IPMI vulnerability, Sonus Ribbon recommends not connecting the BMC Ethernet port to an external network unless the network is deemed well-protected.

[Reference: NIST National Vulnerability Database website]

...

Multiexcerpt
MultiExcerptNameME1

SBC 5000/7000 Series BMC Ports

 
Caption
0Table
1SBC 5000/7000 Series BMC Ports


Protocol

Network Port

Application Level ProtocolProcess Using the Ports

Usage

Notes
TCP22SSHSSHDBMC CLI via SSHBMC CLI over SSHv2.
TCP80
 
TLS 1.2lighttpdBMC GUI redirection to port 443

HTTP server redirects browser to port 443 for HTTPS. No actual BMC access on port 80.

TCP443
 
TLS 1.2lighttpd
 
BMC GUI via HTTPS
 

TCP

5120

 
TCP
 
cdserver opp

BMC Remote Console: CD

 


TCP

5121

 

 not used

 
not used

BMC Remote Console: Keyboard and Mouse

 


TCP

5123

 
not used
 
not used

BMC Remote Console: Diskette

 

TCP

5555

 
not used
 
not used

BMC Remote Console: Encryption

 

TCP

5556

 
not used
 
not used

BMC Remote Console: Authentication

 


TCP

6481

 
not used
 
not used

BMC Remote Console: Servicetag Daemon

  

TCP

7578

 
TCP

BMC Remote Console: Video

 

TCP7579
  


BMC Remote Console: Serial
 

TCPRandom portTCPIPMI




Multiexcerpt
MultiExcerptNameME2

SBC Core Management Ports

 
Caption
0Table
1SBC Core Management Ports


 
Protocol

Network Port

Application Level ProtocolProcess Using the Ports

Usage

Notes

TCP

 

 

 

 

 

 

 

 

 

 












22

 
SSH
 
SSHD

SBC application CLI via SSH 

Application CLI over SSHv2.

80

 
TLS 1.2apache2

Embedded Management Application (EMA) GUI redirection to port 443

HTTP server redirects browser to port 443 for HTTPS. No actual EMA access on port 80. 

443

 
 TLS 1.2apache2
 

EMA GUI via https

 

444

 
connexip manager
 
apache2

EMA GUI, Platform Mode via https

 

2022

 
confd
 

Netconf OAM interface 

Netconf over SSHv2. Used by

Sonus

Ribbon EMS to manage the SBC.

2024

 
sftp
 

Linux SFTP access via SSH 

 

3091
 
ssreq-tcp
 
SSREQSSReq troubleshooting toolDefault TCP port

4680

  



SecureLink client GUI via http 

The SecureLink client is a RASO feature that creates and maintains an SSH connection to the SecureLink server at

SonusHQ

RibbonHQ, to support remote troubleshooting. This port presents a GUI interface to manage the SL client.

NOTE: SecureLink runs on a separate VM instance for SBC SWe; hence this port is not applicable for SBC SWe.

UDP

 

 


Port 4680 is restricted to "localhost." This ensures that Gatekeeper (the SecureLink GUI) cannot be accessed remotely using the management port of the SBC. 

UDP



123
 
NTP
 
NTPDNetwork Timing Protocol Daemon (NTPD)
 

161   

 
SNMP
 
SNMP daemon

SNMP agent 

Statistics and status retrieval. Read only.

3054
 
DIAMETER+
 
DSPSX call processing requestsThis port is used for call processing requests coming from the PSX to the SBC over Diameter+. This can also be configured through PKT ports.
3055
 
DIAMETER+
 
DSKeep alive messages and registration (Diameter).This can also be configured through PKT ports.

3069  

 
DMARSH
 
SCPA

ERE   

ERE SIP SCPA process.

3090
 
ssreq-udp
 
SSREQSSReq troubleshooting toolDefault UDP port

65xxx  

  


PSX    

Dynamically allocated server port number. Part of SBC communication with external PSX.

 



SBC Core Media Physical Ports at Interface IP Addresses

Caption
0Table
1SBC Core Media Physical Ports at Interface IP Addresses


Protocol

Network Port

Application Level ProtocolProcess Using the Ports

Usage

Notes

UDP

500

 
IKE
 
IKE

IKE

IKEv1 or IKEv2 Internet Key Exchange for IPSec

1024-65534

  
RTP, RTCP,SRTP,SRTCP

RTP, RTCP, SRTP, SRTCP

Real time media

ESP

N/A

 

 


IPSec ESP

Encapsulating Security Payload