Differences between revisions 10 and 11
Revision 10 as of 2023-08-21 01:02:29
Size: 1759
Comment:
Revision 11 as of 2023-08-21 01:02:44
Size: 1770
Comment:
Deletions are marked like this. Additions are marked like this.
Line 30: Line 30:
{{FW.png}} FW.png {{attachment:FW.png}} FW.png

NAT Router configuration

  • NAT Router is Ubiquiti Networks "Edge Router 4"

  • NAT Router has been configured (by Larry@LIGO GC) through the GUI interface, which is only available from the martian network. To launch the GUI interface, simply access to the martian IP of the router (192.168.113.2) with a web browser. You can find the user name and password at the usual secret place. User Name: 40Mubnt Password: ll@cit_admin_ubnt

EdgeRouterNATSettings_2021-09-29_14-46-22.png

  • Open ports:

    • 22 (ssh) - port forwarded to nodus
    • 873 (rsync) - port forwarded to nodus
    • 8080/8081 (elogd) - port forwarded to nodus
    • 30889 (apache) - port forwarded to nodus
    • 31200 (NDS) - port forwarded to megatron
    • 22220 (ssh) - port forwarded to port 22 on c1teststand for direct ssh access.
  • Along with the NAT router installation, firewall rule of the shorewall on nodus was turned off as it is no longer necessary. We still neet to keep shorewall itself running to open the specified ports. The WAN (GC net) side cable of nodus was removed. NodusShorewallSetting

  • To log into c1teststand from outside internet (usual martian workstation passwords):
    • ssh controls@nodus.ligo.caltech.edu -p 22220

  • To log into nodus from outside internet (you know the password if you are supposed to know it):
    • ssh controls@nodus.ligo.caltech.edu


NAT Router Firewall configuration

As of Aug 15, 2023

FW.png FW.png FW_IP_GROUP.png FW_LAN1.png FW_LAN2.png FW_LAN3.png FW_LAN4.png FW_WAN_IN1.png FW_WAN_OUT1.png FW_WAN_OUT2.png FW_WAN_OUT3.png FW_WAN_OUT4.png FW_WAN_OUT5.png FW_WAN_OUT6.png FW_WAN_OUT7.png FW_WAN_OUT8.png

FirewallSetting (last edited 2023-08-21 02:11:12 by KojiaraiATligoDOTorg)