EPICS Controls Argonne National Laboratory

Experimental Physics and
Industrial Control System

1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  <20142015  2016  2017  2018  2019  2020  2021  2022  2023  2024  Index 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  <20142015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
<== Date ==> <== Thread ==>

Subject: Re: TCP and UDP port numbers fr multiple IOCs
From: Andrew Johnson <[email protected]>
To: Hovanes Egiyan <[email protected]>
Cc: "[email protected]" <[email protected]>
Date: Wed, 21 May 2014 17:39:08 -0500
Hi Hovanes,

On 05/21/2014 05:19 PM, Hovanes Egiyan wrote:
> The PVs from these softIOCs need to be accessed from another network in
> our lab that
> happens to be behind a firewall for security reasons. If we can assign
> the TCP address manually then the network administrator only needs to open
> a dozen (or two) predefined port #s between the two different firewalled
> networks, otherwise
> we apparently need to have the whole ephemeral port # range open between
> the networks ,
> which is a possibility too. There was a  similar question back in 2008
> according to
> techtalk, and it seemed that such a thing might get implemented, but I
> do not
> think the EPICS base version we are using has that capability yet.

This sounds like you should look at using a PV Gateway, configured
across the two subnets if your security guys will allow it, but not
necessarily if they'd rather do the hole punch. The gateway should
probably live on a different host where it gets to use the regular 5064
TCP port number, and it forwards the requested PVs to the firewalled
clients. You can configure which PVs are allowed through, and whether
writes are allowed etc.

Here at the APS we run PV gateways to allow all our experimental
beamlines to access selected PVs from the accelerator control system;
each beamline gets its own gateway between their subnet and the central one.

- Andrew
-- 
Advertising may be described as the science of arresting the human
intelligence long enough to get money from it. -- Stephen Leacock

References:
TCP and UDP port numbers fr multiple IOCs Hovanes Egiyan
Re: TCP and UDP port numbers fr multiple IOCs Andrew Johnson
Re: TCP and UDP port numbers fr multiple IOCs Hovanes Egiyan

Navigate by Date:
Prev: Re: TCP and UDP port numbers fr multiple IOCs Hovanes Egiyan
Next: Re: procServ and user id Ralph Lange
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  <20142015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
Navigate by Thread:
Prev: Re: TCP and UDP port numbers fr multiple IOCs Hovanes Egiyan
Next: make extensions error GUO Zhiying
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  <20142015  2016  2017  2018  2019  2020  2021  2022  2023  2024 
ANJ, 17 Dec 2015 Valid HTML 4.01! · Home · News · About · Base · Modules · Extensions · Distributions · Download ·
· Search · EPICS V4 · IRMIS · Talk · Bugs · Documents · Links · Licensing ·