2-18
To reduce the risk of being attacked by malicious users against opened socket and enhance switch
security, the S3100 series Ethernet switches provide the following functions, so that a cluster socket is
opened only when it is needed:
z Opening UDP port 40000 (used for cluster) only when the cluster function is implemented,
z Closing UDP port 40000 at the same time when the cluster function is closed.
On the management device, the preceding functions are implemented as follows:
z When you create a cluster by using the build or auto-build command, UDP port 40000 is opened
at the same time.
z When you remove a cluster by using the undo build or undo cluster enable command, UDP port
40000 is closed at the same time.
On member devices, the preceding functions are implemented as follows:
z When you execute the add-member command on the management device to add a candidate
device to a cluster, the candidate device changes to a member device and its UDP port 40000 is
opened at the same time.
z When you execute the auto-build command on the management device to have the system
automatically add candidate devices to a cluster, the candidate devices change to member devices
and their UDP port 40000 is opened at the same time.
z When you execute the administrator-address command on a device, the device's UDP port
40000 is opened at the same time.
z When you execute the delete-member command on the management device to remove a
member device from a cluster, the member device's UDP port 40000 is closed at the same time.
z When you execute the undo build command on the management device to remove a cluster, UDP
port 40000 of all the member devices in the cluster is closed at the same time.
z When you execute the undo administrator-address command on a member device, UDP port
40000 of the member device is closed at the same time.
Examples
# Configure the current switch as a management device and set the cluster name to aaa.
<Sysname> system-view
System View: return to User View with Ctrl+Z
[Sysname] cluster
[Sysname-cluster] build aaa
There is no base topology, if set up from local flash file?(Y/N)
n
#Apr 3 08:15:03:166 2000 aaa_0. H3C CLST/5/Cluster_Trap:- 1 -
OID:1.3.6.1.4.1.2011.6.7.1.0.3(hgmpMemberStatusChange):member 00.00.00.00.00.12.
a9.90.22.40 role change, NTDPIndex:0.00.00.00.00.00.12.a9.90.22.40, Role:1
[aaa_0.Sysname-cluster]