Version 6.6
155
MP-11x & MP-124
User's Manual
13. Security
Parameter
Value per Rule
1
2
3
4
5
Burst Bytes
0
0
50000
50000
0
Action Upon Match
Allow
Allow
Allow
Allow
Block
The firewall rules in the above configuration example do the following:
Rules 1 and 2:
Typical firewall rules that allow packets ONLY from specified IP
addresses (e.g., proxy servers). Note that the prefix length is configured.
Rule 3:
A more "advanced” firewall rule - bandwidth rule for ICMP, which allows a
maximum bandwidth of 40,000 bytes/sec with an additional allowance of 50,000 bytes.
If, for example, the actual traffic rate is 45,000 bytes/sec, then this allowance would be
consumed within 10 seconds, after which all traffic exceeding the allocated 40,000
bytes/sec is dropped. If the actual traffic rate then slowed to 30,000 bytes/sec, the
allowance would be replenished within 5 seconds.
Rule 4:
Allows traffic from the LAN voice interface and limits bandwidth.
Rule 5:
Blocks all other traffic.
Table
13-2: Internal Firewall Parameters
Parameter
Description
Source IP
[AccessList_Source_IP]
Defines the IP address (or DNS name) or a specific host name of the
source network (i.e., from where the incoming packet is received).
Source Port
[AccessList_Source_Port]
Defines the source UDP/TCP ports (of the remote host) from where
packets are sent to the device.
The valid range is 0 to 65535.
Note:
When set to 0, this field is ignored and any source port
matches the rule.
Prefix Length
[AccessList_PrefixLen]
(
Mandatory
) Defines the IP network mask - 32 for a single host or
the appropriate value for the source IP addresses.
A value of 8 corresponds to IPv4 subnet class A (network mask of
255.0.0.0).
A value of 16 corresponds to IPv4 subnet class B (network mask
of 255.255.0.0).
A value of 24 corresponds to IPv4 subnet class C (network mask
of 255.255.255.0).
The IP address of the sender of the incoming packet is trimmed in
accordance with the prefix length (in bits) and then compared to the
parameter ‘Source IP’.
The default is 0 (i.e., applies to all packets). You
must
change this
value to any of the above options.
Note:
A value of 0 applies to
all
packets, regardless of the defined IP
address. Therefore, you must set this parameter to a value other
than 0.
Start Port
[AccessList_Start_Port]
Defines the destination UDP/TCP start port (on this device) to where
packets are sent.
The valid range is 0 to 65535.
Note:
When the protocol type isn't TCP or UDP, the entire range
must be provided.
Summary of Contents for Media Pack MP-11x
Page 2: ......
Page 14: ...User s Manual 14 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 24: ...User s Manual 24 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 25: ...Part I Getting Started with Initial Connectivity...
Page 26: ......
Page 35: ...Part II Management Tools...
Page 36: ......
Page 38: ...User s Manual 38 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 86: ...User s Manual 86 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 94: ...User s Manual 94 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 100: ...User s Manual 100 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 108: ...User s Manual 108 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 109: ...Part III General System Settings...
Page 110: ......
Page 118: ...User s Manual 118 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 121: ...Part IV General VoIP Configuration...
Page 122: ......
Page 152: ...User s Manual 152 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 202: ...User s Manual 202 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 204: ...User s Manual 204 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 230: ...User s Manual 230 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 231: ...Part V Gateway Application...
Page 232: ......
Page 234: ...User s Manual 234 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 274: ...User s Manual 274 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 278: ...User s Manual 278 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 298: ...User s Manual 298 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 326: ...User s Manual 326 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 327: ...Part VI Stand Alone Survivability Application...
Page 328: ......
Page 336: ...User s Manual 336 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 358: ...User s Manual 358 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 361: ...Part VII Maintenance...
Page 362: ......
Page 368: ...User s Manual 368 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 406: ...User s Manual 406 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 409: ...Part VIII Status Performance Monitoring and Reporting...
Page 410: ......
Page 441: ...Part IX Diagnostics...
Page 442: ......
Page 456: ...User s Manual 456 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 458: ...User s Manual 458 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Page 471: ...Part X Appendix...
Page 472: ......