Version 6.6
131
MP-11x & MP-124
User's Manual
12. Security
12
Security
This section describes the VoIP security-related configuration.
12.1 Configuring Firewall Settings
The device provides an internal firewall that enables you to configure network traffic
filtering rules (
access list
). You can add up to 50 firewall rules. The access list offers the
following firewall possibilities:
Block traffic from known malicious sources
Allow traffic only from known "friendly" sources, and block all other traffic
Mix allowed and blocked network sources
Limit traffic to a user-defined rate (blocking the excess)
Limit traffic to specific protocols, and specific port ranges on the device
For each packet received on the network interface, the table is scanned from top to bottom
until the first matching rule is found. This rule can either permit (
allow
) or deny (
block
) the
packet. Once a rule in the table is located, subsequent rules further down the table are
ignored. If the end of the table is reached without a match, the packet is accepted.
Notes:
•
This firewall applies to a very low-level network layer and overrides your
other security-related configuration. Thus, if you have configured higher-
level security features (e.g., on the Application level), you must also
configure firewall rules to permit this necessary traffic. For example, if
you have configured IP addresses to access the Web and Telnet
interfaces in the Web Access List (see 'Configuring Web and Telnet
Access List' on page
Error! Bookmark not defined.
), you must
configure a firewall rule that permits traffic from these IP addresses.
•
Only Security Administrator users or Master users can configure firewall
rules.
•
Setting the 'Prefix Length' field to
0
means that the rule applies to
all
packets, regardless of the defined IP address in the 'Source IP' field.
Therefore, it is highly recommended to set this parameter to a value
other than 0.
•
It is recommended to add a rule at the end of your table that blocks all
traffic and to add firewall rules above it that allow required traffic (with
bandwidth limitations). To block all traffic, use the following firewall rule:
- Source IP: 0.0.0.0
- Prefix Length: 0 (i.e., rule matches all IP addresses)
- Start Port - End Port: 0-65535
- Protocol:
Any
- Action Upon Match:
Block
•
You can also configure the firewall settings using the table ini file
parameter, AccessList (see 'Security Parameters' on page
446
).
Summary of Contents for Media Pack MP-124
Page 2: ......
Page 14: ...User s Manual 14 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 18: ...User s Manual 18 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 23: ...Part I Getting Started with Initial Connectivity...
Page 24: ......
Page 32: ...User s Manual 32 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 33: ...Part II Management Tools...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 86: ...User s Manual 86 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 88: ...User s Manual 88 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 93: ...Part III General System Settings...
Page 94: ......
Page 103: ...Part IV General VoIP Configuration...
Page 104: ......
Page 130: ...User s Manual 130 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 164: ...User s Manual 164 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 174: ...User s Manual 174 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 199: ...Part V Gateway Application...
Page 200: ......
Page 202: ...User s Manual 202 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 240: ...User s Manual 240 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 286: ...User s Manual 286 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 287: ...Part VI Stand Alone Survivability Application...
Page 288: ......
Page 296: ...User s Manual 296 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 319: ...Part VII Maintenance...
Page 320: ......
Page 326: ...User s Manual 326 Document LTRT 65422 MP 11x MP 124 Reader s Notes...
Page 359: ...Part VIII Status Performance Monitoring and Reporting...
Page 360: ......
Page 389: ...Part IX Diagnostics...
Page 390: ......
Page 404: ...User s Manual 404 Document LTRT 65422 MP 11x MP 124...
Page 417: ...Part X Appendix...
Page 418: ......
Page 580: ...User s Manual 580 Document LTRT 65422 MP 11x MP 124 Reader s Notes...