Version 6.6
147
Mediant 3000
User's Manual
12. Security
The firewall rules in the above configuration example do the following:
Rules 1 and 2:
Typical firewall rules that allow packets ONLY from specified IP
addresses (e.g., proxy servers). Note that the prefix length is configured.
Rule 3:
A more "advanced” firewall rule - bandwidth rule for ICMP, which allows a
maximum bandwidth of 40,000 bytes/sec with an additional allowance of 50,000 bytes.
If, for example, the actual traffic rate is 45,000 bytes/sec, then this allowance would be
consumed within 10 seconds, after which all traffic exceeding the allocated 40,000
bytes/sec is dropped. If the actual traffic rate then slowed to 30,000 bytes/sec, the
allowance would be replenished within 5 seconds.
Rule 4:
Allows traffic from the LAN voice interface and limits bandwidth.
Rule 5:
Blocks all other traffic.
Internal Firewall Parameters
Parameter
Description
Source IP
[AccessList_Source_IP]
Defines the IP address (or DNS name) or a specific host name of the
source network (i.e., from where the incoming packet is received).
Source Port
[AccessList_Source_Port]
Defines the source UDP/TCP ports (of the remote host) from where
packets are sent to the device.
The valid range is 0 to 65535.
Note:
When set to 0, this field is ignored and any source port
matches the rule.
Prefix Length
[AccessList_PrefixLen]
(
Mandatory
) Defines the IP network mask - 32 for a single host or
the appropriate value for the source IP addresses.
A value of 8 corresponds to IPv4 subnet class A (network mask
of 255.0.0.0).
A value of 16 corresponds to IPv4 subnet class B (network mask
of 255.255.0.0).
A value of 24 corresponds to IPv4 subnet class C (network mask
of 255.255.255.0).
The IP address of the sender of the incoming packet is trimmed in
accordance with the prefix length (in bits) and then compared to the
parameter ‘Source IP’.
The default is 0 (i.e., applies to all packets). You
must
change this
value to any of the above options.
Note:
A value of 0 applies to
all
packets, regardless of the defined
IP address. Therefore, you must set this parameter to a value other
than 0.
Start Port
[AccessList_Start_Port]
Defines the destination UDP/TCP start port (on this device) to where
packets are sent.
The valid range is 0 to 65535.
Note:
When the protocol type isn't TCP or UDP, the entire range
must be provided.
End Port
[AccessList_End_Port]
Defines the destination UDP/TCP end port (on this device) to where
packets are sent.
The valid range is 0 to 65535.
Note:
When the protocol type isn't TCP or UDP, the entire range
must be provided.
Summary of Contents for Mediant 3000
Page 2: ......
Page 26: ...User s Manual 26 Document LTRT 89729 Mediant 3000 Reader s Note...
Page 27: ...Part I Getting Started with Initial Connectivity...
Page 28: ......
Page 40: ...User s Manual 40 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 41: ...Part II Management Tools...
Page 42: ......
Page 44: ...User s Manual 44 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 80: ...User s Manual 80 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 98: ...User s Manual 98 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 103: ...Part III General System Settings...
Page 104: ......
Page 113: ...Part IV General VoIP Configuration...
Page 114: ......
Page 144: ...User s Manual 144 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 164: ...User s Manual 164 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 222: ...User s Manual 222 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 224: ...User s Manual 224 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 275: ...Part V Gateway and IP to IP Application...
Page 276: ......
Page 278: ...User s Manual 278 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 399: ...Part VI Session Border Controller Application...
Page 400: ......
Page 402: ...User s Manual 402 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 464: ...User s Manual 464 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 465: ...Part VII Stand Alone Survivability Application...
Page 466: ......
Page 474: ...User s Manual 474 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 494: ...User s Manual 494 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 497: ...Part VIII IP Media Capabilities...
Page 498: ......
Page 501: ...Part IX High Availability System...
Page 502: ......
Page 515: ...Part X Maintenance...
Page 516: ......
Page 522: ...User s Manual 522 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 524: ...User s Manual 524 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 552: ...User s Manual 552 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 562: ...User s Manual 562 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 565: ...Part XI Status Performance Monitoring and Reporting...
Page 566: ......
Page 578: ...User s Manual 578 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 609: ...Part XII Diagnostics...
Page 610: ......
Page 624: ...User s Manual 624 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 626: ...User s Manual 626 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 638: ...User s Manual 638 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 639: ...Part XIII Appendix...
Page 640: ......
Page 864: ...User s Manual 864 Document LTRT 89729 Mediant 3000 Reader s Notes...
Page 871: ...Version 6 6 871 Mediant 3000 User s Manual 55 Selected Technical Specifications Reader s Notes...