
User's Manual
143
February 2007
MP-202 Telephone Adapter
12. Security
For example, when you point your Web browser to a Web page on the Internet, a request
is sent out to the Internet for this page. When the request reaches the MP-202, the firewall
will identify the request type and origin--HTTP and a specific PC in your home network, in
this case. Unless you have configured access control to block requests of this type from
this computer, the firewall will allow this request to pass out onto the Internet (refer to 'WAN
PPPoE' on page
82
for more on setting access controls). When the Web page is returned
from the Web server the firewall will associate it with this session and allow it to pass,
regardless of whether HTTP access from the Internet to the home network is blocked or
permitted.
Note that it is the
origin of the request
, not subsequent responses to this request, that
determines whether a session can be established or not.
You can choose from among three pre-defined security levels for the MP-202: Minimum,
Typical, and Maximum (the default setting). The table below summarizes the behavior of
the MP-202 for each of the three security levels.
Table
12-1: Behavior for the Three Security Levels
Security Level
Requests Originating
in the WAN
(Incoming Traffic)
Requests
Originating
in the LAN
(Outgoing Traffic)
Maximum
Security
(Default)
Blocked: No access to home network
from Internet, except as configured in
the Local Servers, DMZ host and
Remote Access screens
Limited: Only commonly- used services,
such as Web- browsing and e-mail, are
permitted
Typical Security
Blocked: No access to home network
from Internet, except as configured in
the Local Servers, DMZ host and
Remote Access screens
Unrestricted: All services are permitted,
except as configured in the Access
Control screen
Minimum
Security
Unrestricted: Permits full access from
Internet to home network; all connection
attempts permitted.
Unrestricted: All services are permitted,
except as configured in the Access
Control screen
These services include Telnet, FTP, HTTP, HTTPS, DNS, IMAP, POP3 and SMTP.
The list of allowed services at 'Maximum Security' mode can be edited in the screen'
'Access Contro'l on page
144
'.
Some applications (such as some Internet messengers and Peer-To-Peer client
applications) tend to use these ports if they cannot connect with their own default ports.
When applying this behaviour, these applications will not be blocked outbound, even at
Maximum Security Level.
¾
To configure the MP-202's security settings:
(Refer to the figure 'General Security Level Settings')
1.
Choose from among the three predefined security levels described in the table above.
'Maximum Security' is the default setting.
Using the Minimum Security setting may expose the home network to
significant security risks, and thus should only be used, when necessary, for
short periods of time.