348
X4000
User’s Guide
Configuration of Security Functions and Firewall
10
Reorganizing a chain
Proceed as follows to reorganize an existing chain of rules:
➤
Go to
IP
➧
A
CCESS
L
ISTS
➧
R
ULES
➧
REORG.
➤
Select Index of Rule that gets Index 1.
➤
Confirm with REORG.
10.2.9
Local Filters
Access to the local UDP and TCP services on
X4000
(telnet,
➤➤
CAPI
, trace,
etc.) can be controlled via the separate Setup Tool menu
IP
➧
L
OCAL
S
ERVICES
A
CCESS
C
ONTROL
. One or more restrictions can be defined here for each
service. If no entry exists for a service, there are no access restrictions for this
service, i.e. access is possible to this service over all interfaces and from any
source address, provided this is not prohibited by the use of NAT (see
chapter 10.2.7, page 331
) or global filters (see
chapter 10.2.8, page 335
).
Strategy
As soon as at least one entry for local filters exists in
X4000
, incoming requests
for the corresponding local services of
X4000
are only allowed if
1.
the source address is 127.0.0.1 (loopback address), or
2.
no entry exists for the corresponding service, or
3.
the incoming call is expressly allowed by at least one entry.
The existing entries are processed in the order in which they are listed in the
corresponding table in the SNMP shell (localTcpAllowTable or
localUdpAllowTable). If an entry in this sorted list does not apply, the next
entry is checked. This enables requests over several interfaces or from several
IP addresses to be admitted individually to a certain service.
If a matching entry for a request has still not been found after checking the last
entry in the list, there are two alternatives:
■
The request is forwarded to the relevant service if no entry in the list refers
to this service.
If you work with Windows PCs in your network, it is usually advisable to define
a NetBIOS filter. An example of this configuration is explained step by step in
chapter 7.1.5, page 132
.
Summary of Contents for X4000
Page 4: ...4 X4000 User s Guide...
Page 6: ...6 X4000 User s Guide Table of Contents...
Page 14: ...14 X4000 User s Guide Table of Contents...
Page 30: ...30 X4000 User s Guide Welcome 1...
Page 34: ...34 X4000 User s Guide General Safety Precautions 2...
Page 68: ...68 X4000 User s Guide Hardware Description and Installation 3...
Page 92: ...92 X4000 User s Guide Configuration Requirements 4...
Page 118: ...118 X4000 User s Guide Fast Configuration with the Configuration Wizard Basic Unit 6...
Page 362: ...362 X4000 User s Guide Configuration of Security Functions and Firewall 10...
Page 374: ...374 X4000 User s Guide Configuration Management 11...
Page 386: ...386 X4000 User s Guide Troubleshooting 12...
Page 433: ...X4000 User s Guide 433 15...
Page 449: ...X4000 User s Guide 449 15...
Page 468: ...468 X4000 User s Guide General Safety Precautions in 15 Different Languages 15...
Page 496: ...496 X4000 User s Guide Index...
Page 498: ...498 X4000 User s Guide Document 71000L Version1 3...