![CTEK Z4550 User Manual Download Page 15](http://html1.mh-extra.com/html/ctek/z4550/z4550_user-manual_2693789015.webp)
10 October 2016
11
General Configuration
Firewall Status - When enabled the firewall blocks all WAN traffic except for port 80 and the serial pad port if,
and only if the serial pad is active. Since an SMS command (TechNote TN009) can be used to temporarily open
ports for ad-hoc maintenance there are very few reasons to ever disable the firewall.
WAN Ping Response – When Disabled ICMP Ping requests will be ignored
NAT Traffic to WAN - Must be Enabled for normal operation
XML Interface: Can be enabled to open port 5070 for XML applications
IP White List
Enable to limit access to specified addresses or ranges of address. The White list applies to both WAN and LAN side
connections. If it is enabled, be sure to create an entry for LAN access.
IP Address (for white list) – specified as an address followed by a netmask in the Classless Inter-Domain Routing (CIDR)
format as in 192.168.1.0/24 to allow the entire class C range beginning at 192.168.1.0 for LAN administration
SMS Management
Enable to allow SMS management commands as defined in TechNote TN009
White List Status (SMS)
Enable to limit SMS access to specified phone numbers
SSH Access
Enable to allow SSH access from LAN, WAN, or both
Note
– The SSH password can and should be changed if SSH is enabled
Note
– For file transfers the Secure Copy (SCP) utility can be used with the same login credentials as SSH
Web Administration
Provides a mechanism to enable or disable HTTP access through the WAN, LAN, or both. Also provides a mechanism to
specify an IP port number other than 80 for HTTP access through the WAN, LAN, or both.
6.3 Additional Security Features
Authlogread
Using SSH the command line utility authlogread can be used to determine the last 20 login attempts since the unit was
last rebooted.
Intrusion Detection
If the Z4550 has the TCOPlus management option (APN001) installed, the intrusion detection feature under Tools/Wan
Management can be used to alarm 3 consecutive failed login attempts, and if desired to lockout any subsequent login
activity until the unit receives administrative attention.