background image

Protecting the system

This filter blocks the firewall against connection setups at privileged ports (0 ... 1023) for TCP and UDP. Most rele-
vant data services are offered via privileged ports (establishing names, file transfer, etc.).

IP Spoofing Blocking

This filter blocks the firewall against “fake” (spoof) packets on the “wrong side” of the firewall. As a result, data pa-
ckets which would certainly belong in the LAN based on their IP address, but would be routed to the port for the DSL
modem by an attacker from the Internet, are ignored (same applies to ISDN links to the Internet).

DNS-filter

This filter permits establishing of names (assignment of IP-addresses to URLs) by enabling outgoing UPD and TCP
packets at port 53, as well as incoming ones from port 53. Longer replies and zone transfers are also permitted by en-
abling TCP. No DNS queries can pass through the firewall when this filter is de-activated!

Active FTP - Filter

Together with the corresponding software module in the firewall this filter permits active FTP. Active FTP differs
from passive FTP in that the FTP server sets up a connection for data transfer at the request of the clients (applies
both to the response to the FTP command “ls” and to the file transfer proper). The problem here is that the connecti-
on setup by the FTP server is made at any non-privileged port, thus requiring that a large region of the firewall be
enabled.

Outgoing connections at ports 20 and 21 and incoming ones from these ports to non-privileged ports are enabled.

Passive FTP - Filter

This filter permits file transfer via FTP, with the connection always being established by the FTP client. Outgoing
connections to port 21 and incoming ones from this port to non-privileged ports are enabled.

HTTP - Filter

This filter permits Web browsing by enabling packets to ports 80 and 8080 (when using http proxies) for outgoing
connections and incoming packets from these ports to non-privileged ports.

HTTPS - Filter

This filter permits secure Web surfing by enabling packets to port 443 for outgoing connections and incoming pa-
ckets from this port to non-privileged ports. The https protocol is frequently used for home banking and online shop-
ping; http connections are used for transfer of secure packets using encryption.

HBCI - Filter

This filter permits the use of HBCI for home banking by enabling packets to port 3000 for outgoing connections and
incoming ones from this port to non-privileged ports.

E-mail send filter

This filter permits transmission of e-mails via SMTP (= sending e-mails) by enabling packets to port 25 for outgoing
connections and incoming packets from this port to non-privileged ports.

E-mail reception - Filter

This filter permits transmission of e-mails via POP (= receiving e-mails) by enabling packets to port 110 for outgoing
connections and incoming packets from this port to non-privileged ports.

Configure firewall filters

Filter Wizard

26

Summary of Contents for T444

Page 1: ......

Page 2: ...atanappropriatewastedisposalfacilityattheendof itsusefulservicelife Youwillfindadditionalinformationonanindividualreturningoftheoldappli ances under www funkwerk ec com 2009 Funkwerk Enterprise Commun...

Page 3: ...DHCP Recommended configuration Default setting 9 Things to note for this configuration 9 AddressassignmentwithoutDHCP set mixedIPaddresses 11 Things to note for this configuration 12 LAN Client PC Con...

Page 4: ...Realplayer Filter 28 Mediaplayer Filter 28 Filter update 28 2...

Page 5: ...erouter AllLANclientsthatarelinkedareintegratedintothelocalnetworkviatheTCP IPproto col Further PCs can be linked to your network via RAS access Here the IP address is always assigned by the telephone...

Page 6: ...in your list fall back When anInternetconnectionis terminated the first ISP in the list is usedwhen the next connectionattempt is initi ally carried out Note For more information about configuring ISP...

Page 7: ...nwhichtherouterisintegra ted The router DHCP must be de activated in the configuration for this Default setting of the PABX Default IP addresses for the local area network In its basic setting you can...

Page 8: ...within thesameIPnetwork APCwiththeIPaddress192 168 2 1islocatedinadifferentnetwork APCfromthePABXnet would not be able to locate this other PC if it is not within its own network In addition the same...

Page 9: ...ox or cell phone without a B channel of the telephone system being allocated Normal call distribution OneBchannelisde activatedandthecallsignaledatthesubscriberenteredunder Callallocation forthe Exter...

Page 10: ...tomaticallyinformyourDynamicDNS provider ofyourcurrentdynamicIPaddresseach timeaconnectionissetupwith theInternet TheinformationabouttheIPaddressistransferredafterset tingupanewInternetconnection aswe...

Page 11: ...xternal access is provided with user name and password protection If the call is made from an external location only the phone number can also be monitored as an added protection feature Access can be...

Page 12: ...inthePABXsystem YoucanthenmanuallysetupaconnectiontotheInternetviatheControlCenterandthe results for this connection are then displayed after a few seconds No actual Internet connection is established...

Page 13: ...ettings for address assignment via DHCP If other means of Internet connection for example modem or an ISDN card have already been configured on the LAN client PC observe the information given in the s...

Page 14: ...ControlPanelfromtheWindowsStartMenu UnderWindows2000 openthefolder NetworkandDial up Connections UnderWindowsXPopenthefolder Networkconnections Selectthe LANConnection forthePABXbypressingtherightmous...

Page 15: ...omatically via DHCP Intheexamplegivenhere theIPaddressesfortheclients PCs canliewithinarangefromIP192 168 1 50to192 168 1 69 TheIPaddressesareassignedintheorderthattheclients PCs requestthem forexampl...

Page 16: ...You must make the following minimum settings manually IPaddressfortheLANclient PC Netmask Subnetmask whichisalsoenteredinthePABXrouter IPaddressofthePABXsystemasthegateway interfacetoothernetworks fo...

Page 17: ...h setaddressassignmentonthefollowing pages Confirm yoursettingsbyclickingOK Example Windows 2000 and Windows XP OpentheControlPanelfromtheWindowsStartMenu UnderWindows2000 openthefolder NetworkandDial...

Page 18: ...8 1 91 Gateway 192 168 1 250 DNSserver 192 168 1 250 Subnetmask 255 255 255 0 PC2 FixedIP 192 168 1 93 Gateway 192 168 1 250 DNSserver 192 168 1 250 Subnetmask 255 255 255 0 PC3 IPviaDHCP 192 168 1 50...

Page 19: ...DHCP server is off NumberofDHCPaddresses DHCP server is off PC1 FixedIP 192 168 1 81 Gateway 192 168 1 250 DNSserver 192 168 1 250 Subnetmask 255 255 255 0 PC3 FixedIP 192 168 1 83 Gateway 192 168 1 2...

Page 20: ...ave beenconfiguredcorrectlyinyourPC seePagein section SettingsimInternetExplorer InternetoptionenofWindows Ifyouhavemadethesettingsasdescribedabove thetelephonesystemwill establishaconnectiontotheIn t...

Page 21: ...ngefrom192 168 1 50 to 192 168 69 Whenthesevaluesaredisplayed thenetworkadapterandtheWindowsnetworksettingshave beenconfiguredcorrectly Should theprogram Winipcfg showothervalues clickthebuttons Enabl...

Page 22: ...lueforthephysicaladdressisdifferent foreachnetworkadapter Thevaluesfortheleasedependon whenthePCisswitchedon If other data are shown this may be due to the following reasons Changeshavealreadybeenmade...

Page 23: ...rent foreachnetworkadapter Thevaluesfortheleasedependon whenthePCisswitchedon If other data continues to be shown this may be due to the following reasons Changeshavealreadybeenmadetotheinitial settin...

Page 24: ...ystem s Configurator Internet Explorer settings Windows Internet options ThefollowingdescriptionillustratesthesettingsforInternetconnectionsforthevariousoperatingsystems Proceed as described below for...

Page 25: ...Configuring Internet access on a PC Checking the TCP IP Configuration 21...

Page 26: ...s of data security and are an ideal compliment to one another but can not replace one another To configure self defined filters click the button New or change an existing entry in the filter list by d...

Page 27: ...s located in the same IP subnetwork as the WAN port This parameter is currently not used and will not be significant for future software updates You can configure the following parameters Nameofthefil...

Page 28: ...the WAN address of the PABX system Configuration example for a portmapping entry into the firewall for the ssh protocol Thesshprotocol secureshell isusedamongother thingsfor webserveradministration o...

Page 29: ...ileges in exchange networks using port mapping by your telephone system router enter the name of the appli cation and the terms port and firewall in an Internet search engine configuration instruction...

Page 30: ...that a large region of the firewall be enabled Outgoingconnectionsatports20and21andincomingonesfromtheseportstonon privilegedportsareenabled Passive FTP Filter This filter permits file transfer via FT...

Page 31: ...incoming packets from that port to non privileged ports TELNET Filter ThisfilterpermitstheuseofthetelnetserviceprogrammeatcomputersintheInternetbyenablingpacketstoport23 for outgoing connections and i...

Page 32: ...r Wizard operates using a descriptive file that you can easily update without necessarily having to update the software in your PABX your router or PC Check at regular intervals whether new descriptio...

Page 33: ...beforethisbuttonisactivated Thebutton Help islocatedintheconfigurationbranch Network Filters Thetextthatisdisplayedwhenyouclickthisbuttonistakendirectlyfromthefile Filter_Info txt allowing the Help f...

Page 34: ...S 6 Dynamic ISDN 4 Dynamic ISDN for outgoing calls 5 F Fallback 4 Filter Wizard 25 26 27 Firewall 6 I Internet Explorer settings 20 Internet options of Windows 20 Internet connections 1 IP address all...

Page 35: ...31...

Page 36: ...cations GmbH S dwestpark 94 D 90449 N rnberg For information on support and service offerings please visit our Website at www Funkwerk ec com where you will find a Service Support area Subject to modi...

Reviews: