background image

QuadroCS Manual II: Administrator's Guide 

Administrator's Menus 

 

Quadro

CS

 (SW Version 3.0.x) 

41

 

Filtering Rules 

The 

Filtering Rules 

page allows the configuration of filters for the incoming and outgoing traffic.  

To prevent misconfiguration, only one rule per service is allowed. The user may use IP groups to include several IP addresses for this rule. As the 
filtering rules specify the operation mode of the firewall, they only take effect if the firewall has been enabled (additionally NAT should be enabled to 
use the 

Port Forwarding

 function in the 

Incoming Traffic / Port Forwarding

 filtering rules). The filtering rules are independent from the security 

level, so they will work if enabled, no matter what security level has been selected. 

Please Note:

 Applying firewall rules will just prevent the establishment of new connections that violate the rules. Applying rules does not kill existing 

connections that violate the rule. 

View All

 displays all configured filters specified by their 

State

 

(enabled or disabled), the selected 

Service

, the set 

Action

 

(allowed or blocked), the IP addresses the filters apply to (if 

Restricted

) and the destination of port forwarding (

Redirect to

in case of 

Incoming Traffic/Port Forwarding

). As it is read-only, 

no modifications are allowed and no functional buttons are 
available.  

The 

Incoming Traffic/Port Forwarding

 filter is for incoming 

traffic. The rules here allow or deny systems on the Internet to 
reach the services of Quadro’s LAN. NAT service should be 
enabled on the Quadro to provide the possibility of 

Port 

Forwarding

 in the

 Incoming Traffic/Port Forwarding

 filtering 

rules. The 

Port Forwarding

 function will be unavailable if NAT is 

disabled on the Quadro. 

 

The 

Outgoing Traffic

 filter is for outgoing traffic. The rules here 

allow or deny Quadro’s LAN users to reach external services. 

Management Access

 is used to enable management access to 

the Quadro from the Internet. A host on the Internet can be 
allowed to reach the Quadro. 

SIP Access

 is to allow or deny the SIP access to or from the 

particular SIP servers, SIP hosts or a group of them. The 

SIP 

Access 

filtering rule may prevent or allow incoming or outgoing 

SIP calls to or from specified SIP server(s) or host(s).

 

When 

Blocked IP List

 is used, traffic from specific hosts may be 

blocked, no matter what services are opened in the other filters. 
NO traffic will be allowed to the specified hosts. The 

Blocked IP 

List

 service has a higher priority if the same host is also listed in 

the 

Allowed IP List

 table. 

Allowed IP List

 allows trusted hosts to reach your network and 

vice versa. It is an exception to other rules and only all services 
may be allowed for a single host.  

 

Fig. II-61: Filtering Rules page 

The 

Filtering Rules

 page provides several links. Each link opens its specific parameters on the same page. Only 

Change Policy 

(see chapter 

Firewall and NAT

), 

Manage user Defined Services 

(see chapter 

Service Pool

) and 

Manage IP Pool Groups

 (see chapter 

IP Pool

) are leading to 

separate pages.

 

The 

Filtering Rules

 page also includes the currently selected firewall security (

Policy

) level and its description. 

The table displayed on the bottom of the page shows the filters selected above, specified by their 

State

 (enabled or disabled), the selected 

Service

the set 

Action

 (allowed or blocked), the IP addresses the filters apply to (if 

Restricted

) and the destination of port forwarding (

Redirect to

, in case 

of 

Incoming Traffic/Port Forwarding

). With the exception of View All, the table offers the following functional buttons: 

• 

Enable

 is used to enable the rule. If no records are selected the “No record(s) selected” error occurs. 

• 

Disable

 is used to disable the rule. If no records are selected the “No record(s) selected” error occurs. 

• 

Add

 opens a filter specific page where new rules may be defined by a 

Service

, an 

Action,

 a 

Restriction

 to certain IP address(es) or IP 

groups, and if adding a rule for 

Incoming Traffic/Port Forwarding

, the destination IP address for 

Forwarding: 

Summary of Contents for QUADRO CS

Page 1: ...QuadroCS Manual II Administrator s Guide QuadroCS SW Version 3 0 x Edition 1 SW Release 3 0 9 and higher August 2005...

Page 2: ...Password 12 Events 13 Time Date Settings 15 Mail Settings 16 Firmware Update 16 Networking Tools 18 Diagnostics 19 Upload Language Pack 19 Conference Management Menu 20 Conferences 20 Conference Codec...

Page 3: ...Guide that explains all QuadroCS management menus available for administrators only Further it includes a list of all System Default Values Manual III Conference User s Guide explains all menus that...

Page 4: ...o Conference Server Management if the Quadro Conference Server acts as a client to a DHCP server The button Renew WAN IP Address is used to get a new WAN IP address i e the Quadro Conference Server mo...

Page 5: ...ill demand a confirmation before deleting an existing entry Select All Selects all table entry s for example for further deletion Inverse Selection Inverts an existing selection of table entry s If no...

Page 6: ...be run upon the first startup of the Quadro Conference Server The Wizard navigates through the following basic configuration parameters and settings LAN Settings DHCP Settings Regional Settings WAN S...

Page 7: ...Address requires the Quadro host address for the LAN interface Subnet Mask requires Quadro host subnet mask Fig 0 5 System Configuration Wizard System Configuration page The Regional Settings are use...

Page 8: ...r all packets are sent to for example the IP address of the provider s router Fig 0 6 System Configuration Wizard WAN IP Configuration page Status The system status window displays non editable tables...

Page 9: ...roCS Status Network Status page When opening the corresponding Interface statistics window at first no traffic values are displayed Then every one minute traffic statistics will be updated These table...

Page 10: ...low receiving system Received MultiCast Packets The area Transmit Values displays the number of the following values Transmitted Bytes Transmitted Ethernet Packets Transmitted packets containing Error...

Page 11: ...atus page Hardware Status The Hardware Status table displays a list of the hardware devices present and currently available on the QuadroCS s board The hardware device version number and additional co...

Page 12: ...you will replace your current one lose all recorded conferences and reboot the device You will not be automatically redirected to the GUI start page After the successful reboot you need to enter the...

Page 13: ...all new events as read Fig II 16 Event warning on the main menu page The System Events table is the list of new and read system events The table shows the Status of the event new or read as well as t...

Page 14: ...will take place if an action below Flash LED or Send Mail has been selected even if not selected explicitly Flash LED the second LED yellow will be blinking once a second and a notification will be d...

Page 15: ...local country time zone Timezones are specified by GMT Greenwich Mean Time and by specific timezones for the United States and Canada Enable Simple Network Time Protocol Server enables the SNTP Simpl...

Page 16: ...s Enable SMTP Authentication checkboxmust be selected if the specified SMTP server requires an authentication In this case authentication User Name and Password configured on the SMTP server should be...

Page 17: ...ayed showing the result of a verification of the image being burned Fig II 24 Firmware Update page 2 This page displays non editable information about the image validity The Image Check will display i...

Page 18: ...ewall has been enabled see chapter Firewall For the purpose of tracerouting several IP packets are sent out UDP User Datagram Protocol is used to send packets and ICMP Internet Control Message Protoco...

Page 19: ...em Diagnostic page Upload Language Pack Upload Language Pack page allows to upload a custom language for GUI and Voice Messages of the QuadroCS The language of voice messages can be switched to the cu...

Page 20: ...ble is created as a link By clicking on the column heading the table will be sorted by the selected column Each record in the table has a checkbox assigned to the row The checkbox is used to edit acti...

Page 21: ...ext fields require the settings of the SIP Outbound Proxy server which acts as a SIP server where all the SIP requests and other SIP messages are transferred Some SIP servers use outbound proxy server...

Page 22: ...d to a maximum duration in minutes Leave the field empty for unlimited conference duration Conference Recording Space is used to select the percentage of total QuadroCS s memory space that can be used...

Page 23: ...ding text field 6 Choose a Recording Space from the homonymous drop down list to assign a percentage of memory to the corresponding conference 7 Enable Leave Active checkbox for the conference to rema...

Page 24: ...be used as the preferred codec If the remote party does not support the preferred codec the following codecs will be tried out strictly in the top down order given in the Active Codecs table Each reco...

Page 25: ...ne if the SIP session is still active Fig II 37 SIP Settings page The DNS server for SIP radio button group allows to choose between regular DNS servers configured in the DNS Settings page and specifi...

Page 26: ...for narrow band services type packaging of code words is used where packing code words into octets is starting from the most significant rather than the least significant position in the octet If Use...

Page 27: ...Silence Suppression checkbox selection enables voice activity detection for the selected codec Fig II 39 RTP Settings Edit Entry To Edit Codec Parameters 1 Select the codec from the Codecs Table that...

Page 28: ...ress of the mapped host for SIP TCP traffic over NAT Mapped Port requires the port number on the mapped host for the SIP TCP traffic over NAT Fig 0 40 SIP Parameters page The RTP Parameters page is us...

Page 29: ...ed to its row It is used to delete or to edit the corresponding record An error occurs if no records are selected and the user activates the delete or edit button No records selected The error message...

Page 30: ...Select the checkboxes of the corresponding IP range s that ought to be deleted from the NAT Exclusion Table Press Select all if all IP ranges ought to be deleted 2 Press the Delete button on the NAT E...

Page 31: ...is displayed Each column heading in the aforementioned tables is made as a link By clicking on the column heading the tables will be sorted by the selected column Upon sorting ascending or descending...

Page 32: ...Call Duration column in the Successful Calls table are used to search by the call duration The duration has to be selected from the listed values The From field has to indicate a shorter duration tha...

Page 33: ...c have been matched to the Best Matching algorithm the pattern in the higher position in the table will get the higher position in the rearranged list The pattern in the highest position of the rearra...

Page 34: ...e Use Conference Settings list The Destination IP Address text field requires the IP address of the destination for a direct call or the SIP server for calls through the SIP server The Destination Por...

Page 35: ...the Destination IP Address the Port Number the Username the Password and the Call End Point if required For IP PSTN calls enable Multiple Logons if necessary 9 Choose a Fail Reason from the correspon...

Page 36: ...undetected Attention It is highly recommended to select the Embedded Memory Storage prior to unplugging the USB Flash Memory Otherwise data stored on the USB Flash Memory may be corrupted or lost It i...

Page 37: ...in the corresponding text field Additionally functional tokens can be used to automatically insert the Conference ID Subject Description Participants Password Scheduling information as well as a poss...

Page 38: ...page DHCP Settings The DHCP Settings page gives the possibility to enable a DHCP server and control the QuadroCS user s LAN settings Thus QuadroCS LAN users will be provided automatically with the fol...

Page 39: ...cribing all the leased IP hosts and their parameters The table contains the following columns IP address host IP address assigned by QuadroCS MAC address host MAC address provided by the host itself L...

Page 40: ...t block anything by default It is recommended if the device is already located behind another firewall or if every filter has been configured correctly Medium Security Traffic originating from the LAN...

Page 41: ...ss to the Quadro from the Internet A host on the Internet can be allowed to reach the Quadro SIP Access is to allow or deny the SIP access to or from the particular SIP servers SIP hosts or a group of...

Page 42: ...s 255 0 0 0 8 255 255 0 0 16 255 255 255 0 24 255 255 255 255 32 Group indicates the user defined groups that include IP addresses that ought to be allowed or blocked Fig II 62 Filtering Rules Page to...

Page 43: ...st of possible protocols to be selected Port Range requires a port range for the defined service Fig II 64 Service Pool Page to add a new Service To Add a new Service 1 Select the Manage User Defined...

Page 44: ...r will occur One row must be selected Please Note Changing a group name will also change the references to this group including groups where this group is a member of and all affected filter rules ena...

Page 45: ...p 8 To add a member with these parameters to the selected group press Save To Delete a Member 1 Select the Manage IP Pool Groups link The IP Pool Configuration page appears with the table of groups if...

Page 46: ...es the name of the host in the Internet The TZO Connection Type text field is used for a special parameter required by the DynDNS provider TZO The DHS Cloak Title text field is used for a special para...

Page 47: ...now leads to the Epygi Technical Support System Registration page and requires customer s information to submit the registration form Remind me later hides the registration notification until the nex...

Page 48: ...ly generated SIP Registration server sip epygi com SIP server port 5060 SIP Registration enabled Outbound SIP server undefined Moderator s settings for default conference Max 10 new participants allow...

Page 49: ...l II Administrator s Guide Appendix System Default Values QuadroCS SW Version 3 0 x 49 Issue System Default Value Comments Call Routing No entries Recording Common Settings Memory Allocation Embedded...

Page 50: ...n you may not transfer the Licensed Materials to a third party 6 Protection And Security Except as permitted under Section 5 of this Agreement you agree not to deliver or otherwise make available the...

Page 51: ...nt is found to be illegal or unenforceable this Agreement shall not be rendered inoperative but the remaining provisions shall continue in full force and effect 12 No Waiver Failure by either you or t...

Reviews: