
IP PBXs USER MANUAL
www.fs.com
97
There are 4 default intrusion detection and prevention rules to secure SIP, IAX2, Web and SSH services on your IPPBX system. And by
default all of them are activated to keep your IPPBX system safe.
Each of the intrusion detection and prevention rule is configured with a maximum
Illegal Attempts
and the
Observation
time duration,
once the
Illegal Attempts
reached the given value in the given
Observation
time duration, the source IP address of where the illegal
attempts coming from will be banned by the firewall for the given time duration specified in Ban for field. Banned IP will be listed on the
IP Blacklist
page.
Besides the 4 default rules, if you want to add more rules you can do it on the
Firewall
page
Auto Defense
section.
12.4.3
IP Blacklist
Path:
System -> Security Center -> IP Blacklist
IP Blacklist will list all suspected intruders/attackers’ IP addresses. The list is automatically generated by the system firewall if possible
intrusion/attacking had been detected. And the list will show the IP address of the banned hosts, as well as what kind of service intrusion
was detected.
If an IP address appears incorrectly in the list of rejected IP, you can click on the
button to remove it from the IP blacklist.
12.4.4
IP Whitelist
Path:
System -> Security Center -> IP Whitelist
IP Whitelist allows you to add IP addresses and network addresses to the IPPBX system as a trusted. The IP addresses in the whitelist will
always be treated as trusted IP and will not be regulated by the firewall rules.