820
Viewing and changing the status of Firewall Filters
N0008589 3.3
Stateful Packet Filters
Business Communications Manager supports stateful packet filtering for IP protocols. Stateful
packet filters monitor active sessions and record session information such as IP addresses and port
numbers. They maintain state information for each flow (TCP, UDP or ICMP). Stateful filters use
the state information to determine if a packet is responding to an earlier request that has been
validated by the rule set. If the packet is in response to a previous request, the packet is treated in
the same manner. It will either be blocked or allowed though.
Stateful packet filters protect your network against Internet attacks such as source spoofing, where
an attacker pretends to be a trusted user by using an IP address that is within the accepted range of
IP addresses of your internal network. Business Communications Manager stateful packet filtering
validates that addresses coming from outside the network are valid outside addresses. Stateful
packet filters also protect your network from a denial-of-service attack, where an attacker tries to
block valid users from accessing a resource or a server.
Stateful filtering supports TCP, UDP, IP, and ICMP. Stateful filtering supports the following
applications: H.323, FTP, HTTP, POP3, Telnet, SMTP, DNS, DHCP, TFTP, GOPHER, FINGER,
NNTP, NetBios, POP2, RPC, SNMP and SUNNFS.
IP Firewall filters and NAT
When you use NAT and IP Firewall filters, there are two interactions you need to be aware of.
•
On inbound traffic, the NAT rules are applied before the IP Firewall Filter rules.
•
On outbound traffic, the IP Firewall Filter rules are applied before the NAT rules.
Viewing and changing the status of Firewall Filters
1
On the navigation tree, click the
Services
key and click the
Policy Management
key.
2
Click the
IP Firewall Filters
heading.
The Firewall Filters Summary screen appears. The Summary screen attributes are:
3
Press the
Tab
key to save your settings.
Table 258
IP Firewall Filters Summary
Attribute
Description
Description
Shows a description of Firewall Filters.
Version
Shows the version number of the subsystem.
Status
Shows the status of Firewall Filters. This box also provides commands to enable or disable
Firewall Filters.
Possible values:
Disabled
,
Enabled
When the status is Enabled, the state of all of the traffic is monitored. Rules can then be set for
each of the interfaces, as necessary.
The default value is:
Disabled.
Summary of Contents for BCM 3.7
Page 4: ...4 Software licensing N0008589 3 3...
Page 32: ...32 Contents N0008589 3 3 W 937 Index 939...
Page 46: ...46 Tables N0008589 3 3...
Page 64: ...64 How to get help N0008589 3 3...
Page 90: ...90 Manually activating Telnet N0008589 3 3...
Page 116: ...116 Delayed system restart N0008589 3 3...
Page 194: ...194 Configuring a data module N0008589 3 3...
Page 276: ...276 Setting line telco features N0008589 3 3...
Page 310: ...310 Using COS passwords N0008589 3 3...
Page 364: ...364 Enhanced 911 E911 configuration N0008589 3 3...
Page 380: ...380 Renumbering DNs N0008589 3 3...
Page 398: ...398 Saving wizard pages on your computer N0008589 3 3...
Page 458: ...458 Voice Mail settings N0008589 3 3...
Page 488: ...488 Setting system telco features N0008589 3 3...
Page 508: ...508 Other programming that affects public networking N0008589 3 3...
Page 522: ...522 PRI networking using Call by Call services N0008589 3 3...
Page 592: ...592 Monitoring Hunt groups N0008589 3 3...
Page 636: ...636 Configuring Double Density N0008589 3 3...
Page 640: ...640 Using the Network Update Wizard N0008589 3 3...
Page 666: ...666 Importing and Exporting DHCP data N0008589 3 3...
Page 722: ...722 Restarting the router N0008589 3 3...
Page 726: ...726 Important Web Cache considerations N0008589 3 3...
Page 748: ...748 Configuring an Interface with NAT N0008589 3 3...
Page 794: ...794 IPSec N0008589 3 3...
Page 818: ...818 Configuring the Policy Agent characteristics N0008589 3 3...
Page 832: ...832 Firewall rules for Business Communications Manager with Dialup interfaces N0008589 3 3...
Page 876: ...876 ISDN Programming N0008589 3 3...
Page 1004: ...1004 Index N0008589 3 3...