![Nortel SMC 2450 Implementation Manual Download Page 111](http://html1.mh-extra.com/html/nortel/smc-2450/smc-2450_implementation-manual_1706451111.webp)
Firewall deployment
Page 111 of 260
Secure Multimedia Controller
Implementation Guide
Unavailable policy logging
When a packet hits the firewall and there is not a rule to match it, it is silently
dropped without logging a message. These dropped packets may be from
services that are failing when the SMC is placed within the path of the traffic;
therefore, logging these messages (called unavailable policies) is critical to
determining which additional rules are required for a particular installation.
Procedure 28
Enabling unavailable policy logging
1
Log on to the Web UI.
2
Navigate to
Multimedia Security > Security Settings > Log >
Messages
.
3
Enable
Unavailable Policies
.
4
Click
Apply
.
End of Procedure
Result
: The firewall logs now list additional packets that were dropped.
These packets can be correlated to the IP addresses of the client to determine
which ones are being dropped.
An example of an unavailable policy entry:
Mar 1 13:01:37 127.0.0.1 id=firewall time="2006-03-01
13:01:37" fw=a10-10-10-10 pri=4 proto=6(tcp)
src=2.2.2.100 : 32802 dst=3.3.3.200 : 22 mid=2076 mtp=10
msg="Access Policy not found, dropping packet from ext n/
w" agent=Firewall
Summary of Contents for SMC 2450
Page 2: ......
Page 4: ...Page 4 of 260 Revision history 553 3001 225 Standard 1 00 May 2006...
Page 10: ...Page 10 of 260 Contents 553 3001 225 Standard 1 00 May 2006 Format 251 Log message table 253...
Page 16: ...Page 16 of 260 List of procedures 553 3001 225 Standard 1 00 May 2006...
Page 20: ...Page 20 of 260 About this document 553 3001 225 Standard 1 00 May 2006...
Page 56: ...Page 56 of 260 Description 553 3001 225 Standard 1 00 May 2006...
Page 76: ...Page 76 of 260 Hardware installation 553 3001 225 Standard 1 00 May 2006...
Page 120: ...Page 120 of 260 Firewall deployment 553 3001 225 Standard 1 00 May 2006...
Page 160: ...Page 160 of 260 Secure UNIStim deployment 553 3001 225 Standard 1 00 May 2006...
Page 182: ...Page 182 of 260 Maintenance 553 3001 225 Standard 1 00 May 2006...
Page 196: ...Page 196 of 260 The Command Line Interface CLI 553 3001 225 Standard 1 00 May 2006...
Page 212: ...Page 212 of 260 Logging 553 3001 225 Standard 1 00 May 2006...
Page 250: ...Page 250 of 260 Appendix D Software licenses 553 3001 225 Standard 1 00 May 2006...
Page 260: ...Page 260 of 260 Appendix E SMC packet filter log messages 553 3001 225 Standard 1 00 May 2006...
Page 261: ......