Configuration
4.11 Security
CP 1243-7 LTE
Operating Instructions, 04/2017, C79000-G8976-C381-03
67
4.11.2
Firewall
4.11.2.1
Notation for the source IP address (advanced firewall mode)
If you specify an address range for the source IP address in the advanced firewall settings of
the CP, make sure that the notation is correct:
●
Separate the two IP addresses only using a hyphen.
Correct: 192.168.10.0-192.168.10.255
●
Do not enter any other characters between the two IP addresses.
Incorrect: 192.168.10.0 - 192.168.10.255
If you enter the range incorrectly, the firewall rule will not be used.
4.11.2.2
Firewall settings for configured connection connections via a VPN tunnel
IP rules in advanced firewall mode
If you set up configured connection connections with a VPN tunnel between the CP and a
communications partner, you will need to adapt the local firewall settings of the CP:
In advanced firewall mode ("Security > Firewall > IP rules") select the action "Allow*" for both
communications directions of the VPN tunnel.
4.11.3
Authorized phone numbers
SMS messages received only from subscribers with an authorized phone number
The CP only accepts an SMS if the sending communication partner is authorized based on
its phone number. These phone numbers are configured for the CP in STEP 7 in the
"Authorized phone numbers" list in the Security settings.
"Authorized phone numbers"
A phone number entered here gives the sender who transfers this phone number the right to
trigger connection establishment by the CP.
●
If only an asterisk (*) is entered in the list, the CP accepts SMS messages from all
senders.
●
An asterisk (*) after a phone number body authorizes connection establishment for all
nodes connected to the body (extension numbers).
Example: +49123456* auth49123456101, +49123456102, +49123456207 etc.
If the "Authorized phone numbers" list is empty, the CP cannot be induced to a connection
establishment by a mobile phone.