155
set pinhole name
name
int-start-port [ 0 - 65535 ]
Specifies the port number your ARRIS® Gateway should use when forwarding traffic of the specified type.
Under most circumstances, you would use the same number for the external and internal port.
Security Stateful Packet Inspection (SPI) commands
set security firewall-level [ low | high | off ]
All computer operating systems are vulnerable to attack from outside sources, typically at the operating sys-
tem or Internet Protocol (IP) layers. Stateful Inspection firewalls intercept and analyze incoming data packets
to determine whether they should be admitted to your private LAN, based on multiple criteria, or blocked.
Stateful inspection improves security by tracking data packets over a period of time, examining incoming and
outgoing packets. Outgoing packets that request specific types of incoming packets are tracked; only those
incoming packets constituting a proper response are allowed through the firewall.
The
high
setting is recommended, but for special circumstances, a
low
level of firewall protection is available.
You can also turn all firewall protection
off
. Defaults to
low
.
set security spi ip4 invalid-addr-drop [ on | off ]
Enables or disables whether Broadband packets with invalid source or destination addresses should be
dropped. Default is
on
.
set security spi ip4 private-addr-drop [ on | off ]
Enables or disables whether Broadband packets with private source or destination addresses should be
dropped. Default is
off
.
set security spi unknown-ethertypes-drop [ on | off ]
Enables or disables whether packets with unknown ether types are to be dropped. Default is
on
.
set security spi portscan-protect [ on | off ]
Enables or disables whether to detect and drop port scans. Default is
on
.
set security spi invalid-tcp-flags-drop [ on | off ]
Enables or disables whether packets with invalid TCP flag settings (NULL, FIN, Xmas, etc.) are to be dropped.
Default is
on
.
set security spi ip4 invalid-addr-drop [ on | off ]
Broad sets of addresses exist that should not be used as one or both of source or destination addresses. These
include the following:
IP address/mask
Source or destination
10.0.0.0/8
source
192.168.0.0.0/16
source
169.254.0.0/16
source
172.16.0.0/12
source
Содержание NVG595
Страница 1: ...ARRIS NVG595 Fiber Business Gateway ARRIS Embedded Software Version 9 1 2 Administrator s Handbook ...
Страница 10: ...Administrator s Handbook 10 ...
Страница 65: ...65 ...
Страница 68: ...Administrator s Handbook 68 ...
Страница 84: ...Administrator s Handbook 84 The following is an example log portion saved as a TXT file ...
Страница 90: ...Administrator s Handbook 90 ...
Страница 185: ...185 Please visit http www ARRIS com recycle for instructions on recycling ...
Страница 210: ...Administrator s Handbook 210 ...
Страница 220: ...Administrator s Handbook 218 ...
Страница 224: ...Administrator s Handbook 222 ...
Страница 226: ...Administrator s Handbook 224 ...