Version 6.6
153
MP-11x & MP-124
User's Manual
13. Security
13
Security
This section describes the VoIP security-related configuration.
13.1 Configuring Firewall Settings
The device provides an internal firewall that enables you to configure network traffic
filtering rules (
access list
). You can add up to 50 firewall rules. The access list offers the
following firewall possibilities:
Block traffic from known malicious sources
Allow traffic only from known "friendly" sources, and block all other traffic
Mix allowed and blocked network sources
Limit traffic to a user-defined rate (blocking the excess)
Limit traffic to specific protocols, and specific port ranges on the device
For each packet received on the network interface, the table is scanned from top to bottom
until the first matching rule is found. This rule can either permit (
allow
) or deny (
block
) the
packet. Once a rule in the table is located, subsequent rules further down the table are
ignored. If the end of the table is reached without a match, the packet is accepted.
Notes:
•
This firewall applies to a very low-level network layer and overrides your other
security-related configuration. Thus, if you have configured higher-level security
features (e.g., on the Application level), you must also configure firewall rules to
permit this necessary traffic. For example, if you have configured IP addresses to
access the Web and Telnet interfaces in the Web Access List (see 'Configuring
Web and Telnet Access List' on page
), you must configure a firewall rule that
permits traffic from these IP addresses.
•
Only Security Administrator users or Master users can configure firewall rules.
•
Setting the 'Prefix Length' field to
0
means that the rule applies to
all
packets,
regardless of the defined IP address in the 'Source IP' field. Therefore, it is highly
recommended to set this parameter to a value other than 0.
•
It is recommended to add a rule at the end of your table that blocks all traffic and
to add firewall rules above it that allow required traffic (with bandwidth limitations).
To block all traffic, use the following firewall rule:
- Source IP: 0.0.0.0
- Prefix Length: 0 (i.e., rule matches all IP addresses)
- Start Port - End Port: 0-65535
- Protocol:
Any
- Action Upon Match:
Block
•
You can also configure the firewall settings using the table ini file parameter,
AccessList (see 'Security Parameters' on page
Содержание Media Pack MP-11x
Страница 2: ......
Страница 14: ...User s Manual 14 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 24: ...User s Manual 24 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 25: ...Part I Getting Started with Initial Connectivity...
Страница 26: ......
Страница 35: ...Part II Management Tools...
Страница 36: ......
Страница 38: ...User s Manual 38 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 86: ...User s Manual 86 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 94: ...User s Manual 94 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 100: ...User s Manual 100 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 108: ...User s Manual 108 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 109: ...Part III General System Settings...
Страница 110: ......
Страница 118: ...User s Manual 118 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 121: ...Part IV General VoIP Configuration...
Страница 122: ......
Страница 152: ...User s Manual 152 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 202: ...User s Manual 202 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 204: ...User s Manual 204 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 230: ...User s Manual 230 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 231: ...Part V Gateway Application...
Страница 232: ......
Страница 234: ...User s Manual 234 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 274: ...User s Manual 274 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 278: ...User s Manual 278 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 298: ...User s Manual 298 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 326: ...User s Manual 326 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 327: ...Part VI Stand Alone Survivability Application...
Страница 328: ......
Страница 336: ...User s Manual 336 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 358: ...User s Manual 358 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 361: ...Part VII Maintenance...
Страница 362: ......
Страница 368: ...User s Manual 368 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 406: ...User s Manual 406 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 409: ...Part VIII Status Performance Monitoring and Reporting...
Страница 410: ......
Страница 441: ...Part IX Diagnostics...
Страница 442: ......
Страница 456: ...User s Manual 456 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 458: ...User s Manual 458 Document LTRT 65432 MP 11x MP 124 This page is intentionally left blank...
Страница 471: ...Part X Appendix...
Страница 472: ......
Страница 650: ...International Headquarters Contact us www audiocodes com info Website www audiocodes com Document LTRT 65432...