Version 6.6
145
Mediant 3000
User's Manual
12. Security
12
Security
This section describes the VoIP security-related configuration.
12.1 Configuring Firewall Settings
The device provides an internal firewall that enables you to configure network traffic
filtering rules (
access list
). You can add up to 25 firewall rules. The access list offers the
following firewall possibilities:
Block traffic from known malicious sources
Allow traffic only from known "friendly" sources, and block all other traffic
Mix allowed and blocked network sources
Limit traffic to a user-defined rate (blocking the excess)
Limit traffic to specific protocols, and specific port ranges on the device
For each packet received on the network interface, the table is scanned from top to bottom
until the first matching rule is found. This rule can either permit (
allow
) or deny (
block
) the
packet. Once a rule in the table is located, subsequent rules further down the table are
ignored. If the end of the table is reached without a match, the packet is accepted.
Notes:
•
This firewall applies to a very low-level network layer and overrides all
your other security-related configuration. Thus, if you have configured
higher-level security features (e.g., on the Application level), you must
also configure firewall rules to permit this necessary traffic. For example,
if you have configured IP addresses to access the Web and Telnet
interfaces in the Web Access List (see 'Configuring Web and Telnet
Access List' on page
), you must configure a firewall rule that permits
traffic from these IP addresses.
•
Only Security Administrator users or Master users can configure firewall
rules.
•
Setting the 'Prefix Length' field to
0
means that the rule applies to
all
packets, regardless of the defined IP address in the 'Source IP' field.
Therefore, it is highly recommended to set this parameter to a value
other than 0.
•
It is recommended to add a rule at the end of your table that blocks all
traffic and to add firewall rules above it that allow required traffic (with
bandwidth limitations). To block all traffic, use the following firewall rule:
- Source IP: 0.0.0.0
- Prefix Length: 0 (i.e., rule matches all IP addresses)
- Start Port - End Port: 0-65535
- Protocol:
Any
- Action Upon Match:
Block
•
You can also configure the firewall settings using the table ini file
parameter, AccessList (see 'Security Parameters' on page
Содержание Mediant 3000
Страница 1: ...User s Manual Version 6 6 Enterprise Session Border Controller VoIP Digital Media Gateway Mediant 3000...
Страница 2: ......
Страница 21: ...Version 6 6 21 Mediant 3000 User s Manual 1 Overview Figure 1 2 Mediant 3000 TP 6310 Functional Block Diagram...
Страница 22: ...User s Manual 22 Document LTRT 89729 Mediant 3000 Figure 1 3 Mediant 3000 TP 8410 Functional Block Diagram...
Страница 26: ...User s Manual 26 Document LTRT 89729 Mediant 3000 Reader s Note...
Страница 27: ...Part I Getting Started with Initial Connectivity...
Страница 28: ......
Страница 40: ...User s Manual 40 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 41: ...Part II Management Tools...
Страница 42: ......
Страница 44: ...User s Manual 44 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 80: ...User s Manual 80 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 98: ...User s Manual 98 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 103: ...Part III General System Settings...
Страница 104: ......
Страница 113: ...Part IV General VoIP Configuration...
Страница 114: ......
Страница 144: ...User s Manual 144 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 164: ...User s Manual 164 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 222: ...User s Manual 222 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 224: ...User s Manual 224 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 275: ...Part V Gateway and IP to IP Application...
Страница 276: ......
Страница 278: ...User s Manual 278 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 399: ...Part VI Session Border Controller Application...
Страница 400: ......
Страница 402: ...User s Manual 402 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 464: ...User s Manual 464 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 465: ...Part VII Stand Alone Survivability Application...
Страница 466: ......
Страница 474: ...User s Manual 474 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 494: ...User s Manual 494 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 497: ...Part VIII IP Media Capabilities...
Страница 498: ......
Страница 501: ...Part IX High Availability System...
Страница 502: ......
Страница 515: ...Part X Maintenance...
Страница 516: ......
Страница 522: ...User s Manual 522 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 524: ...User s Manual 524 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 552: ...User s Manual 552 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 562: ...User s Manual 562 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 565: ...Part XI Status Performance Monitoring and Reporting...
Страница 566: ......
Страница 578: ...User s Manual 578 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 609: ...Part XII Diagnostics...
Страница 610: ......
Страница 624: ...User s Manual 624 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 626: ...User s Manual 626 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 638: ...User s Manual 638 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 639: ...Part XIII Appendix...
Страница 640: ......
Страница 864: ...User s Manual 864 Document LTRT 89729 Mediant 3000 Reader s Notes...
Страница 871: ...Version 6 6 871 Mediant 3000 User s Manual 55 Selected Technical Specifications Reader s Notes...
Страница 872: ...User s Manual Ver 6 6 www audiocodes com...