Version 6.6
133
MP-11x & MP-124
User's Manual
12. Security
Parameter
Value per Rule
1
2
3
4
5
Burst Bytes
0
0
50000
50000
0
Action Upon Match
Allow
Allow
Allow
Allow
Block
The firewall rules in the above configuration example do the following:
Rules 1 and 2:
Typical firewall rules that allow packets ONLY from specified IP
addresses (e.g., proxy servers). Note that the prefix length is configured.
Rule 3:
A more "advanced” firewall rule - bandwidth rule for ICMP, which allows a
maximum bandwidth of 40,000 bytes/sec with an additional allowance of 50,000 bytes.
If, for example, the actual traffic rate is 45,000 bytes/sec, then this allowance would be
consumed within 10 seconds, after which all traffic exceeding the allocated 40,000
bytes/sec is dropped. If the actual traffic rate then slowed to 30,000 bytes/sec, the
allowance would be replenished within 5 seconds.
Rule 4:
Allows traffic from the LAN voice interface and limits bandwidth.
Rule 5:
Blocks all other traffic.
Table
12-2: Internal Firewall Parameters
Parameter
Description
Source IP
[AccessList_Source_IP]
Defines the IP address (or DNS name) or a specific host name of the
source network (i.e., from where the incoming packet is received).
Source Port
[AccessList_Source_Port]
Defines the source UDP/TCP ports (of the remote host) from where
packets are sent to the device.
The valid range is 0 to 65535.
Note:
When set to 0, this field is ignored and any source port
matches the rule.
Prefix Length
[AccessList_PrefixLen]
(
Mandatory
) Defines the IP network mask - 32 for a single host or
the appropriate value for the source IP addresses.
A value of 8 corresponds to IPv4 subnet class A (network mask of
255.0.0.0).
A value of 16 corresponds to IPv4 subnet class B (network mask
of 255.255.0.0).
A value of 24 corresponds to IPv4 subnet class C (network mask
of 255.255.255.0).
The IP address of the sender of the incoming packet is trimmed in
accordance with the prefix length (in bits) and then compared to the
parameter ‘Source IP’.
The default value is 0 (i.e., applies to all packets). You
must
change
this value to any of the above options.
Note:
A value of 0 applies to
all
packets, regardless of the defined IP
address. Therefore, you must set this parameter to a value other
than 0.
Start Port
[AccessList_Start_Port]
Defines the destination UDP/TCP start port (on this device) to where
packets are sent.
The valid range is 0 to 65535.
Note:
When the protocol type isn't TCP or UDP, the entire range
must be provided.
Содержание MediaPack MP-112
Страница 2: ......
Страница 14: ...User s Manual 14 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 21: ...Part I Getting Started with Initial Connectivity ...
Страница 22: ......
Страница 30: ...User s Manual 30 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 31: ...Part II Management Tools ...
Страница 32: ......
Страница 34: ...User s Manual 34 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 78: ...User s Manual 78 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 84: ...User s Manual 84 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 86: ...User s Manual 86 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 91: ...Part III General System Settings ...
Страница 92: ......
Страница 102: ...User s Manual 102 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 103: ...Part IV General VoIP Configuration ...
Страница 104: ......
Страница 162: ...User s Manual 162 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 172: ...User s Manual 172 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 199: ...Part V Gateway Application ...
Страница 200: ......
Страница 202: ...User s Manual 202 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 240: ...User s Manual 240 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 286: ...User s Manual 286 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 287: ...Part VI Stand Alone Survivability Application ...
Страница 288: ......
Страница 296: ...User s Manual 296 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 319: ...Part VII Maintenance ...
Страница 320: ......
Страница 326: ...User s Manual 326 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 347: ...Part VIII Status Performance Monitoring and Reporting ...
Страница 348: ......
Страница 377: ...Part IX Diagnostics ...
Страница 378: ......
Страница 390: ...User s Manual 390 Document LTRT 65417 MP 11x MP 124 ...
Страница 392: ...User s Manual 392 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 403: ...Part X Appendix ...
Страница 404: ......
Страница 618: ...User s Manual 618 Document LTRT 65417 MP 11x MP 124 Reader s Notes ...
Страница 622: ...User s Manual Ver 6 6 www audiocodes com ...