X3200
User’s Guide
299
Access Security
7
Reorganizing a chain
Proceed as follows to reorganize an existing chain of rules:
➤
Go to
IP
➧
A
CCESS
L
ISTS
➧
R
ULES
➧
REORG.
➤
Select Index of Rule that gets Index 1.
➤
Confirm with REORG.
7.2.9
Local Filters
Access to the local UDP and TCP services on
X3200
(telnet,
➤➤
CAPI
, trace,
etc.) can be controlled via the separate Setup Tool menu
IP
➧
L
OCAL
S
ERVICES
A
CCESS
C
ONTROL
. One or more restrictions can be defined here for each ser-
vice. If no entry exists for a service, there are no access restrictions for this ser-
vice, i.e. access is possible to this service over all interfaces and from any
source address, provided this is not prohibited by the use of NAT (see
chapter 7.2.7, page 282
) or global filters (see
chapter 7.2.8, page 286
).
Strategy
As soon as at least one entry for local filters exists in
X3200
, incoming requests
for the corresponding local services of
X3200
are only allowed if
1.
the source address is 127.0.0.1 (loopback address), or
2.
no entry exists for the corresponding service, or
3.
the incoming call is expressly allowed by at least one entry.
The existing entries are processed in the order in which they are listed in the
corresponding table in the SNMP shell (localTcpAllowTable or
localUdpAllowTable). If an entry in this sorted list does not apply, the next en-
try is checked. This enables requests over several interfaces or from several IP
addresses to be admitted individually to a certain service.
If a matching entry for a request has still not been found after checking the last
entry in the list, there are two alternatives:
■
The request is forwarded to the relevant service if no entry in the list refers
to this service.
If you work with Windows PCs in your network, it is usually advisable to define
a NetBIOS filter. An example of this configuration is explained step by step in
chapter 5.1.7, page 124
.
Содержание X3200
Страница 4: ...4 BinTec Communications AG...
Страница 28: ...28 BinTec Communications AG Welcome 1...
Страница 255: ...X3200 User s Guide 255 IPX Settings 6 Enter Age Multiplier if applicable Confirm with OK Press SAVE...
Страница 258: ...258 BinTec Communications AG Advanced Configuration 6...
Страница 348: ...348 BinTec Communications AG Technical Data 10...
Страница 361: ...X3200 User s Guide 361 12 Niemals Scheuermittel alkalische Reinigungsmittel scharfe oder scheuernde Hilfsmittel benutzen...
Страница 369: ...X3200 User s Guide 369 12 BinTec Communications AG...
Страница 393: ...X3200 User s Guide 393 12...
Страница 394: ...394 BinTec Communications AG General Safety Precautions in 15 Different Languages 12...
Страница 412: ...412 BinTec Communications AG Glossary...
Страница 419: ...X3200 User s Guide 419 Index WINS 210 229 X X 31 TEI 182...