elmeg T444 Скачать руководство пользователя страница 27

Discarding of the packet is generally a safe procedure, as only those packets for which an explicit rule (i.e. deliberately
configured) exists are authorized in such a configuration.

When defining the filters it is essential to take into account that basically all packets are permitted at all LAN ports
(LAN1, LAN2, USB port). You therefore do not need to define filter rules for passing IP packets from the LAN to the
PABX system / router, nor for their »Return«.

Four place holders are provided to achieve an abstraction when defining the filters:

LAN_ADDR

Represents the LAN address for the router, based on the default configuration, i. e.
192.168.1.250 with the network mask 255.255.255.0 (192.168.1.250 / 24).

LAN_NET

This place holder represents all of the LAN addresses, based on the default configurati-
on, i.e. 192.168.1.0 with network mask 255.255.255.0 (192.168.1.0 / 24).

WAN_ADDR

This place holder represents the WAN address for the router that is assigned dynami-
cally by the ISP when PPoE or PPP is used. Dynamic allocation allows an IP address to
be assigned from the inventory of your ISP for the WAN port each time a connection is
set up to the Internet. The WAN address can not be entered as an absolute value for fil-
ter configuration when you are defining the configuration. PPPoE is required for
T-DSL for example; PPP is used for Internet connections with ISDN dial-in. If you
have been assigned a set public IP address by your provider for your Internet access,
this address will be used for WAN_ADDR.

The firewall is adapted automatically in accordance with the defined rules after the IP
address is assigned to the WAN port (or ISDN channel).

WAN_NET

Represents all WAN addresses located in the same IP subnetwork as the WAN port.
This parameter is currently not used and will not be significant for future software
updates.

You can configure the following parameters:

Name of the filter

Each filter must be assigned a unique name. Select a name for the filter that uniquely
describes the function for that filter - this will make it easier for you later if you wish to
change any filters.

Action

The following options can be selected: allow, deny, discard and portmap. When »al-
low« is selected, all packets which correspond to the parameters of the associated filter
can pass through. When »deny« is selected, the corresponding IP packets are rejected
and the sender of the packet is informed. »discard« results in packets being discarded
(refused) without the sender being informed. The option »portmap« permits specific
forwarding of packets with TCP and UDP protocols to the IP address of a PC in the
LAN.

TCP Flag

If a TCP connection is to be set up (for example for downloading files), certain bit sam-
ples are set in the packets involved with this - the TCP flags. The option »connection in
progress« stands for the SYN flag; the option »connection established« for the
»Established flag«

Protocols

UDP, TCP, ICMP and »all protocols« can be selected as protocols. The selection of the
protocol can affect further options, as, for example, there are no TCP flags available for
UDP, or no port for ISM, while there are certain types of protocols available however.

Interface

Here you can define the interfaces for the correspondend filter. At present, the setting
»WAN« is useful for most cases, as all packets are allowed at internal interfaces with
this setting.

Connection

Use this field to define the direction of the IP packet for which the configured filter is
valid. Possible parameters: in, out and in/out (bi-directional).

Source address definition

Configure firewall filters

23

Содержание T444

Страница 1: ......

Страница 2: ...atanappropriatewastedisposalfacilityattheendof itsusefulservicelife Youwillfindadditionalinformationonanindividualreturningoftheoldappli ances under www funkwerk ec com 2009 Funkwerk Enterprise Commun...

Страница 3: ...DHCP Recommended configuration Default setting 9 Things to note for this configuration 9 AddressassignmentwithoutDHCP set mixedIPaddresses 11 Things to note for this configuration 12 LAN Client PC Con...

Страница 4: ...Realplayer Filter 28 Mediaplayer Filter 28 Filter update 28 2...

Страница 5: ...erouter AllLANclientsthatarelinkedareintegratedintothelocalnetworkviatheTCP IPproto col Further PCs can be linked to your network via RAS access Here the IP address is always assigned by the telephone...

Страница 6: ...in your list fall back When anInternetconnectionis terminated the first ISP in the list is usedwhen the next connectionattempt is initi ally carried out Note For more information about configuring ISP...

Страница 7: ...nwhichtherouterisintegra ted The router DHCP must be de activated in the configuration for this Default setting of the PABX Default IP addresses for the local area network In its basic setting you can...

Страница 8: ...within thesameIPnetwork APCwiththeIPaddress192 168 2 1islocatedinadifferentnetwork APCfromthePABXnet would not be able to locate this other PC if it is not within its own network In addition the same...

Страница 9: ...ox or cell phone without a B channel of the telephone system being allocated Normal call distribution OneBchannelisde activatedandthecallsignaledatthesubscriberenteredunder Callallocation forthe Exter...

Страница 10: ...tomaticallyinformyourDynamicDNS provider ofyourcurrentdynamicIPaddresseach timeaconnectionissetupwith theInternet TheinformationabouttheIPaddressistransferredafterset tingupanewInternetconnection aswe...

Страница 11: ...xternal access is provided with user name and password protection If the call is made from an external location only the phone number can also be monitored as an added protection feature Access can be...

Страница 12: ...inthePABXsystem YoucanthenmanuallysetupaconnectiontotheInternetviatheControlCenterandthe results for this connection are then displayed after a few seconds No actual Internet connection is established...

Страница 13: ...ettings for address assignment via DHCP If other means of Internet connection for example modem or an ISDN card have already been configured on the LAN client PC observe the information given in the s...

Страница 14: ...ControlPanelfromtheWindowsStartMenu UnderWindows2000 openthefolder NetworkandDial up Connections UnderWindowsXPopenthefolder Networkconnections Selectthe LANConnection forthePABXbypressingtherightmous...

Страница 15: ...omatically via DHCP Intheexamplegivenhere theIPaddressesfortheclients PCs canliewithinarangefromIP192 168 1 50to192 168 1 69 TheIPaddressesareassignedintheorderthattheclients PCs requestthem forexampl...

Страница 16: ...You must make the following minimum settings manually IPaddressfortheLANclient PC Netmask Subnetmask whichisalsoenteredinthePABXrouter IPaddressofthePABXsystemasthegateway interfacetoothernetworks fo...

Страница 17: ...h setaddressassignmentonthefollowing pages Confirm yoursettingsbyclickingOK Example Windows 2000 and Windows XP OpentheControlPanelfromtheWindowsStartMenu UnderWindows2000 openthefolder NetworkandDial...

Страница 18: ...8 1 91 Gateway 192 168 1 250 DNSserver 192 168 1 250 Subnetmask 255 255 255 0 PC2 FixedIP 192 168 1 93 Gateway 192 168 1 250 DNSserver 192 168 1 250 Subnetmask 255 255 255 0 PC3 IPviaDHCP 192 168 1 50...

Страница 19: ...DHCP server is off NumberofDHCPaddresses DHCP server is off PC1 FixedIP 192 168 1 81 Gateway 192 168 1 250 DNSserver 192 168 1 250 Subnetmask 255 255 255 0 PC3 FixedIP 192 168 1 83 Gateway 192 168 1 2...

Страница 20: ...ave beenconfiguredcorrectlyinyourPC seePagein section SettingsimInternetExplorer InternetoptionenofWindows Ifyouhavemadethesettingsasdescribedabove thetelephonesystemwill establishaconnectiontotheIn t...

Страница 21: ...ngefrom192 168 1 50 to 192 168 69 Whenthesevaluesaredisplayed thenetworkadapterandtheWindowsnetworksettingshave beenconfiguredcorrectly Should theprogram Winipcfg showothervalues clickthebuttons Enabl...

Страница 22: ...lueforthephysicaladdressisdifferent foreachnetworkadapter Thevaluesfortheleasedependon whenthePCisswitchedon If other data are shown this may be due to the following reasons Changeshavealreadybeenmade...

Страница 23: ...rent foreachnetworkadapter Thevaluesfortheleasedependon whenthePCisswitchedon If other data continues to be shown this may be due to the following reasons Changeshavealreadybeenmadetotheinitial settin...

Страница 24: ...ystem s Configurator Internet Explorer settings Windows Internet options ThefollowingdescriptionillustratesthesettingsforInternetconnectionsforthevariousoperatingsystems Proceed as described below for...

Страница 25: ...Configuring Internet access on a PC Checking the TCP IP Configuration 21...

Страница 26: ...s of data security and are an ideal compliment to one another but can not replace one another To configure self defined filters click the button New or change an existing entry in the filter list by d...

Страница 27: ...s located in the same IP subnetwork as the WAN port This parameter is currently not used and will not be significant for future software updates You can configure the following parameters Nameofthefil...

Страница 28: ...the WAN address of the PABX system Configuration example for a portmapping entry into the firewall for the ssh protocol Thesshprotocol secureshell isusedamongother thingsfor webserveradministration o...

Страница 29: ...ileges in exchange networks using port mapping by your telephone system router enter the name of the appli cation and the terms port and firewall in an Internet search engine configuration instruction...

Страница 30: ...that a large region of the firewall be enabled Outgoingconnectionsatports20and21andincomingonesfromtheseportstonon privilegedportsareenabled Passive FTP Filter This filter permits file transfer via FT...

Страница 31: ...incoming packets from that port to non privileged ports TELNET Filter ThisfilterpermitstheuseofthetelnetserviceprogrammeatcomputersintheInternetbyenablingpacketstoport23 for outgoing connections and i...

Страница 32: ...r Wizard operates using a descriptive file that you can easily update without necessarily having to update the software in your PABX your router or PC Check at regular intervals whether new descriptio...

Страница 33: ...beforethisbuttonisactivated Thebutton Help islocatedintheconfigurationbranch Network Filters Thetextthatisdisplayedwhenyouclickthisbuttonistakendirectlyfromthefile Filter_Info txt allowing the Help f...

Страница 34: ...S 6 Dynamic ISDN 4 Dynamic ISDN for outgoing calls 5 F Fallback 4 Filter Wizard 25 26 27 Firewall 6 I Internet Explorer settings 20 Internet options of Windows 20 Internet connections 1 IP address all...

Страница 35: ...31...

Страница 36: ...cations GmbH S dwestpark 94 D 90449 N rnberg For information on support and service offerings please visit our Website at www Funkwerk ec com where you will find a Service Support area Subject to modi...

Отзывы: