![FireBrick FB6402 Скачать руководство пользователя страница 103](http://html1.mh-extra.com/html/firebrick/fb6402/fb6402_user-manual_2291301103.webp)
System Services
86
table
If specified, then the service only accepts requests/connections on the specified
routing table. If not specified then the service works on any routing table. Where
the service is also a client then this specifies the routing table to use (default 0).
allow
If specified then this is a list of ranges of IP addresses and ip group names from
which connections are allowed. If specified as an empty list then no access is
allowed. If omitted then access is allowed from everywhere. Note that if
local-
only
is specified, the allow list allows access from addresses that are not local,
if they are in the
allow
list.
local-only
This normally defaults to
true
, but not in all cases. If true then access is only
allowed from machines on IPs on the local subnet
a
(and any addresses in the
allow
list, if specified).
log
The standard
log
,
log-error
, and
log-debug
settings can be used to
specified levels of logging for the service.
a
A locally-attached subnet is one which can be directly reached via one of the defined interfaces, i.e. is not accessed via a gateway.
Tip
Address ranges in
allow
can be entered using either <first address>-<last_address> syntax, or
using CIDR notation : <start address>/<prefix length>. If a range entered using the first syntax
can be expressed using CIDR notation, it will be automatically converted to that format when the
configuration is saved. You can also use name(s) of defined IP address group(s), which are pre-defined
ranges of IPs.
12.3. HTTP Server configuration
The HTTP server's purpose is to serve the HTML and supporting files that implement the web-based user-
interface for the FB6000. It is not a general-purpose web server that can be used to serve user documents, and
so there is little to configure.
12.3.1. Access control
By default, the FB6000 will allow access to the user interface from any machine, although obviously access to
the user interface normally requires the correct login credentials to be provided. However, if you have no need
for your FB6000 to be accessed from arbitrary machines, then you may wish to 'lock-down' access to the user
interface to one or more client machines, thus removing an 'attack vector'.
Access can be restricted using
allow
and
local-only
controls as with any service. If this allows access,
then a user can try and login. However, access can also be restricted on a per user basis to IP addresses and
using profiles, which block the login even if the passord is correct.
Additionally, access to the HTTP server can be completely restricted (to all clients) under the control of a
profile. This can be used, for example, to allow access only during certain time periods.
12.3.1.1. Trusted addresses
Trusted addresses are those from which additional access to certain functions is available. They are specified
by setting the
trusted
attribute using address ranges or IP address group names. This trusted access allows
visibility of graphs without the need for a password, and is mandatory for packet dump access.
12.4. Telnet Server configuration
The Telnet server allows standard telnet-protocol clients (available for most client platforms) to connect to
the FB6000 and access a command-line interface (CLI). The CLI is documented in Chapter 16 and in the
Appendix E.
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......