
85
Chapter 12. System Services
A system service provides general functionality, and runs as a separate concurrent process alongside normal
traffic handling.
Table 12.1 lists the services that the FB6000 can provide :-
Table 12.1. List of system services
Service
Function
SNMP server
provides clients with access to management information using the Simple Network
Management Protocol
NTP client
automatically synchronises the FB6000's clock with an NTP time server (usually
using an Internet public NTP server)
Telnet server
provides an administration command-line interface accessed over a network
connection
HTTP server
serves the web user-interface files to a user's browser on a client machine
DNS
relays DNS requests from either the FB6000 itself, or client machines to one or
more DNS resolvers
Services are configured under the "Setup" category, under the heading "General system services", where there
is a single services object (XML element :
<services>
). The services object doesn't have any attributes
itself, all configuration is done via child objects, one per service. If a service object is not present, the service is
disabled. Clicking on the Edit link next to the services object will take you to the lists of child objects. Where
a service object is not present, the table in that section will contain an "Add" link. A maximum of one instance
of each service object type can be present.
12.1. Protecting the FB6000
Whilst the FB6000 does have a comprehensive firewall, the design of the FB6000 is that it should be able to
protect itself sensibly without the need for a separate firewall. You can, of course, configure the fireall settings
to control access to system services as well, if you want.
Each service has specific access control settings, and these default to not allowing external access (i.e. traffic
not from locally Ethernet connected devices. You can also lock down access to a specific routing table, and
restrict the source IP addresses from which connections are accepted.
In the case of the web interface, you can also define trusted IP addresses which are given priority access to
the login page even.
12.2. Common settings
Most system service have common access control attributes as follows.
Tip
You can verify whether the access control performs as intended using the diagnostic facility described
in Section 13.2
Table 12.2. List of system services
Attribute
Function
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......