MiVoice Office 250 Installation and Administration Guide
450
ip access-group s0in in
ip nat outside
• The following section defines the access control list (the rules) for traffic coming from the Internet
to either the Internal LAN or the DMZ. This is the first line of defense, so filter as much as possible.
Responses to communications initiated from inside (for example, http request for a Web page)
are controlled by the firewall functionality through dynamic ACLs.
ip access-list extended s0in
permit tcp any host 208.132.23.66 eq 5566
permit udp any host 208.132.23.66 eq 5567
permit udp any host 208.132.23.66 range 6004 6247
deny ip any any
• The following section sets up the connection to the DMZ. NAT is not enabled between the Internet
and the DMZ. Traffic from the Internet is filtered using the access-group called DMZ. The “inspect”
statement enables the stateful firewall functionality.
interface Ethernet 1/0
description Site DMZ LAN
ip address 208.132.23.66 255.255.255.192
ip inspect dmzinspector in
ip access-group e1in in
ip inspect name dmzinspector udp
ip inspect name dmzinspector tcp
ip inspect name dmzinspector sip
• The following section defines the access control list (the rules) for traffic coming from the DMZ
to either the Internal LAN or the Internet. Limit the communications between the DMZ and the
internal LAN as much as possible in the event one of the DMZ nodes is compromised.
ip access-list extended e1in
deny ip any 192.168.100.0 0.0.0.255
permit ip any any
!
ITP Phones and Networking
This example shows that to add support for networking, you expand the ACL to allow the Private
Networking port to be accessible from the Internet to the MiVoice Office 250. Responses to
communications initiated from inside (for example, http request for a Web page) are controlled by
the firewall functionality through dynamic ACLs.
ip access-list extended s0in
permit tcp any host 208.132.23.66 eq 5566
permit udp any host 208.132.23.66 eq 5567
permit tcp any host 208.132.23.66 eq 5570
permit udp any host 208.132.23.66 range 6004 6247
deny ip any any
Содержание MIVOICE OFFICE 250
Страница 1: ...MiVoice Office 250 INSTALLATION AND ADMINISTRATION GUIDE RELEASE 6 3 SP3 ...
Страница 24: ...MiVoice Office 250 Installation and Administration Guide xxiv ...
Страница 29: ...Chapter 1 MiVoice Office 250 New Features ...
Страница 41: ...MiVoice Office 250 New Features 13 Other Enhancements MiVoice Office 250 Release 6 2 supports Exchange 2016 ...
Страница 54: ...MiVoice Office 250 Installation and Administration Guide 26 ...
Страница 55: ...Chapter 2 Document Overview ...
Страница 62: ...MiVoice Office 250 Installation and Administration Guide 34 ...
Страница 63: ...Chapter 3 Product Description ...
Страница 86: ...MiVoice Office 250 Installation and Administration Guide 58 ...
Страница 87: ...Chapter 4 Specifications ...
Страница 157: ...Chapter 5 Installation ...
Страница 251: ...Installation 223 ...
Страница 274: ...MiVoice Office 250 Installation and Administration Guide 246 4 Test for quality ...
Страница 396: ...MiVoice Office 250 Installation and Administration Guide 368 ...
Страница 397: ...Chapter 6 Reference ...
Страница 416: ...MiVoice Office 250 Installation and Administration Guide 388 ...
Страница 417: ...Appendix A Private Networking ...
Страница 445: ...Appendix B Network IP Topology ...
Страница 486: ...MiVoice Office 250 Installation and Administration Guide 458 ...
Страница 487: ...Appendix C Open Source License Agreements ...
Страница 506: ...MiVoice Office 250 Installation and Administration Guide 478 ...
Страница 507: ...Appendix D Phones ...