IPSec
771
Programming Operations Guide
In addition to the above rules, Remote User tunnels need extra rules. These are extra rules are for
the QOTD (Quote of the Day) server, Password server and ICMP that the IPSec client issues.
Table 229
,
Table 230
and
Table 231
show the rules required.
Table 229
Firewall rules for the QOTD server
Protocol
TCP
Source IP
IP address of the client tunnel (this may be the IP address pool range or the fixed IP
address assigned to the tunnel)
Source Mask
255.255.255.255
Destination IP
The IP address of the Private network that the client IP address comes from (for
example, if the Client tunnel IP address is 10.10.10.20 and the Private interface IP
address is 10.10.10.1, then the destination IP is 10.10.10.1)
Destination Mask
255.255.255.255
Destination Port
17
Table 230
Firewall filter for the Password server
Protocol
TCP
Source IP
IP address of the client tunnel (this may be the IP address pool range or the fixed IP
address assigned to the tunnel)
Source Mask
255.255.255.255
Destination IP
The IP address of the Private network that the client IP address comes from (for
example, if the Client tunnel IP address is 10.10.10.20 and the Private interface IP
address is 10.10.10.1, then the destination IP is 10.10.10.1)
Destination Mask
255.255.255.255
Destination Port
586
Table 231
Firewall filter for the ICMP that the Client sends to the tunnel endpoint
Protocol
ICMP
Source IP
Client PC IP address
Source mask
255.255.255.255
Destination IP
Remote Endpoint address
Destination mask
255.255.255.255
Table 232
Firewall filter for Private Network
Protocol
IP
Source IP
Private Network IP address
Source Mask
Private Network Subnet mask
Source Port
All
Destination IP
Private Network IP address
Destination Mask
Private Network Subnet mask
Destination Port
All
Содержание BCM 3.7
Страница 1: ...Part No N0008589 3 3 December 2006 Business Communications Manager 3 7 Programming Operations Guide...
Страница 4: ...4 Software licensing N0008589 3 3...
Страница 32: ...32 Contents N0008589 3 3 W 937 Index 939...
Страница 46: ...46 Tables N0008589 3 3...
Страница 64: ...64 How to get help N0008589 3 3...
Страница 90: ...90 Manually activating Telnet N0008589 3 3...
Страница 116: ...116 Delayed system restart N0008589 3 3...
Страница 194: ...194 Configuring a data module N0008589 3 3...
Страница 276: ...276 Setting line telco features N0008589 3 3...
Страница 310: ...310 Using COS passwords N0008589 3 3...
Страница 364: ...364 Enhanced 911 E911 configuration N0008589 3 3...
Страница 380: ...380 Renumbering DNs N0008589 3 3...
Страница 398: ...398 Saving wizard pages on your computer N0008589 3 3...
Страница 458: ...458 Voice Mail settings N0008589 3 3...
Страница 488: ...488 Setting system telco features N0008589 3 3...
Страница 508: ...508 Other programming that affects public networking N0008589 3 3...
Страница 522: ...522 PRI networking using Call by Call services N0008589 3 3...
Страница 592: ...592 Monitoring Hunt groups N0008589 3 3...
Страница 636: ...636 Configuring Double Density N0008589 3 3...
Страница 640: ...640 Using the Network Update Wizard N0008589 3 3...
Страница 666: ...666 Importing and Exporting DHCP data N0008589 3 3...
Страница 722: ...722 Restarting the router N0008589 3 3...
Страница 726: ...726 Important Web Cache considerations N0008589 3 3...
Страница 748: ...748 Configuring an Interface with NAT N0008589 3 3...
Страница 794: ...794 IPSec N0008589 3 3...
Страница 818: ...818 Configuring the Policy Agent characteristics N0008589 3 3...
Страница 832: ...832 Firewall rules for Business Communications Manager with Dialup interfaces N0008589 3 3...
Страница 876: ...876 ISDN Programming N0008589 3 3...
Страница 1004: ...1004 Index N0008589 3 3...