Security Triggers
125
Model 3086 G.SHDSL Integrated Access Device User Guide
6 • Security
After configuring the FTP portfilter, you can open an ftp session from Remote to Local, however you can issue
ftp commands (e.g., login, cd, etc.) but transfer data (e.g., ls, dir, get, put commands). The portfilter allows an
ftp control channel but does not allow the use of a secondary data channel for passing data by ftp.
To enable the ftp data channel, add a trigger which will open a secondary channel only when data is being
passed. This prevents the need to open too many ports which offer a security risk.
1.
From the Configuration Menu, > Configuration > Security > Firewall Trigger Configuration > New Trig-
ger.
2.
Set the parameters as follows:
– Transport Type = tcp
– Port Number Start = 21
– Port Number End = 21
– Allow Multiple Hosts = Block
– Max Activity Interval = 3000
– Enable Session Chaining = Block
– Enable UDP Session Chaining = Block
– Binary Address Replacement = Block
– Address Translation Type = none
3.
Click on
Apply
.
You should now be able to use ftp commands to pass data between Remote and Local.
Содержание ipRocketLink IAD 3086
Страница 113: ...113 Chapter 5 Specialized Configurations Chapter contents IP Configurations 114 Router 114 DHCP Server and Relay 114...
Страница 118: ...5 Specialized Configurations Model 3086 G SHDSL Integrated Access Device User Guide 118 IP Configurations...
Страница 128: ...6 Security Model 3086 G SHDSL Integrated Access Device User Guide 128 Intrusion Detection System IDS...
Страница 133: ...133 Chapter 8 Monitoring Status Chapter contents Status LEDs 134...
Страница 157: ...157 Appendix C Cable Recommendations Chapter contents DSL Cable 158 Ethernet Cable 158 Adapter 158...