Version 6.6
353
October 2014
Installation & Operation Manual
33. Configuring Security Settings
33.14
Firewall Functionality on Media Gateway Boards
The Mediant 8000 provides Firewall functionality that helps to protect Media Gateway
boards from unauthorized access. Media Gatewayboards may be configured to block
incoming traffic from a specific IP address or from a specific network. Advanced
functionality, such as being able to limit traffic based on individual packet size and
bandwidth allocation, is provided.
Firewall definitions are not bound to a specific application and therefore may be used
to protect the Media Gateway boards from all types of attacks and intrusion attempts –
in the OAM (management), Call Control and Media subnets.
33.14.1
Firewall Rules
The Firewall Profile consists of a number of Firewall Rules. Each incoming Ethernet
packet is checked against the defined rules. If a matching rule is found, an action is
performed (a packet is dropped or accepted).
By default, each Firewall Profile contains the following rules:
Default rules that allow communication with SC board and Redundant Media
Gateway board (may not be modified by user)
"Deny all" last rule
Note:
In its default configuration, the Firewall Profile does not contain rules that
allow a specific Media Gateway board to communicate with Media Gateway
Controllers and other Media Gateways. Hence, such rules must be manually
provisioned by the user, otherwise control/media traffic is blocked.
The Firewall configuration consists of two parts:
Create and configure Firewall Profile
Associate Firewall Profile with specific Media Gateway board
Note:
A single Firewall Profile can be used for multiple Media Gateway boards.
However, you can also define a separate Firewall Profiles for each Media Gateway
board.
To add and configure Firewall Profiles:
1.
Click
to access the Media Gateway status screen.
2.
In the Navigation pane, select
Security
Firewall Profile
; the Firewall Profiles
list is displayed.
3.
Use the
or
buttons to add or remove entries (Firewall Profiles).
Summary of Contents for Mediant 8000
Page 2: ......
Page 33: ...Part I Hardware Overview This part describes the hardware overview of the Mediant 8000 chassis...
Page 34: ......
Page 90: ......
Page 158: ......
Page 264: ......
Page 546: ......
Page 775: ...Part VI Maintenance This part describes the Mediant 8000 maintenance procedures...
Page 776: ......
Page 834: ......
Page 879: ...Part VIII Appendices This part describes additional Mediant 8000 configuration procedures...
Page 880: ......
Page 924: ...Media Gateway Mediant 8000 www audiocodes com Installation Operation Maintenance Manual...