Virtual Private Networks (VPNs) 5-27
ATMP example
To enable a firewall to allow ATMP traffic, you must provision the firewall to allow inbound and outbound UDP
packets specifically destined for por t 5150. The source por t may be dynamic, so often it is not useful to apply
a compare function on this por tion of the control/negotiation packets. You must also set the firewall to allow
inbound and outbound GRE packets (Protocol 47, Internet Assigned Numbers Document, RFC 1700), enabling
transpor t of the tunnel payload.
From the Main Menu navigate to Display/Change IP Filter Set, and from the pop-up menu select
Basic Firewall
.
Select
Display/Change Input Filter
.
Display/Change Input Filter screen
Select Input Filter 1 and press Return. In the Change Input Filter 1 screen, set the Destination Por t information
as shown below.
Change Output Filter 2
Enabled: Yes
Forward: Yes
Call Placement/Idle Reset: No Change
Force Routing: No
Source IP Address: 0.0.0.0
Source IP Address Mask: 0.0.0.0
Dest. IP Address: 0.0.0.0
Dest. IP Address Mask: 0.0.0.0
TOS: 0
TOS Mask: 0
Protocol Type: GRE
Return/Enter accepts * Tab toggles * ESC cancels.
Enter the packet specific information for this filter.
Main
Menu
System
Filter
Sets
Display/Change
Filter Set
Configuration
Basic
Firewall
+--#----Source IP Addr----Dest IP Addr------Proto-Src.Port-D.Port--On?-Fwd--+
+---------------------------------------------------------------------------+
| 1 0.0.0.0 0.0.0.0 TCP NC =2000 Yes No |
| 2 0.0.0.0 0.0.0.0 TCP NC =6000 Yes No |
| |
+---------------------------------------------------------------------------+
Summary of Contents for Netopia Embedded Software
Page 10: ...x Administrator s Handbook ...
Page 16: ...1 6 Administrator s Handbook ...
Page 44: ...2 28 Administrator s Handbook ...
Page 108: ...3 64 Administrator s Handbook ...
Page 176: ...5 34 Administrator s Handbook ...
Page 202: ...6 26 Administrator s Handbook ...
Page 244: ...7 42 Administrator s Handbook ...
Page 340: ...Index 6 ...