5-31
Basic Configuration
5.9.3. IP Security
The IP Security feature allows the RPS to restrict unauthorized IP addresses from establishing
inbound connections to the unit via Telnet or Web Browser. This allows you to grant access to
only a specific group of Telnet or Web IP addresses, or block a particular IP address completely.
In the default state, the RPS accepts incoming IP connections from all hosts.
In the Text Interface, IP Security parameters are defined via the Network Configuration menu. In
the Web Browser Interface, these parameters are found by placing the cursor over the "Network
Configuration" link, and then clicking on the "IP Security" link in the resulting fly-out menu.
In the default state, IP Security is disabled. The IP Security Function employs a TCP Wrapper
program which allows the use of standard, Linux operators, wild cards and net/mask pairs to
create a host based access control list.
The IP Security configuration menus include "hosts.allow" and "hosts.deny" client lists. When
setting up IP Security, you must enter IP addresses for hosts that you wish to allow in the Allow
list, and addresses for hosts that you wish to deny in the Deny list. Since Linux operators, wild
cards and net/mask pairs are allowed, these lists can indicate specific addresses, or a range of
addresses to be allowed or denied.
When the IP Security feature is properly enabled, and a client attempts to connect, the RPS will
perform the following checks:
1. If the client’s IP address is found in the "hosts.allow" list, the client will be granted
immediate access. Once an IP address is found in the Allow list, the RPS will not check
the Deny list, and will assume you wish to allow that address to connect.
2. If the client’s IP address is not found in the Allow list, the RPS will then proceed to check
the Deny list.
3. If the client’s IP Address
is
found in the Deny list, the client
will not
be allowed to connect.
4. If the client’s IP Address
is not
found in the Deny list, the client
will
be allowed to connect,
even if the address was not found in the Allow list.
Notes:
• If the RPS finds an IP Address in the Allow list, it will not check the Deny list, and
will allow the client to connect.
• If both the Allow and Deny lists are left blank, then the IP Security feature will
be disabled, and all IP Addresses will be allowed to connect (providing that the
proper password is supplied.)
• When the Allow and Deny lists are defined, the user is only allowed to specify the
Client List; the Daemon List and Shell Command cannot be defined.