
SIP User's Manual 13. Security
Version 5.0 299 October 2006
Figure 13-16 shows an advanced example of an access list definition via ini file:
Figure 13-16: Advanced Example of an Access List Definition via ini File
[ ACCESSLIST ]
FORMAT AccessList_Index = AccessList_Source_IP, AccessList_Net_Mask,
AccessList_Start_Port, AccessList_End_Port, AccessList_Protocol,
AccessList_Packet_Size, AccessList_Byte_Rate, AccessList_Byte_Burst,
AccessList_Allow_Type;
AccessList 10 = 10.0.0.0, 255.0.0.0, 0, 65535, any, 0, 40000, 50000, allow ;
AccessList 15 = 10.31.4.0, 255.255.255.0, 4000, 9000, any, 0, 0, 0, allow ;
AccessList 20 = 0.0.0.0, 0.0.0.0, 0, 65535, any, 0, 0, 0, block;
[ \ACCESSLIST ]
Explanation of the example access list:
This access list consists of three rules:
Rule #10: traffic from the subnet 10.xxx.yyy.zzz is allowed if the traffic rate does not
exceed 40 KB/s.
Rule #15: if a packet didn't match rule #10, that is, the excess traffic is over 40 KB/s,
and coming from the subnet 10.31.4.xxx to ports 4000 to 9000, then it is allowed.
Rule #20: all other traffic (which didn't match the previous rules), is blocked.
The internal firewall can also be configured via the Embedded Web Server (refer to Section
5.6.8.3 on page 101).
Komentáře k této Příručce