Avaya 3.7 Configuration Manual page 306

Release 3.7
Table of Contents

Advertisement

Firewall rules template
The destination is Public and the services are FTP, SSH, Telnet, HTTP, HTTPS, POP3,
IMAP, or ICMPechorequest.
All other incoming traffic is blocked.
Outgoing traffic to the semi-private zone that is allowed includes
Any allowed traffic from other zones
VPN traffic
Table 37: Semi-private high security firewall rules
Rule Name
Action
InBoundSe
Permit
miPrivateV
PNAccess
InBoundSe
Permit
miPrivatePi
ngAccess
InBoundSe
Permit
miPrivateto
DMZAcces
s
InBoundSe
Deny
miPrivateD
enyAccess
InBoundSe
Permit
miPrivateto
PublicAcce
ss
InBoundSe
Deny
miPrivateBl
ockAll
306 Avaya VPNmanager Configuration Guide Release 3.7
Source
Destination
Service
Any
SemiPrivate
IKE_IN
IP
IPSEC_NAT_T_IN
PublicIP
AH/ESP
ICMPDestUnreach
Any
SemiPrivate
ICMPEchoReq(PING)
IP
PublicIP
Any
DMZNet
ICMPEchoReq(PING)
FTP-Ctrl/PassiveFTP
SSH/TELNET
HTTP/HTTPS
DNS-TCP/DNS-UDP
POP3/IMAP/SMTP
NNTP
Any
DMZNet
Any
PrivateNet
Manageme
ntNet
SemiPrivate
IP
Any
Any
ICMPEchoReq(PING)
FTP-Ctrl/PassiveFTP
SSH/TELNET
HTTP/HTTPS
DNS-TCP/DNS-UDP
POP3/IMAP/SMTP
NNTP
Any
Any
Any
Direc
Zone
Keep
tion
State
In
SemiP
No
rivate
In
SemiP
Yes
rivate
In
SemiP
Yes
rivate
In
SemiP
No
rivate
In
SemiP
Yes
rivate
In
SemiP
No
rivate
Keep State
Permit incoming
VPN and ICMP
unreachable
Permit incoming
PING
Permit incoming
services to DMZNet
Deny traffic to
PrivateNet,
ManagementNet
and DMZNet
Permit clear traffic
to Public network/
VPN traffic with
Public IP as tunnel
endpoint
Deny the rest of
traffic
1 of 2

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vpnmanager

Table of Contents