Firewall-Other Security Settings - Panasonic KX-NS1000 Installation Manual

Pure ip-pbx
Hide thumbs Also See for KX-NS1000:
Table of Contents

Advertisement

8.6.14 Firewall—Other Security Settings
PC Programming Manual References
27.7 Router Configuration—Firewall—[2-1] One Touch Security
8.6.14 Firewall—Other Security Settings
Description
The following additional filtering settings are available.
Other Security Settings
Private IP Address Filtering
ICMP Echo Request Packet Filtering
ICMP Redirect Settings
NET BIOS Packet Filtering
Private IP Address Filtering
This setting is a filter for private IP addresses. It blocks private IP addresses in both directions.
If the WAN interface is connected to an edge, communication using the WAN's private IP addresses
is not allowed. Therefore, if this feature is enabled, the following types of packets will be discarded.
1.
Packets travelling from the LAN to the WAN whose destination IP address is a private IP address
2.
Packets travelling from the WAN to the LAN whose source IP address is a private IP address
However, if the WAN interface's IP address is a private IP address, this feature will be automatically
disabled. Also, communication over an IPsec VPN is exempt from this filter.
ICMP Echo Request Packet Filtering
This setting determines whether the PBX responds to ICMP echo requests on either the WAN interface
or LAN interface.
ICMP Redirect Settings
Depending on the settings, the PBX will send ICMP redirect packets and notify the sender of changes
to the route.
Depending on the settings, the PBX will receive ICMP redirect packets and will update its routing table
based on the content of the received packet.
NET BIOS Packet Filtering
This setting filters packets so that Windows services such as DCE and RPC, NetBIOS, Direct Hosting,
SMB, etc., are limited to the LAN and do not travel onto the WAN.
In particular, it is necessary to filter RPC packets, since several vulnerabilities have been found in the
Windows RPC interface.
By using a filter rule to discard packets for these ports travelling from the LAN to the WAN, traffic for
external Windows sharing features (NetBIOS) will be blocked.
Conditions
For details about which security settings should be enabled, consult the network administrator.
PC Programming Manual References
27.7 Router Configuration—Firewall—[2-1] One Touch Security
362
Installation Manual
Description
Block private IP addresses
Block ICMP echo requests
Settings for sending and receiving ICMP
redirect packets.
Block external sharing packets from NetBIOS.
Document Version 2016-03

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents