Configuring Firewall Allowed Rules - AudioCodes Mediant 4000 SBC User Manual

Session border controller
Hide thumbs Also See for Mediant 4000 SBC:
Table of Contents

Advertisement

33.3

Configuring Firewall Allowed Rules

If you want to configure firewall rules (see 'Configuring Firewall Rules' on page 165) that
block specific network traffic, you must first configure firewall rules that allow traffic
needed in your deployment. Therefore, in addition to allowing basic traffic (such as OAMP,
SIP signalling, and media), you must also allow HA maintenance traffic between the Active
and Redundant devices:
Please configure firewall rules 10 through 21, as shown below, where 10.31.4.61 is the IP
address of the Maintenance interface ("HA_IF") of the Redundant device and 10.31.4.62
the IP address of the Maintenance interface ("HA_IF") of the Active device.
Source
Index
Source IP
Port
0
...
Various rules for basic traffic.
9
10.31.4.61
669
10
10.31.4.62
669
11
12
10.31.4.61
0
13
10.31.4.62
2442
14
10.31.4.61
2442
15
10.31.4.62
0
10.31.4.61
80
16
17
10.31.4.62
80
18
10.31.4.61
670
19
10.31.4.61
680
10.31.4.62
670
20
21
10.31.4.62
680
22
0.0.0.0
0
User's Manual
UDP ports 669, 670 and 680 (HA synchronization and keep alive)
TCP ports 2442 and 80 (HA control and data)
Allowed Firewall Rules for HA
Prefix
Start
End Port Protocol
Length
Port
32
669
669
32
669
669
32
2442
2442
32
0
65535
32
0
65535
32
2442
2442
32
0
65535
32
0
65535
32
670
670
32
680
680
32
670
670
32
680
680
0
0
65535
Note:
The index numbers in the table above may change according to your specific
allow and block rules.
The last rule (Index 22) is an example of a blocking traffic rule (blocks all other
traffic).
Configure the firewall on the Active device. This configuration is automatically
applied to the Redundant device.
If you have an external firewall located between the Active and the Redundant HA
Maintenance interfaces, you must open (allow) the same port ranges as
configured in the table above, on that external firewall.
Use
Interface
Specific
Name
Interface
udp
Enable
HA_IF
udp
Enable
HA_IF
tcp
Enable
HA_IF
tcp
Enable
HA_IF
tcp
Enable
HA_IF
tcp
Enable
HA_IF
tcp
Enable
HA_IF
tcp
Enable
HA_IF
udp
Enable
HA_IF
udp
Enable
HA_IF
udp
Enable
HA_IF
udp
Enable
HA_IF
Any
Disable
--
612
Mediant 4000 SBC
Action
Packet
Byte
Upon
Size
Rate
Match
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Allow
0
0
Block
0
0
Document #: LTRT-40203
Byte
Burst
0
0
0
0
0
0
0
0
0
0
0
0
0

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mediant 4000b sbc

Table of Contents