Siemens RX1500 User Manual page 329

Ruggedcom rox ii series
Hide thumbs Also See for RX1500:
Table of Contents

Advertisement

RUGGEDCOM ROX II
User Guide
Parameter
Address
Mask
4.
Click Add to create the new restriction. The Server Restrictions form appears.
Figure 312: Server Restrictions Form
1. Flags List
5.
Configure the following parameter(s) as required:
CAUTION!
Security hazard – risk of unauthorized access and/or exploitation. It is recommended to restrict
queries via ntpdc and ntpq, unless the queries come from a localhost, or to disable this feature
entirely if not required. This prevents DDoS (Distributed Denial of Service) reflection/amplification
attacks. Configure the following flags to the restrict default entry: kod, nomodify, nopeer,
noquery and notrap.
Parameter
Flags
Adding a Server Restriction
Description
Synopsis: The host type represents either an IP address or a DNS domain name.,
default
The address to match. The address can be a host or network IP address or a valid host
DNS name.
Synopsis: The ipv4-address type represents an IPv4 address in dotted-quad notation.
The IPv4 address may include a zone index, separated by a % sign. The zone index is
used to disambiguate identical address values. For link-local addresses, the zone index
will typically be the interface index number or the name of an interface. If the zone index
is not present, the default zone of the device will be used. The canonical format for the
zone index is the numerical format, default
The mask used to match the address. Mask 255.255.255.255 means the address is
treated as the address of an individual host.
1
Description
Synopsis: ignore, kod, limited, lowpriotrap, nomodify, nopeer, noquery, noserve,
notrap, notrust, ntpport, version
Synopsis: "flags" occurs in an unbounded array
Flags restrict access to NTP services. An entry with no flags allows free access to the
NTP server.
• Version: Denies packets that do not match the current NTP version.
• ntpport: Matches only if the source port in the packet is the standard NTP UDP port
(123).
• notrust: Denies service unless the packet is cryptographically authenticated.
• notrap: Declines to to provide mode 6 control message trap service to matching hosts.
Chapter 5
Setup and Configuration
297

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rx1501Rx1510Rx1511Rx1512

Table of Contents