Creating A Network Service - ADTRAN BlueSecure Controller Setup And Administration Manual

Software release version: 6.5
Table of Contents

Advertisement

Chapter 8: Roles and Role Elements
LDAP - Lightweight directory access protocol
H.323 - ITU-T standard for sending voice (audio) and video using IP on a LAN
without QoS
TFTP - Trivial File Transfer Protocol
NTP - Network Time Protocol
SNMP - Simple Network Management Protocol
Note: The standard network services available on the BSC might change in future
releases of the BSC system software.
You can modify existing BSC network service settings or add services that are not
included in this list. You can set QoS parameters for traffic priority and differentiated
services code point (DSCP) marking in a network service, and include that service in
network usage policies when defining a role. An override option in the role determines
whether the traffic priority and DSCP marking settings in a policy's network service take
precedence over the corresponding settings in the role.
You can also globally block or apply bandwidth limits to specific services known to be
used in denial-of-service (DoS) attacks that can originate from the introduction of new
Internet worms. This service blocking/limiting capability enables you to stop a flood of
network traffic before it adversely affects your protected network.
If a large number of virus-infected hosts reside on your network, then they can generate
high volumes of traffic that can in turn cause high CPU usage and traffic drops on
network equipment including BlueSecure Controllers.You can combat the effects of DoSs
and viruses by applying the DoS bandwidth limitations to affected network services.
Additionally, you can permit or deny specific services to users who are in the BSC
Intrusion Detection System's Blocked State.
After defining services, you can organize them into service groups. Using service groups
can streamline role administration, by enabling you to apply one network usage policy to
the entire service group rather than creating a separate policy for each individual
network service. See "Defining User Roles to Enforce Network Usage Policies" on
page 8-2 for more information on defining roles and network usage policies.

Creating a Network Service

To add a network service, do the following:
Displaying the
1.
Click the User Roles tab in the BSC administrator console, and then click the Services
Create a
tab.
Service page
Select Service from the Create drop-down list on the Services page.
2.
The Create a service page appears as shown in Figure 8-14.
8-14

Advertisement

Table of Contents
loading

Table of Contents