D-Link NetDefend DFL-210 User Manual page 238

Network security firewall ver 2.26.01
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

6.2.8. The SIP ALG
OutboundToProxy
OutboundFromProxy
InboundFromProxy
InboundToProxy
With Record-Route disabled, the following IP rules must be added to those above:
OutboundBypassProxy
InboundBypassProxy
Solution B - Without NAT
The setup steps are as follows:
1.
Define a single SIP ALG object using the options described above.
2.
Define a Service object which is associated with the SIP ALG object. The service should have:
Destination Port set to 5060 (the default SIP signalling port)
Type set to TCP/UDP
3.
Define four rules in the IP rule set:
An Allow rule for outbound traffic from the clients on the internal network to the proxy
located on the DMZ interface.
An Allow rule for outbound traffic from the proxy behind the DMZ interface to the remote
clients on the Internet.
An Allow rule for inbound SIP traffic from the SIP proxy behind the DMZ interface to the
clients located on the local, protected network.
An Allow rule for inbound SIP traffic from clients and proxies on the Internet to the proxy
behind the DMZ interface.
4.
If Record-Route is not enabled at the proxy, direct exchange of SIP messages must also be
allowed between clients, bypassing the proxy. The following two additional rules are therefore
needed when Record-Route is disabled:
An Allow rule for outbound traffic from the clients on the local network to the external
clients and proxies on the Internet.
An Allow rule for inbound SIP traffic from the Internet to clients on the local network.
The IP rules with Record-Route enabled are:
OutboundToProxy
OutboundFromProxy
InboundFromProxy
InboundToProxy
With Record-Route disabled, the following IP rules must be added to those above:
OutboundBypassProxy
Action
Src Interface
NAT
lan
Allow
dmz
Allow
dmz
Allow
wan
Action
Src Interface
NAT
lan
Allow
wan
Action
Src Interface
Allow
lan
Allow
dmz
Allow
dmz
Allow
wan
Action
Src Interface
Allow
lan
238
Chapter 6. Security Mechanisms
Src Network
Dest Interface
lannet
dmz
ip_proxy
wan
ip_proxy
core
all-nets
dmz
Src Network
Dest Interface
lannet
wan
all-nets
core
Src Network
Dest Interface
lannet
dmz
ip_proxy
lan
ip_proxy
core
all-nets
dmz
Src Network
Dest Interface
lannet
wan
Dest Network
ip_proxy
all-nets
dmz_ip
ip_proxy
Dest Network
all-nets
ipdmz
Dest Network
ip_proxy
lannet
dmz_ip
ip_proxy
Dest Network
all-nets

Advertisement

Table of Contents
loading

Table of Contents