Dynamic Defense; Table 12: Ucm6510 Firewall Dynamic Defense - Grandstream Networks UCM6510 IP PBX User Manual

Ip pbx
Hide thumbs Also See for UCM6510 IP PBX:
Table of Contents

Advertisement

The new rule will be listed at the bottom of the page with sequence number, rule name, action, protocol,
type, source, destination and operation. Users can click on
rule. Save the change and reboot the device for the configuration to take effect.

DYNAMIC DEFENSE

Dynamic defense can blacklist hosts dynamically when the UCM6510 is set to "Route" under web GUI-
>Settings->Network Settings->Basic Settings: Method. If enabled, the traffic via TCP connection
coming into the UCM6510 can be monitored, which helps prevent massive connection attempts or brute
force attacks to the device. The blacklist can be created and updated by the UCM6510 firewall, which will
then be displayed in the web page. Please refer to the following table for dynamic defense options on the
UCM6510.
Dynamic Defense
Enable
Periodical Time
Interval
Blacklist Update
Interval
Connection
Threshold
Dynamic Defense
Whitelist
The following figure shows a configuration example like this:
Firmware Version 1.0.0.25
VoIPon www.voipon.co.uk sales@voipon.co.uk Tel: +44 (0)1245 808195 Fax: +44 (0)1245 808299

Table 12: UCM6510 Firewall Dynamic Defense

Enable dynamic defense. The default setting is disabled.
Configure the dynamic defense periodic time interval (in minutes). If the
number of TCP connections from a host exceeds the "Connection Threshold"
within this period, this host will be added into Blacklist. The valid value is
between 1 and 59 when dynamic defense is turned on. The default setting is
59.
Configure the blacklist update time interval (in seconds). The default setting is
120. This defines how long the IP will be blocked once added into the
UCM6510 blacklist. For example, if it's set to 300 seconds, the blocked IP
address will only be able to establish TCP connection with the UCM6510 again
after 300 seconds.
Configure the connection threshold. Once the number of connections from the
same host reaches the threshold during "Periodical Time Interval", it will be
added into the blacklist. The default setting is 100.
Configure the dynamic defense whitelist. This is a list of IPs that will not be
blocked by the UCM6510.
For example,
192.168.1.3
192.168.1.4
UCM6510 IP PBX User Manual
to edit the rule, or click on
to delete the
Page 43 of 229

Advertisement

Table of Contents
loading

Table of Contents