Avaya B5800 Bedienungsanleitung Seite 278

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 314
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 277
packet, up through the application layer, is examined. A stateful inspection firewall also
monitors the state of the connection and compiles the information in a state table. Stateful
inspection firewalls close off ports until the connection to the specific port is requested. This is
an enhancement to security against port scanning. Port scanning is the act of systematically
scanning a computer's ports. Since a port is a place where information goes into and out of a
computer, port scanning identifies open doors to a computer. Port scanning has legitimate uses
in managing networks, but port scanning also can be malicious in nature if someone is looking
for a weakened access point to break into your computer.
Firewall policies
The goals of firewall policies are to monitor, authorize and log data flows and events. They
also restrict access using IP addresses, port numbers and application types and sub-types.
This appendix focuses on identifying the port numbers used by Avaya products so effective
firewall policies can be created without disrupting business communications or opening
unnecessary access into the network.
Knowing that the source column in the port usage tables provided below is the socket initiator
is key in building some types of firewall policies. Some firewalls can be configured to
automatically create a return path through the firewall if the initiating source is allowed through.
This option removes the need to enter two firewall rules, one for each stream direction, but
can also raise security concerns.
Another feature of some firewalls is to create an umbrella policy that allows access for many
independent data flows using a common higher layer attribute. Finally, many firewall policies
can be avoided by placing endpoints and the servers that serve those endpoints in the same
firewall zone.
TFTP port usage
IP Office upgrade wizard and VM Pro all use TFTP for commands and data transfer. B5800
Branch Gateway implements a version of the TFTP Transfer Identifier mechanism (TID)
defined by RFC 1350.
The general mechanism is each has a TFTP listener on port 69, any received command (READ
request) is responded to with a TFTP response (WRITE request) to port 69. Any subsequent
data transfer uses the source ports from both request and response.
IP Office Manager (upgrade wizard) B5800 Branch Gateway
TFTP Read, src port 2421, dst port 69 >
< TFTP Write, src port 4153, dst port 69
Avaya port matrix for B5800 Branch Gateway and SIP phones
278 Implementing the Avaya B5800 Branch Gateway for an Avaya Aura
®
Configuration October 2012
Seitenansicht 277
1 2 ... 273 274 275 276 277 278 279 280 281 282 283 ... 313 314

Kommentare zu diesen Handbüchern

Keine Kommentare