Version 7.2 1037 Mediant 1000B Gateway & E-SBC
User's Manual 65. Configuration Parameters Reference
Parameter Description
Firewall Table
Firewall
configure network >
access-list
[AccessList]
The table defines the device's access list (firewall), which defines network
traffic filtering rules.
The format of the ini file table parameter is:
[AccessList]
FORMAT AccessList_Index = AccessList_Source_IP,
AccessList_Source_Port, AccessList_PrefixLen, AccessList_Source_Port,
AccessList_Start_Port, AccessList_End_Port, AccessList_Protocol,
AccessList_Use_Specific_Interface, AccessList_Interface_ID,
AccessList_Packet_Size, AccessList_Byte_Rate, AccessList_Byte_Burst,
AccessList_Allow_Type;
[\AccessList]
For example:
AccessList 10 = mgmt.customer.com, , , 32, 0, 80, tcp, 1, OAMP, 0, 0, 0,
allow;
AccessList 22 = 10.4.0.0, , , 16, 4000, 9000, any, 0, , 0, 0, 0, block;
In the example above, Rule #10 allows traffic from the host
‘mgmt.customer.com’ destined to TCP ports 0 to 80 on interface OAMP
(OAMP). Rule #22 blocks traffic from the subnet 10.4.xxx.yyy destined to
ports 4000 to 9000.
For more information, see ''Configuring Firewall Rules'' on page 171.
65.4.2 HTTPS Parameters
The Secure Hypertext Transport Protocol (HTTPS) parameters are described in the table
below.
Table 65-23: HTTPS Parameters
Parameter Description
Secured Web Connection
(HTTPS)
configure system > web >
secured-connection
[HTTPSOnly]
Determines the protocol used to access the Web interface.
ï‚§ [0] HTTP and HTTPS (default).
ï‚§ [1] HTTPs Only = Unencrypted HTTP packets are blocked.
Note: For the parameter to take effect, a device reset is required.
configure system > web > https-
port
[HTTPSPort]
Defines the local Secured HTTPS port of the device. The
parameter allows secure remote device Web management from
the LAN. To enable secure Web management from the LAN,
configure the desired port.
The valid range is 1 to 65535 (other restrictions may apply within
this range). The default port is 443.
Note: For the parameter to take effect, a device reset is required.
Require Client Certificates for
HTTPS connection
configure system > web > req-
client-cert
[HTTPSRequireClientCertificate]
Enables the requirement of client certificates for HTTPS
connection.
ï‚§ [0] Disable = (Default) Client certificates are not required.
ï‚§ [1] Enable = Client certificates are required. The client
certificate must be preloaded to the device and its matching