EasyManua.ls Logo

D-Link DFL-260E

D-Link DFL-260E
589 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Action Src Interface Src Network Dest Interface Dest Network
Proxy&Clients (ip_proxy)
InboundTo
Proxy&Clients
Allow wan all-nets lan lannet
(ip_proxy)
If Record-Route is enabled then the networks in the above rules can be further restricted by using
"(ip_proxy)" as indicated.
Scenario 3
Protecting proxy and local clients - Proxy on the DMZ interface
This scenario is similar to the previous but the major difference is the location of the local SIP proxy
server. The server is placed on a separate interface and network to the local clients. This setup adds
an extra layer of security since the initial SIP traffic is never exchanged directly between a remote
endpoint and the local, protected clients.
The complexity is increased in this scenario since SIP messages flow across three interfaces: the
receiving interface from the call initiator, the DMZ interface towards the proxy and the destination
interface towards the call terminator. This the initial messages exchanges that take place when a call
is setup in this scenario are illustrated below:
6.2.8. The SIP ALG Chapter 6. Security Mechanisms
299

Table of Contents

Other manuals for D-Link DFL-260E

Related product manuals