Mitel 3000
Broadband Module Manual
64
Security Level
There are four pre-defined security levels (high, medium, low and none) that contain different
security filters for each interface (WAN/LAN, WAN/DMZ, DMZ/LAN). When “None” is
selected, all traffic is blocked. Additional filters can be added to each security level as
required.
The default setting is High Security Level.
The Medium Security level has additional filters. For example it is set up to allow access to a
web server or a mail server on the DMZ from the External interface.
The Low Security level adds more filters. For example, as well as allowing access to a web
server or a mail server on the DMZ, it also allows Telnet and FTP access from the External
interface.
The pre-defined security configurations are:
High Security Level
(from any source IP address or
any source port)
External
<>
Internal
External
<>
DMZ
DMZ
<>
Internal
Service Destination Port In Out In Out In Out
ICMP N/A N/A F T F T F T
Any TCP 0 -65535 F T F T F T
Any UDP 0 - 65535 F T F T F T
RMCP TCP 50 F T F T T F
TCP 51 F T F T T F
ISAKMP UDP 500 F T F T T F
SSL TCP 443 F T F T T F
Kerberos TCP 88 F T F T T F
Kerberos UDP 88 F T F T T F
HTTP TCP 80 F T T T F T
DNS UDP 53 F T T T T T
Telnet TCP 23 F T F T F T
SMTP TCP 25 F T F T F T
POP3 TCP 110 F T F T F T
FTP TCP 21 F T F T F T
SSH TCP 22 F T T T T F
SIP UDP 5060 - 6000 T T T T T T
IPT TCP 5566 T T T T T T
Medium Security Level
(from any source IP address or
any source port)
External
<>
Internal
External
<>
DMZ
DMZ
<>
Internal
Service Destination Port In Out In Out In Out
ICMP N/A N/A F T F T F T
Any TCP 0 - 65535 F T F T F T
Any UDP 0 - 65535 F T F T F T
RMCP TCP 50 F T F T T F
TCP 51 F T F T T F
ISAKMP UDP 500 F T F T T F
SSL TCP 443 F T F T T F
Kerberos TCP 88 F T F T T F
Kerberos UDP 88 F T F T T F
HTTP TCP 80 F T T T F T