GRANDSTREAM GCC601X(W) Imwe Networking Solution Firewall

ZVIMWE ZVEKUSHANDISA

GCC601X(W) Firewall
Mugwaro iri, tichasuma magadzirirwo maparamita eGCC601X(W) Firewall Module.

PAKUPEDZAVIEW

The overview peji inopa vashandisi ruzivo rwepasi rose muGCC firewall module uye zvakare kutyisidzira kwekuchengetedza uye nhamba, pamusoro.view peji ine:

  • Firewall Service: inoratidza iyo firewall sevhisi uye mamiriro epasuru ine inoshanda uye yakapera mazuva.
  • Yepamusoro Chengetedzo Rogi: inoratidza matanda epamusoro echikamu chega chega, mushandisi anogona kusarudza chikamu kubva pane yekudonhedza pasi runyorwa kana kudzvanya pane museve icon kuti udzoserwe kune yekuchengetedza peji peji kuti uwane rumwe ruzivo.
  • Dziviriro Statistics: inoratidza akasiyana edziviriro statistics, pane sarudzo yekubvisa manhamba ese nekudzvanya pane zvigadziriso icon.
  • Yepamusoro Yakasefa Zvishandiso: inoratidza epamusoro maapplication akasefa nenhamba yekuverenga.
  • Utachiona Files: inoratidza zvakaongororwa files uye akawana hutachiona files zvakare, kugonesa / kudzima iyo anti-malware vashandisi vanogona kudzvanya pane zvigadziriso icon.
  • Kutyisidzira Level: inoratidza nhanho yekutyisidzira kubva pakukosha kusvika kudiki ine ruvara kodhi.
  • Threat Type: inoratidza marudzi ekutyisidzira ane kodhi yemavara uye nhamba yekudzokorora, vashandisi vanogona kutenderedza mbeva cursor pamusoro peruvara kuratidza zita uye nhamba kuitika.
  • Top Threat: inoratidza kutyisidzira kwepamusoro nemhando uye kuverenga.

Vashandisi vanogona kuona zviri nyore zviziviso zvakanyanya uye kutyisidzira.

Firewall

 

Vashandisi vanogona kudzvanya pane museve icon pasi pePamusoro Chengetedzo Log kuti udzoserwe kuSecurity Log chikamu, kana kutenderedza pamusoro pegiya icon pasi peDziviriro Statistics kujekesa manhamba kana pasi peVirus. files kudzima iyo Anti-malware. Pasi peKutyisidzira Level uye Threat Type, vashandisi vanogona zvakare kutenderera pamusoro pemagirafu kuratidza zvimwe zvakawanda. Ndapota tarisa kune nhamba dziri pamusoro.

FIREWALL POLICY

Mitemo Policy

Mitemo mutemo inobvumira kutsanangura kuti iyo GCC mudziyo uchabata sei inbound traffic. Izvi zvinoitwa pane WAN, VLAN, uye VPN.

Firewall

  • Inbound Policy: Tsanangura sarudzo ichatorwa neGCC kune traffic yakatangwa kubva kuWAN kana VLAN. Sarudzo dziripo ndeye Gamuchira, Ramba, uye Drop.
  • IP Masquerading: Gonesa IP masquerading. Izvi zvinomisa iyo IP kero yevatambi vemukati.
  • MSS Clamping: Kugonesa iyi sarudzo kunobvumira iyo MSS (Maximum Segment Size) kuti ikurukurwe panguva yemusangano weTCP nhaurirano.
  • Log Drop / Ramba Traffic: Kugonesa iyi sarudzo kunoburitsa irogi yeese traffic yakadonhedzwa kana kurambwa.
  • Drop / Ramba Traffic Log Limit: Taura huwandu hwematanda pasekondi, miniti, awa kana zuva. Iyo chiyero ndeye 1 ~ 99999999, kana isina chinhu, hapana muganhu.

Inbound Mitemo

Iyo GCC601X(W) inobvumira kusefa kweinouya traffic kune network network kana port WAN uye inoshandisa mitemo yakadai se:

  • Gamuchira: Kubvumira traffic kuti ipfuure.
  • Ramba: Mhinduro inotumirwa kune kure kure ichiti packet yarambwa.
  • Drop: Paketi ichadonhedzwa pasina chiziviso kune kure kure.

Firewall

 

Firewall

 

Firewall

Kutumira Mitemo

GCC601X(W) inopa mukana wekubvumidza traffic pakati pemapoka akasiyana uye mainterfaces (WAN/VLAN/VPN).
Kuti uwedzere mutemo wekutumira, ndapota famba uchienda kuFirewall Module → Firewall Policy → Forwarding Rules, wobva wadzvanya pakanzi “Wedzera” kuti uwedzere mutemo mutsva wekutumira kana kudzvanya pakanzi “Edit” kuti ugadzirise mutemo.

Firewall

Advanced NAT

NAT kana Netiweki kero shandurudzo sezita rinoratidza kuti ishanduro kana mepu yemakero epachivande kana emukati kumakero eIP veruzhinji kana zvichipesana, uye GCC601X(W) inotsigira zvese.

  • SNAT: Kwakabva NAT inoreva kumepu kwevatengi 'IP kero (Yakavanzika kana Yemukati Kero) kune yeruzhinji.
  • DNAT: Kwainoenda NAT ndiyo inodzosera kumashure maitiro eSNAT uko mapaketi anozoendeswa kune yakatarwa kero yemukati.

Iyo Firewall Yepamberi NAT peji inopa kugona kuseta iyo yekumisikidza kune sosi uye kwekuenda NAT. Enda kune Firewall Module → Firewall Policy → Yepamberi NAT.

SNAT

Kuti uwedzere SNAT tinya pabhatani rekuti “Wedzera” kuti uwedzere SNAT nyowani kana kudzvanya pakanzi “Edit” kuti ugadzirise yakambogadzirwa. Tarisa kune manhamba uye tafura iri pazasi:

NAME

Tarisa kune iri pazasi tafura paunenge uchigadzira kana kugadzirisa yeSNAT yekupinda:

Firewall

DNAT
Kuti uwedzere DNAT tinya pakanzi “Wedzera” kuti uwedzere DNAT itsva kana kudzvanya pakanzi “Edit” kuti ugadzirise yakambogadzirwa. Tarisa kune manhamba uye tafura iri pazasi:

Tarisa kune iri pazasi tafura paunenge uchigadzira kana kugadzirisa DNAT yekupinda:

Firewall

Global Configuration

Flush Connection Reload

Kana iyi sarudzo ikagoneswa uye shanduko yefirewall configuration yaitwa, hukama huripo hwaive hwatenderwa nemirairo yapfuura yefirewall huchamiswa.

Kana iyo mitsva yemitemo yefirewall isingabvumidze kubatana kwakamiswa kare, inomiswa uye haizokwanisi kubatana zvakare. Nesarudzo iyi yakadzimwa, majoikisheni aripo anotenderwa kuenderera kusvika nguva yapera, kunyangwe mitemo mitsva isingabvumidze kubatana uku kugadzirwe.

Firewall

KUDZIVIRIRA KWEZVINHU

DoS Defense
Basic Settings - Chengetedzo Defense
Denial-of-Service Attack kurwiswa kwakanangana nekuita kuti zviwanikwa zvenetiweki zvisawanikwe kune vashandisi vari pamutemo nekuzadza muchina wakanangwa nezvikumbiro zvakawanda zvichiita kuti sisitimu iwande kana kupaza kana kudzima.

Firewall

 

Firewall

 

Firewall

IP Kunze

Papeji rino, vashandisi vanogona kuwedzera IP kero kana IP siyana kuti dzirege kuverengerwa kubva kuDoS Defense scan. Kuti uwedzere IP kero kana IP renji kune iyo rondedzero, tinya pa "Wedzera" bhatani sezvakaratidzwa pazasi:

Taura zita, wobva wachinja chimiro ON mushure meizvozvo tsanangura iyo IP kero kana IP renji.

 

Firewall

 

Spoofing Defense

Chikamu chekudzivirira cheSpoofing chinopa akati wandei-matanho kune akasiyana maitiro e spoofing. Kuti udzivirire network yako kubva pakubirwa, ndapota gonesa matanho anotevera kuti ubvise njodzi yekuti traffic yako ibatirwe uye iparadzwe. GCC601X(W) zvishandiso zvinopa matanho ekupikisa spoofing paruzivo rweARP, pamwe neruzivo rweIP.

Firewall

ARP Spoofing Defense

  • Vhara ARP Inopindura neIsingaenderane Kwakabva MAC Kero: Iyo GCC mudziyo unosimbisa kwainoenda MAC kero yepakiti chaiyo, uye kana mhinduro yagamuchirwa nemudziyo, inosimbisa kwainobva MAC kero uye ichaita shuwa kuti inowirirana. Zvikasadaro, chishandiso cheGCC hachizoendesa pakiti.
  • Vhara ARP Inopindura neIsingaenderane Kwekuenda MAC Kero: Iyo GCC601X(W) ichasimbisa kwainobva MAC kero kana mhinduro yagamuchirwa. Chishandiso chino simbisa kero yeMAC yekuenda uye ichaita shuwa kuti dzinoenderana.
  • Zvikasadaro, chishandiso hachizoendesa pakiti.
  • Ramba VRRP MAC MuARP Tafura: Iyo GCC601X(W) ichaderera kusanganisira chero inogadzirwa chaiyo MAC kero mutafura yeARP.

ANTI-MALWARE

Muchikamu chino, vashandisi vanogona kugonesa Anti-malware uye kugadzirisa yavo siginecha raibhurari ruzivo.

Configuration

Kugonesa Anti-malware, enda kuFirewall module → Anti-Malware → Kugadzirisa.
Anti-malware: shandura ON / OFF kugonesa / kudzima iyo Anti-malware.

Cherechedza:
Kusefa HTTPs URL, ndapota shandisa "SSL Proxy".

Spoofing Defense

ARP Spoofing Defense

Vhara ARP Inopindura neIsingaenderane Kwakabva MAC Kero: Iyo GCC mudziyo unosimbisa kwainoenda MAC kero yepakiti chaiyo, uye kana mhinduro yagamuchirwa nemudziyo, inosimbisa kwainobva MAC kero uye ichaita shuwa kuti inowirirana. Zvikasadaro, chishandiso cheGCC hachizoendesa pakiti.

Vhara ARP Inopindura neIsingaenderane Kwekuenda MAC Kero: Iyo GCC601X(W) ichasimbisa kwainobva MAC kero kana mhinduro yagamuchirwa. Chishandiso chino simbisa kero yeMAC yekuenda uye ichaita shuwa kuti dzinoenderana.

Zvikasadaro, chishandiso hachizoendesa pakiti.
Ramba VRRP MAC MuARP Tafura: Iyo GCC601X(W) ichaderera kusanganisira chero inogadzirwa chaiyo MAC kero mutafura yeARP.

ANTI-MALWARE

Muchikamu chino, vashandisi vanogona kugonesa Anti-malware uye kugadzirisa yavo siginecha raibhurari ruzivo.

Configuration

Kugonesa Anti-malware, enda kuFirewall module → Anti-Malware → Kugadzirisa.
Anti-malware: shandura ON / OFF kugonesa / kudzima iyo Anti-malware.

Data Packet Yekuongorora Kudzama: Tarisa packet yemukati yetraffic yega yega zvinoenderana nekugadziriswa. Kudzika kudzika, kunowedzera mwero wekuona uye kukwira kweCPU kushandiswa. Kune 3 level yekudzika pasi, yepakati nepamusoro.

Scan Compressed Files: inotsigira kuongorora kwekumanikidzwa files

Firewall

Pamusoroview peji, vashandisi vanogona kutarisa nhamba uye kuva nepamusoroview. Zvakare, zvinokwanisika kudzima iyo Anti-malware zvakananga kubva pane ino peji nekudzvanya pane zvigadziriso icon sezvakaratidzwa pazasi:

Firewall

Zvinogoneka zvakare kutarisa chengetedzo log kuti uwane rumwe ruzivo

Firewall

Virus Signature Library
Pane ino peji, vashandisi vanogona kugadzirisa iyo anti-malware siginecha ruzivo rweraibhurari, kugadzirisa zuva nezuva kana kugadzira hurongwa, ndapota tarisa kune iri pazasi:

Cherechedza:
Nekumisikidza, inovandudzwa pane imwe nguva yakatarwa (00:00-6:00) mazuva ese.

Firewall

KUDZIVIRIRA KUPINDA

Intrusion Prevention System (IPS) uye Intrusion Detection System (IDS) inzira dzekuchengetedza dzinoongorora traffic yetiweki yezviitiko zvinofungirwa uye kuedza kusingatenderwe kuwana. IDS inozivisa zvinogona kutyisidzira kuchengetedza nekuongorora mapaketi etiweki nematanda, nepo IPS ichishinga kudzivirira kutyisidzira uku nekuvhara kana kudzikisira traffic yakaipa munguva chaiyo. Pamwe chete, IPS neIDS zvinopa nzira yakasarudzika yekuchengetedzwa kwetiweki, zvichibatsira kudzivirira kubva pakurwisa kwecyber uye kuchengetedza ruzivo rwakadzama. Botnet itiweki yemakomputa akakanganiswa ane malware uye anodzorwa nemutambi ane hutsinye, anowanzo shandiswa kuita mahombe ecyberattacks kana zviitiko zvisiri pamutemo.

IDS/IPS

Basic Settings – IDS/IPS
Pane iyi tebhu, vashandisi vanogona kusarudza IDS/IPS modhi, Chengetedzo Dziviriro Level.

IDS/IPS Mode:

  • Zivisa: tarisa traffic uye zivisa vashandisi chete pasina kuivharira, izvi zvakaenzana neIDS (Intrusion Detection System).
  • Zivisa & Vimba: inoona kana kuvharira traffic uye inozivisa nezve nyaya yekuchengetedza, izvi zvakaenzana ne IPS (Intrusion Prevention System).
  • Hapana Chiito: hapana zviziviso kana kudzivirira, IDS / IPS yakaremara mune iyi kesi.

Chengetedzo Yekudzivirira Chikamu: Sarudza mwero wekudzivirira (Yakaderera, Yepakati, Yakakwirira, Yakanyanya kukwirira uye Tsika). Matanho ekudzivirira akasiyana anoenderana neakasiyana ekudzivirira. Vashandisi vanogona kugadzirisa rudzi rwekudzivirira. Iyo yakakwira mwero wedziviriro, mitemo yekudzivirira yakawanda, uye Tsika inogonesa vashandisi kusarudza izvo zvichaonekwa neIDS/IPS.

Firewall

Izvo zvakare zvinogoneka kusarudza tsika yekuchengetedza nhanho uye wozosarudza kubva pane iyo rondedzero kutyisidzira chaiko. Ndokumbira utarise mufananidzo uri pazasi:

Firewall

Kuti utarise zviziviso uye zviito zvakatorwa, pasi peChengetedzo log, sarudza IDS/IPS kubva pane yekudonha-pasi rondedzero sezvakaratidzwa pazasi:

Firewall

IP Kunze
Makero eIP ari pachirongwa ichi haaonekwe neIDS/IPS. Kuwedzera IP kero pane rondedzero, tinya bhatani rekuti "Wedzera" sezvaratidzwa pazasi:

Firewall

Isa zita, wobva wagonesa chimiro, wobva wasarudza mhando (Kwakabva kana Kwainoenda) yeIP kero(s). Kuwedzera IP kero tinya pakanzi "+" uye kudzima IP kero tinya pakanzi "-" sezvaratidzwa pazasi:

Firewall

Botnet
Basic Settings - Botnet
Pane ino peji, vashandisi vanogona kugadzirisa zvigadziriso zvekutanga zvekutarisa inobuda Botnet IP uye Botnet Domain Zita uye pane zvitatu zvingasarudzwa:
Monitor: maaramu anogadzirwa asi haana kuvharwa.
Block: monitors uye inovharira anobuda IP kero / Domain mazita anowana botnets.
Hapana Chiito: Iyo IP kero / Domain zita reinobuda botnet harionekwe.

Firewall

IP/Domain Name Kunze
IP kero pane iyi runyorwa haizo onekwa kuBotnets. Kuwedzera IP kero pane rondedzero, tinya bhatani rekuti "Wedzera" sezvaratidzwa pazasi:
Isa zita, wobva wagonesa chimiro. Kuwedzera IP address/Domain name tinya pa “+” icon uye kudzima IP address/Domain name tinya pa “-” icon sezvaratidzwa pazasi:

Firewall

Siginecha Raibhurari - Botnet
Pane ino peji, vashandisi vanogona kugadzirisa iyo IDS/IPS uye Botnet siginecha raibhurari ruzivo nemaoko, kugadzirisa zuva nezuva kana kugadzira hurongwa, ndapota tarisa kune iri pazasi:

Cherechedza:
Nekumisikidza, inovandudzwa pane imwe nguva yakatarwa (00:00-6:00) mazuva ese.

15

KUDZORA ZVIRI MUKATI

Iyo Yemukati Kudzora chimiro inopa vashandisi kugona kusefa (kubvumira kana kuvharira) traffic zvichibva paDNS, URL, mazwi makuru, uye kushandiswa.

DNS Sefa

Kusefa traffic yakavakirwa paDNS, enda kuFirewall module → Kudzora Zvemukati → DNS Kusefa. Dzvanya pa "Wedzera" bhatani kuti uwedzere DNS Sefa itsva sezvakaratidzwa pazasi:

Firewall

Wobva waisa zita reDNS sefa, gonesa chimiro, uye sarudza chiito (Bvumira kana Bvisa) seSefiltered DNS, pane mbiri sarudzo:

Nyore Mechi: iyo domain zita rinotsigira akawanda-level domain zita rinoenderana.
Wildcard: keywords uye wildcard * inogona kuiswa, wildcard * inogona kungowedzerwa isati yasvika kana mushure mekupinda keyword. For example: *.imag, nhau*, *nhau*. Iyo * pakati inobatwa seyakajairika hunhu.

Firewall

Kuti utarise iyo yakasefa DNS, vashandisi vanogona kuiwana paKupfuuraview peji kana pasi peSecurity log sezvakaratidzwa pazasi:

Firewall

Web Kusefa
Basic Settings - Web Kusefa
Pa peji, vashandisi vanogona kugonesa / kudzima pasi rose web kusefa, ipapo vashandisi vanogona kugonesa kana kudzima web URL kusefa, URL chikamu kusefa uye kusefa kiyi zvakazvimiririra uye kusefa maHTTP URLs, ndapota shandisa "SSL Proxy".

Firewall

URL Kusefa
URL kusefa kunoita kuti vashandisi vasefa URL kero uchishandisa angave akapusa match (domain zita kana IP kero) kana kushandisa Wildcard (semuenzaniso *example*).
Kugadzira a URL kusefa, enda kuFirewall Module → Kusefa Yemukati → Web Kusefa peji → URL Kusefa tab, wobva wadzvanya pakanzi "Wedzera" sezvaratidzwa pazasi:

Taura zita, wobva wachinja chimiro ON, sarudza chiito (Bvumira, Vhara), uye pakupedzisira tsanangura iyo URL kungave uchishandisa zita rakareruka rezita, IP kero (Simple match), kana kushandisa wildcard. Ndokumbira utarise mufananidzo uri pazasi:

Firewall

URL Category Sefa
Vashandisi vanewo sarudzo yekusasefa chete neimwe domain/IP kero kana wildcard, asiwo kusefa nezvikamu zve ex.ample Kurwisa uye Kutyisidzira, Vakuru, nezvimwe.
Kuvharisa kana kubvumidza chikamu chose, tinya pane yekutanga sarudzo pamutsara uye sarudza Zvese Bvumira kana Zvese Vhara. Izvo zvakare zvinogoneka kuvharira / kubvumidza neadiki-zvikamu sezvinoratidzwa pazasi:

Firewall

Keywords Sefa
Keyword kusefa kunoita kuti vashandisi kusefa vachishandisa ingave yenguva dzose kutaura kana Wildcard (eg *example*).
Kuti ugadzire kusefa mazwi akakosha, enda kuFirewall Module → Kusefa Yemukati → Web Kusefa peji → Keywords Kusefa tebhu, wobva wadzvanya bhatani rekuti "Wedzera" sezvaratidzwa pazasi:

Firewall

Rondedzera zita, wobva wachinja chimiro KUTI, sarudza chiito (Bvumira, Bvisa), uye pakupedzisira tsanangura zvakasefa ungave uchishandisa chirevo chenguva dzose kana kadhi remusango. Ndokumbira utarise mufananidzo uri pazasi:

Firewall

Kana makiyi kusefa kwave ON uye chiito chacho chakaiswa kuBlock. Kana vashandisi vakaedza kuwana kune example "YouTube" pabrowser, ivo vanozokurudzirwa neyambiro yefirewall sezvinoratidzwa pazasi:

Firewall

Example ye keywords_ kusefa paBhurawuza
Kuti uwane rumwe ruzivo nezve yambiro, vashandisi vanogona kuenda kuFirewall module → Chengetedza Log.

Firewall

URL Signature Library
Pa peji ino, vashandisi vanogona kugadzirisa iyo Web Kusefa siginecha ruzivo rweraibhurari nemaoko, gadziridza zuva nezuva, kana kugadzira hurongwa, ndapota tarisa kune iri pazasi:

Cherechedza:
Nekumisikidza, inovandudzwa pane imwe nguva yakatarwa (00:00-6:00) mazuva ese.

Firewall

Application Sefa
Basic Settings - Application Sefa
Pa peji, vashandisi vanogona kugonesa / kudzima kusefa kwepasirese application, ipapo vashandisi vanogona kugonesa kana kudzima nezvikamu zveapp.
Enda kuFirewall module → Zvemukati Kudzora → Kusefa Kwekushandisa, uye pane yekutanga zvigadziriso tebhu, gonesa Kusefa Kwekushandisa pasi rose, zvinogonekawo kugonesa Kuzivikanwa kweAI kuti ive nani.

Cherechedza:
kana AI Recognition ikagoneswa, AI yakadzama yekudzidza algorithms ichashandiswa kukwenenzvera iko kurongeka uye kuvimbika kweiyo application classification, iyo inogona kushandisa yakawanda CPU uye ndangariro zviwanikwa.

Firewall

App Sefa Mitemo

PaApp Filtering Rules tab, vashandisi vanogona Bvumira/Kuvhara nechikamu cheapp sezvakaratidzwa pazasi:

Firewall

Bvisa Mitemo Yekusefa
Kana chikamu cheapp chasarudzwa, vashandisi vanozove nesarudzo yekupfuura mutemo wakajairwa (chikamu cheapp) neinodarika mitemo yekusefa.
For exampuye, kana iyo Browsers app chikamu chakaiswa kuBlock, saka isu tinogona kuwedzera mutemo wekusefa kuti ubvumire Opera Mini, nenzira iyi chikamu chese chebrowser app chakavharwa kunze kweOpera Mini.
Kuti ugadzire mutemo weKusefa unodarika, tinya bhatani rekuti "Wedzera" sezvaratidzwa pazasi:

 

Firewall

Wobva watsanangura zita uye wochinja chimiro ON, isa chiitiko Kubvumidza kana Kuvhara uye pakupedzisira sarudza kubva pane iyo rondedzero maapplication anotenderwa kana kuvharwa. Ndokumbira utarise mufananidzo uri pazasi:

Firewall

Siginecha Raibhurari - Kusefa Kwekushandisa
Pane ino peji, vashandisi vanogona kugadzirisa iyo Chikumbiro Kusefa siginecha ruzivo rweraibhurari, kugadzirisa zuva nezuva kana kugadzira hurongwa, ndapota tarisa kune iri pazasi:

Cherechedza:
Nekumisikidza, inovandudzwa pane imwe nguva yakatarwa (00:00-6:00) mazuva ese.

Firewall

SSL PROXY

SSL proxy iseva inoshandisa SSL encryption kuchengetedza kufambisa data pakati pemutengi neseva. Inoshanda zviri pachena, encrypting uye decrypting data pasina kuonekwa. Kunyanya, iyo inovimbisa kuburitswa kwakachengeteka kweruzivo rwakadzama pawebhusaiti.
Kana SSL Proxy ikagoneswa, GCC601x(w) ichaita seSSL Proxy server yevatengi vakabatana.

Basic Settings - SSL Proxy

Kubatidza zvinhu zvakaita seSSL Proxy, Web Kusefa, kana Anti-malware inobatsira kuona mamwe marudzi ekurwiswa pa webnzvimbo, dzakadai seSQL jekiseni uye kuyambuka-saiti scripting (XSS) kurwisa. Kurwiswa uku kunoedza kukuvadza kana kuba ruzivo kubva webnzvimbo.

Kana aya maficha ari kushanda, anogadzira matanda ekuzivisa pasi peSecurity Log.
Nekudaro, kana aya maficha akabatidzwa, vashandisi vanogona kuona yambiro nezve zvitupa pavanenge vachitsvaga web. Izvi zvinoitika nekuti bhurawuza harizive chitupa chiri kushandiswa. Kuti udzivise yambiro idzi, vashandisi vanogona kuisa chitupa mubrowser yavo. Kana chitupa chisina kuvimbwa nacho, mamwe maapplication anogona kusashanda nemazvo kana uchiwana internet
Kusefa kweHTTPS, vashandisi vanogona kugonesa SSL proxy nekufamba kuenda kuFirewall module → SSL Proxy → Basic Settings, wobva wachinja ON SSL proxy, mushure mekusarudza CA Certificate kubva pane yekudonhedza pasi kana kudzvanya pakanzi "Wedzera" kuti ugadzire chitupa chitsva cheCA. Ndokumbira utarise kune manhamba uye tafura iri pazasi:

Firewall]

 

Firewall

Kuti SSL Proxy itange kushanda, vashandisi vanogona kudhawunirodha chitupa cheCA nekudzvanya pane yekurodha icon sezvakaratidzwa pazasi:

Zvadaro, chitupa cheCA chinogona kuwedzerwa kune zvakagadzirirwa zvishandiso pasi pezvitupa zvinovimbwa.

 

Firewall

 

Firewall

 

Firewall

Kwakabva Kero
Kana pasina kero yakataurwa, zvese zvinobuda zvinofambiswa zvinofambiswa kuburikidza neSSL proxy. Nekudaro, pakuwedzera nemaoko kero nyowani, idzo chete dzakasanganisirwa dzinozove proxied kuburikidza neSSL, kuve nechokwadi chekusarudza encryption zvichienderana neyakatsanangurwa mushandisi maitiro.

Firewall

 

Firewall

SSL Proxy Exemption List
SSL proxy inosanganisira kubvunzurudza uye kuongorora SSL/TLS encrypted traffic pakati pemutengi neseva, izvo zvinowanzoitika kuitira kuchengetedza uye kutarisa mukati memakambani network. Nekudaro, kune mamwe mamiriro ekuti SSL proxy ingave isingafadzi kana inoshanda kune chaiyo webnzvimbo kana domains.
Rondedzero yekuregererwa inobvumira vashandisi kudoma yavo IP kero, domain, IP renji, uye web chikamu chekusunungurwa kubva kuSSL proxy.
Dzvanya pa "Wedzera" bhatani kuti uwedzere kuregererwa kweSSL sezvakaratidzwa pazasi:

Firewall

Pasi pe "Zviri mukati", vashandisi vanogona kuwedzera zvirimo nekudzvanya pakanzi "+ icon" vodzima nekudzvanya pakanzi "- icon" sezvaratidzwa pazasi:

Firewall

SECURITY LOG

Log
Papeji rino, matanda ekuchengetedza anonyorwa nezvakawanda senge Source IP, Source interface, Attack Type, Chiito, uye Nguva. Dzvanya pabhatani rekuti "Refresh" kuti uvandudze rondedzero uye bhatani re "Export" kudhawunirodha runyorwa kumuchina wemuno.

Vashandisi vanewo sarudzo yekusefa matanda ne:

1. Nguva
Cherechedza:
Marogi anochengetwa nekusarudzika kwemazuva zana nemakumi masere. Kana dhisiki nzvimbo yasvika pachikumbaridzo, matanda ekuchengetedza anozocheneswa otomatiki.
2. Kurwisa
Ronga zvinyorwa ne:
1. Kunobva IP
2. Source Interface
3. Kurwisa Type
4. Chiito

Firewall

Kuti uwane rumwe ruzivo, tinya pakanzi "exclamation icon" pasi peDetails column sezvakaratidzwa pamusoro:
Chengetedzo log

 

Firewall

Kana vashandisi vadzvanya bhatani re "Export", iyo Excel file zvichadhaunirodwa kumuchina wavo wepanzvimbo. Ndokumbira utarise mufananidzo uri pazasi:

Firewall

E-mail Notifications
Papeji, vashandisi vanogona kusarudza kuti ndedzipi tyisidziro dzinofanirwa kuziviswa nezvekushandisa E-mail kero. Sarudza zvaunoda kuziviswa kubva pane rondedzero.
Cherechedza:
Email Zvirongwa zvinofanirwa kugadzirwa kutanga, tinya pa "Email Settings" kugonesa uye kugadzirisa E-mail zviziviso. Ndokumbira utarise mufananidzo uri pazasi:
E

Firewall

Zvinodiwa:

  • Chigadzirwa Model: GCC601X (W) Firewall
  • Inotsigira: WAN, VLAN, VPN
  • Zvimiro: Mitemo Yemitemo, Mitemo Yekutumira, Yepamberi NAT

Mibvunzo Inowanzo bvunzwa (FAQ)

Mubvunzo: Ndingabvisa sei Dziviriro Statistics?

A: Famba pamusoro pegiya icon pasi peDziviriro Statistics uye tinya kuti ubvise nhamba.

Zvinyorwa / Zvishandiso

GRANDSTREAM GCC601X(W) Imwe Networking Solution Firewall [pdf] User Manual
GCC601X W, GCC601X W Imwe Networking Solution Firewall, GCC601X W, One Networking Solution Firewall, Networking Solution Firewall, Solution Firewall, Firewall

References

Siya mhinduro

Yako email kero haizoburitswa. Nzvimbo dzinodiwa dzakamakwa *