RedMax EXtreme EX-LRT Průvodce řešením problémů Strana 49

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 142
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 48
Oracle SBC Security Guide
NN 6300 724k CAM 16G memory copper single GigE
Platform
NN 6300
CAM
724K
Memory
16G
Software Release
7.1.2
Configuration Model
PBRB
SSNHTN
SNB
media-manager
max-signaling-bandwidth
2500000
max-untrusted-signaling
1
1
1
min-untrusted-signaling
1
1
1
tolerance-window
30
realm-config (peer)
access-control-trust-level
high
average-rate-limit
0
invalid-signal-threshold
0
maximum-signal-threshold
0
untrusted-signal-threshold
0
realm-config (core)
access-control-trust-level
high
average-rate-limit
0
invalid-signal-threshold
0
maximum-signal-threshold
0
untrusted-signal-threshold
0
Observations/Limitations
The settings outlined in this appendix are beneficial when facing malicious attacks from any unknown
sources; this is a typical concern when deploying peering traffic on the public Internet. Setting access-
control-trust-level to “high” in both peer realm and an ACL (access-control) will yield an
implicit deny scenario where traffic from unknown source IP addresses will be silently discarded at the
hardware level in order to protect both the SBC’s host CPU and core devices from being attacked. The
design of this configuration is not to prevent cases where malicious attacks are generated behind the
trusted source IP within peer’s network, since all traffic from peer is consider as “trusted”. Therefore, the
SBC will forward all traffic from trusted sources to the core network as allowed by the system’s hardware
or software capabilities. There is no demotion event when access-control-trust-level at realm
is set “high” as packets from trusted peer endpoint are always allocated the trusted queue for processing.
An alternative DDoS prevention practice in peering is to set access-control-trust-level to
“medium”, but this type of configuration requires settings of “max-untrusted-signaling”,
min-untrusted-signalingand maximum-signal-threshold”, which vary greatly
Zobrazit stránku 48
1 2 ... 44 45 46 47 48 49 50 51 52 53 54 ... 141 142

Komentáře k této Příručce

Žádné komentáře