Solved

Firewall questions - a phone device Positron - is in the DMZ but I want to only allow certain IPs

Posted on 2014-01-30
4
429 Views
Last Modified: 2014-01-31
a positron? phone system is on the lan. someone put it on the dmz - it needs to get data? from the Voip provider? but others are hacking into it.  the voip provider is saying to white list their IP addresses.

a) can't do that when it's in the DMZ, right?
b) moving it back behind the firewall, I need to know what ports to forward to it, right?  they should be able to tell me that?
c) then I have to hope the router will allow enough port forwarding rules?
0
Comment
  • 2
  • 2
4 Comments
 
LVL 15

Assisted Solution

by:Robert Sutton Jr
Robert Sutton Jr earned 500 total points
ID: 39823079
BTW, I live in Warren County, NJ. Now, to your question.

You will be able to port forward a range of ports. If you run a  static nat from the trusted Ip or their entire network you should be able to do the same under the port forward rules since you will be specifying the destination Ip (on your local lan) from your static 1:1 NAT rule. Everything headed for that destination host on your local lan from that trusted network should I assume would fall within your port forwarding range.

IE: Static NAT 10.1.1.0 : 192.168.1.242(destination host)

Under the port forward section say you need ports 15000-20000 forward:
IE: Destination: 192.168.1.242      Port Range: 15000 to 20000    Packet type TCP/UDP or both depending on your needs

This will allow only traffic from that outside host to the destination address provided that its only looking for those ports. Everything else is dropped.

Hope this helps.
0
 

Author Comment

by:BeGentleWithMe-INeedHelp
ID: 39823098
thanks.  But what about if there is a range of public IP addresses you want to allow to come in?  Depends on the firewall I guess?  Either the firewall will accommodate a range / subnet or just have to make several rules and hope the firewall can accommodate that many?

forward ports 15000 to 20000 from 4.3.3.3 to 192.168.1.50
forward ports 15000 to 20000 from 4.3.3.4 to 192.168.1.50
forward ports 15000 to 20000 from 4.3.3.5 to 192.168.1.50
forward ports 15000 to 20000 from 4.3.3.6 to 192.168.1.50
forward ports 15000 to 20000 from 4.3.3.7 to 192.168.1.50
forward ports 15000 to 20000 from 4.3.3.8 to 192.168.1.50

rather than the easier:

forward ports 15000 to 20000 from 4.3.3.0/24 to 192.168.1.50

(yeah, /24 is more than the 6 I mention above... but just using it as an example : )
0
 
LVL 15

Accepted Solution

by:
Robert Sutton Jr earned 500 total points
ID: 39823137
You can on some devices set an ip range. However, with the one you are referring to, I don't believe that option is available. So, to save yourself the hassle, you may have to either choose one of the following and then make only 1 port forwarding rule under the port forwarding section.

Option 1:
1) Static route 4.3.3.0 to 192.168.1.50 (this will include any address in that subnet provided you know that they are all trusted from your provider of VOIP)
Then open the specified port range and set the destination host address as 192.168.1.50

Option 2:
Static route(Whitelist):
4.3.3.3 : 192.168.1.50
4.3.3.4 : 192.168.1.50
4.3.3.5 : 192.168.1.50
4.3.3.6 : 192.168.1.50
4.3.3.7 : 192.168.1.50
4.3.3.8 : 192.168.1.50

If you can't get a definitive answer from your VOIP provider, then option 2 is the best bet. Remember, set the static routes in your whitelist section. Then, you will only need to add 1 service type and port range in your port forwarding section pointing towards your host of 192.168.1.50.

This way, any traffic coming from 4.3.3.0 hitting your Ip will get dropped if its not looking for those ports you specify. Hope this helps.
0
 

Author Closing Comment

by:BeGentleWithMe-INeedHelp
ID: 39824459
THANKS!
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Quality settings for cisco routers 8 53
Static Route 22 48
Tools to detect weak WiFi routers prior connecting to it 14 105
Port Forwarding on Cisco 881 14 44
Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now