Rule Set page field descriptions

Last Updated : Nov 15, 2016 |

Name

Description

Name

The name of the Rule Set.

Description

The description of the Rule Set.

SM Type

Session Manager or Branch Session Manager.

Button

Description

Commit

Save and apply the changes.

Cancel

Cancel the changes.

Rules tab

Name

Description

Enabled

Enable or disable the rule.

Name

The name of the SIP Firewall rule. The name can have a maximum of 80 characters.

Action Type

The action type for the rule:

  • None: No specific action required. Use this action when you want to only generate a log or alarm for matching SIP traffic. Rule traversal continues when a SIP packet matches a rule with the None action.

  • Permit: If the rule conditions are met, allow the SIP message to pass through the SIP Firewall. If the rule conditions are not met, the SIP message is not affected or dropped.

  • Drop: If the rule conditions are met, drop the SIP message.

  • Rate Block: If the packets matching the rule exceed a certain count in a certain period, block the matching SIP packets for the duration of timeout. You define the timeout period using the Threshold parameters.

  • Rate Limit: If the packets matching the rule exceed a certain count in a certain period, drop the additional matching SIP packets for the duration of the period. You define the time period using the Threshold parameters.

Log Type

Specify if you want to generate a log, send an alarm, or take no action.

Log Message

The message that will be logged when the Log Type is Yes or Alarm.

Button

Description

Enabled

Enable or disable all rules in the Firewall Rule Set.

New

Define a new SIP Firewall rule.

Edit

Edit the selected SIP Firewall rule.

Delete

Delete the selected rule or rules.

Up

Move a selected rule up in the list.

Down

Move a selected rule down in the list.

Blacklist tab

Name

Description

Enabled

Enable or disable dropping of messages from untrusted hosts.

Key

Key for filtering messages.

Value

The value of the Key. The Value can be one of the following:

  • Remote IP address: IP address of the host from where the messages are sent.

  • CONTACT: The string value to search in the Contact SIP Header in the SIP message. The string value can be a complete or partial SIP URI, for example, jdoe@avaya.com for a specific user, or @avaya.com for a domain of users.

  • FROM: The string value to search in the From SIP Header in the SIP message. The string value can be a complete or partial SIP URI, for example, jdoe@avaya.com for a specific user, or @avaya.com for a domain of users.

When you select Remote IP Address in the Key field, and select Enable IPv6, the Value field supports both IPv4 and IPv6 addresses. When you specify an IPv6 address in the Value field, you must also specify an IPv6 prefix mask.

IP Address Mask

Subnet mask used for the blacklist operation.

This field supports values between 1 and 128 and is mandatory.

Button

Description

New

Create a rule for dropping messages from untrusted hosts.

Delete

Delete the selected Blacklist rule.

Whitelist tab

Name

Description

Enabled

Enable (allow) or disable do not allow) messages from trusted hosts to bypass the SIP Firewall.

Key

Key for filtering messages.

Value

Value of the Key. The Value can be one of the following:

  • Remote IP address: IP address of the host from where the messages are sent.

  • CONTACT: The string value to search in the Contact SIP Header in the SIP message. The string value can be a complete or partial SIP URI, for example, jdoe@avaya.com for a specific user, or @avaya.com for a domain of users.

  • FROM: The string value to search in the From SIP Header in the SIP message. The string value can be a complete or partial SIP URI, for example, jdoe@avaya.com for a specific user, or @avaya.com for a domain of users.

IP Address Mask

Subnet mask used for the whitelist operation.

Button

Description

New

Create a rule for allowing messages from trusted hosts to bypass the SIP Firewall.

Delete

Delete the selected Whitelist rule.