Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Port 5060 block on MBG other than the service provider 1

Status
Not open for further replies.

tech1302

Technical User
Mar 8, 2013
197
GB
HI

Is it possible to block Port 5060 on the MBG other than the service provider.
MBG is on gateway mode.

Thanks

 
are you saying that you want to drop all traffic other than service providers or just 5060 ?

you can use a white list to only allow external connections from their Ip on later versions of MBG

If I never did anything I'd never done before , I'd never do anything.....

 
@Billz66 Ideally i need to block 5060 everyone other than the service provider
If i use the white list, would it affect the teleworkers ?
 
yep
are they mobile or can you allow their location in teh white list
ive started doing black white deny as default mbg with pub ip setting and importing country based cidr lists to limit dodgy sip sniffers from bad countries

If I never did anything I'd never done before , I'd never do anything.....

 
@Billz66

how would i set this up please.
Help files are no use. Cheers
 
on MBg under system config IP blocking
from memory the MBg has to be at least version 10

if you have a text file containing the following



202.100.100.0/24
### Mitel Deployment and AMC
85.214.114.203/32
216.191.234.91/32

and set it to the white list entry
then set the rule to black /White/Deny
then all other connections would be dropped unless they came from a public ip within the allowed subnets and or addresses

NOTE: I normally allow mitel amc and deployment addresses to make sure that SYNC and Micollab deployment isnt affected



If I never did anything I'd never done before , I'd never do anything.....

 
@Billz66

Cheers for that
what is 202.100.100.0/24 not related to Mitel is it
 
thats an example of a network that would be allowed to connect to the public address of the MBG

- basically add all the addresses that you want to be able to connect to the white list

you can download cidr country lists from the internet but they are not 100% accurate so you might have to adjust of you want to block by country

If I never did anything I'd never done before , I'd never do anything.....

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top