12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Packet Filter Policiesserver includes denial-of-service attacks. We recommend that you use VPN options to give more securityfor ICA connections. You can use all of the usual log options with WinFrame.Characteristics• Internet Protocol(s): TCP• Port Number(s): 1494For more information on how to add the Citrix ICA policy, refer to the Advanced FAQs in the KnowledgeBase. Go to www.watchguard.com/support and log in to the LiveSecurity Service.Clarent-gatewayClarent Corporation supplies IP telephone technology to mainstream carriers and service providers.Clarent products allow voice-over-IP between Clarent gateways across the Internet. This policy givessupport to the Clarent v3.0 product and later.Clarent products use two sets of ports, one for gateway-to-gateway communications (UDP ports 4040,4045, and 5010) and one for gateway-to-command center communications (UDP ports 5001 and 5002).Use the Clarent-command policy for the gateway-to-command center communications.Allow incoming connections only from specified external gateways to your gateway or command center.Clarent also gives support for the use of PCAnywhere for management. Refer to the PCAnywhere policynotes for more information.The Clarent-gateway policy could put network security at risk because it allows traffic inside the firewallbased only on network address. This is not a trusted method of authentication. In addition, your Clarentserver could receive denial-of-service attacks in this configuration. Where possible, we recommend thatyou use VPN options to give more security for Clarent-gateway connections.Characteristics• Internet Protocol(s): UDP• Port Number(s): 4040, 4045, 5010Clarent-commandClarent Corporation supplies IP telephone technology to mainstream carriers and service providers.Clarent products allow voice-over-IP between Clarent gateways across the Internet. This policy givessupport to the Clarent v3.0 product and later.Clarent products use two sets of ports, one for gateway-to-gateway communications (UDP ports 4040,4045, and 5010) and one for gateway-to-command center communications (UDP ports 5001 and 5002).Use the Clarent-command policy for the gateway-to-command center communications.Allow incoming connections only from specified external gateways to your gateway or command center.Clarent also gives support for the use of PCAnywhere for management. Refer to the PCAnywhere policynotes for more information.The Clarent-command policy could put network security at risk because it allows traffic inside the firewallbased only on network address. This is not a trusted method of authentication. In addition, yourClarent server could receive denial-of-service attacks in this configuration. Where possible, we recommendthat you use VPN options to give more security for Clarent-command connections.<strong>User</strong> <strong>Guide</strong> 381

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!