18.4. Restricting Access by Caller ID

If your phone line has caller ID enabled and your modem supports it, mgetty can be configured to block certain callers based on their phone numbers. By default, any caller will be allowed to connect—but you can change this so that only a few numbers are allowed by following these steps:

1.
On the main page of the module, click on the Caller ID Access icon. This will take you to a form listing restricted numbers, which will probably be empty if you have not added any yet.

2.
Click on the Add a new caller ID number link, which will take you to a form for entering the new number.

3.
Set the Phone number option to Numbers starting with, and in the field next to it enter a partial or complete phone number that you want to allow. If you enter something like just 555, any caller whose phone number starts with 555 (such as 555-1234) will be allowed.

4.
Set the Action field to Allow.

5.
Click the Create button, which will save the number and return you to the list of those that are allowed and denied.

6.
To add another allowed number, repeat Steps 2 through 5.

7.
Finally, click on Add a new caller ID number again and on the creation form set Phone number to All numbers and the Action to Deny.

8.
Click the Create button to have this final deny entry added to the list. From now on, only the phone numbers that you explicitly allowed will be able to connect.

Because the system checks each entry in the list in order and stops when it finds one that matches, any entry that denies (or allows) all callers must appear at the bottom of the list—otherwise, those after it will never be processed. If you want to allow a new phone number in the future, you must add it, then use the arrows in the Move column to move it above the final entry that denies everyone.

Because some clients may not provide caller ID information, the Unknown numbers option for the Phone number field can be used to match their calls. Allowing all unknown callers is not a good way to block known attackers though, as they may just disable the sending of caller ID information on their phone line.

Caller ID restrictions should never be the only form of security on your dial-in server, as caller numbers are supplied by the phone company and thus not totally under your control. PPP authentication should be enabled as well, so that all clients are forced to log in.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.191.222.231