06.05.2013 Views

Ponton X/P 2.3 ? Installation and Configuration Guide

Ponton X/P 2.3 ? Installation and Configuration Guide

Ponton X/P 2.3 ? Installation and Configuration Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6.5 Access to the Administration Tool<br />

Advanced <strong>Configuration</strong><br />

This section describes how to configure the <strong>Ponton</strong> XP system so that access to the<br />

Messenger administration tool (or other components) restricted based on IP addresses.<br />

By default only the HttpListener <strong>and</strong> the SoapListener are open to anyone. All other<br />

components are restricted to only local <strong>and</strong> private IP addresses. If you try to access<br />

any of these components from a non authorized IP address, you will get an Error 403 –<br />

Access denied.<br />

The authorized IPs are by default<br />

127.0.0.1<br />

192.168.0.0 – 192.168.255.255<br />

10.0.0.0-10.255.255.255<br />

172.16.0.0-172.16.255.255<br />

169.254.0.0-169.254.255.255<br />

Note: Clearly, access restrictions to your Messenger system may also be defined by<br />

means of appropriate firewall settings.<br />

Within the <strong>Ponton</strong> XP/Tomcat configuration, access is defined by means of so-called<br />

security valves, any number of which may be specified. These security valves can<br />

restrict access from certain addresses/address spaces or to specific components of the<br />

<strong>Ponton</strong> XP system such as the Messenger, the Listener, the administration tool, the<br />

adapter interface, etc.<br />

The relevant access settings are specified in the Tomcat configuration file<br />

as follows.<br />

[installation root]/tomcat-4.1.27/conf/server.xml<br />

By default you will see the following line at the end of the server.xml:<br />

<br />

allow="127\.0\.0\.1,192\.168\..*,10\..*,172\.16\..*,<br />

169\.254\..*"<br />

pattern="/pontonxp/private/.*,/pontonxp/index.*,<br />

/pontonxp/Mess…"<br />

This will restrict the access to Admintool <strong>and</strong> Adapter-Service to just private IP<br />

networks. The values for allowed IPs <strong>and</strong> the URI patterns are regular expressions for<br />

maximum flexibility. These expressions have to be separated by commas.<br />

Characters in regular expressions have the following meaning:<br />

. – any character will match<br />

<strong>Ponton</strong> X/P <strong>2.3</strong> – <strong>Installation</strong> <strong>and</strong> <strong>Configuration</strong> <strong>Guide</strong> 70

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!