Table 33 Implicit Ip Filter Rules; Table 34 Default Ip Policy Rules - Brocade Communications Systems 53-1001763-02 Administrator's Manual

Brocade communications systems iron user manual
Table of Contents

Advertisement

7
IP Filter policy
TABLE 32
Service name
snmp
ssh
sunrpc
telnet
www
TCP and UDP protocols are valid selections. Fabric OS v6.2.0 and later does not support
configuration to filter other protocols. Implicitly, ICMP type 0 and type 8 packets are always allowed
to support ICMP echo request and reply on commands like ping and traceroute. For the action, only
"permit" and "deny" are valid.
For every IP Filter policy, the two rules listed in
implicitly to the end of the policy. This ensures that TCP and UDP traffic to dynamic port ranges is
allowed, so that management IP traffic initiated from a switch, such as syslog, radius and ftp, is not
affected.
TABLE 33
Source address
Any
Any
A switch with Fabric OS v6.2.0 or later will have a default IP Filter policy for IPv4 and IPv6. The
default IP Filter policy cannot be deleted or changed. When an alternative IP Filter policy is
activated, the default IP Filter policy becomes deactivated.
Filter policy.
TABLE 34
Rule number
1
2
3
4
5
6
7
9
10
11
12
156
Supported services (Continued)
Port number
161
22
111
23
80
Implicit IP Filter rules
Destination port
1024-65535
1024-65535
Default IP policy rules
Source address
Destination port
Any
22
Any
23
Any
897
Any
898
Any
111
Any
80
Any
443
Any
161
Any
111
Any
123
Any
600-1023
Table 33
are always assumed to be appended
Protocol
Action
TCP
Permit
UDP
Permit
Table 34
Protocol
TCP
TCP
TCP
TCP
TCP
TCP
TCP
UDP
UDP
UDP
UDP
lists the rules of the default IP
Action
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Permit
Fabric OS Administrator's Guide
53-1001763-02

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents