Configuring Ethernet Frame Filtering; Displaying And Maintaining A Packet Filter Firewall - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1796
C
94: F
HAPTER
IREWALL
Configuring Ethernet
Frame Filtering
n
Displaying and
Maintaining a Packet
Filter Firewall
C
ONFIGURATION
fragment of each packet in order to obtain the match information of the
subsequent fragments. The default mode is normal match mode.
1 Configure IPv4 packet filtering on an interface:
To do...
Enter system view
Enter interface view
Configure IPv4 packet
filtering on an interface
2 Configure IPv6 packet filtering on an interface
IPv6 packet filtering is a basic firewall function of an IPv6-based ACL. You can
configure IPv6 packet filtering on either the inbound or outbound direction of an
interface. However, only one IPv6 ACL is allowed on each direction.
Follow these steps to configure IPv6 packet filtering on an interface
To do...
Enter system view
Enter interface view
Configure IPv4 packet filtering
on an interface
Follow these steps to configure Ethernet frame filtering:
To do...
Enter system view
Enter interface view
Configure Ethernet frame filtering for
the inbound/outbound direction of
interface and set the number of the
ACL to be used
The Ethernet frame filtering is effective only after you add the interface into a
bridge group.
To do...
View the Ethernet frame
filtering statistics
View the statistics of the
firewall
Use the command...
system-view
interface interface-type interface-number
firewall packet-filter { acl-number | name
acl-name } { inbound | outbound }
[ match-fragments { normally | exactly } ]
Use the command...
system-view
interface interface-type
interface-number
firewall packet-filter ipv6
{ acl6-number | name
acl6-name } { inbound |
outbound }
Use the command...
system-view
interface interface-type
interface-number
firewall ethernet-frame-filter
{ acl-number | name acl-name }
{ inbound | outbound }
Use the command...
display firewall ethernet-frame-filter { all |
dlsw | interface interface-type
interface-number }
display firewall-statistics { all | interface
interface-type interface-number |
fragments-inspect }
Remarks
-
-
Required
IPv4 packets are not
filtered by default
Remarks
-
-
Required
IPv6 packets are not filtered
by default
Remarks
-
-
Required
No filtering is
performed by
default
Remarks
Available in any
view
Available in any
view

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents