Filtering Example #1 - Netopia 2200 series Software User's Manual

For 2200 and 3300 series gateways
Table of Contents

Advertisement

Fwd: Shows whether the filter forwards (Yes) a packet or discards (No) it when there's
a match.
Src-IP: The packet source IP address to match.
Src-Mask: The packet source subnet mask to match.
Dst-IP: The packet destination IP address to match.
Dst-Mask: The packet destination IP address to match.
Protocol: The protocol to match. This can be entered as a number (see the table
below) or as TCP or UDP if those protocols are used.
Src Port: The source port to match. This is the port on the sending host that originated
the packet.
Dst Port: The destination port to match. This is the port on the receiving host for which
the packet is intended.
NC: Indicates No Compare, where specified.

Filtering example #1

Returning to our filtering rule example from above (see
translated into a filter. Start with the rule, then fill in the filter's attributes:
The rule you want to implement as a filter is:
"Block all Telnet attempts that originate from the remote host 199.211.211.17."
The host 199.211.211.17 is the source of the Telnet packets you want to block, while
the destination address is any IP address. How these IP addresses are masked deter-
mines what the final match will be, although the mask is not displayed in the table that
displays the filter sets (you set it when you create the filter). In fact, since the mask for
the destination IP address is 0.0.0.0, the address for Destination IP address could
have been anything. The mask for Source IP address must be 255.255.255.255 since
an exact match is desired.
160
Protocol
Number to use
N/A
0
ICMP
1
TCP
6
UDP
17
Full name
Ignores protocol type
Internet Control Message Protocol
Transmission Control Protocol
User Datagram Protocol
page
157), look at how a rule is

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3300 series33423356Firmware version 7.6

Table of Contents