A, February; Figure 15-9 Configuring Layer 7 Deny Filter - Nortel Web OS Switch Software Application Manual

Switch software
Table of Contents

Advertisement

When a client request is received with www.a.com in the Host Header and .jpg in the URL,
the request will be load balanced between Server 1 and Server 2.
To accomplish this configuration, you must assign multiple strings (a Host Header string and a
URL string) for each real server.
Layer 7 Deny Filter
Web OS allows you to secure your switch from virus attacks by configuring the switch with a
list of potential offending string patterns (HTTP URL request). The switch examines the HTTP
content of the incoming client request for the matching string pattern. If the matching virus
pattern is found, then the packet is dropped and a reset frame is sent to the offending client.
SYSLOG messages and SNMP traps are generated warning operators of a possible attack.
Figure 15-9
ured for Layer 7 deny filter, so it blocks the incoming packet with the virus string and prevents
it from entering the network.

Figure 15-9 Configuring Layer 7 Deny Filter

212777-A, February 2002

shows an incoming client request with a virus string. The Web switch is config-
1. Client sends
a URL request
with a virus
string.
Any virus string
Clients
www.playdog.com
STOP
Internet
Chapter 15: Content Intelligent Switching
Web OS 10.0 Application Guide
2. Switch filter
processes the
string and
denies entry to
Real servers
the network.
Web Switch
n
417

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web os 10.0

Table of Contents