Table 1-62 Packet Type In Which The Filtering Based On The Flag (Ack And Syn) Conditions Of Tcp Header Is Limited In Use - Hitachi GR2000 Series Configuration Commands

Hitachi gigabit router configuration guide
Hide thumbs Also See for GR2000 Series:
Table of Contents

Advertisement

Hitachi Gigabit Router GR2000 Series Enhanced Version Configuration Commands, Vol. 2
Description:
Default:
Range of value:
Description:
Default:
Range of value:
Note: Define the filtering according to the GR2000 Configuration Settings (universal CLI) manual
*
when the IPv4 packets shown in the table below are filtered under the ACK/SYN flag
conditions of a TCP header.
The filtering of the IPv4 packets shown in the table below that is performed under the ACK/
SYN flag conditions of a TCP header is limited when IPv4 packets are used in a way except as
described above. The IPv4 packets cannot be properly filtered even if "ack" and "syn"
parameters are set to the filter flow information.
Table 1-62 Packet Type in which the Filtering Based on the Flag (ACK and SYN)
Packet Type
IPv4 packet generated by this router
Packet applied to the conditions below among the
IPv4 packets relayed by this router:
(1) Packet with option (IP header)
Packet applied to the conditions below among the
IPv4 packets relayed by this router:
(2) Packet requiring fragmentation
(3) Packet requiring redirection
(4) Packet in which ARP has not been solved
Description:
Default:
Range of value:
1-118
Specifies TCP one-way communication permission (ACK flag).
The
-ack_check_off
when its ACK flag is on. The
packet when its ACK flag is on.
-ack_check_off
None
Specifies permission for establishing a virtual circuit (SYN
flag). The
filtering when its SYN flag is on. The
the packet when its SYN flag is on.
-syn_check_off
None
Conditions of TCP Header Is Limited in Use
Specifies the ICMP type number in decimal
Undefined
0–255
option excludes the packet from filtering
-ack_check
option excludes the packet from
-syn_check_off
Limited Filtering Item
IPv4 packets do not match the filter list, to which
"-ack_check" or "-syn_check" is set, in conditions. In other
words, both ACK and SYN flags are searched for filtering
as if packet 0 were input.
The same as described above.
The packets to be discarded are properly discarded when
they conform to the filtering conditions.
The packets to be relayed do not match the filter list, to
which "-ack_check" or "-syn_check" is set, in conditions
when they conform to the filtering conditions. In other
words, both ACK and SYN flags are searched for filtering
as if packet 0 were input.
option filters the
option filters
-syn_check
GR2K-GA-0014
Ver. 07-02

Advertisement

Table of Contents
loading

Table of Contents