Packet Filtering Overview; What Can You Filter - 3Com corebuilder 3500 Implementation Manual

Hide thumbs Also See for corebuilder 3500:
Table of Contents

Advertisement

210
C
10: P
HAPTER
ACKET
Packet Filtering
Overview

What Can You Filter?

F
ILTERING
The packet filtering feature allows a switch to make a permit-or-deny
decision for each packet based on the packet contents. Use packet filters
to control traffic on your network segments to:
Improve LAN performance.
Implement LAN security controls.
Shape traffic flow to emulate virtual LAN (VLAN) behavior. See
Chapter 9.
Before you create a packet filter, you must decide which part of the
packet you want to use for your filtering decisions. You can filter on any
data in the first 64 bytes of the frame. You can filter Ethernet, Fast
Ethernet, Fiber Distributed Data Interface (FDDI), or Gigabit Ethernet
frames by the destination address, source address, type, length, or any
attribute within the first 64 bytes. Keep in mind that the offsets may
differ between FDDI and Ethernet, so the same filter may not work on all
interfaces. Ethernet and FDDI packet fields are shown in Figure 35.
Figure 35 Ethernet and FDDI Packet Fields
Destination
Address
(Ethernet Type field if > 1500;
(6 octets)
802.3 Length field if - 1500)
octets
0
6
Source Address
(6 octets)
Destination
Source
Address
Address
(6 octets)
(6 octets)
octets
0
6
Type/Length
12
14
Internal Packet Data
Filter First 64 Bytes of Frame
12
Internal Packet Data
Filter First 64 Bytes of Frame
Ethernet Packet
25
25
64
FDDI Packet
64

Advertisement

Table of Contents
loading

Table of Contents