U
SING
8 –
This chapter describes how to use packet filters to restrict the traffic that reaches the output ports in your TAP
configuration. It covers the following major topics:
• About packet filters, page 54
• Creating packet filters, page 55
• Adding filters to maps, page 56
About packet filters
Packet filters let you selectively duplicate only the traffic of interest to your output ports, thereby enhancing the
utility of existing tools or enabling the creation of entirely new applications. When applied, filters will inspect
every packet at full duplex 10 Gigabits per second, allowing you to selectively duplicate only the traffic of interest
to either 10G or 1G ports.
Filters can be used to gain access to a particular subset of data and thereby reduce the amount of data reaching the
output port and your analysis tool. For example, a 1G tool running packet analysis software can be connected to a
10G link and a filter applied to duplicate only relevant packets for debug—say ICMP packets with a particular
payload. Instead of receiving the entire 10G link, the tool now only receives the ICMP packets.
How packet filters work
Filters work by comparing Ethernet packet headers against a set of user-defined filtering conditions based on the
Ethernet frame's Layer 2 (MAC, VLAN), Layer 3 (IPv4, IPv6, ARP, MPLS), and Layer 4 (TCP, UDP, ICMP)
header information. Depending on how the filter has been applied to the stream, the filter will either:
silently drop matching packets and let all non-matching packets through, or
pass matching packets and silently drop all non-matching packets.
Setting up a filter is a two-stage process:
Create the filter, specifying all the header conditions you want the filter to match against (see the
1.
packet filters" section on page 55
Apply the filter to a port map by setting it to pass or block matching packets (see the
2.
section on page 56
P
F
ACKET
ILTERS
for instructions on setting up filters)
for instructions on apply filters).
DRAFT
8
C
HAPTER
"Creating
"Adding filters to maps"
54
Need help?
Do you have a question about the SmartNA-X and is the answer not in the manual?