General Filter Setup
233
A description of each parameter follows.
■
All
— Creates SYSLOG messages globally for all filtered packets.
■
Radius
— Checks the RADIUS profile (Filter-Log-Packet attribute in
the Access-Accept packet) on a per-user basis.
■
None
— No SYSLOG messages generated.
■
0–493 bytes
— Use a number between 0 and 493 to specify how
many bytes of the discarded packet to send to SYSLOG. Setting to 0
causes the entire packet to be included in the SYSLOG message.
General Filter Setup
This section describes the steps to configure a filter on the RAS 1500.
1
Create a filter using the filter rules described in the
Creating Filters
section. You may use an off-line editor and TFTP the file to the RAS 1500.
For the purposes of this example, the input filter is named ras1500.fil.
2
If you are configuring a user filter - not an interface filter - enable
filter_access
(
off
by default) with the following command. Filter
access should remain off for an interface filter.
set interface [rm0|pem1|pem2]/slot[1-2]/mod:[1-4]
3
Add the filter to the RAS 1500 Managed Filter Table with the following
command:
add filter ras1500.fil
4
The RAS 1500 automatically verifies that new filters are syntactically
correct. For added insurance, issue the following command:
verify filter ras1500.fil
5
Issue the following command to ensure the filter was stored in the RAS
1500 FLASH memory:
list files
6
Assign the filter to a previously created user with the following
command. If using RADIUS, specify the Framed-Filter-ID attribute.
set user <any_user_name> input_filter ras1500.fil ENTER
7
Verify that the filter was applied to the user with either of the following
commands:
show user <user_name>
show remote user <user_name>
Summary of Contents for 3C421600A
Page 14: ......
Page 40: ......
Page 58: ......
Page 120: ......
Page 130: ......
Page 158: ......
Page 178: ......
Page 202: ......
Page 266: ......
Page 286: ......
Page 292: ......
Page 297: ...INDEX 295 V 90 151 W Windows 95 Dial Up Networking 89 World Wide Web WWW 285 X X 75 152...
Page 298: ...296 INDEX...