240
C
HAPTER
14: H
ANDLING
P
ACKET
F
ILTERS
For example, to prevent vandals from changing your routing tables by
sending ICMP redirects, enter the following:
#filter
IP:
010 REJECT icmp-type = 5
IP/IPX-Call Filtering
You define IP/IPX-call filtering rules in the IP-CALL, IPX-CALL protocol
sections of the filter file. Like the rules defined in the IP protocol section,
the IP-CALL filtering rules compare the advertised source or destination
network address, host address and port number, and values defined in
the IP-CALL filter rules. IPX-CALL filtering rules compare
source/destination network addresses, hosts, and socket numbers.
Call filtering occurs after output filters are processed and are used for
ondemand calls only.
For example, to allow outgoing calls from the user of IP address
192.112.42.6, enter the following:
#filter
IP-CALL:
010 ACCEPT src-addr = 192.112.42.6;
020 DENY;
For example, to allow outgoing calls to IPX host 77-88-99-aa-bb-cc, and
reject calls from the source socket number 0x3f00, enter the following:
#filter
IPX-CALL:
010 ACCEPT dst-host = 77-88-99-aa-bb-cc;
020 REJECT src-socket = 0x3f00;
Login-Access Filtering
Login-Access filters are used to restrict login user accessibility to hosts
connected to the RAS 1500. Filtering rules are set in the LOGIN-ACCESS
protocol section of the filter file, using a subnet mask to restrict access
from approved networks.
Summary of Contents for 3C421600A
Page 14: ......
Page 40: ......
Page 58: ......
Page 120: ......
Page 130: ......
Page 158: ......
Page 178: ......
Page 202: ......
Page 266: ......
Page 286: ......
Page 292: ......
Page 297: ...INDEX 295 V 90 151 W Windows 95 Dial Up Networking 89 World Wide Web WWW 285 X X 75 152...
Page 298: ...296 INDEX...