27-8
C
HAPTER
27: P
ACKET
F
ILTERS
or rejects the packet. Interface filters can be applied dynamically without having to
disable and re-enable each network on that interface.
Input Filter
If an input filter is configured on an interface, all received packets are checked
against the filtering rules before being forwarded to another interface.
Output Filters
If an output filter is configured on an interface, all outbound packets are checked
against the filtering rules before exiting the interface.
Input Filters vs. Output Filters
When possible, use the
input
filter to filter an
incoming packet
rather than waiting
to catch a packet as it attempts to exit. This is recommended because:
A packet is prevented from entering, keeping potential intruders from
attacking the OfficeConnect Gateway.
The routing engine does not waste time processing a packet that is going to be
discarded anyway.
Most importantly, the OfficeConnect Gateway does not know which interface
an outgoing packet came in through. If a potential intruder forges a packet
with a false source address (in order to appear as a trusted host or network)
there is no way for an output filter to tell if that packet came in through the
wrong interface. An input filter, on the other hand, can filter out packets
purporting to be from networks that are actually connected to a different
interface.
User Filters
You can configure user filters for a specific user that control access to the network
for that user. This filter is only applied for the duration of the user’s network
connection. As with interface filters, a user filter can be configured as an input or
output.
Assigning Filters
You can assign filters to interfaces and / or users using CLI commands. The
following section describes:
Assigning a filter to an interface
Assigning a filter to a user profile
Setting filter access
Assigning a Filter on an Interface
set interface
<interface_name>input_
filter <filter_name>
output_filter
<filter_name>
Filter_access on
Use this command string to configure an input or output filter on an interface.
For example:
set interface slot:4/port:8 input_filter filter.flt filter_access on
Filter files take effect on an interface immediately on enabled networks when you
issue the
set interface
command.
Summary of Contents for OfficeConnect 3C100XF
Page 1: ...http www 3com com OfficeConnect Gateway CLI User s Guide Release 1 0 Part No 10042302 Rev AA ...
Page 14: ...xiv ...
Page 18: ...iv ABOUT THIS GUIDE ...
Page 30: ...1 12 CHAPTER 1 USING THE COMMAND LINE INTERFACE CLI ...
Page 50: ...3 14 CHAPTER 3 ADMINISTRATIVE CLI COMMANDS ...
Page 58: ...4 8 CHAPTER 4 CONFIGURING AND MANAGING USERS ...
Page 70: ...6 8 CHAPTER 6 BRIDGING COMMANDS ...
Page 78: ...8 4 CHAPTER 8 INTERFACE COMMANDS ...
Page 82: ...9 4 CHAPTER 9 ARP COMMANDS ...
Page 88: ...11 4 CHAPTER 11 DHCP COMMANDS ...
Page 124: ...12 36 CHAPTER 12 IP ROUTING COMMANDS ...
Page 134: ...13 10 CHAPTER 13 DNS COMMANDS ...
Page 142: ...15 6 CHAPTER 15 MULTICASTING AND IGMP COMMANDS ...
Page 160: ...17 8 CHAPTER 17 PPP COMMANDS ...
Page 182: ...21 6 CHAPTER 21 ADDRESS TRANSLATION COMMANDS ...
Page 186: ...22 4 CHAPTER 22 IPSEC COMMANDS ...
Page 188: ...23 2 CHAPTER 23 SECURITY ASSOCIATION SA COMMANDS ...
Page 192: ...24 4 CHAPTER 24 TCP COMMANDS ...
Page 204: ...25 12 CHAPTER 25 SNMP COMMANDS ...
Page 210: ...26 6 CHAPTER 26 IP FILTERS COMMANDS ...
Page 238: ...29 6 CHAPTER 29 TRACEROUTE COMMANDS ...
Page 255: ...xv RFC 1483 16 3 RFC 1483 MER 16 4 ...
Page 256: ...xvi ...
Page 260: ......