232
C
HAPTER
14: H
ANDLING
P
ACKET
F
ILTERS
Deleting a Packet
Filter
To delete a specific packet filter, removing the filter file from the filter list
and permanently from FLASH memory, use the following commands:
delete filter <filter_name>
delete file <file_name>
Verifying Filter File
Syntax
The
verify filter
command is useful if you make changes to a filter
file that has already been added to the managed list and re-TFTP the file
back into FLASH memory (using the same filename). This command
checks the filter syntax, compiles it and if valid, generates no message
and returns the command prompt. If invalid, error messages are
generated detailing the error sources.
Filter file changes are designed to take effect on an interface immediately
after you issue the
set interface
command. So remember to remove
and
reapply
the filter to ensure new filter rules apply to all affected
interfaces.
To verify a filter file, use the following command:
verify filter <filter_name>
Showing Filter File
Contents
To view the contents of an entire filter file that has been added to the
managed list of filters, use the following command:
show filter <filter_name>
To display the contents of the filter file by protocol, use the following
command:
show filter <name> protocol [ ip | ip-call | ip-rip | ipx |
ipx-call | ipx-rip | ipx-sap | login-access]
Generating SYSLOG
Messages for Filtered
Packets
You can save filtered packets to a configured SYSLOG server, allowing
you to track down a potentially malicious user. Due to the large amount
of traffic this command could generate, its anticipated use would only be
for a short time.
Use the following command:
set packet_logging
logging [all | radius | none]
packet_size [0-493 bytes]
Summary of Contents for REMOTE ACCESS SYSTEM 1500
Page 14: ......
Page 40: ......
Page 58: ......
Page 120: ......
Page 130: ......
Page 158: ......
Page 178: ......
Page 202: ......
Page 266: ......
Page 286: ......
Page 292: ......
Page 297: ...INDEX 295 V 90 151 W Windows 95 Dial Up Networking 89 World Wide Web WWW 285 X X 75 152 ...
Page 298: ...296 INDEX ...