238
C
HAPTER
14: H
ANDLING
P
ACKET
F
ILTERS
IP and IPX-RIP Packet Filtering
RIP packets identify all attached networks and the number of router hops
required to reach them. These responses are used to update a router's
routing table. Define IP/IPX-RIP filtering rules in the IP-RIP and IPX-RIP
protocol sections of the filter.
For example, to filter all routes except the IP network address
195.120.254.145, enter the following:
#filter
IP-RIP:
010 ACCEPT network = 195.120.254.145;
020
DENY
;
This filter allows route 195.120.254.145 into the table, rejecting all
others.
For example, if you want to filter all but the following IPX networks, enter
the following:
#filter
IPX-RIP:
010 REJECT network != 00-00-99-ff;
020 REJECT network != 99-88-0-45;
030 REJECT network != 0-8-7-5;
To filter an IP route based on a subnet mask (all but 195.223.0.0
networks), enter the following:
#filter
IP-RIP:
010 REJECT network = 195.223.87.225/16;
Spurious RIP messages can disrupt your routing tables. If you are listening
for RIP messages on a given interface, you may wish to consider filtering
out RIP updates from untrusted networks.
IPX-SAP Filtering
IPX-SAP filtering rules are defined in the IPX-SAP protocol section of the
filter file. The IPX-SAP filtering process compares advertised server name,
service type, network number, node (host) address, and socket number
values to values defined in the IPX-SAP filter rules.
Summary of Contents for REMOTE ACCESS SYSTEM 1500
Page 14: ......
Page 40: ......
Page 58: ......
Page 120: ......
Page 130: ......
Page 158: ......
Page 178: ......
Page 202: ......
Page 266: ......
Page 286: ......
Page 292: ......
Page 297: ...INDEX 295 V 90 151 W Windows 95 Dial Up Networking 89 World Wide Web WWW 285 X X 75 152 ...
Page 298: ...296 INDEX ...