Filter Examples
239
For example, to allow a packet to pass if it is advertised from the server
named sales_1 and its socket number is less than 32, enter the following:
#filter
IPX-SAP:
010 ACCEPT server sales_1;
020 ACCEPT socket < 32
When applied to an input filter, the following example will permit SAP
service type 04 and deny everything else from entering:
#filter
IPX-SAP:
010 ACCEPT service 04
ICMP Packet Filtering
ICMP packets contain messages exchanged by IP modules in both hosts
and gateways to report errors, problems, and operating information.
ICMP message types are listed in Table 61. Note that most are error
messages necessary for the correct operation of TCP/IP.
Table 61
ICMP Message Types
If you are concerned about security, filter out incoming type 5 messages.
Sending ICMP redirects is an easy way for a vandal to change your
routing tables. Although ping is a troubleshooting aid, it allows a
potential intruder to obtain a map of your network by systematically
pinging every possible address. If you are worried, filter out incoming
type 8 packets or outgoing echo replies (type 0).
Type
Description
0
Echo Reply (Ping)
3
Destination Unreachable
4
Source Quench
5
Redirect (change route)
8
Echo Request (Ping)
11
Time Exceeded for a Datagram
12
Parameter Problem on a Datagram
13
Timestamp Request
14
Timestamp Reply
15
Information Request
16
Information Reply
17
Address Mask Request
18
Address Mask Reply
Summary of Contents for REMOTE ACCESS SYSTEM 1500
Page 14: ......
Page 40: ......
Page 58: ......
Page 120: ......
Page 130: ......
Page 158: ......
Page 178: ......
Page 202: ......
Page 266: ......
Page 286: ......
Page 292: ......
Page 297: ...INDEX 295 V 90 151 W Windows 95 Dial Up Networking 89 World Wide Web WWW 285 X X 75 152 ...
Page 298: ...296 INDEX ...