Filter Examples
241
For example, to filter the host where login users initially connect to, enter
the following:
#filter
LOGIN-ACCESS:
010 ACCEPT dst-addr = 187.243.71.54/24
This filter allows users on network 187.243.71.0 to access the configured
host but rejects all others.
RAS 1500 Global
Filtering
The RAS 1500 can filter packets globally traveling in and out of dial-up
ports as well as the network port. The options below provide tighter
network security.
Global Switch to Drop IP Fragments with Offset = 1
This global switch lets you discard all IP packets with an offset value equal
to 1. This packet type typically occurs when a system is under attack from
a user trying to bypass installed filters on an interface by sneaking the
packet by the filter in fragmented form.
The RAS 1500 never generates a packet with an offset of 1. Some routers
used on the same network RAS 1500 may be configured to filter out
specific traffic. In some cases, these routers may not apply the filter
correctly. Should this happen, those packets will be discarded. In
accordance with RFC 1858, this security feature syslogs every instance of
a packet being discarded. The following commands are associated with
this feature:
enable ip security_option drop_all_fragoffset1
(default)
disable ip security_option drop_all_fragoffset1 ENTER
Global Switch to Drop Packets with a Partial TCP Header
This global option allows the global configuration to discard all IP packets
with a partial TCP header. This command is similar to and a subset of the
enable ip security drop_all_fragoffset1
command. The
default setting is
enabled
meaning these packets will be discarded.
When a packet is discarded the event is syslogged. The following
commands are associated with this feature:
enable ip security_option drop_tcp_fragoffset1
(Default)
disable ip security_option drop_tcp_fragoffset1 ENTER
Summary of Contents for REMOTE ACCESS SYSTEM 1500
Page 14: ......
Page 40: ......
Page 58: ......
Page 120: ......
Page 130: ......
Page 158: ......
Page 178: ......
Page 202: ......
Page 266: ......
Page 286: ......
Page 292: ......
Page 297: ...INDEX 295 V 90 151 W Windows 95 Dial Up Networking 89 World Wide Web WWW 285 X X 75 152 ...
Page 298: ...296 INDEX ...