User's Manual
14. Security
Version 4.4.0
275
MP26x/MP27x
2.
In the section 'Matching', define a match between IP addresses and a traffic protocol:
a.
Configure the source address of the packets sent to or received from the network
object. To add an address, select the option 'User Defined' from the drop-down
list; the screen 'Edit Network Object' appears.
Figure
14-27: Add a Specific Host
Click the
New
icon; this commences a sequence that adds a new network
object.
b.
Configure the destination address of the packets sent to or received from the
network object. This address can be configured in the same manner as the
source address.
c.
From the 'Protocol' drop-down list, select a specific traffic protocol or add a new
one (by selecting 'User Defined'); the 'Edit Services' screen appears. Click the
link
New Server Ports
; this commences a sequence that adds a new protocol.
3.
Select the check box 'DSCP' to mark a DSCP value on packets matching this rule; the
screen refreshes, allowing you to enter the hexadecimal value of the DSCP.
4.
Select the check box 'Priority' to add a priority to the rule; the screen refreshes,
allowing you to select between one of eight priority levels, zero being the lowest and
seven the highest (each priority level is mapped to low/medium/high priority). This sets
the priority of a packet on the connection matching the rule, while routing the packet.
Figure
14-28: Set Priority Rule
5.
Select the check box 'Length' to specify the length of packets or the length of their
data portion.
6.
In the section 'Operation', define the action of the rule:
•
Drop:
Deny access to packets that match the source and destination IP
addresses and service ports defined in 'Matching'.
•
Reject:
Deny access to packets that match the source and destination IP
addresses and service ports defined in 'Matching' and sends and sends an ICMP
error or a TCP reset to the origination peer.
•
Accept Connection:
Allow access to packets that match the source and
destination IP addresses and service ports defined in 'Matching'. The data
transfer session is handled using Stateful Packet Inspection (SPI).
Summary of Contents for MP-26 series
Page 2: ......
Page 20: ...User s Manual 20 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 26: ...User s Manual 26 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 28: ...User s Manual 28 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 42: ...Reader s Notes...
Page 68: ...User s Manual 68 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 280: ...User s Manual 280 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 340: ...User s Manual 340 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 386: ...User s Manual 386 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 388: ...Reader s Notes...
Page 390: ...User s Manual 390 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 392: ...User s Manual 392 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 420: ...User s Manual 420 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 430: ...User s Manual 430 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 442: ...User s Manual 442 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 448: ...User s Manual 448 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 450: ...User s Manual 450 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...
Page 451: ...Part III Appendices...
Page 452: ...Reader s Notes...
Page 458: ...User s Manual 458 Document LTRT 23510 MP 26x MP 27x Multimedia Home Gateway Reader s Notes...