130
Network
REJECT (filter table only)
This is used to send back an error packet in response to the matched packet: otherwise it
is equivalent to DROP. This target is only valid in the INPUT, FORWARD and OUTPUT
chains, and user-defined chains which are only called from those chains. Several options
control the nature of the error packet returned:
SNAT (NAT table only)
This target is only valid in the nat table, in the POSTROUTING chain. It specifies that
the source address of the packet should be modified (and all future packets in this
connection will also be mangled), and rules should cease being examined. It takes one
option:
LOG extension
Description
- - reject-with type
The type given can be icmp-net-unreachable, icmp-host-
unreachable, icmp-port-unreachable, icmp-proto-unreachable,
icmp-net-prohibited or icmp-host-prohibited, which return the
appropriate ICMP error message (port-unreachable is the default).
The option echo-reply is also allowed; it can only be used for rules
which specify an ICMP ping packet, and generates a ping reply.
Finally, the option tcp-reset can be used on rules which only match
the TCP protocol: this causes a TCP RST packet to be sent back.
This is mainly useful for blocking ident probes which frequently
occur when sending mail to broken mail hosts (which won't accept
your mail otherwise).
Table 4.10: LOG extension
SNAT target
Description
- - to-source <ipaddr>[-<ipaddr>][:port-port]
This can specify a single new source IP
address, an inclusive range of IP addresses,
and optionally, a port range (which is only
valid if the rule also specifies -p tcp or -p
udp). If no port range is specified, then source
ports below 1024 will be mapped to other
ports below 1024: those between 1024 and
1023 inclusive will be mapped to ports below
1024, and other ports will be mapped to 1024
or above. Where possible, no port alteration
will occur.
Table 4.11: SNAT target
Summary of Contents for AlterPath ACS
Page 16: ...xvi Table of Contents...
Page 29: ...13 This page has been left intentionally blank...
Page 30: ...14 Preface...
Page 68: ...52 Device Access...
Page 86: ...70 Authentication Step 5 Saving changes To save the configuration run the command saveconf...
Page 96: ...80 Authentication Save the configuration to flash 2 cli config savetoflash...
Page 114: ...98 Authentication...
Page 204: ...188 Administration To exit the CLI mode and return to ACS s shell issue the command cli quit...
Page 268: ...252 Power Management with AlterPath PM Integration...
Page 304: ...288 PCMCIA Cards Integration...
Page 338: ...322 Profile Configuration...
Page 364: ...348 Additional Features and Applications...
Page 376: ...360 Appendix A New User Background Information...
Page 406: ...390 Appendix C Cabling and Hardware Information This page has been left intentionally blank...
Page 418: ...402 List of Tables...
Page 420: ...404 List of Figures...