Creating Filters
9-6
PortMaster Configuration Guide
Creating IP Filters
You can create a rule that filters IP packets according to their source and destination IP
addresses. For more information on the command syntax for creating filters, see the
PortMaster Command Line Reference.
To create an IP filter rule that filters by address, use the following command—entered
on one line:
Command>
set filter
Filtername
RuleNumber
permit
|
deny
[
Ipaddress
/
NM
Ipaddress
(
dest
)/
NM
] [
protocol
Number
]
[
log
] [notify]
You can replace
protocol
Number
with one of the following keywords:
•
esp
—matches packets using Encapsulation Security Payload (ESP) protocol. See
RFC 1827 for more information on this protocol.
•
ah
—matches packets using Authentication Header (AH) protocol. See RFC 1826 for
more information on this protocol.
•
ipip
—matches packets using the IP Encapsulation within IP (IPIP). See RFC 2003
for more information on this protocol.
If you are using ChoiceNet, you can also replace either the source or destination IP
address with the value
=ListName
which specifies a list of sites in the
/etc/choicenet/lists
directory in the ChoiceNet server. The equal sign (=) must
immediately precede the value.
Filtering ICMP Packets
Internet Control Message Protocol (ICMP) packets—commonly known as ping
packets—report errors and provide other information about IP packet processing. You
can filter ICMP packets by source and destination IP address, or by ICMP packet type.
Packet types are identified in RFC 1700.
To create an ICMP filter rule, use the following command—entered on one line:
Command>
set filter
Filtername RuleNumber
permit
|
deny
[
Ipaddress
/
NM
Ipaddress
(
dest
)/
NM
]
icmp
[
type
Itype
] [
log
]
Summary of Contents for PortMaster
Page 16: ...Contents xvi Configuration Guide for PortMaster Products...
Page 26: ...Subscribing to PortMaster Mailing Lists xxvi PortMaster Configuration Guide...
Page 32: ...Basic Configuration Steps 1 6 PortMaster Configuration Guide...
Page 114: ...Configuring WAN Port Settings 6 12 PortMaster Configuration Guide...
Page 128: ...Configuring Login Users 7 14 PortMaster Configuration Guide...
Page 158: ...Restricting User Access 9 16 PortMaster Configuration Guide...
Page 168: ...Configuring Ports for Modem Use 10 10 PortMaster Configuration Guide...
Page 222: ...Frame Relay Subinterfaces 13 16 PortMaster Configuration Guide...
Page 236: ...Troubleshooting a Synchronous V 25bis Connection 14 14 PortMaster Configuration Guide...
Page 252: ...Using ISDN for On Demand Connections 15 16 PortMaster Configuration Guide...
Page 264: ...Using ISDN for Internet Connections 16 12 PortMaster Configuration Guide...
Page 276: ...Configuration Steps for Dial In Access 17 12 PortMaster Configuration Guide...
Page 286: ...Configuration Steps for Shared Device Access 18 10 PortMaster Configuration Guide...
Page 296: ...Troubleshooting a Leased Line Connection 19 10 PortMaster Configuration Guide...
Page 310: ...B 4 PortMaster Configuration Guide...
Page 352: ...Command Index Command Index 6 PortMaster Configuration Guide...