Example Filters
9-10
PortMaster Configuration Guide
Input Filter for an Internet Connection
The filter in this example is designed as an input filter for a network hardwired port that
connects to the Internet. You can use this filter for a dial-on-demand connection by
attaching it to the location entry.
The rules for the filter are set as follows:
Command>
set filter internet.in 1 deny 192.168.1.0/24 0.0.0.0/0 log
Command>
set filter internet.in 2 permit tcp estab
Command>
set filter internet.in 3 permit 0.0.0.0/0 10.0.0.3/32 tcp dst eq 25
Command>
set filter internet.in 4 permit 0.0.0.0/0 172.16.0.4/32 tcp dst eq 21
Command>
set filter internet.in 5 permit tcp 0.0.0.0/0 192.168.0.5/32 dst eq 80
Command>
set filter internet.in 6 permit tcp src eq 20 dst gt 1023
Command>
set filter internet.in 7 permit udp dst eq 53
Command>
set filter internet.in 8 permit tcp dst eq 53
Command>
set filter internet.in 9 permit icmp
Table 9-3 describes, line by line, each rule in the filter.
Table 9-3
Description of Internet Filter
Rule
Description
1.
Denies any incoming packets from the Internet claiming to be from—
or
spoofing
—your own network (192.168.1.0). This rule blocks IP
spoofing attacks. This rule also logs the header information in the
spoofing packets to syslog.
2.
Permits already established TCP connections that originated from your
network—packets with the ACK bit set.
3.
Permits SMTP connections to 10.0.0.3 (the mail server).
4.
Permits FTP connections to host 172.16.0.4.
5.
Permits Hypertext Transfer Protocol (HTTP) access to host 192.168.0.5.
6.
Permits an FTP data channel.
7.
Permits DNS.
8.
Permits DNS zone transfers. (You can write this rule to allow only
connections to your name servers.)
Summary of Contents for PortMaster
Page 16: ...Contents xvi Configuration Guide for PortMaster Products...
Page 26: ...Subscribing to PortMaster Mailing Lists xxvi PortMaster Configuration Guide...
Page 32: ...Basic Configuration Steps 1 6 PortMaster Configuration Guide...
Page 114: ...Configuring WAN Port Settings 6 12 PortMaster Configuration Guide...
Page 128: ...Configuring Login Users 7 14 PortMaster Configuration Guide...
Page 158: ...Restricting User Access 9 16 PortMaster Configuration Guide...
Page 168: ...Configuring Ports for Modem Use 10 10 PortMaster Configuration Guide...
Page 222: ...Frame Relay Subinterfaces 13 16 PortMaster Configuration Guide...
Page 236: ...Troubleshooting a Synchronous V 25bis Connection 14 14 PortMaster Configuration Guide...
Page 252: ...Using ISDN for On Demand Connections 15 16 PortMaster Configuration Guide...
Page 264: ...Using ISDN for Internet Connections 16 12 PortMaster Configuration Guide...
Page 276: ...Configuration Steps for Dial In Access 17 12 PortMaster Configuration Guide...
Page 286: ...Configuration Steps for Shared Device Access 18 10 PortMaster Configuration Guide...
Page 296: ...Troubleshooting a Leased Line Connection 19 10 PortMaster Configuration Guide...
Page 310: ...B 4 PortMaster Configuration Guide...
Page 352: ...Command Index Command Index 6 PortMaster Configuration Guide...