Security 14-7
A filtering rule
The criteria are based on information contained in the packets. A filter is simply a rule that prescribes cer tain
actions based on cer tain conditions. For example, the following rule qualifies as a filter:
Block all Telnet attempts that originate from the remote host 199.211.211.17.
This rule applies to Telnet packets that come from a host with the IP address 199.211.211.17. If a match
occurs, the packet is blocked.
Here is what this rule looks like when implemented as a filter on the Netopia R7200:
To understand this par ticular filter, look at the par ts of a filter.
Parts of a filter
A filter consists of criteria based on packet attributes. A typical filter can match a packet on any one of the
following attributes:
■
The source IP address (where the packet was sent from)
■
The destination IP address (where the packet is going)
■
The type of higher-layer Internet protocol the packet is carr ying, such as TCP or UDP
Port numbers
A filter can also match a packet’s por t number attributes, but only if the filter’s protocol type is set to TCP or
UDP, since only those protocols use por t numbers. The filter can be configured to match the following:
■
The source por t number (the por t on the sending host that originated the packet)
■
The destination por t number (the por t on the receiving host that the packet is destined for)
By matching on a por t number, a filter can be applied to selected TCP or UDP ser vices, such as Telnet, FTP, and
World Wide Web. The following tables show a few common ser vices and their associated por t numbers:
Internet service
TCP port
Internet service
TCP port
FTP
20/21
Finger
79
Telnet
23
World Wide Web
80
SMTP (mail)
25
News
144
Gopher
70
rlogin
513
+-#--Source IP Addr--Dest IP Addr-----Proto-Src.Port-D.Port--On?-Fwd-+
+--------------------------------------------------------------------+
| 1 199.211.211.17 0.0.0.0 TCP 23 Yes No |
+--------------------------------------------------------------------+
Summary of Contents for R7200
Page 1: ...Netopia R7200 SDSL Router Nokia Speedlink certified User s Reference Guide ...
Page 12: ...User s Reference Guide ...
Page 18: ...2 4 User s Reference Guide ...
Page 42: ...5 14 User s Reference Guide ...
Page 56: ...User s Reference Guide ...
Page 72: ...8 16 User s Reference Guide ...
Page 82: ...9 10 User s Reference Guide ...
Page 112: ...10 30 User s Reference Guide ...
Page 118: ...11 6 User s Reference Guide ...
Page 150: ...13 20 User s Reference Guide ...
Page 200: ...User s Reference Guide ...
Page 206: ...A 6 User s Reference Guide ...
Page 220: ...B 14 User s Reference Guide ...
Page 234: ...E 4 User s Reference Guide ...
Page 250: ...8 User s Reference Guide ...
Page 256: ...Index 6 ...
Page 258: ...2 User s Reference Guide ...