13-10 User’s Reference Guide
Src. Port:
The source por t to match. This is the por t on the sending host that originated the packet.
D. Port:
The destination por t to match. This is the por t on the receiving host for which the packet is intended.
On?:
Displays
Yes
when the filter is in effect or
No
when it is not.
Fwd:
Shows whether the filter for wards (
Yes
) a packet or discards (
No
) it when there’s a match.
Filtering example #1
Returning to our filtering rule example from above (see
page 13-7
), look at how a rule is translated into a filter.
Star t with the rule, then fill in the filter’s attributes:
1.
The rule you want to implement as a filter is:
Block all Telnet attempts that originate from the remote host 199.211.211.17.
2.
The host 199.211.211.17 is the source of the Telnet packets you want to block, while the destination
address is any IP address. How these IP addresses are masked determines what the final match will be,
although the mask is not displayed in the table that displays the filter sets (you set it when you create the
filter). In fact, since the mask for the destination IP address is 0.0.0.0, the address for Dest IP Addr could
have been anything. The mask for Source IP Addr must be 255.255.255.255 since an exact match is
desired.
■
Source IP Addr = 199.211.211.17
■
Source IP address mask = 255.255.255.255
■
Dest IP Addr = 0.0.0.0
■
Destination IP address mask = 0.0.0.0
Note:
To learn about IP addresses and masks, see
Appendix B, “Understanding IP Addressing.”
3.
Using the tables on
page 13-8
, find the destination por t and protocol numbers (the
local
Telnet por t):
■
Proto = TCP (or 6)
■
D. Por t = 23
4.
The filter should be enabled and instructed to block the Telnet packets containing the source address
shown in step 2:
■
On? = Yes
■
Fwd = No
This four-step process is how we produced the following filter from the original rule:
+-#---Source IP Addr---Dest IP Addr-----Proto-Src.Port-D.Port--On?-Fwd-+
+----------------------------------------------------------------------+
| 1 192.211.211.17 0.0.0.0 TCP 0 23 Yes No |
| |
+----------------------------------------------------------------------+
Summary of Contents for R9100
Page 1: ...Netopia R9100 Ethernet Router for DSL and Cable Modems User s Reference Guide ...
Page 12: ...User s Reference Guide ...
Page 18: ...2 4 User s Reference Guide ...
Page 32: ...4 10 User s Reference Guide ...
Page 46: ...5 14 User s Reference Guide ...
Page 60: ...User s Reference Guide ...
Page 76: ...8 16 User s Reference Guide ...
Page 106: ...10 6 User s Reference Guide ...
Page 138: ...12 20 User s Reference Guide ...
Page 188: ...User s Reference Guide ...
Page 194: ...A 6 User s Reference Guide ...
Page 208: ...B 14 User s Reference Guide ...
Page 222: ...E 4 User s Reference Guide ...
Page 228: ...F 6 User s Reference Guide ...
Page 236: ...8 User s Reference Guide ...
Page 242: ...Index 6 ...
Page 244: ...2 User s Reference Guide ...