SmartNA-X 1G/10G Modular | Restricting Traffic with Filters |
53
SmartNA-X
™
1G/10G User Guide 1.4
©
2015 Network Critical Solutions Limited
Header type
Filtering options
• 100, 150—Multiple labels. Multiple labels may each
use a range or mask.
Table 3: Layer 3 headers
Header type
Filtering options
IPv4 addressing
Filters by IPv4 address. You may give either a single
specification, to find packets where either the source or the
destination address matches, or separate specifications for
source and/or destination address.
The following formats can be used to filter on a single IPv4
address, a range of addresses, or multiple addresses:
• 192.168.0.1—A single address
• 192.168.0.4-10—An inclusive range
• 192.168.0.*—Wildcard (192.168.0.0-255)
• 10.10.0.0/255.255.255.252—Mask (10.10.0.0-3)
• 10.10.0.3, 10.10.0.5—Multiple addresses Ranges and
wildcards may be used in any segment(s). Multiple
addresses may each use either ranges and wildcards or a
mask.
For ARP packets, use source for the sender address and
destination for the target address.
IPv4 fragment
Filters by IPv4 fragments. Enter
0
not a fragment, or
1
is a
fragment.
IP protocol
Filters by IP protocol number. Some commonly used IP
protocols numbers are:
• 1—ICMP
• 6—TCP
• 17—UDP
• 132—SCTP
The following formats can be used to specify a single
protocol, a range of protocols, or multiple protocols:
• 1—A single protocol
• 1-2—An inclusive range
• 0/1—A value/mask pair (here: all even protocols)
• 6, 17—Multiple protocols. Multiple protocols may each
use a range or mask.
IPv6 addressing
Filters by IPv6 address. You may give either a single
specification to find packets where either the source or the
destination address matches, or separate specifications for
source and/or destination address.
The following formats can be used to filter on a single IPv6
address, a range of addresses, or multiple addresses: