Ubigate iBG3026 Configuration Guide
© SAMSUNG Electronics Co., Ltd.
229
CHAPTER 22.
Packet Filtering
Ubigate iBG3026s can be configured for MAC and IP traffic filtering
capabilities. IP traffic filtering allows creation of rule sets that selectively
block TCP/IP packets on a specified interface. Filters are applied
independently to all interfaces: Ethernet, serial, or WAN, as well as
independently to interface direction: IN(packets coming in to the Ubigate
iBG3026) or OUT(packets going out of the Ubigate iBG3026).
IP packet filtering capability can be used to restrict access to the Ubigate
iBG3026 from untrusted, external networks or from specific, internal
networks. An example would be a filter that prohibits external users from
establishing Telnet sessions to the Ubigate iBG3026, and allows only specific
internal users Telnet access to the system.
At the end of every rule list is an implied ‘deny all traffic’ statement.
Therefore, all packets not explicitly permitted by filtering rules, are denied.
This effectively means that once you enter a ‘deny’ statement in your filter
list, you are implicitly denying all packets from crossing the interface.
Therefore, it is important that each filter list contain at least one ‘permit’
statement.
The order in which you enter the filtering rules is important. As the Ubigate
iBG3026 is evaluating each packet, the SNOS tests the packet against each
rule statement sequentially. After a match is found, no more rule statements
are checked. For example, if you create a rule statement that explicitly
permits all traffic, all traffic is passed since no further rules are checked.
The SNOS permits easy re-ordering of filter commands through
access-list
insert
and
delete
commands.
Summary of Contents for Ubigate iBG3026
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 72: ......
Page 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 110: ......
Page 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 262: ......
Page 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 346: ......
Page 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 718: ...EQBD 000026 Ed 00 ...