![background image](http://html1.mh-extra.com/html/zyxel-communications/p-660r-t1/p-660r-t1_support-notes_944594052.webp)
P-660 Series Support Notes
Filter Types and SUA
Conceptually, there are two categories of filter rules:
device
and
protocol
. The
Generic filter rules belong to the device category; they act on the raw data from/to
LAN and WAN. The IP and IPX filter rules belong to the protocol category; they act
on the IP and IPX packets.
In order to allow users to specify the local network IP address and port number in the
filter rules with SUA connections, the TCP/IP filter function has to be executed before
SUA for WAN outgoing packets and after the SUA for WAN incoming IP packets.
But at the same time, the Generic filter rules must be applied at the point when the
P-660 is receiving and sending the packets; i.e. the ISDN interface. So, the execution
sequence has to be changed. The logic flow of the filter is shown in Figure 1 and the
sequence of the logic flow for the packet from LAN to WAN is:
•
LAN device and protocol input filter sets.
•
WAN protocol call and output filter sets.
•
If SUA is enabled, SUA converts the source IP address from 192.168.1.33 to
203.205.115.6 and port number from 1023 to 4034.
51
All contents copyright © 2005 ZyXEL Communications Corporation.