Prestige 791R G.SHDSL Router
12.4 Filter Types and NAT
There are two classes of filter rules,
Generic Filter
Device rules and Protocol Filter (
TCP/IP
) rules.
Generic Filter rules act on the raw data from/to LAN and WAN. Protocol Filter
rules act on IP packets.
When NAT (Network Address Translation) is enabled, the inside IP address and port number are replaced
on a connection-by-connection basis, which makes it impossible to know the exact address and port on the
wire. Therefore, the Prestige applies the protocol filters to the “native” IP address and port number before
NAT for outgoing packets and after NAT for incoming packets. On the other hand, the generic (or device)
filters are applied to the raw packets that appear on the wire. They are applied at the point where the
Prestige is receiving and sending the packets; for instance, the interface. The interface can be an Ethernet,
or any other hardware port. The following figure illustrates this.
Figure 12-14 Protocol and Device Filter Sets
12.5 Example Filter
Let’s look at an example to block outside users from Telnetting into the Prestige.
12-16
Filter Configuration
Summary of Contents for Prestige 791R
Page 1: ...Prestige 791R G SHDSL Router User s Guide Version 3 40 June 2004...
Page 22: ......
Page 24: ......
Page 45: ......
Page 73: ......
Page 83: ......
Page 97: ......
Page 101: ......
Page 133: ......
Page 155: ......
Page 169: ......
Page 191: ......
Page 201: ......
Page 209: ......
Page 211: ......
Page 221: ......
Page 225: ......