Prestige 660R ADSL 2+ Access Gateway
22-14
Filter Configuration
22.5 Filter Types and NAT
There are two classes of filter rules,
Generic Filter
Device rules and Protocol Filter (
TCP/IP
) rules. Generic
Filter rules act on the raw data from/to LAN and WAN. Protocol Filter
rules act on IP packets.
When NAT (Network Address Translation) is enabled, the inside IP address and port number are replaced
on a connection-by-connection basis, which makes it impossible to know the exact address and port on the
wire. Therefore, the Prestige applies the protocol filters to the “native” IP address and port number before
NAT for outgoing packets and after NAT for incoming packets. On the other hand, the generic (or device)
filters are applied to the raw packets that appear on the wire. They are applied at the point where the Prestige
is receiving and sending the packets; for instance, the interface. The interface can be an Ethernet, or any other
hardware port. The following figure illustrates this.
Figure 22-10 Protocol and Device Filter Sets
22.6 Example Filter
Let’s look at an example to block outside users from telnetting into the Prestige.
Summary of Contents for ZyXEL Prestige 660R
Page 1: ...Prestige 660R ADSL 2 Access Gateway User s Guide Version 3 40 April 2004...
Page 24: ......
Page 50: ......
Page 52: ......
Page 60: ......
Page 72: ......
Page 74: ......
Page 92: ......
Page 94: ......
Page 98: ......
Page 107: ...Maintenance V Part V Maintenance This part covers the maintenance screens...
Page 108: ......
Page 120: ......
Page 122: ......
Page 128: ......
Page 132: ......
Page 136: ......
Page 188: ......
Page 208: ......
Page 222: ......
Page 238: ......
Page 242: ......
Page 252: ......
Page 258: ......
Page 274: ......
Page 286: ......