PassFinder AP2520 VoIP Router/Gateway Operation Manual
Version 1.10 / Mar. 2002
AddPac Technology Co., Ltd.
-
106
-
4.7.
Filter (Access-List) Configuration
Packet filtering enables the manager to control packet movement on the
network. With the packet filtering function, the manager can prevent
unqualified user’s access to the inside network from outside and disclosure of
information.
The PassFinder AP2520 Gateway uses the access-list to control traffic from a
certain user (or an equipment or a network) to a certain network (or an
equipment.) In this way, the Gateway can permit or deny packets passing
through certain interfaces.
There are two kinds of access-list – the standard access-list and the extended
access-list. The standard access-list uses IP addresses of the source and the
destination in controlling traffic. And the extended access-list uses application
port numbers and protocol IDs as well as IP addresses of the source and the
destination in controlling traffic. The access-list is a continuous set of
permit/deny conditions that are applied to the IP address. Software of the
PassFinderAP2520 Gateway checks theses conditions with each address field of
the packet.
With the first condition that matches with the address field, the Gateway
decides to accept or reject the packet. After first matching, software stops
testing the address. Therefore, orders of conditions are very important to
normally operating the access-list. If there is no matching condition, software
rejects the corresponding packet. (Default)
The PassFinderAP2520 Gateway supports 30 standard access-lists (List # 0~29)
and 30 extended access-list(List # 30 ~ 59.)
Information