130
Network
REJECT (filter table only)
This is used to send back an error packet in response to the matched packet: otherwise it
is equivalent to DROP. This target is only valid in the INPUT, FORWARD and OUTPUT
chains, and user-defined chains which are only called from those chains. Several options
control the nature of the error packet returned:
SNAT (NAT table only)
This target is only valid in the nat table, in the POSTROUTING chain. It specifies that
the source address of the packet should be modified (and all future packets in this
connection will also be mangled), and rules should cease being examined. It takes one
option:
LOG extension
Description
- - reject-with type
The type given can be icmp-net-unreachable, icmp-host-
unreachable, icmp-port-unreachable, icmp-proto-unreachable,
icmp-net-prohibited or icmp-host-prohibited, which return the
appropriate ICMP error message (port-unreachable is the default).
The option echo-reply is also allowed; it can only be used for rules
which specify an ICMP ping packet, and generates a ping reply.
Finally, the option tcp-reset can be used on rules which only match
the TCP protocol: this causes a TCP RST packet to be sent back.
This is mainly useful for blocking ident probes which frequently
occur when sending mail to broken mail hosts (which won't accept
your mail otherwise).
Table 4.10: LOG extension
SNAT target
Description
- - to-source <ipaddr>[-<ipaddr>][:port-port]
This can specify a single new source IP
address, an inclusive range of IP addresses,
and optionally, a port range (which is only
valid if the rule also specifies -p tcp or -p
udp). If no port range is specified, then source
ports below 1024 will be mapped to other
ports below 1024: those between 1024 and
1023 inclusive will be mapped to ports below
1024, and other ports will be mapped to 1024
or above. Where possible, no port alteration
will occur.
Table 4.11: SNAT target
Содержание AlterPath ACS
Страница 16: ...xvi Table of Contents...
Страница 29: ...13 This page has been left intentionally blank...
Страница 30: ...14 Preface...
Страница 68: ...52 Device Access...
Страница 86: ...70 Authentication Step 5 Saving changes To save the configuration run the command saveconf...
Страница 96: ...80 Authentication Save the configuration to flash 2 cli config savetoflash...
Страница 114: ...98 Authentication...
Страница 204: ...188 Administration To exit the CLI mode and return to ACS s shell issue the command cli quit...
Страница 268: ...252 Power Management with AlterPath PM Integration...
Страница 304: ...288 PCMCIA Cards Integration...
Страница 338: ...322 Profile Configuration...
Страница 364: ...348 Additional Features and Applications...
Страница 376: ...360 Appendix A New User Background Information...
Страница 406: ...390 Appendix C Cabling and Hardware Information This page has been left intentionally blank...
Страница 418: ...402 List of Tables...
Страница 420: ...404 List of Figures...