
Network Diagnostic Tools
90
Checking rule-set 1 [filters] - No matched rules in rule-set,
no-match-action is DROP, no further rule-sets considered
Final action is to DROP the session.
13.2. Access check
For each network service implemented by the FB6000 (see Chapter 12), this command shows whether a specific
IP address will be able to access or utilise the service, based on any access restrictions configured on the service.
For example, the following shows some service configurations (expressed in XML), and the access check result
when checking access for an external address,
1.2.3.4
:-
<http local-only="false"/>
Web control page access via http:-
This address is allowed access to web control pages subject to
username/password being allowed.
<telnet allow="admin-ips"
local-only="false"/>
Telnet access:-
This address is not allowed access due to the allow list on telnet
service.
(in this example,
admin-ips
is the name of an IP address group that does not include
1.2.3.4
)
<dns local-only="true"/>
DNS resolver access:-
This address is not on a local Ethernet subnet and so not allowed access.
13.3. Packet Dumping
The FireBrick includes the ability to capture packet dumps for diagnostic purposes. This might typically be used
where the behaviour of the FB6000 is not as expected, and can help identify whether other devices are correctly
implementing network protocols - if they are, then you should be able to determine whether the FB6000 is
responding appropriately. The packet dumping facility may also be of use to you to debug traffic (and thus
specific network protocols) between two hosts that the brick is routing traffic between.
This feature is provided via the FB6000's HTTP server and provides a download of a pcap format file (old
format) suitable for use with
tcpdump
or Wireshark.
A packet dump can be performed by either of these methods :-
• via the user interface, using a web-page form to setup the dump - once the capture data has been downloaded
it can be analysed using
tcpdump
or Wireshark
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......