
Session Handling
43
7.3.2. Processing flow
The following processing flow applies to rules and rule-sets :-
• Rule-sets are processed sequentially.
• Each rule-set can optionally specify entry-criteria - if present, these criteria must be matched against for the
rules within the rule-set to be considered.
• If the rule-set's entry-criteria are not met, processing immediately procedes with the next rule-set, if any.
• If the rule-set's entry-criteria are met, or no entry-criteria were specified, processing of the rules within that
rule-set begins :-
• Rules are processed sequentially.
• Each session-rule specifies criteria, and an action to be taken when traffic meets that criteria ; the action
values are their meanings are shown in Table 7.1. Once a rule matches, no more rules in that rule set are
considered.
• If all of the rules in a rule-set have been considered, and none of them matched against the traffic, then
the action specified by the
no-match-action
attribute (of the rule-set) is taken. The available actions
are the same as for a session-rule.
Table 7.1. Action attribute values
"action" attribute
Action taken
drop
immediately cease rule processing, 'quietly' drop the
packet and create a short-lived session to drop further
packets matching the rule criteria
reject
immediately cease rule processing, drop the packet,
send rejection notification back to the traffic source
and create a short-lived session to drop further packets
matching the rule criteria
accept
immediately cease rule processing, and establish a
normal session
continue
'jump' out of the rule-set ; processing resumes with the
next rule-set, if any
ignore
immediately cease rule processing, 'quietly' drop the
packet but do not create a short-lived session (in
contrast to the
drop
action)
The short-lived session that is created when either
drop
and
reject
are actioned will appear in the session
table when it is viewed in the web user interface (or via the CLI) - see Figure 7.1 for an example of ICMP
sessions resulting from some pings ; the session lifetime is around one second.
Figure 7.1. Example sessions created by drop and reject actions
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......