![GE MDS ORBIT ECR Скачать руководство пользователя страница 215](http://html.mh-extra.com/html/ge/mds-orbit-ecr/mds-orbit-ecr_technical-manual_129632215.webp)
MDS 05-6632A01, Rev. F
MDS Orbit MCR/ECR Technical Manual
215
Figure 3-120. Packets Terminated at the Unit
Figure 3-121 shows flow of packets originating from the unit, such as DNS queries and/or VPN
connection setup traffic originating from local VPN service within the unit.
Figure 3-121. Packets Originating from the Unit
Figure 3-122 shows the flow of packets being forwarded (routed) through the unit, such as IP packets
arriving inside IPsec VPN tunnel, being routed from cellular WAN to the local Ethernet interface.
Figure 3-122. Packets Being Forwarded Through the Unit
NOTE
If the firewall service is enabled and no filter is applied to an interface, then both incoming and
outgoing traffic is dropped on that interface.
Configuring
Packet filter configuration on the unit involves following these high level steps:
Create a filter and choose its default policy. For example, there are usually two ways to organize a
1.
filter:
Create a "restrictive" filter. The first rules are added to permit the desired types of traffic, and
a final rule, or default policy, is created that denies all other traffic. The example filter rules
below permit SSH traffic on TCP port 22, and ICMP messages such as pings and routing error
notifications. All other traffic is denied.
-
Rule 1 = permit protocol=tcp, dst port=22
-
Rule 2 = permit protocol=icmp
-
Rule 3 = deny everything
Or create a "permissive" filter. The first rules are added to deny the undesired types of traffic,
and a final rule, or default policy, is created that permits all other traffic. The example filter
rules below deny HTTP traffic on TCP port 80, and ICMP message such as pings and routing
error notifications. All other traffic is permitted.
-
Rule 1 = deny protocol=tcp, dst port=80
-
Rule 2 = deny protocol=icmp
-
Rule 3 = permit everything
Apply the filter to input or output direction of the interface. This selection depends on whether the
2.
rules should apply to traffic that ingresses or egresses the device.
Ingress
Interface
Local
Processes
Packet
Filtering
Egress
Interface
Local
Processes
Packet
Filtering
Packet
Egress
Interface
Packet
Filtering
Packet
Ingress
Interface
Содержание MDS ORBIT ECR
Страница 15: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 15 ...
Страница 35: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 35 ...
Страница 145: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 145 ...
Страница 188: ...188 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 302: ...302 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F Figure 3 224 SNMP Main Page ...
Страница 380: ...380 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 389: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 389 ...
Страница 393: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 393 ...
Страница 407: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 407 ...
Страница 449: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 449 ...
Страница 451: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 451 ...
Страница 452: ...452 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 453: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 453 ...
Страница 459: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 459 NOTES ...
Страница 460: ...460 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Страница 461: ......
Страница 463: ...GE MDS LLC Rochester NY 14620 Telephone 1 585 242 9600 FAX 1 585 242 9620 www gemds com 175 Science Parkway ...