XYR301E Wireless Ethernet
User Manual
Page 66
April 2012
3.18
Filtering
When configured as a Bridge, the XYR301-E will transmit all broadcast messages appearing at its wired Ethernet port.
When the XYR301-E is configured as a Router, this does not occur.
In many cases, the intended recipient of the broadcast traffic does not lie at the opposite end of a proposed radio link.
Reducing unnecessary broadcast traffic sent over the radio link, will increase available bandwidth for data. The
XYR301-E has a filtering feature to help reduce unnecessary wireless transmissions and enhance security.
The XYR301-E may be configured to reject or accept messages to and from certain Addresses. To accept wireless
messages from particular devices a “Whitelist” of Addresses must be made. Alternatively to reject messages from
particular devices, a “Blacklist” of Addresses must be made. Filtering applies only to messages appearing at the wired
Ethernet port of the configured XYR301-E.
The Filter comprises of three lists: MAC Addresses, IP Address/Protocol/Port and ARP Filters. Each list may be set as
either a Blacklist (to block traffic for listed devices and protocols), or as a Whitelist (to allow traffic for listed devices
and protocols). The Filter operates on four rules listed below.
The MAC Address filter is always checked before the IP Address filter.
If a message matches a MAC filter entry, it will not be subsequently processed by the IP filter. If the MAC
filter list is a Whitelist, the message will be accepted. If the MAC filter list is a Blacklist, the message will be
dropped.
The MAC address list checks the Source address of the message only.
The IP Address filter checks both the source address and the destination address of the message. If either
address match, then the rule is activated.
ARP filtering applies only to ARP request packets (typically these are broadcast packets) which are sourced
from the Ethernet interface and destined for the wireless interface. (ARP requests from devices on the wireless
network will always be passed to the Ethernet interface. ARP response packets will always be passed).
When configuring a Whitelist it is important to add the Addresses of all devices connected to the XYR301-E wired
Ethernet port, that communicate over the wireless link. It is particularly important to add the Address of the
configuration PC to the Whitelist. Failure to add this address will prevent the configuration PC from making any
further changes to configuration. Design of the filter may be simplified by monitoring network traffic and forming a
profile of traffic on the wired network. Network Analysis software, such as the freely available “Wireshark” program,
will list broadcast traffic sent on the network.
Содержание XYR301E
Страница 2: ...Page ii April 2012 ...
Страница 18: ......