Configuring Filters
9-3
Overview of PortMaster Filtering
Filter Organization
Filters are stored in a filter table in the PortMaster nonvolatile configuration memory.
Filters can be created or modified at any time, and the changes are not applied to an
active use of the filter. Filter names must be between 1 and 15 characters.
Each packet filter can contain three sets of rules: IP, IPX, and SAP. Within each set, the
rules are numbered starting at one. Newly created packet filters contain zero rules, or an
empty set of rules.
An empty set of rules is equivalent to the permit rule. If a filter contains one or more
rules in the set, any packet not explicitly permitted by a rule is denied at the end of the
rule set.
Restricting access based
on source and
destination address
You can create filters that evaluate both the source and
destination addresses of a packet against a rule list. The
number of significant bits used in IP address comparisons
can be set, allowing filtering by host, subnet, network
number, or group of hosts whose addresses are within a
given bit-aligned boundary.
Restricting access to
particular protocols
Packets of certain protocols can be permitted or denied
by a filter, including IPX, SAP, TCP, UDP, and ICMP
packets.
Restricting access to
network services
You can create filters that use the source and destination
port numbers to control access to certain network
services. The evaluation can be based upon whether the
port number is less than, equal to, or greater than a
specified value.
Restricting access based
on TCP status
You can create filters that use the status of TCP
connections as part of the rule set. This feature can allow
network users to open connections to external networks
without allowing external users access to the local
network.
Table 9-1
Filter Options
(Continued)
Option
Description
Содержание PortMaster
Страница 16: ...Contents xvi Configuration Guide for PortMaster Products...
Страница 26: ...Subscribing to PortMaster Mailing Lists xxvi PortMaster Configuration Guide...
Страница 32: ...Basic Configuration Steps 1 6 PortMaster Configuration Guide...
Страница 114: ...Configuring WAN Port Settings 6 12 PortMaster Configuration Guide...
Страница 128: ...Configuring Login Users 7 14 PortMaster Configuration Guide...
Страница 158: ...Restricting User Access 9 16 PortMaster Configuration Guide...
Страница 168: ...Configuring Ports for Modem Use 10 10 PortMaster Configuration Guide...
Страница 222: ...Frame Relay Subinterfaces 13 16 PortMaster Configuration Guide...
Страница 236: ...Troubleshooting a Synchronous V 25bis Connection 14 14 PortMaster Configuration Guide...
Страница 252: ...Using ISDN for On Demand Connections 15 16 PortMaster Configuration Guide...
Страница 264: ...Using ISDN for Internet Connections 16 12 PortMaster Configuration Guide...
Страница 276: ...Configuration Steps for Dial In Access 17 12 PortMaster Configuration Guide...
Страница 286: ...Configuration Steps for Shared Device Access 18 10 PortMaster Configuration Guide...
Страница 296: ...Troubleshooting a Leased Line Connection 19 10 PortMaster Configuration Guide...
Страница 310: ...B 4 PortMaster Configuration Guide...
Страница 352: ...Command Index Command Index 6 PortMaster Configuration Guide...