Example Filters
9-14
PortMaster Configuration Guide
If you use the following example, replace the name
server
with the IP address or
hostname of your Internet server:
Command>
set filter restrict.in 1 deny 192.168.1.0/24 0.0.0.0/0 log
Command>
set filter restrict.in 2 permit 0.0.0.0/0 10.0.0.3/32 tcp estab
Command>
set filter restrict.in 3 permit 0.0.0.0/0 10.0.0.3/32 tcp dst eq 21
Command>
set filter restrict.in 4 permit 0.0.0.0/0 10.0.0.3/32 tcp src eq 20
dst gt 1023
Command>
set filter restrict.in 5 permit 0.0.0.0/0 10.0.0.3/32 tcp dst eq 119
Command>
set filter restrict.in 6 permit 0.0.0.0/0 10.0.0.3/32 tcp dst eq 25
Command>
set filter restrict.in 7 permit 0.0.0.0/0 10.0.0.3/32 tcp dst eq 80
Command>
set filter restrict.in 8 permit 0.0.0.0/0 10.0.0.3/32 udp dst eq 53
Command>
set filter restrict.in 9 permit 0.0.0.0/0 10.0.0.3/32 tcp dst eq 53
Command>
set filter restrict.in 10 permit 0.0.0.0/0 10.0.0.3/32 icmp
Table 9-4
describes, line by line, each rule in the filter
.
To log all packets that are denied, add the following rule to the end of your filter:
Command>
set filter
filtername RuleNumber
deny log
Table 9-4
Description of Restrictive Internet Filter
Rule
Description
1.
Denies any incoming packets from your own network (192.168.1.0)
and makes a log.
2.
Permits packets from any established TCP connection to 10.0.0.3 (the
Internet server).
3.
Permits FTP from any IP address to 10.0.0.3
(the server).
4.
Permits the FTP data back channel.
5.
Permits incoming NNTP (news) to 10.0.0.3 (the Internet server).
6.
Permits incoming SMTP (mail) to 10.0.0.3 (the Internet server).
7.
Permits HTTP requests to 10.0.0.3 (the Internet server).
8.
Permits DNS queries to 10.0.0.3 (the Internet server).
9.
Permits DNS zone transfers from 10.0.0.3 (the Internet server).
10.
Permits ICMP to 10.0.0.3 (the Internet server). You can further limit
ICMP packet types to types 0, 3, 8, and 11 using four rules instead of
one.
Содержание PortMaster
Страница 16: ...Contents xvi Configuration Guide for PortMaster Products...
Страница 26: ...Subscribing to PortMaster Mailing Lists xxvi PortMaster Configuration Guide...
Страница 32: ...Basic Configuration Steps 1 6 PortMaster Configuration Guide...
Страница 114: ...Configuring WAN Port Settings 6 12 PortMaster Configuration Guide...
Страница 128: ...Configuring Login Users 7 14 PortMaster Configuration Guide...
Страница 158: ...Restricting User Access 9 16 PortMaster Configuration Guide...
Страница 168: ...Configuring Ports for Modem Use 10 10 PortMaster Configuration Guide...
Страница 222: ...Frame Relay Subinterfaces 13 16 PortMaster Configuration Guide...
Страница 236: ...Troubleshooting a Synchronous V 25bis Connection 14 14 PortMaster Configuration Guide...
Страница 252: ...Using ISDN for On Demand Connections 15 16 PortMaster Configuration Guide...
Страница 264: ...Using ISDN for Internet Connections 16 12 PortMaster Configuration Guide...
Страница 276: ...Configuration Steps for Dial In Access 17 12 PortMaster Configuration Guide...
Страница 286: ...Configuration Steps for Shared Device Access 18 10 PortMaster Configuration Guide...
Страница 296: ...Troubleshooting a Leased Line Connection 19 10 PortMaster Configuration Guide...
Страница 310: ...B 4 PortMaster Configuration Guide...
Страница 352: ...Command Index Command Index 6 PortMaster Configuration Guide...