46
MDS Orbit MCR-4G Technical Manual
MDS 05-6628A01, Rev. B
6. Create the last rule for this “restrictive” filter to deny everything else. Note that rules are applied in
ascending order using rule IDs. Any rules added after this last rule will have no effect, as they
would match “any” traffic, and be dropped. In this example rule ID 10 is chosen. This facilitates
the insertion of new rules prior to this last one to support future new traffic types.
admin@(none) 19:33:20% set services firewall filter IN_UNTRUSTED rule 10 match protocol all
admin@(none) 19:33:20% set services firewall filter IN_UNTRUSTED rule 10 actions action drop
7. Apply this filter to incoming direction on cellular interface “eth1”.
admin@(none) 19:33:20% set interfaces interface eth1 filter input IN_UNTRUSTED
8. Create a “permissive” filter that permits all traffic. Later on, if needed, this filter can be enhanced
to deny certain traffic from getting out of the cellular interface.
admin@(none) 19:33:20% set services firewall filter OUT_UNTRUSTED rule 10 match protocol all
admin@(none) 19:33:20% set services firewall filter OUT_UNTRUSTED rule 10 actions action accept
9. Apply this filter to outgoing direction on cellular interface “eth1”.
admin@(none) 19:33:20% set interfaces interface eth1 filter output OUT_UNTRUSTED
10. Commit configuration and exit configuration mode.
admin@(none) 19:33:20% commit
admin@(none) 19:33:20% exit
admin@(none) 19:33:20>
Monitoring
At this time there are no commands to monitor traffic statistics for packets being dropped or permitted by
the firewall. This feature may be added to future revisions of firmware.
Network Address Translation (NAT)
Understanding
Network address translation allows one to map private IP addresses to public IP addresses and vice versa.
There are two basic kinds of network address translation:
• Source NAT
• Destination NAT
Содержание Orbit MCR-4G
Страница 144: ...136 MDS Orbit MCR 4G Technical Manual MDS 05 6628A01 Rev B NOTES...
Страница 145: ...MDS 05 6628A01 Rev B MDS Orbit MCR 4G Technical Manual 137 NOTES...
Страница 146: ...138 MDS Orbit MCR 4G Technical Manual MDS 05 6628A01 Rev B...
Страница 148: ...GE MDS LLC Rochester NY 14620 Telephone 1 585 242 9600 FAX 1 585 242 9620 www gemds com 175 Science Parkway...