IP Filtering
7-3
8000-A2-GB21-20
November 1997
NOTE:
If both the source and destination port numbers are 0s (zeros), the system
filters ICMP packets in addition to the packet types defined in the rule.
In this release, you can configure up to two filters on the MCC card and up to
eight filters on each DSL card. Also, up to 33 rules can be configured for each
filter. Keep in mind that for each filter, you will need to configure the default filter
action (either to forward or discard packets).
For detailed information on the IP Filter Configuration screen and the IP Network
screen, see Chapters 5 and 6 of the
HotWire DSLAM for 8540 and 8546 DSL
Cards User’s Guide.
Security Advantages
Filtering provides security advantages on LANs as described in the following
subsections.
NOTE:
All upstream traffic from an ES is forwarded by a HotWire 5246 or 5446 RTU
to the DSL card unless it is addressed to another ES (in the same subnet) on
the same LAN.
Management Traffic Leakage
Filtering can be used to prevent unwanted traffic from leaking into the
management domain. That is, filtering prevents NSP packets with management
IP destinations from being accepted for local delivery or routing.
For example, if the NSP network is 155.1.00.00 and the management network is
135.1.00.00, filters can be defined that would prevent any traffic entering from the
10BaseT port from being forwarded to the 135.1.00.00 network through the DSL
card.
NSP
97-15460-01
Router
10BaseT
MCC Card
DSL Card
135.1.00.00
155.1.00.00
X
NOTE:
Filters reduce packet throughput.