Ubigate iBG2016 Configuration Guide
© SAMSUNG Electronics Co., Ltd.
229
CHAPTER 2.
Packet Filtering
Ubigate iBG2016s can be configured for MAC and IP traffic filtering
capabilities. IP traffic filtering allows creation of rule sets that selectively
block TCP/IP packets on a specified interface. Filters are applied
independently to all interfaces: Ethernet, serial, or WAN, as well as
independently to interface direction: IN(packets coming in to the Ubigate
iBG2016) or OUT(packets going out of the Ubigate iBG2016).
IP packet filtering capability can be used to restrict access to the Ubigate
iBG2016 from untrusted, external networks or from specific, internal
networks. An example would be a filter that prohibits external users from
establishing Telnet sessions to the Ubigate iBG2016, and allows only specific
internal users Telnet access to the system.
y
At the end of every rule list is an implied ‘deny all traffic’ statement.
Therefore, all packets not explicitly permitted by filtering rules, are denied.
This effectively means that once you enter a ‘deny’ statement in your filter
list, you are implicitly denying all packets from crossing the interface.
Therefore, it is important that each filter list contain at least one ‘permit’
statement.
y
The order in which you enter the filtering rules is important. As the Ubigate
iBG2016 is evaluating each packet, the SNOS tests the packet against each
rule statement sequentially. After a match is found, no more rule statements
are checked. For example, if you create a rule statement that explicitly
permits all traffic, all traffic is passed since no further rules are checked.
y
The SNOS permits easy re-ordering of filter commands through
access-list
insert
and
delete
commands.
Содержание Ubigate iBG2016
Страница 1: ......
Страница 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 34: ......
Страница 42: ...CHAPTER 1 Basic Configuration 8 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 62: ...CHAPTER 4 System Logging 28 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 70: ......
Страница 108: ......
Страница 126: ...CHAPTER 1 Layer 2 Switching 90 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 140: ...CHAPTER 4 RIP 104 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 156: ...CHAPTER 6 BGP 120 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 176: ...CHAPTER 7 MultiCast Protocols 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 180: ...CHAPTER 8 VRRP 144 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 264: ...CHAPTER 10 QoS 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 270: ...CHAPTER 11 VLAN forwarding with QoS 234 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 272: ......
Страница 278: ...CHAPTER 1 Authentication Authorization Accounting 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 298: ...CHAPTER 3 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 356: ...CHAPTER 5 IPSEC 306 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 358: ......
Страница 390: ...CHAPTER 2 VoIP Gateway Management 336 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 514: ...CHAPTER 4 H 323 Gateway Management 460 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 670: ...CHAPTER 8 Routing and Digit Manipulation 616 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 744: ...EQBD 000071 Ed 00 ...