Ubigate iBG3026 Configuration Guide
© SAMSUNG Electronics Co., Ltd.
229
CHAPTER 22.
Packet Filtering
Ubigate iBG3026s can be configured for MAC and IP traffic filtering
capabilities. IP traffic filtering allows creation of rule sets that selectively
block TCP/IP packets on a specified interface. Filters are applied
independently to all interfaces: Ethernet, serial, or WAN, as well as
independently to interface direction: IN(packets coming in to the Ubigate
iBG3026) or OUT(packets going out of the Ubigate iBG3026).
IP packet filtering capability can be used to restrict access to the Ubigate
iBG3026 from untrusted, external networks or from specific, internal
networks. An example would be a filter that prohibits external users from
establishing Telnet sessions to the Ubigate iBG3026, and allows only specific
internal users Telnet access to the system.
At the end of every rule list is an implied ‘deny all traffic’ statement.
Therefore, all packets not explicitly permitted by filtering rules, are denied.
This effectively means that once you enter a ‘deny’ statement in your filter
list, you are implicitly denying all packets from crossing the interface.
Therefore, it is important that each filter list contain at least one ‘permit’
statement.
The order in which you enter the filtering rules is important. As the Ubigate
iBG3026 is evaluating each packet, the SNOS tests the packet against each
rule statement sequentially. After a match is found, no more rule statements
are checked. For example, if you create a rule statement that explicitly
permits all traffic, all traffic is passed since no further rules are checked.
The SNOS permits easy re-ordering of filter commands through
access-list
insert
and
delete
commands.
Содержание Ubigate iBG3026
Страница 1: ......
Страница 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 34: ......
Страница 42: ...CHAPTER 1 Basic Configuration 8 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 70: ...CHAPTER 5 RMON Configuration 36 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 72: ......
Страница 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 110: ......
Страница 126: ...CHAPTER 10 Layer 2 Switching 88 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 260: ...CHAPTER 20 VLAN forwarding with QoS 222 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 262: ......
Страница 268: ...CHAPTER 21 Authentication Authorization Accounting 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 346: ......
Страница 378: ...CHAPTER 27 VoIP Gateway Management 336 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 716: ...CHAPTER 37 Survivable Telephony 674 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 718: ...EQBD 000026 Ed 00 ...