CHAPTER 22. Packet Filtering
230
© SAMSUNG Electronics Co., Ltd.
MAC filtering is supported on inbound packets only. MAC filtering can be
applied to:
Source MAC and source mask addresses
Destination MAC and destination mask addresses
Ethernet type
Class of Service(CoS)
VLAN ID
Example: Blocking Telnet Access
Consider a Ubigate iBG3026 connected via a bundle ‘WAN1’(wan IP address
200.1.1.1) to an ISP, with Ethernet 0/1(IP address 222.199.19.3) connected to
the internal network. The network administrator wants to completely block
Telnet access to the Ubigate iBG3026 from all external networks as well as
from all internal networks except 222.199.19.0/28. All other TCP/IP traffic,
such as FTP, Ping, and HTTP, is to flow unrestricted through the Ubigate
iBG3026.
Configure the Ubigate iBG3026
Router# configure term
Router/configure# ip access-list filtera
Router/configure/ip/access-list filtera# add deny tcp any
200.1.1.1 dport =23
Router/configure/ip/access-list# add permit tcp
222.199.19.0/28 222.199.19.3 dport =23
Router/configure/ip/access-list# add deny tcp any
222.199.19.3 dport=23
Router/configure/ip/access-list# add permit ip any any
Router/configure/ip/access-list# end
Router# save local
Содержание Ubigate iBG3026
Страница 1: ......
Страница 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 34: ......
Страница 42: ...CHAPTER 1 Basic Configuration 8 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 70: ...CHAPTER 5 RMON Configuration 36 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 72: ......
Страница 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 110: ......
Страница 126: ...CHAPTER 10 Layer 2 Switching 88 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 260: ...CHAPTER 20 VLAN forwarding with QoS 222 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 262: ......
Страница 268: ...CHAPTER 21 Authentication Authorization Accounting 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 346: ......
Страница 378: ...CHAPTER 27 VoIP Gateway Management 336 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 716: ...CHAPTER 37 Survivable Telephony 674 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 718: ...EQBD 000026 Ed 00 ...