![TELES ECOTEL Скачать руководство пользователя страница 46](http://html1.mh-extra.com/html/teles/ecotel/ecotel_manual_1082146046.webp)
C O N F I G U R A T I O N F I L E S
C H A P T E R 5
46
ECOTEL 3G 16.1. Revised: 1 March 2011.
quick
Allows short-cut rules in order to speed up the filter or override later rules. If a packet matches a filter
rule that is marked as quick, this rule will be the last rule checked, allowing a short-circuit path to avoid
processing later rules for this packet. If this option is missing, the rule is taken to be a "fall-through rule,
meaning that the result of the match (block/pass) is saved and that processing will continue to see if there
are any more matches.
on <interface>
The firewall rule is used only for the defined interface (e.g. emac0, pppoe0).
from <networkaddress/mask>
to <networkaddress/mask>
from
defines the source IP-address range for incoming packets.
to
defines the target IP-address range for
outgoing packets. The IP address appears in decimal notation, followed by a slash (
/
) and the netmask in bit
notation.
any
stands for all IP addresses (e.g.:
to any
).
NOTE: If you use the rule
pass in/out
in combination with the option
from <ip> to <ip>
,
you must specify a protocol number with
proto
and a
port
number. If you not specify the port,
the system may not be reachable. EXAMPLE:
fw=
pass in
quick on pppoe0
proto tcp from
any
to
any
port eq
4445
proto <protocol>
defines the protocol, for which the rule is valid (e.g.: proto tcp, proto udp, proto icmp).
port eq <num>
<num> defines the port as number (e.g.: port eq 4445).
keep state
Ensures that the firewall checks packets from the beginning to the end of a session. This is necessary, as the
firewall does not know when a session begins or ends.
flags S
Only syn. packets are accepted and recorded in the state table. In conjunction with keep state, packets from
sessions that have been inactive will also be routed. The advantage of this entry is that random packets will
not be accepted.
keep frags
Fragmented packets are also routed.
Table 5.6
Settings in the
[firewall]
Section of the
ip.cfg
(continued)
[firewall]
fw=<mode> <direction> <list>
Содержание ECOTEL
Страница 1: ...Software version 16 1 ECOTEL 3G Family...