Application Note
128
7.2.10 HTTP filter
7.2.10.1 Scenario
7.2.10.2 Configuration
Step 1: create the filter rule for HTTP filter
$create filter rule entry ruleid 5 action drop ruledir in
$
entry created
rule id : 5 rule action : drop
set priority : - admin status : disable
stats admin status : disable rule priority : high
rule direction : in applywhenreq : disable
pkt type : ucast
application description : -
snoop level : interface
$
Step 2: create the subrule
$create filter subrule tcp ruleid 5 subruleid 1 dstportfrom 80
srcportcmp any ds tportcmp inrange subruleprio high
entry created
rule id : 5 subrule id : 1
start source port : - end source port : -
start destination port : 80 end destination port : 65535
source port comparison : any destination port comparison :
inrange
subrule priority : high
transport header : ethernet
$
Step 3: enable the rule
$modify filter rule entry ruleid 5 status enable
rule id : 5 rule action : drop
set priority : - admin status : disable
stats admin status : disable rule priority : high
rule direction : in applywhenreq : disable
pkt type : ucast
application description : -
snoop level : interface
set done
rule id : 5 rule action : drop
set priority : - admin status : enable
stats admin status : disable rule priority : high
rule direction : in applywhenreq : disable
pkt type : ucast
application description : -
snoop level : interface
$
Step 4: create the port to map this filter
$create filter rule map ifname eoa-0 stageid 1 ruleid 5
entry created
interface : eoa-0 stage id : 1
rule id : 5 order id : 5
Comments to this Manuals