APC IP DSLAM User's Guide Page 130

  • Download
  • Add to my manuals
  • Print
  • Page
    / 603
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 129
Application Note
122
7.2.7 IP Filter
IP Filter is software that provides statefull packet filtering
capability. It can also be used to deliver NAT (Network
Address Translation) capabilities. IP Filter provides
protection to a single server or a network of servers and
clients.
7.2.7.1 Scenario
7.2.7.2 Configuration
Step 1: create the filer rule for IP filter
$create filter rule entry ruleid 2 action drop ruledir in
entry created
rule id : 2 rule action : drop
set priority : - admin status : disable
stats admin status : disable rule priority : high
rule direction : in applywhenreq : disable
pkt type : ucast
application description : -
snoop level : interface
$
Step 2: create the subrule
$create filter subrule ip ruleid 2 subruleid 1 srcaddrcmp notingenlist
entry created
rule id : 2 subrule id : 1
start src ip addr : - end src ip addr : -
start dest ip addr : - end dest ip addr : -
start ip prot type : - end ip prot type : -
ip src addr mask : 0xffffffff ip dest addr mask : -
src ip addr comp : not in gen list dest ip addr comp : any
subrule priority : asinrule ip prot type comp : any
transport header : ethernet
$
Step 3: enable the rule
$create filter rule map ifname eoa-0 stageid 1 ruleid 2
entry created
interface : eoa-0 stage id : 1
rule id : 2 order id : 2
$
Step 4: create the port to map this filter
$create filter rule map ifname eoa-1 stageid 1 ruleid 2
entry created
interface : eoa-1 stage id : 1
rule id : 2 order id : 2
Page view 129
1 2 ... 125 126 127 128 129 130 131 132 133 134 135 ... 602 603

Comments to this Manuals

No comments