Enterasys APS-3000 Especificaciones Pagina 478

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 500
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 477
21-22 topology Commands
Usage
Ifthespecifiedexceptionfilterpositionalreadycontainsanexceptionfilter,theconfigcommand
overwritestheexistingexceptionfilter.Usethecreatecommandtoinsertorappendanexception
filteratthe specifiedposition.
Ifadvancedfiltermodehasbeenenabledwiththeenableadvancefilteringcommand(page203),
the
Advancedmodesyntaxispresented.Ifadvancedfiltermodeisnotenabled,theBasicmode
syntaxispresented.
Examples
Thefollowingexamplemodifiesanexistingfilter.
EWC.enterasys.com:topology:r1:l3:exceptions# config 2 proto tcp 1.1.1.1/32 port
80 in dst allow
proto{udp|tcp|ah|esp|none
|icmp|gre|<0255>}
Specifiestheprotocolforthisfilterrulebynumberorname.
Validnumbervaluesarefrom0–255.Validnamevaluesare:
udp - UDP protocol
tcp - TCP protocol
ah - Authentication Header protocol
esp - Encapsulating Security Payload protocol
none - No protocols
icmp - ICMP protocol
gre - Generic Route Encapsulation protocol
A.B.C.D/<032> SpecifiestheIPv4IPaddressandmask.
(port<065535>[<065535>]) SpecifiesaTCPorUDPportorportrangetowhichthisfilter
rulewillbeapplied.Thefirstvaluespecifieseithertheportor
thestartofaportrange.Thesecondvalueoptionallyspecifies
theendof
aportrange.Thisparameterisonlyvalidwheneither
TCPorUDPisthespecifiedprotocol.Validportvaluesarefrom
0–65535.
(type<0255>[<0255>]) SpecifiesanICMPtypeorrangeofICMPtypes.Thisparameter
isonlyvalidwhenICMPisthe sp ecifiedprotocol.Validvalues
arefrom
0–255.
Basic:in(none|dst)
Advanced:
in(none|src|dst|both)
Specifiesthedirectionofpacketflowinspecifiesapacket
flowfromtheAPtotheAC.
nonespecifiesthattheindirectiondoesnotapplytothefilter
rule.
dstspecifiesthattheIPaddressfor thisfilterruleisthe
destinationofthe
packetflow.
srcspecifiesthattheIPaddressforthisfilterruleisthesourceof
thepacketflow.
bothspecifiesthattheIPaddressforthisfilterrulecanbeeither
sourceordestination.
(allow|deny) Specifieswhetherpacketswillbeallowedordeniedwhen
meetingthecriteriaspecifiedinthe
filterrule.
Vista de pagina 477
1 2 ... 473 474 475 476 477 478 479 480 481 482 483 ... 499 500

Comentarios a estos manuales

Sin comentarios