Perle Systems P840 Transport Control Protocol / Internet Protocol TCP/IP, Filter only TCP/IP

Page 50

Filtering

Transport Control Protocol / Internet Protocol (TCP/IP)

The previous example showed how to filter all Ethernet frames that contained an IP protocol packet. However, IP is used as the Network-layer protocol for more than 40 different Transport-layer protocols, TCP being only one of them. Therefore, with the mask that was used as noted in the previous IP example, all Transport layer protocols that used IP would also be filtered. This may not be desirable in all cases.

For this example, the discrimination of the Transport Layer used within an IP packet will be demonstrated. This requires an AND function, since we want to filter data that both is IP and contains TCP information.

Within the IP frame, there is a single octet field that may be used to indicate the protocol of the Transport layer, or the protocol of the data in the IP packet. If TCP were the protocol within the IP packet, this octet, or 8-bit byte, would be equal to 6.

The location of this field, remembering that the start of the Ethernet frame is always the base reference, is octet 23.

Filter only TCP/IP

To filter only those packets that are TCP/IP, the mask would therefore be : 12-0800&23-06

The 12-0800 is the IP expression and the 23-06 will represent TCP in an IP frame. The “&” is the logical AND operator, so the expression requires that the frame be both an IP and TCP.

Filter all IP without TCP traffic

To filter all IP packets that do not contain TCP traffic, the mask would be : 12-0800&~(23-06)

Filter all except TCP/IP

To filter all other packets except TCP/IP packets, the mask would be: ~(12-0800&23-06)

Local Area Transport (LAT)

The Local Area Transport (LAT) protocol is used exclusively by DEC for terminal access between DEC hosts and terminal servers located on an Ethernet network.

This example is similar to the Internet Protocol example described previously.

The protocol type field value that is used for LAT frames is equal to 6004.

Filter all LAT

Therefore, to filter all LAT frames, the filter mask would be: 12-6004

Filter all but LAT

To filter all frames but LAT frames, the filter mask would be: ~(12-6004)

50

Image 50
Contents Perle P840 Introduction P840 RouterProxy ARP ARP-Address Resolution ProtocolIP Routing and the P840 Router Complete IP Connection IP Header Details Redirect Icmp MessagesUnreachable QuenchPing Update MechanismRIP-Routing Information Protocol Time and Mask serverStation Address Learning Bridging and the P840 RouterInitial Bridging Process Aging Timer Aging Exception Filled Address TableAddress Purging Link Compression P840 Router Feature DefinitionsTelnet Typical Compression Ratios by File Type Multilink WAN TopologiesBandwidth On Demand MultipointOperating Software Upgrades Time of Day Connect ApplicationCall Establishment Methods P840 Isdn Connection ManagementWide Area Network Topologies Supported Isdn Connection Management Auto-Call Time-of-Day ConnectionsAddress Connect Manual CallConnection Process CombinationSuspension Process Idle TimerProtocol Awareness Interesting TrafficP840 Session Participation Spoofing Suspended ServerIP Address Connect IP SpecificsTermination Process Suspension of TCP/IP SessionsConsole Connector Pinout InformationEvent Logs Event logsEvent Logs Event Logs Event Logs Event Logs Event Logs Alarm logs Event Logs Event Logs Event Logs Code Description Code Event Logs Event Logs Event Logs Event Logs Event Logs PPP Security logs MAC Address Filtering SecurityFiltering Security-Filter if DestinationSecurity-Filter if Source Security-Forward if Destination Filtering Security-Forward if SourceFiltering Protocol Discrimination Pattern Filter OperatorsBridge Pattern Filtering Filter all IP Packets Protocol Type FieldInternet Protocol IP IP, and no moreFiltering Filter all IP without TCP traffic Transport Control Protocol / Internet Protocol TCP/IPFilter only TCP/IP Filter all except TCP/IPEthernet Broadcasting Bandwidth ConservationFilter all DEC Ethernet MulticastingEthernet Station Addresses General RestrictionsInternet Addresses Mask Combinations Mask would be 6-010203040506&12-0800&23-06 ExampleIP Router Pattern Filtering Frame Formats Ethernet Type Codes Octet Locations on an IP Routed TCP/IP Frame Octet Locations on a Bridged XNS Frame

P840 specifications

Perle Systems is renowned for its high-performance networking hardware, and the Perle P840 model exemplifies this reputation with its advanced features and technologies. Designed for small to medium-sized enterprises, the P840 serves as a versatile and reliable solution for connectivity needs.

One of the main features of the Perle P840 is its robust network performance, supporting both Ethernet and serial connectivity. With support for RS-232, RS-422, and RS-485 interfaces, the P840 enables seamless integration of legacy devices into modern network architectures, allowing businesses to leverage existing infrastructure without the need for extensive upgrades.

The P840 also boasts advanced security features to protect sensitive data during transmission. It supports SSL encryption and VPN capabilities, ensuring that data travels securely across the network. Additionally, it implements strong authentication protocols, providing organizations with peace of mind knowing that their communications are safeguarded against potential threats.

Another standout characteristic of the P840 is its flexibility in configuration. It offers multiple port configurations, allowing for customization based on specific user needs. With options for both managed and unmanaged modes, the device can easily adapt to various network environments. This flexibility makes it suitable for diverse applications, including industrial automation, process control, and telecommunications.

The Perle P840 is designed for durability and reliability, featuring a rugged enclosure that can withstand demanding environments. Its solid-state components reduce the risk of failure, contributing to increased uptime and lower maintenance costs. Furthermore, the compact design allows for easy installation in tight spaces, making it a practical choice for various deployment scenarios.

In terms of management and monitoring, the P840 includes an intuitive web-based interface, enabling administrators to configure settings and monitor network performance effortlessly. SNMP support further enhances management capabilities, allowing for integration into larger network management systems.

Overall, the Perle P840 stands out as a powerful solution for enterprises seeking seamless connectivity, robust security, and flexibility in configuration. Its combination of advanced features and durable design makes it an ideal choice for industries requiring reliable serial and network connectivity in challenging environments. With the P840, businesses can build a resilient networking infrastructure that supports their growing demands while safeguarding their critical data.