Chapter Nine: Advanced Installations | IP filters 133 |
|
|
When done, the filter stack should look like this:
Allowing incoming traffic only from a specific network
This example shows how to allow the DIVA LAN ISDN Modem to only receive incoming data from a specific network (112.111.212.0) on the Internet. Data from all other networks is dropped. However, outgoing traffic is not affected.
This requires defining two filters. Since these filters are applied against data from the Internet, they are defined for the ISP profile.
1st filter
Define the 1st filter to forward only incoming traffic from 112.111.212.0. Place this filter in the third position in the stack.
2nd filter
Define the 2nd filter to forward all outgoing traffic. The easiest way to do this is to edit the existing filter that is set to “Forward all datagrams being sent from anywhere that contain any protocol.” Change it to “Forward outgoing datagrams being sent from anywhere that contain any protocol.”