Security 13-7

How individual filters work

As described above, a filter applies criteria to an IP packet and then takes one of three actions:

A filter’s actions

Passes the packet to the local or remote network

Blocks (discards) the packet

Ignores the packet

A filter passes or blocks a packet only if it finds a match after applying its criteria. When no match occurs, the filter ignores the packet.

A filtering rule

The criteria are based on information contained in the packets. A filter is simply a rule that prescribes certain actions based on certain conditions. For example, the following rule qualifies as a filter:

Block all Telnet attempts that originate from the remote host 199.211.211.17.

This rule applies to Telnet packets that come from a host with the IP address 199.211.211.17. If a match occurs, the packet is blocked.

Here is what this rule looks like when implemented as a filter on the Netopia R9100:

+-#--

Source IP Addr--

Dest IP Addr-----

Proto-Src.Port-D.Port--

On?-Fwd-+

+--------------------------------------------------------------------

 

 

+

1

199.211.211.17

0.0.0.0

TCP 23

Yes No

+--------------------------------------------------------------------

 

 

+

To understand this particular filter, look at the parts of a filter.

Parts of a filter

A filter consists of criteria based on packet attributes. A typical filter can match a packet on any one of the following attributes:

The source IP address (where the packet was sent from)

The destination IP address (where the packet is going)

The type of higher-layer Internet protocol the packet is carrying, such as TCP or UDP

Port numbers

A filter can also match a packet’s port number attributes, but only if the filter’s protocol type is set to TCP or UDP, since only those protocols use port numbers. The filter can be configured to match the following:

The source port number (the port on the sending host that originated the packet)

The destination port number (the port on the receiving host that the packet is destined for)

Page 145
Image 145
Farallon Communications R9100 How individual filters work, filter’s actions, filtering rule, Parts of a filter, Port numbers

R9100 specifications

Farallon Communications R9100 is a high-performance network device designed to meet the demanding needs of modern telecommunications. This robust system specializes in delivering reliable, efficient, and scalable solutions for various networking environments. Its architectural design integrates cutting-edge technologies that enhance performance while ensuring compatibility with existing infrastructure.

One of the standout features of the R9100 is its advanced routing capabilities. Equipped with powerful processors, it supports multiple routing protocols, including OSPF, BGP, and EIGRP. This flexibility allows network administrators to optimize data flow and maintain seamless connectivity across diverse network topologies. The R9100 also includes sophisticated Quality of Service (QoS) mechanisms, enabling prioritization of critical traffic, which is essential for latency-sensitive applications.

Another significant aspect of the R9100 is its support for various interfaces. Whether organizations require Ethernet, fiber, or wireless connections, the R9100 accommodates a broad range of interface options. This versatility ensures that it can be deployed in various environments, from large enterprise networks to smaller branch offices.

Security is a crucial consideration in today’s networking landscape, and the R9100 addresses this with built-in security features. These include stateful firewall capabilities, Intrusion Detection System (IDS), and comprehensive Virtual Private Network (VPN) support. Such features allow organizations to safeguard sensitive data and maintain compliance with industry regulations.

The R9100 also prioritizes ease of management. With a user-friendly interface and robust monitoring tools, network administrators can easily configure and manage the device. This capability facilitates rapid troubleshooting and performance tuning, ensuring minimal downtime and optimal user experience.

Energy efficiency is an additional characteristic that sets the R9100 apart from its competitors. Designed with eco-friendly technologies, it minimizes power consumption while maximizing output, making it an ideal choice for organizations looking to reduce their carbon footprint.

In conclusion, Farallon Communications R9100 stands out as a versatile and powerful network device that meets the complexities of modern telecommunications. With its advanced routing features, robust security measures, varied interface options, and energy-efficient design, the R9100 is a formidable player in the networking landscape. Organizations can rely on this solution to enhance their network performance and evolve alongside their growing technological needs.