None

Hitachi Gigabit Router GR2000 Series Enhanced Version Configuration Commands, Vol. 2

{-ackDescription:checkoff-ackSpecifiescheck}TCP one-way communication permission (ACK flag). The -ack_check_offoption excludes the packet from filtering when its ACK flag is on. The -ack_checkoption filters the packet when its ACK flag is on.

Default: -ack_ _off

Range of value:

{-synDescription:checkoff-synSpecifiescheck}permission for establishing a virtual circuit (SYN flag). The -syn_check_offoption excludes the packet from filtering when its SYN flag is on. The -syn_checkoption filters the packet when its SYN flag is on.

Default: -syn_ _off

Range of value: None

Note: Define the filtering according to the GR2000 Configuration Settings (universal CLI) manual

*when the IPv4 packets shown in the table below are filtered under the ACK/SYN flag conditions of a TCP header.

The filtering of the IPv4 packets shown in the table below that is performed under the ACK/ SYN flag conditions of a TCP header is limited when IPv4 packets are used in a way except as described above. The IPv4 packets cannot be properly filtered even if "ack" and "syn" parameters are set to the filter flow information.

Table 1-62 Packet Type in which the Filtering Based on the Flag (ACK and SYN) Conditions of TCP Header Is Limited in Use

Packet Type

Limited Filtering Item

 

 

IPv4 packet generated by this router

• IPv4 packets do not match the filter list, to which

 

 

"-ack_check" or "-syn_check" is set, in conditions. In other

 

 

words, both ACK and SYN flags are searched for filtering

 

 

as if packet 0 were input.

 

 

Packet applied to the conditions below among the

The same as described above.

IPv4 packets relayed by this router:

 

(1)

Packet with option (IP header)

 

 

 

Packet applied to the conditions below among the

• The packets to be discarded are properly discarded when

IPv4 packets relayed by this router:

they conform to the filtering conditions.

(2)

Packet requiring fragmentation

• The packets to be relayed do not match the filter list, to

(3)

Packet requiring redirection

which "-ack_check" or "-syn_check" is set, in conditions

(4)

Packet in which ARP has not been solved

when they conform to the filtering conditions. In other

 

 

words, both ACK and SYN flags are searched for filtering

 

 

as if packet 0 were input.

 

 

 

-icmpDescription:type<No.>Specifies the ICMP type number in decimal

Default: Undefined

Range of value: 0–255

1-118

GR2K-GA-0014

 

Ver. 07-02

Page 160
Image 160
Hitachi GR2000 Series manual Default -ack off Range of value, Default -syn off Range of value None