Hitachi Gigabit Router GR2000 Series Enhanced Version Configuration Commands, Vol. 2

 

Table 1-28 Packet Type in which the Filtering Based on the Flag (ACK and SYN)

 

Conditions of TCP Header Is Limited in Use

 

 

Packet Type

Limited Filtering Item

 

 

IPv4 packet generated by this router

• IPv4 packets do not match the filter list, to which

 

 

"-ack_check" or "-syn_check" is set, in conditions. In other

 

 

words, both ACK and SYN flags are searched for filtering

 

 

as if packet 0 were input.

 

 

Packet applied to the conditions below among the

The same as described above.

IPv4 packets relayed by this router:

 

(1)

Packet with option (IP header)

 

 

 

Packet applied to the conditions below among the

• The packets to be discarded are properly discarded when

IPv4 packets relayed by this router:

they conform to the filtering conditions.

(2)

Packet requiring fragmentation

• The packets to be relayed do not match the filter list, to

(3)

Packet requiring redirection

which "-ack_check" or "-syn_check" is set, in conditions

(4)

Packet in which ARP has not been solved

when they conform to the filtering conditions. In other

 

 

words, both ACK and SYN flags are searched for filtering

 

 

as if packet 0 were input.

 

 

 

Input Examples

1. Setting the filter flow information

Designation of relay and/or discard

Designate relaying the packets with the transmitter IP address being 10.10.10.2, the high-order protocol being TCP and the destination port number being 23 (telnet). Designate other packets to be discarded.

 

 

￿

D ignati n

f policy routing

 

 

 

 

Output packets with transmi ter IPv4 addresses being 10.10.10.2 from the

 

 

interface with the in erface name of Osaka making the next hop ddress

 

-

10.10.20.20.

erTokyooutlist

1tcp10.10.10.2ny23

action

 

 

 

fl

-yes

2000ipanyany-ction

-drop

 

flrwardyes{

 

 

 

 

show

flow

{

 

 

 

 

 

filterTokyo

 

 

 

};

};

 

list

out1cp10.10.10.2any23actionforward;

 

1-36

 

2000ipanyanyactiondrop;

GR2K-GA- 014

 

 

￿

 

 

 

 

 

Ver. 7-02

 

 

 

 

 

 

 

 

 

(config)#};flwyes{.Osaka1020.20};filterTokyo.10shflowlist1ipf-lowyesilterinTokyo{10.10in.10list.2any1ipactionany10policy.10.10.Osaka2action10.10-policy.20.20;

Page 78
Image 78
Hitachi GR2000 Series manual GR2K-GA, Packet Type Limited Filtering Item