Intel A31032-001 Combining automapping and manual mapping, Use the show block command to verify

Models: A31032-001

1 196
Download 196 pages 18.6 Kb
Page 45
Image 45

C H A P T E R 3SSL Processing

 

Combining automapping and manual mapping

NOTE: If both manual

Any combination of automapping and manual mapping entries, up to

mappings and applicable

a total of 1000, can be used provided the server IP address and

automappings are

network port combinations are unique. Several of the scenarios in

available, the 7110/7115

Chapter 4 include step-by-step mapping procedures.

always uses the manual

 

 

mapping.

Blocking

 

NOTE: Blocking is

For security purposes, the 7110/7115 allows the blocking of

always performed before

particular IP addresses and ports. IP/port combinations can be

mapping.

blocked on the basis of:

 

Specific IP, specific port

 

Subnet of IPs, specific port

 

All IPs, specific port

 

Specific IP, Specific Port

 

To block a specific server IP and specific port combination:

 

1.

Type the create block command.

 

2.

Type the IP address.

 

3.

Press Enter to accept the default IP mask

 

4.

Type the specific port.

 

5.

Press Enter to accept the default port mask.

Example:

Intel 7115> create block

Client IP to block [0.0.0.0]: 10.1.2.1

Client IP mask [0.0.0.0]: 255.255.255.255

Server IP to block [0.0.0.0]: 20.1.2.1

Server IP mask [0.0.0.0]: 255.255.255.255

Server Port to block: 80

Server Port mask [0xffff]:<Enter>

Use the show block command to verify:

Intel 7115> show block

(1)block 10.1.2.1 255.255.255.255 20.1.2.1 255.255.255.255 80 0xffff

3-23

Page 45
Image 45
Intel A31032-001 Combining automapping and manual mapping, Use the show block command to verify