Motorola 3342, 7000, 3352N, 2200 Link Packet Filter, What’s a filter and what’s a filter set?, 163

Models: 2200 3342 3352N 3352 7000

1 368
Download 368 pages 62.68 Kb
Page 163
Image 163

Link: Packet Filter

When you click the Packet Filter link the Filter Sets screen appears.

Security should be a high priority for anyone administering a network connected to the Internet. Using packet filters to control network communications can greatly improve your network’s security. The Packet Filter engine allows creation of a maximum of eight Filter Sets. Each Filter Set can consist of many rules. There can be a maximum of 32 filter rules in the system.

WARNING:

Before attempting to configure filters and filter sets, please read and understand this entire section thoroughly. Motorola Netopia® Gateways incorporating NAT have advanced security features built in. Improperly adding filters and filter sets increases the possibility of loss of communication with the Gateway and the Internet. Never attempt to configure filters unless you are local to the Gateway.

Although using filter sets can enhance network security, there are disadvantages:

Filters are complex. Combining them in filter sets introduces subtle interactions, increasing the likelihood of implementation errors.

Enabling a large number of filters can have a negative impact on performance. Processing of packets will take longer if they have to go through many checkpoints in addition to NAT.

Too much reliance on packet filters can cause too little reliance on other security methods. Filter sets are not a substitute for password protection, effective safeguarding of passwords, and general awareness of how your network may be vulnerable.

Netopia Embedded Software Version 7.7.4’s packet filters are designed to provide security for the Internet connections made to and from your network. You can customize the Gateway’s filter sets for a variety of packet filtering applications. Typically, you use filters to selectively admit or refuse TCP/IP connections from certain remote networks and specific hosts. You will also use filters to screen particular types of connec- tions. This is commonly called firewalling your network.

Before creating filter sets, you should read the next few sections to learn more about how these powerful security tools work.

What’s a filter and what’s a filter set?

A filter is a rule that lets you specify what sort of data can flow in and out of your network. A particular filter can be either an input filter—one that is used on data (packets) coming in to your network from the Inter- net—or an output filter—one that is used on data (packets) going out from your network to the Internet.

A filter set is a group of filters that work together to check incoming or outgoing data. A filter set can consist of a combination of input and output filters.

163

Page 163
Image 163
Motorola 3342, 7000, 3352N, 2200 manual Link Packet Filter, What’s a filter and what’s a filter set?, 163