Administrator’s Handbook

set security pkt-filter filterset filterset-name[ input_filter output_filter ] index dst-compare [ nc ne lt le eq gt ge ]

Sets the destination compare operator action for the specified filter rule. dst-compareonly displays when the protocol is TCP or UDP.

Operator

Action

nc

No compare

ne

Not equal to

lt

Less than

le

Less than or equal to

eq

Equal to

ge

Greater than or equal to

gt

Greater than

set security pkt-filter filterset filterset-name[ input_filter output_filter ] index src-port value

Specifies the source IP port to match packets (the port on the sending host that originated the packet, if the underlying protocol is TCP or UDP). src-portdoes not display if nc is set for src-compareor dst-com- pare.

set security pkt-filter filterset filterset-name[ input_filter output_filter ] index dst-port value

Specifies the destination IP port to match packets (the port on the receiving host that the packet is des- tined for, if the underlying protocol is TCP or UDP). dst-port does not display if nc is set for src-compare or dst-compare.

set security pkt-filter interface assigned-filterset filterset-name

Associates a filterset with a LAN or WAN interface.

Example:

set security pkt-filter ethernet A assigned-filterset set1

296

Page 296
Image 296
Motorola 3352N, 7000, 3342, 2200 manual 296