P
ACKET
F
ILTERING
C
OMMANDS
23-7filter netbios
This command filters NetBIOS30 packets entering the specified input
port.
Syntax
filter netbios {add | del} interface
add - Enables NetBIOS filtering.
del - Disables NetBIOS filtering.
•interface
-unit - Stack unit. (Range: 1)
-port-list - Single port number or list of ports. (Range: 1-18)
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
NetBIOS is commonly used in local area networks to facilitate sharing
resources such as printers or files between co mputers. However, when
providing network services over the Internet to different custome rs,
all information about local resources should be protected. Sending
NetBIOS packets over TCP or UDP protocols can be manually
disabled at the host computer. However, to ensure that this
information is never sent out on the Internet, NetBIOS packet
filtering should be enabled on all data ports if the switch is not
operating behind a firewall.
When NetBIOS packet filtering is enabled, NetBIOS packets
addressed to any
of the TCP or UDP ports 136-139 or 445, and
carrying a DSAP
31
value of 0xE0 or 0xF0, will be dropped from the
specified interface.
To specify a port list, use a hyphen to indicate a range of p orts, or a
comma to indicate a group of non-consecutive ports.
30. NetBIOS - Network Basic Input Output System
31. DSAP - Destination Server Access Point; i.e., a session service tag