
Prestige 662H/HW Series User’s Guide
CHAPTER 36
Filter Configuration
This chapter shows you how to create and apply filters.
36.1 About Filtering
Your Prestige uses filters to decide whether or not to allow passage of a data packet and/or to make a call. There are two types of filter applications: data filtering and call filtering. Filters are subdivided into device and protocol filters, which are discussed later.
Data filtering screens data to determine if the packet should be allowed to pass. Data filters are divided into incoming and outgoing filters, depending on the direction of the packet relative to a port. Data filtering can be applied on either the WAN side or the Ethernet side. Call filtering is used to determine if a packet should be allowed to trigger a call.
Outgoing packets must undergo data filtering before they encounter call filtering. Call filters are divided into two groups, the
Figure 205 Outgoing Packet Filtering Process
Call Filtering
|
|
|
|
|
|
|
|
|
|
| No |
|
|
|
|
|
|
|
| Active Data |
|
| |||||
|
|
| Data | No |
| match |
| No |
|
|
|
|
|
|
| ||||||||||||
Outgoing |
|
| match | default |
|
|
|
| Call Filters |
| match |
|
| Initiate call |
| ||||||||||||
Packet |
|
| Filtering |
|
|
|
|
|
|
|
|
| if line not up |
| |||||||||||||
|
|
| Call Filters |
|
|
|
| (if applicable) |
|
|
|
|
| ||||||||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Send packet | ||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| and reset | |
|
|
|
| Match |
|
| Match |
|
|
|
|
| Match |
|
|
|
|
|
| Idle Timer | |||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Drop |
| Drop packet |
|
|
|
|
| Drop packet |
|
|
|
|
|
|
|
|
|
| ||||||
|
|
| packet |
| if line not up |
|
|
|
|
| if line not up |
|
|
|
|
|
|
|
|
|
| ||||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| Or |
|
|
|
|
|
| Or |
|
|
|
|
|
|
|
|
| |||
|
|
|
|
|
|
|
|
|
|
| Send packet |
|
|
|
|
| Send packet |
|
|
|
|
|
| ||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |||||||||||
|
|
|
|
|
|
|
|
|
| but do not reset |
|
| but do not reset |
| |||||||||||||
|
|
|
|
|
|
|
|
|
|
| Idle Timer |
|
|
|
|
|
| Idle Timer |
|
|
|
|
|
| |||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Two sets of factory filter rules have been configured in menu 21 to prevent NetBIOS traffic from triggering calls. A summary of their filter rules is shown in the figures that follow.
The following figure illustrates the logic flow when executing a filter rule.
Chapter 36 Filter Configuration | 362 |