Chapter 11 Packet Filter

 

Table 63 Security > Packet Filter > Edit (Protocol Filter) > Edit Rule (continued)

 

LABEL

DESCRIPTION

 

More

Select Yes to pass a matching packet to the next filter rule before an action is

 

 

taken. Select No to act upon the packet according to the action fields.

 

 

 

 

Log

Select a logging option from the following:

 

 

None – No packets will be logged.

 

 

Match - Only packets that match the rule parameters will be logged.

 

 

Not Match - Only packets that do not match the rule parameters will be logged.

 

 

Both – All packets will be logged.

 

 

 

 

Action Match

Select the action for a matching packet.

 

 

Options are Check Next Rule, Forward and Drop.

 

 

 

 

Action Not Match

Select the action for a packet not matching the rule.

 

 

Options are Check Next Rule, Forward and Drop.

 

 

 

 

Back

Click this to return to the previous screen without saving.

 

 

 

 

Apply

Click this to save your changes.

 

 

 

 

Cancel

Click this to restore your previously saved settings.

 

 

 

11.2.3 Editing Generic Filters

Use this screen to display a generic filter set on your ZyXEL Device. The purpose of generic rules is to allow you to filter non-IP packets. For IP packets, it is generally easier to use the IP rules directly.

For generic rules, the ZyXEL Device treats a packet as a byte stream as opposed to an IP or IPX packet. You specify the portion of the packet to check with the Offset (from 0) and the Length fields, both in bytes. The ZyXEL Device applies the Mask (bit-wise ANDing) to the data portion before comparing the result against the Value to determine a match. The Mask and Value are specified in hexadecimal numbers. Note that it takes two hexadecimal digits to represent a byte, so if the length is 4 bytes, the value in either field will take 8 digits, for example, FFFFFFFF.

In the Packet Filter screen, select Generic Filter from the Filter Type field. Then click the Edit button from the Modify field to display the following screen.

Figure 104 Security > Packet Filter > Edit (Generic Filter)

 

181

P-660HN-F1 User’s Guide