242
C
HAPTER
14: H
ANDLING
P
ACKET
F
ILTERS
Global Switch to Filter Out All IP Options
Sometimes IP options may be generated from an outside source in an
attempt to get past routing tables in a network. The RAS 1500 provides a
global feature to filter out all IP packets with IP options. By using the
command below, you can discard all packets like this, which will create a
SYSLOG message each time one of these packets is discarded. The
following commands are associated with this feature:
enable ip security_option allow_all_header_options ENTER
disable ip security_option allow_all_header_options
(Default)
Global Switch to Filter Out IP Source Route Options
This global option addresses the particular path a sender chooses to take
through the network to reach its destination, as specified in the sender
packet IP header. Using this command, you can discard packets of this
type although this is a lower level of security than All Header Options. The
following commands are associated with this feature:
enable ip security_option disallow_source_route_options ENTER
disable ip security_option disallow_source_route_options
(Default)
Keywords
This section describes valid keywords you can use for each protocol
section.
IP and IP-CALL Sections
Keyword
Description
Operators
Value
src-addr
source IP address
= or !=
ddd.ddd.ddd.ddd/mask
dst-addr
destination IP address
= or !=
ddd.ddd.ddd.ddd/mask
tcp-src-port
TCP source port #
all
1-65536
tcp-dst-port
TCP destination port #
all
1-65536
tcp-one-way Not supported in this release
udp-src-port UDP source port #
all
1-65536
udp-dst-port UDP destination port #
all
1-65536
icmp-type
ICMP message type
= or !=
0-255
protocol
protocol-specific field
= or !=
udp, tcp, icmp
generic
field offset, length, mask values
generic
generic
Summary of Contents for REMOTE ACCESS SYSTEM 1500
Page 14: ......
Page 40: ......
Page 58: ......
Page 120: ......
Page 130: ......
Page 158: ......
Page 178: ......
Page 202: ......
Page 266: ......
Page 286: ......
Page 292: ......
Page 297: ...INDEX 295 V 90 151 W Windows 95 Dial Up Networking 89 World Wide Web WWW 285 X X 75 152 ...
Page 298: ...296 INDEX ...