
54 MergePoint 5224/5240 Service Processor Manager Installer and Administrator Guide
Rules
Each chain can have one or more rules that define the following:
• The packet characteristics being filtered. The packet is checked for characteristics defined in
the rule, for example, a specific IP header, input and output interfaces and protocol.
• What to do when the packet characteristics match the rule. The packet is handled according to
the specified action (called a Rule Target, Target Action or Policy).
When a packet is filtered, its characteristics are compared against the rules one
-by-one. All
characteristics must match.
Add rule and edit rule options
When you add or edit a rule, you can define any of the options described in the following table.
Table 4.19: Filter Options for Packet Filtering Rules
Filter Options Description
Protocol You can select a protocol for filtering from one of the following options:
•ALL
•TCP
• UDP
•ICMP
•GRE
• ESP
•AH
Source IP/mask
Destination IP/mask
A host IP address or subnetwork IP address in the form: hostIPaddress
or networkIPaddress/NN. If you specify a source IP, incoming packets
are filtered for the specified IP address. If you specify a destination IP,
outgoing packets are filtered for the specified IP address.
Input or Output Interface The input or output interface used by the incoming or outgoing packet.
Choices are:
• Public 1 (eth0)
• Public 2 (eth1)
• Failover (bond0)
• PCMCIA (eth2)
• PCMCIA (eth3)
• Any private port (priv0)
Fragments The types of packets to be filtered:
• All packets and fragments
• Head fragments and unfragmented packets
•Non-head fragments only
Rule target • Accept
•Drop
• Reject
Comentarios a estos manuales