
238 Configuring Enterprise Edge Services
Enterprise Edge 2.0 Programming Operations Guide P0911588 Issue 01
Note: By default, there are no packet filters.
10. Click Save.
After you enter all the Input and Output Filters for an interface:
11. Type in the Input Filters’ Rule Order for the interface you are configuring.
12. Type in the Output Filters’ Rule Order for the interface you are configuring.
Stateful Packet Filters
Enterprise Edge supports stateful and basic packet filtering for IP protocols.
Stateful packet filters monitor active sessions and records session information such
as IP addresses and port numbers. They maintain state information for each flow
(TCP, UDP or ICMP). Stateful filters use the state information to determine if a
packet is responding to an earlier request from an internal node. If the packet is in
response to a request previously made from within the network, the packet is
forwarded to its destination. If a packet originates from an external node, it is
dropped unless a filter rule specifically allows it to be routed to an internal node.
Destination Range Mask Allows you to specify the source destination mask of the packet
to be filtered.
If you enter 255.255.255.255 then the Public IP is a single
address.
If you enter 0.0.0.0 then the Public IP is all possible addresses.
Destination Port Range (#-#)
Allows you to specify a single or range of entries (1-65535) or
the following; ALL, FTP, Telnet, SMTP, SNMP, DNS,
DHCP, TFTP, Gopher, Finger, HTTP, POP, NNTP,
NetBios, RPC,andSUNNFS.
Source Routing Allows you to specify how Source Routing is checked.
Ignore: source routing is not checked.
Allow: packets with source routing are matched.
Deny: packets without source routing are matched.
The default is Ignore.
IP Options Allows you to specify how Source Routing is checked.
Ignore: IP options are not checked.
Allow: packets with IP options are matched.
Deny: packets without IP options are matched.
The default is Ignore.
Quick Allows you to specify the order of rule match. Yes means that
the first rule match is used. No means the last rule match is
used.
Packet Filter Feature Comments
Comentários a estes Manuais