
Configuring IP Inbound Traffic Filters Using the BCC
308645-14.00 Rev 00
8-5
You cannot specify a precedence value greater than the maximum allowable
number of traffic filters (31 in nonextended mode and 127 in extended mode). For
more information about nonextended and extended traffic filtering modes, see
“Extended and Nonextended Filtering Modes” on page 8-6
.
Filter Criteria and Actions
When you create an IP traffic filter template or an inbound IP traffic filter, you
must apply IP-specific filter criteria and actions.
You can filter IP inbound traffic based on specified bit patterns in one of the
following headers in an IP datagram:
•IP header
• Header of the upper-layer protocol (TCP or UDP)
The BCC provides default filter criteria (predefined criteria) for inbound traffic
filters. Predefined criteria consist of predefined offsets and lengths from common
reference points in the IP header. Table 3-2 on page 3-3 lists the predefined
criteria for IP inbound traffic filters with the reference field, offset, and length of
each criterion.
In addition to the predefined filter criteria, you can also define a criterion for
creating IP inbound traffic filters (user-defined criteria) based on bit patterns in
the packet header. You apply user-defined criteria by specifying an offset and
length to the following reference fields in the IP header. Table 3-7 on page 3-10
lists the user-defined criteria for creating inbound traffic filters.
IP Filtering Actions
The filter action determines what happens to packets that match the filter criteria.
You can configure IP inbound traffic filters to perform the following actions:
• Accept
The router processes any packet that matches the filter criteria.
•Drop
The router does not route any packet that matches the filter criteria.
•Log
Comentários a estes Manuais