
Understanding Version 10.0 Traffic Filters
A-3
Converting Version 5 Combination Filters to Version 10.0 Filters
This section describes how to convert Version 5 combination filters to Version
10.0 filters.
Forwarding Strategy
If your filtering strategy involves forwarding most traffic and dropping only
specified packets, configure filters only for the specific types of traffic you want to
drop.
Firewall Strategy
If your filtering strategy involves blocking most traffic and accepting only
specified packets (a “firewall” strategy), begin with a drop-all filter on the
interface. Add more specific, higher-precedence accept and drop filters to achieve
the desired result on that interface.
The drop-all filter describes the broadest range of packets you need to block from
the interface. From this group of packets, you specify the other, higher-precedence
filters, which create exceptions or “holes” in the drop-all range.
To ensure that all unwanted traffic gets dropped:
1. Choose a field that appears in every packet of the protocol you want to
filter.
2. Determine the length of the field.
3. Determine the maximum possible value of the field.
4. Determine the minimum value of the field.
5. Enter these values when you define the drop-all filter.
Comentários a estes Manuais