User guide

iGuard/inSight User Guide
Release 7.0.0.4
153
8. Verify that the new filter is listed in the window that is launched.
CIDR Classless Inter-Domain Routing notation improves the efficiency of the IPv4 addressing
scheme by allowing routers to interpret addresses as if they were classful. You can use it by
entering the IP address followed by its subnet mask. [IPv6 is not yet supported.]
Add a Port Network Capture Filter
You can create a network capture filter to exclude traffic using a certain port from analysis by the
capture engine.
Suppose you want iGuard to exclude traffic from port 443, which is primarily used for encrypted
data, but because port 443 is also used by AOL America Online, significant data could be lost by
filtering out all traffic using that port.
To retain the AOL traffic while excluding all encrypted data, you could create a multiple capture
filter to routinely save significant data while dropping traffic that would not reveal any useful results.
In this case, you will want to use the "store" capture action first because the "ignore" action
works on whatever traffic is left after the AOL traffic is saved. However, even if you create the
filters in the wrong order initially, you can reprioritize them later.
1. Go to System > System Administration > Capture Filters > Create Network Filter.
2. Add a filter name and description.