User`s guide

BLACK BOX® CS Installation, Administration, and User’s Guide 15
Packet Filtering on CS
Add Rule and Edit Rule Options
When you add or edit a rule you can define any of the options described in the
following table.
You can flag any of the above elements with inverted so that the target action
is performed on packets that do not match any of the criteria specified in that
line. For example, if you select DROP as the target action, specify “Inverted”
for a source IP address, and do not specify any other criteria in the rule, any
Table 1-3: Filter Options for Packet Filtering Rules
Filter Options Description
Source IP and Mask
Destination IP and Mask
If you specify a source IP, incoming packets are filtered for
the specified IP address. If you specify a destination IP,
outgoing packets are filtered for the specified IP address.
If you fill in a source or destination mask, incoming or
outgoing packets are filtered for IP addresses from the
subnetwork in the specified netmask.
Protocol
You can select a protocol for filtering from one of the
following options:
•ALL
Numeric Protocol Options
TCP Protocol Options
UDP Protocol Options
ICMP Protocol Options
Input Interface
The input interface (ethN) used by the incoming packet.
Output Interface
The output interface (ethN) used by the outgoing packet.
Fragments
The types of packets to be filtered:
All packets
2nd, 3rd... fragmented packets
Non-fragmented and 1st fragmented packets