User guide

Table Of Contents
SET UP
UMTS GPRS EDGE router ref. RAS-3G User guide ref. 9020009-01 Page 69
The cautious default policy is to choose the value “Drop”; at the opposite, if the value “Accept” is
selected, a frame which does not match any of the rules of the filter is transmitted.
Step 2 : Add a rule to the filter
Click the “add a rule” button.
“Direction” parameter
:
Select the direction of the data flow to which the rule applies.
“Action” parameter
:
Select the value “Accept” if the IP packet has to be transmitted in the selected direction.
Select the value “Drop” if the IP packet has to be rejected.
“Protocol” parameter
:
Select the level 3 protocol concerned.
“Source IP address”
& “Source port” parameters :
Enter the value of the source IP address and the source port number.
It is possible to enter a range of source IP addresses and not a single IP address by selecting a
netmask value from 1 to 32; It is the number of binary 1 of the netmask; for instance, the value 24
means 255.255.255.0; the value 16 means 255.255.0.0.
”Destination IP address”
& “destination port” parameters :
Enter the value of the destination IP address and the destination port number. Select the netmask
value.
20.3 Remote users filters
A remote user filter applies to the IP packets received inside a remote user connection.
25 remote user filters can be configured and assigned individually to each of the users declared in the
user list.
A remote user filter is a table of destination port numbers and IP addresses belonging to the LAN
network.
Once a remote user is connected to the RAS-3G router, the router applies the filter assigned to him
(see the remote user form).
According to his identity (Login and password, he will thus only access to the IP domain defined by the
filter.
Example :
Filter name : Access to the device PLC1 (html and modbus)
Filter policy : All is forbidden except what we specify
Rules list
Action Device Service
Allow PLC1 192.168.0.12 80
Allow PLC1 192.168.0.12 Modbus 502
A filter must be assigned at least to one user to become enabled.