System information
Filter Setup for Selected Probe
225
Filtering by Port
Filtering by port is useful in many different troubleshooting and security monitoring
scenarios. The Port Filter rule lets you filter by either source or destination port, or traffic
moving between specific source and destination ports.
Filtering by Protocol Data fields
Observer’s Protocol Data Field filter rule lets you search for specific values in selected
protocol header fields. For example, you can filter for ICMP “destination unreachable”
packets, as well as wireless control, data, and management packets, to name but two. You
can also define your own custom protocol filter, either by port or search pattern.
Choose IP-TCP, IP-UDP, or IPX.
Select a port or range of ports to filter for.
Select what direction you want to filter for. If the “other port”
option is left unchecked, Observer filters for packets to or
from any port to the given port.
By checking the “other port” box, you can specify a second
port, allowing you to filter for traffic between specific source
and destination ports in both directions.
Select one of the pre-defined protocol filters from the
protocol selection tree, or select “User Defined” to
create a custom protocol filter using a Port or Pattern
rule.
Lets you add, edit, or delete user defined protocols.