User manual
8-30 Packet Filter
s
Keywords
This section describes valid keywords you can use for each
protocol section
IP and IP-CALL Sections
Keyword Description Operators Value
src-addr
source IP address eq/ne ddd.ddd.ddd.ddd/mask
dst-addr
destination IP address eq/ne ddd.ddd.ddd.ddd/mask
tcp-src-port
TCP source port # all 1-65536
tcp-dst-addr
TCP destination port # all 1-65536
tcp-one-way
Limit TCP traffic to one
way
eq/ne 1-65536
udp-src-port
UDP source port # all 1-65536
udp-dst-addr
UDP destination port # all 1-65536
protocol
protocol-specific field eq/ne udp, tcp, icmp
generic
field based on offset,
length, mask, value
generic generic
IPX and IPX-CALL Sections
Keyword Description Operators Value
src-net
source network address eq/ne as xx-xx-xx-xx
dst-net
destination network
address
eq/ne as xx-xx-xx-xx
src-host
source host address eq/ne as xx-xx-xx-xx-xx-xx
dst-host
destination host address eq/ne as xx-xx-xx-xx-xx-xx
src-socket
source socket number all 1-ffff in form 0Xxxxx
dst-socket
destination socket
number
all 1-ffff in form 0Xxxxx
generic
field based on offset,
length, mask, value
generic generic
IP-RIP Section
Keyword Description Operators Value
network
IP network address eq/ne ddd.ddd.ddd.ddd/mask
IPX-RIP Section
Keyword Description Operators Value
network
network address eq/ne as xx-xx-xx-xx