
640 Chapter 67 Configuring IP Filter Rules
N0060606N0060606
Table 157 Add Outbound Filter Rule (Sheet 1 of 4)
Attribute Value Description
General
Seq. No. <numeric> Set the rule order.
In the “Add” window, you can choose the position of the rule by
providing the sequence number value. The new rule will be inserted
at the position determined by the sequence number, and the
previous rules will be shifted accordingly.
In the “Modify” window, the user can change the sequence number.
The rule will be moved at the position determined by the sequence
number, and the previous rules will be shifted accordingly.
Rule Name Specify a name for the rule. The maximum length is 15 characters.
This field is optional and can be left empty.
The same rule name can be repeated under the same interface.
Enable <check box> Determine if a rule is active in the list of rules.
Default: selected.
Stateful <check box> Specify if the states of connections that match this rule will be
monitored. This permits the creation of one-way rules. For example,
you can permit inside traffic to return but block traffic originating
from the outside.
Note: Be aware of the limitation of stateful sessions with VoIP
DSCP marking rules. For VoIP DSCP marking to work, the user can
either configure an outbound filter rule (stateful or not) with
disposition to “mark” or create an inbound stateful filter rule with
disposition to “mark”. A disposition of “mark” allows the inbound
packet to pass but does not mark it.
Default: selected.
Use first match <check box> Specify if the first rule match is used.
If cleared, the last rule match is used.
If multiple rules match, either the first rule with this check box
selected is used, or the last rule that matches in the list of available
matching rules is used if all check boxes are cleared, there is no
concept of more specific matches or less specific matches other
than being determined by the order of the rule in the list of rules.
The lowest sequence number is looked up first.
Default: Selected.
Filter Action
Disposition Block
Pass
Mark
Specify if a packet that matches this rule is blocked, passes
through, or is DSCP marked and passes through.
A value of Mark means that the outbound packet is DSCP marked
then passes through. This value is allowed for outbound rules
(stateful or not) and for stateful inbound rules. A disposition of
“mark” allows the inbound packet to pass but does not mark it.
Default: Block.
Commentaires sur ces manuels