06.03.2015 Views

iPECS SBG-1000 User Manual

iPECS SBG-1000 User Manual

iPECS SBG-1000 User Manual

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>iPECS</strong> <strong>SBG</strong>-<strong>1000</strong> <strong>User</strong> <strong>Manual</strong> (DATA Features)<br />

For more information, refer to Section 5.3.5.<br />

• Priority Select this check box to display a drop-down menu, in which you can select a<br />

priority level assigned to the packets matching the priority rule. For more information, refer to<br />

Section 5.3.3.<br />

• Length Select this check box if you would like to specify the length of packets, or the length<br />

of their data portion.<br />

• Connection Duration Select this check box to apply the filtering rule only on connections<br />

which are open for a certain time period. After selecting the check box, choose whether the<br />

duration of connections matching the rule should be greater or less than the time that you<br />

specify in the adjacent field.<br />

Figure 5.37 Connection Duration<br />

• Connection Size Select this check box to apply the filtering rule only on connections<br />

matching a certain data size limit. This option is best used along with the ‘Connection<br />

Duration’ option, enabling you to fine-tune the filtering mechanism according to your needs.<br />

After selecting the check box, choose whether the connection’s data size should be greater<br />

or less than the number of kilobytes that you specify in the adjacent field.<br />

Figure 5.38 Connection Size<br />

Operation Define what action the rule will take, by selecting one of the following radio buttons:<br />

• Drop Deny access to packets that match the source and destination IP addresses and<br />

service ports defined above.<br />

• Reject Deny access to packets that match the criteria defined, and send an ICMP error or a<br />

TCP reset to the origination peer.<br />

• Accept Connection Allow access to packets that match the criteria defined. The data<br />

transfer session will be handled using Stateful Packet Inspection (SPI), meaning that other<br />

packets matching this rule will be automatically allowed access.<br />

• Accept Packet Allow access to packets that match the criteria defined. The data transfer<br />

session will not be handled using SPI, meaning that other packets matching this rule will not<br />

be automatically allowed access. This can be useful, for example, when creating rules that<br />

allow broadcasting.<br />

Logging Monitor the rule.<br />

56

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!