11.07.2015 Views

PDF user manual for CopperEdge 150

PDF user manual for CopperEdge 150

PDF user manual for CopperEdge 150

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Every source of IP packets can be identified by its PII. Each DSLport, network port, and every virtual circuit aggregated into ahigh-speed digital facility can be referenced by its PII. Each PIIcan be configured with a separate, independent set of IP filters.Each filter, in turn, consists of a specific set of criteria againstwhich incoming packets are compared. If the incoming packetmatches the criteria specified by the filter, the packet is subjectedto the action (Pass, Block, or Chain) specified by that filter.When a packet arrives, it is checked against the filters in thelist, in order. The first filter which matches the packet determineswhich action will be taken. An action code is also programmedinto the filter, defining whether the matched packetwill be passed or blocked, or if the filter will simply be combinedwith another (chained) to further specify the applicable range ofpacket values.For maximum security, a packet which matches no filters is automaticallyblocked. However, an interface <strong>for</strong> which no filtershave been configured passes all packets.1 2 7 (Since IP packets can also be addressed to the CE<strong>150</strong> itself, systemsecurity may be enhanced by establishing a list of filters applicable tothe CE<strong>150</strong>. To configure filters that apply to the overall system, usethe CE<strong>150</strong>’s “virtual PII”: 1.0.0.0. As a further security measure, andto counteract an inherent vulnerability in Internet-compliant systems,the cmFilter table <strong>for</strong> the CE<strong>150</strong> includes a static filter that willimmediately discard any ICMP Redirect messages destined <strong>for</strong> theCE<strong>150</strong>.9LHZLQJ)LOWHUVAs we have seen, each interface can have its own set of filters.In certain cases, this list could be a long one. If you are usingCopperView EMS to control the CE<strong>150</strong>, then you can displaythe entire contents of the filter table. Otherwise, you can retrievethem in batches using the Getall command:CRAFT> getall cmfilter [1.4.7]To view filters singly, begin by retrieving the first filter in thelist:CRAFT> get cmfilter [1.4.7, 1]Then, to view succeeding filters <strong>for</strong> the same interface, simplyuse the Getnext command:CRAFT> getnext cmfilter&RSSHU(GJH,QVWDOODWLRQDQG2SHUDWLQJ*XLGH

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!