Field
|
Description
|
Action
|
If it is set to deny, all frames matching this filter will be discarded and
scanning of the remainder of the filter list will be aborted. If it is set to
permit, all frames matching this filter will be allowed for further
bridging or routing processing.
|
Protocol
|
This filter protocol value matches the Internet Protocol Number in the
frames. These IP numbers are defined in the Network Working Group
Request for Comments (RFC) documents. Setting this to '-1' will make
the filtering match any IP number.
|
Address
|
The source IP address to be matched for this filter. A value of 0 causes
all source address to match.
|
Mask
|
This is the wildcard mask for the SrcAddress bits that must match. 0 bits
in the mask indicate the corresponding bits in the SrcAddress must
match in order for the matching to be successful, and 1 bits are don't care
bits in the matching. A value of 0 causes only IP frames of source
address the same as SrcAddress to match.
|
PortLow
|
If Protocol is UDP or TCP, this is the inclusive lower bound of the
transport-layer source port range that is to be matched, otherwise it is
ignored during matching. This value must be equal to or less than the
value specified for this entry in SrcPortHigh.
|
PortHigh
|
If Protocol is UDP or TCP, this is the inclusive upper bound of the
transport-layer source port range that is to be matched, otherwise it is
ignored during matching. This value must be equal to or greater than the
value specified for this entry in SrcPortLow. If this value is '0', the UDP
or TCP port number is ignored during matching.
|
Address
|
The destination IP address to be matched for this filter. A value of 0
causes all source address to match.
|
Mask
|
This is the wildcard mask for the DestAddress bits that must match. 0
bits in the mask indicate the corresponding bits in the DestAddress must
match in order for the matching to be successful, and 1 bits are don't care
bits in the matching. A value of 0 causes only IP frames of source
address the same as SrcAddress to match.
|
PortLow
|
If Protocol is UDP or TCP, this is the inclusive lower bound of the
transport-layer destination port range that is to be matched, otherwise it
is ignored during matching. This value must be equal to or less than the
value specified for this entry in PortHigh.
|
PortHigh
|
If Protocol is UDP or TCP, this is the inclusive upper bound of the
transport-layer destination port range that is to be matched, otherwise it
is ignored during matching. This value must be equal to or greater than
the value specified for this entry in DestPortLow. If this value is '0', the
UDP or TCP port number is ignored during matching.
|
Precedence
|
The IP traffic precedence parameters in each frame are used to guide the
selection of the actual service parameters when transmitting a datagram
through a particular network. Most network treats high precedence
traffic as more important than other traffic. The IP Precedence value
ranges from '0' to '7', with '7' the highest precedence and '0' the lowest
precedence. The value '-1' means to match frames of any IP precedence.
In other words, the IP precedence parameter will not to checked if this
value is '-1'. The precedence level are:
- routine(0) - Routine traffic precedence
- priority(1) - Priority traffic precedence
- immediate(2) - Immediate traffic precedence
- flash(3) - Flash traffic precedence
- flashOverride(4) - Flash-override traffic precedence
- critical(5) - Critical precedence
- internet(6) - Internetwork control traffic precedence
- network(7) - Network control traffic precedence.
|
TOS
|
The Type of Service (TOS) of the frame. The TOS values ranges from
'0' to '15'. The value '-1' matches any TOS value.
|
ICMPType
|
This filter specifies the ICMP message type to be matched. Setting this
value to '-1' will make the filtering match any ICMP message type.
|
ICMPCode
|
This filter specifies the ICMP message code to be matched. Setting this
value to '-1' will make the filtering match any ICMP code.
|
TCPEstablished
|
This filter if true specifies that for TCP protocol, in an established
connection, a match occurs if the TCP datagram has the
ACK,FIN,PSH,RST,SYN or URG control bits set. If false, a match will
occur for any TCP datagram.
|
LogEnabled
|
Specifies whether filtered frames will be logged by the filtering
subsystem or not. If true, then all frames will be logged. If false, then no
frame will be logged.
|